I have posited several times that compliance with the PCI DSS, with all of its idiosyncrasies and expense, has driven innovation in the payments space to a degree never before seen.  I even wrote a blog on the subject; How PCI Has Driven Innovation in Payments

However, over recent months, I have had the honour of working with several organisations who are throwing their hats in the ring, and trying to come up with ways to increase both the effectiveness of non-cash payments, but also the security.  Admittedly, these are still piggy-backing off credit cards, but the technologies are precursors to the demise of the card number itself. Basically;

If you don’t need a card number at the beginning of a transaction, why have a card OR a number in the first place?

Continue reading “How PCI Is Stifling Payments Innovation” →

For those of you who are unfamiliar with the concept of ‘Disruptive Innovation’ (like me until 5 days ago), it is defined as;

“…a process by which a product or service takes root initially in simple applications at the bottom of a market and then relentlessly moves up market, eventually displacing established competitors.” (http://www.claytonchristensen.com)

For decades, the card schemes (Visa, Mastercard, Amex, Discover etc.) have ruled the non-cash payments space, despite the fact that the technology behind the credit card; the card number, is now over 60 years old. There have been few alternatives proposed because:

  1. There were none that did not rely on some other form of number or separate device to authenticate. For example, bio-metrics has never been 100% free of false positives or false negatives, and therefore is not accurate enough for the payments space. Yet.
  2. Credit cards worked, the infrastructure is pretty much global, and they are still expanding.
  3. The card brands themselves are very aggressive in protecting their empires.

Even the PCI Standards (PCI DSS, PA-DSS, and PTS) can be seen as innovation stiflers, because it’s so difficult to achieve compliance that most organisations have little time or money left to experiment. Also, no-one wants to be the first to stray from the established norm as there’s simply too much to lose, and recovery is increasingly difficult given the globalisation of competition in almost every industry sector.

But, with the massive amount of innovation that AVOIDING PCI has spurned, the number of non-card-brand options has increased to the point where only the most naive of organisations are not looking around for alternative payment methods. Why use a credit card when consumers can obtain lines of credit directly from their banks and access this from their mobile device faster, more securely, and without the outrageous fees the card brands have charged all these years?

The Internet is more distributed and available than the card brands can ever be, and mobile devices already outnumber card payment terminals by orders of magnitude. There will soon be more smartphones than PEOPLE in the world, so the demand for efficiency and functionality will only increase.

And what of chip and PIN (a.k.a. EMV)? Why would anyone bother buying the expensive payment terminal (PED) models currently provided by the Ingenico’s, Verifone’s, and Micros’s of the world, when a simple software ‘fix’ on ANY terminal will provide the same functionality? Functionality that is portable to every form of transaction, from card present, to eComm, to mobile (e.g. myPinPad).

OK, so the last paragraph assumes you’re still using a credit cards, but it just goes to show the knock-on effect that the demise of credit cards will engender. PED manufactures will move into something else that requires hardware, encryption and centralised management (B.Y.O.D perhaps?), most QSA companies will fail (or start doing security properly for a change), and the banks will be held fully accountable for the security of their customer’s payment transactions.

So PCI, which started out as an attempt to keep the US Fed off the card brand’s backs, has, through its complexity, expense, and inflexibility, driven the type of innovation from which there is no turning back. The card brands will either spend all of their money buying companies that provide credit card alternatives in order to future-proof themselves (like Visa buying a stake in Square for example), or they will fail.

I’d say they have 5 – 10 more good years, you simply can’t replace something as ubiquitous as the credit card until the new payment methods have worked out all the kinks. That said, it’s the Internet again that will provide the platform, and software applications that will provide the function, so global distribution is as simple as going online.

I can’t wait to see what’s next.

Have you all seen the ‘sneak peek‘ yet?

I have to admit, that with 3 YEARS to accept and process feedback, I was hoping for a little more in the way of progress.  I’m optimistic that way, but I really should have known better.

Many changes were proposed, lots of the them good, some of them naive and bordering on the comical, but any that made it through are so watered down as to be virtually irrelevant.  And we won’t get any more for 3 more years?

The standard is already behind the times, and is only going to become more so if it does not keep up with payments innovation, and show a better integration with the needs of the business. i.e. STAYING in business.

I have taken the table of changes out of the SSC’s document and added my own thoughts.  Unfortunately they are overwhelmingly negative, and at times my frustration is clear. Go here if you want to download it.

I do however want to make it clear that I’m not against the PCI DSS as much as I appear.  No standard has raised security awareness as much before, or since, and it’s the only one that puts its money where its mouth is.  While there is still some vagueness and room for interpretation, it’s a damned-sight better that just saying ‘use appropriate security based on good practices’ like most do.

The reason I stick to the negative is I’m assuming the positive is self evident, and all I really care about is addressing the gaps to where it should be.  As Ego says in Ratatouille; “In many ways, the work of a critic is easy. We risk very little yet enjoy a position over those who offer up their work and their selves to our judgment. We thrive on negative criticism, which is fun to write and to read. But the bitter truth we critics must face is that, in the grand scheme of things, the average piece of junk is more meaningful than our criticism designating it so.”

This applies every bit as much to my blogs.

I have only addressed the PCI DSS stuff, PA-DSS is not my thing.  If someone wants to take a stab at that, I’ll be happy to post it here as a guest blog.

