Study Finds Unencrypted Payment Data on Business Networks Remains at 70%
OREM, Utah, Nov. 28, 2012 /PRNewswire/ — SecurityMetrics, a leading provider of payment data security and compliance solutions, today published its second annual Payment Card Threat Report revealing unencrypted PAN (Primary Account Number) storage remains alarmingly high. Virtually no change occurred between 2011 and 2012, with card data storage on corporate systems declining less than one quarter of a percent (.24%). The study exposed that greater than 10% of merchants store magnetic stripe track data, essential for the illegal reproduction of credit and debit cards. Financial, hospitality, and retail industries accounted for 55% of the total unencrypted payment card data storage among businesses tested.
“Hackers proactively search for unencrypted card data because it takes less effort to steal,” said Director of Security Assessment, Gary Glover. “Whether a business stores unencrypted card data because of an improperly configured payment application, or because employees handle data improperly, storing card data without encryption is against industry regulation.”
Businesses that store unencrypted payment card data directly violate Payment Card Industry Data Security Standard (PCI DSS) requirements and are more likely to be exploited and suffer severe financial repercussions. Credit card fraud costs U.S. establishments $52.6 billion per year(1), and unencrypted card data storage financially plagues both businesses and consumers when discovered by criminals.
SecurityMetrics releases its annual study to encourage businesses to realize the unknown danger of unencrypted card data storage and the devastating fines that follow. Core to the study was PANscan, a card discovery tool that searches for unencrypted track 1, track 2 and PAN data on networks. To view the report, or download PANscan to determine if your business is storing data, visit https://www.securitymetrics.com/sm/pub/panscan/resources.
About SecurityMetrics (www.securitymetrics.com)
SecurityMetrics assists in protecting electronic commerce and payments leaders, global acquirers, and their retail customers from security breaches and data theft. The company is a leading provider and innovator in merchant data security and compliance, and as an Approved Scanning Vendor and Qualified Security Assessor, has helped over 1 million organizations manage PCI DSS compliance and/or secure their network infrastructure, data communication, and other information assets. Founded in October 2000, SecurityMetrics is a privately held company headquartered in Orem, Utah, USA.
1. U.S. Federal Reserve, March 2011