<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI Talk is Cheap: Even Small Merchants Can Afford It</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: FedupwithPCI</title>
		<link>http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/comment-page-1/#comment-64041</link>
		<dc:creator>FedupwithPCI</dc:creator>
		<pubDate>Mon, 12 Oct 2009 16:55:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3510#comment-64041</guid>
		<description>Rubbish,
The entire drive to PCI compliance is more driven by PCI committee members greed (many of which are involved in the network scanning and on-site consulting review business) than it has anything to do with any real steps toward reforming the overall card processing industry.  Small businesses, like a martial arts school or a bicycle repair shop that just happen to process credit card transactions over an Internet connection are the least of the Industry&#039;s problems.  Hackers simply are not interested in spending a few days setting up to crack into a small merchant&#039;s computer on the hopes of intercepting 50 - 100 credit card transactions a month.  It just is NOT going to happen.  They want the middle to large tier processors where they can be assured of a quantity of data to either resell or use directly.

What is happening is that small businesses, like the ones I mentioned above, are helping fund hundreds of new PCI compliance businesses with plenty of cash from unnecessary quarterly network scans.  It simply results in wasted time from paperwork and trying to understand an industry that is not their core business.  PCI DSS at this level, as currently implemented, does little to nothing to provide any more security to the card industry in general.

I am not bemoaning security standards or best-practices for keeping customer card data safe.  I am just pointing out that it is the small businesses that are the absolute least contributors to the overall card industry losses that are paying the biggest price when tallied up.  When I approach a new customer interested in accepting credit card payment and mention they will need to tag another $100 - $200 a year for quarterly network scans of their PC that they process credit cards on, in addition to any costs in time and software to GET compliant, they will likely tell me to go jump in a lake.

In the old days, the hard sell for a merchant account was always an argument of &quot;will you waive the $50 set-up fee, we really can&#039;t afford that as a small business.&quot;  Now I have to add these fees into the sales process.  All these additional costs for small businesses via PCI DSS are an absolute death knell for anyone trying to sell these services to small businesses or for small businesses themselves.

If the PCI DSS committee members had focused their energies more on the card processors, gateway providers, and the myriad other middle to top tier providers, developed new standards for secure data transmissions, network compliance, etc., I would venture that some 25% - 75% improvement on losses could be seen by the industry in the next 5 years.  Then, they could focus on education services for the small business owners and offer free (yes free) network scans and advice on making a merchant&#039;s data safer for their own peace-of-mind and for the entire industry.

