PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Trustwave Study Says 90 Percent of Card Data Breaches at Small Merchants

By Mercator Advisory Group
May 24, 2011
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
PCI vendor Trustwave has published the results of recent research in a report called Payment Card Trends and Risks for Small Merchants. Their findings indicate that nine out of 10 incidents of secure card data being breached occur at Level 4 merchants – those that process less than 20,000 ecommerce transactions or less than 1 million aggregate transactions annually. Point-of-sale software was the most often breached system type, being the compromise point in about 75 percent of breach incidents. Infosecurity has the story:

Trustwave said that small merchants have been slow to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS). “The big constraints [on small merchants] are time and money”, said Greg Rosenberg, qualified security assessor at Trustwave.

One of the findings that surprised Rosenberg in the study was the relatively short amount of time it takes for merchants to achieve their initial PCI DSS compliance. “About 82% of all of the merchants we dealt with…were able to complete PCI DSS compliance in under 12 hours”, he told Infosecurity.

Another finding that stood out for Rosenberg was that areas where small merchants are often deficient in terms of PCI DSS compliance are not expensive to fix. “These were things like having proper policies and procedures in place and security awareness training; these are low cost items that can be relatively easy to institute”, he said.

Smaller merchants tend to rely on their acquirer or independent sales organization (ISO) to initiate PCI DSS compliance validation. Without directive or enforcement of such initiatives, many will forgo basic steps to protect their networks and their customers’ cardholder data because they feel they do not have the time or the proper resources, or they’re just not aware of the requirement, the survey found.

These institutions, often referred to as the program sponsors, help enforce compliance, mitigate risk and in turn, provide a security benefit for the merchant, as well as the greater population by helping to combat data security threats.

The report, which was a supplement to Trustwave’s 2011 Global Security Report, also found that two groups – food and beverage and retail – made up 75% of all credit card breaches. Of those breaches, 85% affected small merchants.

“Food service tends to lead the pack [in data breaches]. The first challenge for them is that they are using broadband connectivity. They are not using the traditional stand-alone terminals….With the additional network complexity obviously comes the opportunity for someone half way across the world to reach into their network and exploit vulnerabilities that haven’t been addressed”, Rosenberg observed.

The food and beverage industry accounts for a large portion of merchant portfolios as well. So there is a direct correlation that leads these businesses to be more highly weighted in the survey”, he said. “There tends to be high turnover, and they are a fast-paced industry”, he added.

Other key findings in the report showed that merchants that fail to validate compliance with the PCI DSS fail at six of the 12 requirements more than 90% of the time. These statistics provide further evidence that ISOs and acquirers should implement compliance programs to help secure their merchant population, the survey said.

Click here to read more.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Merchant Acquiring

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    ai financial

    Consumers Are Putting More Financial Decisions in AI’s Hands

    April 17, 2026
    cybersecurity frontier ai

    Cybersecurity Must Evolve as Frontier AI Fuels New Fraud Risks

    April 16, 2026
    isos thriving

    In Defiance of the Prognosticators, ISOs Are Thriving Again

    April 15, 2026
    agentic payments

    Beyond the Click: How Agentic Payments Are Redefining Global Financial Flow

    April 14, 2026
    instant payments fraud

    Instant, Irrevocable Payments Demand a Fraud Prevention Reboot

    April 13, 2026
    samsung p2p

    Making Zelle Work Better for Users—and Banks

    April 10, 2026
    fraud escalate

    As Fraud Escalates, Taking a Beat Becomes a Critical Defense

    April 9, 2026
    privacy open banking

    As Open Banking Fuels Interconnectivity, Privacy Matters More

    April 8, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result