WASHINGTON—NAFCU and CUNA are expressing concern over a new report that reveals 80% of global retailers fail to meet the widely accepted Payment Card Industry (PCI) data security standards for their payment card processing systems.
The Verizon 2015 Payment Card Industry Compliance Report, which surveyed 5,000 global merchant companies and financial institutions, stated that “four out of five companies are still failing" in compliance.
The survey explained that the “volume and scale of data breaches in the last 12 months make it clear that current techniques are not stopping attackers—in many cases they are not even slowing them down."
The report explained that the standard, PCI DSS assessment can uncover important security gaps that should be fixed but "is not a guarantee that your customer's data and your reputation are safe. Of all the data breaches that our forensics team has investigated for the last 10 years, not a single company has been found compliant at the time of the breach.”
NAFCU Vice President of Legislative Affairs Brad Thaler sent a letter to leaders of the House and Senate to review the report, copying all members of Congress.
"This should cause serious pause among lawmakers as failing to meet these standards, exacerbated by the lack of a strong federal data safekeeping standard, leaves merchants, and therefore consumers, more vulnerable to breaches," wrote Thaler.
Thaler also noted the report's finding that EMV cards in other countries has not been a silver bullet solution to preventing fraudulent activity; it merely displaces it.
"The report shows that once EMV use increases, criminals shift their focus to card-not-present transactions, such as online shopping," said Thaler. "NAFCU has long argued that any technology standards must be accompanied by strong data safekeeping standards for merchants akin to what credit unions comply with under the Gramm-Leach-Bliley Act."
Thaler urged Congress to come together in a “bipartisan way and put forward legislative recommendations to hold retailers to the same strict standards of cybersecurity and data security that financial institutions must already adhere to.”
NAFCU recommended that legislation address:
- Payment of breach costs by breached entities
- National standards for safekeeping information
- Data security policy disclosure
- Notification of the account servicer
- Disclosure of breached entity
- Enforcement of prohibition on data retention
- Burden of proof in data breach cases
Following the Verizon findings, CUNA President and CEO Jim Nussle released a statement saying, “We're 15 months from the Target breach yet credit unions have received nothing in terms of reimbursement. The same goes for the Home Depot breach. The merchants responsible for the largest breaches over the last two years have paid absolutely nothing while credit unions have had to pony up at least $90 million to cover the costs for merchant data breaches.”
Nussle then stated that as retailers play “shell games over merchant data breaches,” the Verizon report indicates that the massive data breach issue “is a problem sure to repeat itself. The retailers are using a nuance in talking points to distract from the real problem: retailers are not protecting consumers' data, face no legal requirement to do so and get to watch as others fix the problems they create . . . Consumers will benefit if the retailers would start following the industry security standards and support a strong federal data protection law that codifies a requirement that those who accept cards for payment follow the same standard as those who issue cards for payment.”
