PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Cutting the Risk and Cost Associated with PCI Compliance with Blockchain Technology

By Doug Wick
August 27, 2019
in Blockchain, Digital Assets & Crypto, Industry Opinions
0
10
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Cutting the Risk and Cost Associated with PCI Compliance with Blockchain Technology

Cutting the Risk and Cost Associated with PCI Compliance with Blockchain Technology

Merchants and issuers across the payments space are working to reduce both the amount of PCI-sensitive data they store and the number of systems that touch that data, but this can be difficult across disparate and legacy systems. Could blockchain’s distributed ledger architecture be the solution?

PCI compliance is the payment security standard that applies to every entity that processes, stores, or transmits credit card information. Designed to ensure the security of transactions and protect cardholders against fraud and misuse of their personal information, the standards were defined and are maintained by the PCI Security Standards Council, whose founding members include American Express, Discover Financial Services, JCB International, MasterCard, and Visa.

A significant development occurred earlier this year when PCI compliance was achieved by the first and only blockchain-based data security platform. Built on a patent-issued private blockchain model, ALTR is unique in the way it enforces data governance policy, protects stored data from forced access, and provides detailed intelligence about an organization’s data-access needs and habits.

As data breaches continue to threaten brands, reputations and bottom lines, PCI compliance is an indicator that enterprise data security leveraging distributed ledger architecture is no longer just a concept, but is now in the hands of business.

While the norm has been to encrypt transactions and cardholder data against fraud, this new approach takes that data, tokenizes it to render it illegible, and then splits it into fragments that are randomly spread across separate server nodes. It goes against conventional cybersecurity thinking, but with breaches now commonplace this is exactly what is needed to protect cardholder data.

Blockchain reinvented for a higher purpose 

The hype around cryptocurrency has cooled considerably of late, while there is a growing interest in adapting the underlying blockchain technology that powers the exchange of coins for higher purpose in the enterprise. Healthcare, banking and financial services, insurance and even food safety are now areas where the technology is taking on a new life. Leveraging its inbuilt consensus mechanisms to treat sensitive data like money: monitor its usage, govern access to it, and protect it by obscuring it.

The big problem this type of technology solves is to take something digital and preserve it by using an uneditable data structure. Consider that a Bitcoin cannot be copied and spent more than once without changing hands. If you refine blockchain to create private in-house blockchains that operate on a low-latency SaaS model, it quickly becomes clear that the applications extend outward nearly without limit.

Blockchain offers benefits beyond being incredibly secure. Many hacks involve, not just the theft of data, but the changing of the data. Also, blockchain structures offer high availability and resiliency by design, because of their replicated nature. What other types of data could be preserved digitally now in an authentic form ensured by blockchain? Identity data? Ownership data? Intellectual Property? News Content and Images? Voting Records?

Protecting these types of data means more than simply stopping unauthorized access. Insider threats are often a far greater concern, whether a result of deliberate misbehavior or accidental mishandling of information, a distributed nature means data is scattered and useless. Moreover, it also lends itself to documenting evidence of all activity in an unalterable log.

Consider also that the central problem around data usage and storage the question of ‘trust’. It’s not just about keeping the data from being stolen, it’s also about maintaining its integrity. A data security platform that uses a private, permissioned blockchain’s tamper-resistant structure to store all audit records of data access, as well as the data itself, appears well placed to counter those threats.

The unique combination of these characteristics also creates a data infrastructure which increases the resiliency of an organization’s systems and processes. Existing solutions like encryption and tokenization are fragile in that there are keys to steal, and they exact a high cost on the performance and usability of data when they are implemented widely in an enterprise, which is why companies remain reluctant to employ such measures.

A pragmatic use case

While the core technology is crucial, how you bring it out of the lab and into the hands of commerce in a pragmatic way is a crucial hurdle. The challenge writ large is to not simply apply it to a real, tangible problem — that is data security for payments, cards and services — but also to invest in ways for an enterprise to adopt it without having to throw out the systems they already use. Here we can take a cue from the financial sphere, where all the risk checks against the flow of money are embedded in the critical path between the people who want the asset and the asset itself.

Data security itself, under the enterprise blockchain model that recently received PCI certification, is embedded in the actual code base, in the critical path of information through a thin layer of technology wrapped around database drivers, which all applications use to connect to their databases. The platform can act as a data broker – monitoring all data access, governing what types of access are permissible, and even redirecting requests for data to distributed storage when the necessary files have been deposited there. Remarkably, the platform does not replace any existing infrastructure, and in fact its impact is potentially so low that end users are unlikely to even realize it’s there. This new way of implementing data security is “programmable.”

In fact, blockchain and distributed ledger technology offers three central tenets, that are essential components for PCI DSS compliance. The first is that in order to protect data, you need a really good vault. This is described as “at rest” protection for data as it sits in a database, in cybersecurity parlance. The second is you need a valve – that is, a way to slow down or stop the flow of data to applications in real time. Finally, you need a view. This means shared visibility, from the c-suite all the way through to IT, on which individuals are consuming data and why. This view has to be trusted, in that it has to be audited and tamper-proof.

A vault, a valve, and a view – the combination is new paradigm on protecting data, and reduces risk to data significantly, in many cases down to near zero. And here is where blockchain, reengineered for private, permissioned enterprise applications in data security, brings its greatest value for those who want the assurance that comes with PCI compliance. Distributed ledger approaches are now forcing businesses, particularly those in banking and financial services, so that risk to data can be either be slowed down or stopped.

About Doug Wick
Doug leads product and marketing at ALTR. With over 20 years of startup experience, he has broad experience managing product conception and development through to market success. His last role was as CEO of TradeLive, a startup marketplace for IT equipment, with previous executive roles leading product management, sales, and marketing. He is an alumnus of The University of Oklahoma and The University of Chicago Booth School of Business.   

About ALTR
ALTR is the first software company to unleash the cybersecurity benefits of blockchain for the enterprise. The ALTR platform, based on ALTR’s proprietary ALTRchain technology, restores digital trust to organizations by fundamentally changing the way valuable data is monitored, accessed and stored. It is simple to deploy and easy for both technical and non-technical business stakeholders to use, providing them with an intrinsic view and control over the inner data-environment of an organization including how sensitive data assets are used or seen and by whom. The company, which holds 17 issued patents and has dozens more pending, is based in Austin.

10
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: BlockchainPCI Compliance

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    metal cards

    Leveraging Metal Cards to Attract High-Value Customers

    December 9, 2025
    fraud as a service

    Keeping Up with the Most Dangerous Fraud Trends of 2026

    December 8, 2025
    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025
    metal cards

    Metal Card Magnitude: How a Premium Touch Can Enthrall High-Value Customers

    December 2, 2025
    digital gift cards

    How Nonprofits Can Leverage Digital Gift Cards to Help Those in Need

    December 1, 2025
    stored-value prepaid

    How Stored-Value Accounts Are the Next Iteration of Prepaid Payments

    November 26, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result