“Target was certified as meeting the standard for the payment card industry in September 2013. Nonetheless, we suffered a data breach.” Those words by Target Chairman, President, and Chief Executive Officer Gregg Steinhafel affirmed what security experts know as gospel: Compliance does not equal security. “Just because you pass a PCI audit does not mean that you’re secure,” said Eric Chiu, president and founder of HyTrust. “Clearly we saw that in the Target scenario.” PCI standards can suffer from a common regulatory affliction.
Target Breach Lesson: PCI Compliance Isn't Enough
Posted by: John P. Mello Jr. March 18, 2014 12:09 PM“Target was certified as meeting the standard for the payment card industry in September 2013. Nonetheless, we suffered a data breach.” Those words by Target Chairman, President, and Chief Executive Officer Gregg Steinhafel affirmed what security experts know as gospel: Compliance does not equal security. “Just because you pass a PCI audit does not mean that you’re secure,” said Eric Chiu, president and founder of HyTrust. “Clearly we saw that in the Target scenario.” PCI standards can suffer from a common regulatory affliction.