 

 

I can’t resist dramatic titles, but I’m not actually going to badmouth the SSC, PCI, or ‘Just-QSAs’ (see Heads-Up to the Just-QSAs, It’s Time to Diversify), I’m simply going to state my opinion on why every QSA has at some point had to cut significant corners in the assessment process, and written their reports accordingly. If they didn’t, their clients would, quite literally, never have achieved compliance.

Here’s a ridiculous analogy; If every PCI requirement was a tennis ball, you could very easily carry them all from a weight perspective, but it’s impossible to hold them all together without some kind of container (Tennis ball = DSS Requirements, Container = Security Programme). In other words, the requirements themselves are basic, but completely out of context from a ongoing management, business, or even good security practice perspective.

The PCI DSS is 350-odd MINIMUM security controls, that must be in place across all systems, applications, and processes at all times. Even though the individual controls themselves are very reasonable, and SHOULD be mostly in place anyway, there is no way in any environment (that warrants an onsite assessment) that 100% compliance can be maintained at all times. Not without considerable expense anyway.

For example; 1) PCI does not REQUIRE centralised logging, but try complying with 10.5.X without it. 2) You don’t HAVE to use 3rd party penetration testers, but do you really want to employ that skill-set in-house? 3) The paperwork aspect of policies is easy, but it take years and a significant change in corporate culture to put them properly into effect. And so on.

What this leads to is organisations either giving up and accepting ‘tick-in-the-box’ compliance, or spending way too much money on things that provide little value to the overall organisation.

The business must never be changed to fit into PCI compliance alone, the INTENT of PCI must be fit into business to the benefit of both.

As I’ve said countless times, it’s not that the DSS is a bad standard, it’s just that it doesn’t start in the right way, doesn’t finish where it matters, and only covers one specific data type. The outcome of this is that no business is going to make the necessary expense to attempt letter-of-the-law compliance. Nor should they in my opinion, which means that QSAs MUST be … errrr pragmatic in their enforcement.

Which brings up one of the biggest flaws of PCI; The QSA is held accountable to enforce the standard as written, but is also under commercial pressure as a vendor. There are hundreds of other QSA companies just waiting in the wings to ‘help’ businesses achieve compliance if you’re not pragmatic enough for their liking.

The conflict of interest is undeniable, and ruins the objectivity required to conduct the assessment. Not to mention that the price compression associated with this competition has, over time, massively eroded the level of service that can be provided at a reasonable profit.  Junior ‘Just-QSAs’, are the only way to make money in PCI if you don’t sell them other things on the side.

Finally, QSAs are allowed to interpret the DSS to a large degree, as well as make decisions on what constitutes a compensating control. There is very little official guidance, or standardisation in this regard, and the card brands themselves will always refer questions back to the QSA. There have been some very good trainers at the SSC, and some very poor ones, and the far from optimal training program itself just exacerbates the problem faced by businesses looking to do the right thing. That is, the right for PCI compliance, but also the right thing for their business. You can guess which takes priority.

In the end, the right thing is to just do security properly. The benefits far outweigh the costs, and your PCI compliance will be good enough for what it represents.

There are 2 types of Qualified Security Assessor (QSA):  The ‘also-QSA’, who was a security consultant long before PCI, and had performed much of the work as detailed in the Security Core Concept blogs.

Then there are the ‘just-QSAs’ who managed to read a book, pass the CISA/CISM/CISSP exam, and qualify for the ever-so-difficult QSA training. They have delivered nothing but PCI ever since.

In case it’s unclear; first one good, second one bad.

Well, bad for you if you’re one of the ‘justs’, and bad for your clients if you’re all they have to rely on.  You won’t learn how to do security properly, or be able to provide consulting services regardless of the data type, compliance regime, or industry sector. Your clients will never get anything other than tick-in-the-box compliance.

PCI has a shelf life, and I imagine that at the current rate of payments innovation, you have only a few years to diversify. After that there is no way you will be able to maintain your current compensation package. Without some significant experience in non-PCI security areas, your usefulness is limited.

Progress will be difficult if you work for a ‘just-QSA-Company’, because you HAVE nothing else to do. You may want to seriously consider working for a security company that’s in the ‘also’ category.  There are many.

You probably have a training budget too, so spend it.  ISO Lead Auditor, CIPP/X, CLAS (UK), ITIL, Prince II, while not all security specific, are most certainly relevant. Relevant to providing the kind of  guidance that is in depressingly short supply.  If you can use this training to your current company’s benefit, great. If you can help them design non-PCI services, you are way ahead of the game.

However, there is a better than average chance that your career preferences will fall more on one side or the other of ‘business-focused’, or ‘technical-focused’. It’s important therefore that you NOT try to embrace all 6 core concepts at once.  Even security experts need to specialise.

What we are all working towards is an understanding that IT and IT security are business enablers, not a roadblock. PCI is ‘just an expense, with limited to no return on investment’, or at least thats how it is mostly seen.  Our job is to put security into a business context so that the benefits are clear to every level of the organisation.

The CEO cares about the bottom line, s/he does not care about the detail until that detail gets in the WAY of business.  This is why there is so little management buy-in when it comes to security and compliance.  If we can show that a well run IT infrastructure enables business transformation, innovation, enhanced efficiency and so on, we’ll have demonstrated our worth.

THAT’S our job, not just protecting credit card data with a minimal set of security controls to which you had no input.

The fundamentals of security have never changed, and won’t any time soon. So if you take the time to get back to basics, you’ll future-proof your career.

Security is simple, it’s not easy, but it is simple.