Let us not forgot the forest for the trees.  The small mom-and-pop merchant is not the one making money to accepting credit cards.  Indeed the merchant gives away between 2% and 5% of every transaction to Visa/MC/AMEX, etc. on each transaction.  Yet it is the merchant having to pay even more to assure that those profits keep flowing to the big providers and their middle-man partners.</description>
		<content:encoded><![CDATA[<p>Rubbish,<br />
The entire drive to PCI compliance is more driven by PCI committee members greed (many of which are involved in the network scanning and on-site consulting review business) than it has anything to do with any real steps toward reforming the overall card processing industry.  Small businesses, like a martial arts school or a bicycle repair shop that just happen to process credit card transactions over an Internet connection are the least of the Industry&#8217;s problems.  Hackers simply are not interested in spending a few days setting up to crack into a small merchant&#8217;s computer on the hopes of intercepting 50 &#8211; 100 credit card transactions a month.  It just is NOT going to happen.  They want the middle to large tier processors where they can be assured of a quantity of data to either resell or use directly.</p>
<p>What is happening is that small businesses, like the ones I mentioned above, are helping fund hundreds of new PCI compliance businesses with plenty of cash from unnecessary quarterly network scans.  It simply results in wasted time from paperwork and trying to understand an industry that is not their core business.  PCI DSS at this level, as currently implemented, does little to nothing to provide any more security to the card industry in general.</p>
<p>I am not bemoaning security standards or best-practices for keeping customer card data safe.  I am just pointing out that it is the small businesses that are the absolute least contributors to the overall card industry losses that are paying the biggest price when tallied up.  When I approach a new customer interested in accepting credit card payment and mention they will need to tag another $100 &#8211; $200 a year for quarterly network scans of their PC that they process credit cards on, in addition to any costs in time and software to GET compliant, they will likely tell me to go jump in a lake.</p>
<p>In the old days, the hard sell for a merchant account was always an argument of &#8220;will you waive the $50 set-up fee, we really can&#8217;t afford that as a small business.&#8221;  Now I have to add these fees into the sales process.  All these additional costs for small businesses via PCI DSS are an absolute death knell for anyone trying to sell these services to small businesses or for small businesses themselves.</p>
<p>If the PCI DSS committee members had focused their energies more on the card processors, gateway providers, and the myriad other middle to top tier providers, developed new standards for secure data transmissions, network compliance, etc., I would venture that some 25% &#8211; 75% improvement on losses could be seen by the industry in the next 5 years.  Then, they could focus on education services for the small business owners and offer free (yes free) network scans and advice on making a merchant&#8217;s data safer for their own peace-of-mind and for the entire industry.</p>
<p>Let us not forgot the forest for the trees.  The small mom-and-pop merchant is not the one making money to accepting credit cards.  Indeed the merchant gives away between 2% and 5% of every transaction to Visa/MC/AMEX, etc. on each transaction.  Yet it is the merchant having to pay even more to assure that those profits keep flowing to the big providers and their middle-man partners.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zsavonne</title>
		<link>http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/comment-page-1/#comment-63288</link>
		<dc:creator>Zsavonne</dc:creator>
		<pubDate>Wed, 19 Aug 2009 00:19:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3510#comment-63288</guid>
		<description>David you bring up some great points. Small businesses are targets for credit card hackers. In fact, a recent Visa review of fraud cases found that small businesses account for the vast majority of credit and debit card data breaches. </description>
		<content:encoded><![CDATA[<p>David you bring up some great points. Small businesses are targets for credit card hackers. In fact, a recent Visa review of fraud cases found that small businesses account for the vast majority of credit and debit card data breaches.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Taylor</title>
		<link>http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/comment-page-1/#comment-63098</link>
		<dc:creator>Dave Taylor</dc:creator>
		<pubDate>Thu, 13 Aug 2009 21:31:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3510#comment-63098</guid>
		<description>Hi, Bryan,
Good point.  I really ought to write more about the use of service providers &amp; outsourcing.  It keeps coming up in our interviews with merchants.  If you or anyone else reading this has suggestions for an &quot;angle&quot; for the piece, let me know.  Remember, Evan always wants the topic to have a fresh approach. So, suggestions anyone?
thx, Dave T.</description>
		<content:encoded><![CDATA[<p>Hi, Bryan,<br />
Good point.  I really ought to write more about the use of service providers &amp; outsourcing.  It keeps coming up in our interviews with merchants.  If you or anyone else reading this has suggestions for an &#8220;angle&#8221; for the piece, let me know.  Remember, Evan always wants the topic to have a fresh approach. So, suggestions anyone?<br />
thx, Dave T.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan Johnson</title>
		<link>http://storefrontbacktalk.com/securityfraud/pci-talk-is-cheap-even-small-merchants-can-afford-it/comment-page-1/#comment-63093</link>
		<dc:creator>Bryan Johnson</dc:creator>
		<pubDate>Thu, 13 Aug 2009 20:27:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=3510#comment-63093</guid>
		<description>I agree with you David. Opinion does not always translate into action when it comes to merchants taking the necessary steps to achieve compliance and secure credit card data. At the same time, I think that service providers in the payment processing industry are getting much better at developing solutions that lessen PCI Compliance scope and secure sensitive data for merchants - which will help move things along faster. </description>
		<content:encoded><![CDATA[<p>I agree with you David. Opinion does not always translate into action when it comes to merchants taking the necessary steps to achieve compliance and secure credit card data. At the same time, I think that service providers in the payment processing industry are getting much better at developing solutions that lessen PCI Compliance scope and secure sensitive data for merchants &#8211; which will help move things along faster.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

