Visa To Franchisors: “We’re Here To Talk, Not To Listen”
Written by Todd L. MichaudJune 17th, 2010
When it comes to PCI compliance for franchisors, Visa is completely out of touch with reality. That's from the pen of Franchisee Columnist Todd Michaud, who spent 9 hours with Visa execs at a franchisee symposium on Wednesday (June 16).
The morning was spent providing horror stories about how the sophisticated Russian organized crime syndicates responsible for the lion-share of breaches operate. The afternoon, meanwhile, was spent talking--indirectly--about what role tokenization and encryption may or may not play in the future of card data protection. Retailers representing more than 50,000 domestic locations were all in the same room, and not once were they asked their thoughts and opinions on the matter. "What a wasted opportunity," Michaid wrote.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
5 Comments | Read Visa To Franchisors: “We’re Here To Talk, Not To Listen”
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

June 18th, 2010 at 8:54 am
Why are people surprised? The PCI DSS is not about securing Data. It is for indemnifying the card companies against liability for breaches. Period.
June 18th, 2010 at 11:32 am
Funny, that’s what I’ve been saying all along. PCI’s primary function is a liability shield for the card brands. To me, this is why Visa can say “…no compromised entity has yet been found to be in compliance with PCI DSS at the time of a breach.” I would go further, “no compromised entity will be found in compliance…”; they have an incentive to make sure the merchant is out-of-compliance in the event of a breach.
June 18th, 2010 at 1:33 pm
Similarly, I’ve always pointed out to those who see PCI as the savior of identity theft that it is only about liability transfer.
June 18th, 2010 at 3:08 pm
As a 40 year industry veteran, data security is a noble goal. However, I propose that
1. PCI is purposefully written to be confusing, like the IRS code, as a money grab the card associations
2. PCI does nothing to address the greater need for overall data security nor other payment methods such as ACH or checking account data
3. It is a tactic to drive small and medium size acquirers from the field. The card associations have thousands of members, say 3000, if they can reduce the number to 500, because transaction volume will not decrease, the expenses of the card associations drastically drop while their income remains unchanged.
4. As another respondent wrote, it’s a liability shield.
More time and money is spent attempting to prevent the unpreventable than catching and punishing the offenders.
IRS, TSA and now PCI
June 19th, 2010 at 5:57 pm
@Biff and Steve:
Well said, both! You’ve caught on to the REAL credit card scam… PCI DSS!
PCI SSC and the brands do seem to have intentionally designed PCI DSS requirements in such a manner that they can always claim a breached system was non-compliant even if a Report of Compliance certification was granted mere hours before the breach occurred.
And if a breach had been occurring and went undetected during a QSA review which resulted in a ROC being issued, PCI SSC will merely claim that the QSA was not qualified — and that you should not have used that QSA, even though PCI SSC issued the QSA its qualification…
I willing to wager that even Las Vegas casino owners wish they could stack the house odds in their favor the way PCI SSC does!