PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Trustwave Study Says 90 Percent of Card Data Breaches at Small Merchants

By Mercator Advisory Group
May 24, 2011
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
PCI vendor Trustwave has published the results of recent research in a report called Payment Card Trends and Risks for Small Merchants. Their findings indicate that nine out of 10 incidents of secure card data being breached occur at Level 4 merchants – those that process less than 20,000 ecommerce transactions or less than 1 million aggregate transactions annually. Point-of-sale software was the most often breached system type, being the compromise point in about 75 percent of breach incidents. Infosecurity has the story:

Trustwave said that small merchants have been slow to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS). “The big constraints [on small merchants] are time and money”, said Greg Rosenberg, qualified security assessor at Trustwave.

One of the findings that surprised Rosenberg in the study was the relatively short amount of time it takes for merchants to achieve their initial PCI DSS compliance. “About 82% of all of the merchants we dealt with…were able to complete PCI DSS compliance in under 12 hours”, he told Infosecurity.

Another finding that stood out for Rosenberg was that areas where small merchants are often deficient in terms of PCI DSS compliance are not expensive to fix. “These were things like having proper policies and procedures in place and security awareness training; these are low cost items that can be relatively easy to institute”, he said.

Smaller merchants tend to rely on their acquirer or independent sales organization (ISO) to initiate PCI DSS compliance validation. Without directive or enforcement of such initiatives, many will forgo basic steps to protect their networks and their customers’ cardholder data because they feel they do not have the time or the proper resources, or they’re just not aware of the requirement, the survey found.

These institutions, often referred to as the program sponsors, help enforce compliance, mitigate risk and in turn, provide a security benefit for the merchant, as well as the greater population by helping to combat data security threats.

The report, which was a supplement to Trustwave’s 2011 Global Security Report, also found that two groups – food and beverage and retail – made up 75% of all credit card breaches. Of those breaches, 85% affected small merchants.

“Food service tends to lead the pack [in data breaches]. The first challenge for them is that they are using broadband connectivity. They are not using the traditional stand-alone terminals….With the additional network complexity obviously comes the opportunity for someone half way across the world to reach into their network and exploit vulnerabilities that haven’t been addressed”, Rosenberg observed.

The food and beverage industry accounts for a large portion of merchant portfolios as well. So there is a direct correlation that leads these businesses to be more highly weighted in the survey”, he said. “There tends to be high turnover, and they are a fast-paced industry”, he added.

Other key findings in the report showed that merchants that fail to validate compliance with the PCI DSS fail at six of the 12 requirements more than 90% of the time. These statistics provide further evidence that ISOs and acquirers should implement compliance programs to help secure their merchant population, the survey said.

Click here to read more.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Merchant Acquiring

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    cross-border tokenized deposits

    Ant International and HSBC Pilot Cross-Border Tokenized Deposit Transfers on Swift

    December 12, 2025
    Fiserv stablecoin

    Three Small Business Trends That Banks Can Hop On in 2026

    December 11, 2025
    echeck

    Beyond Paper: Why More Businesses Are Turning to eChecks

    December 10, 2025
    metal cards

    Leveraging Metal Cards to Attract High-Value Customers

    December 9, 2025
    fraud as a service

    Keeping Up with the Most Dangerous Fraud Trends of 2026

    December 8, 2025
    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result