In this blog, I will illustrate what the “seven deadly sins” of PCI and cybersecurity are and what you can do to avoid these potential pitfalls to better protect your business.
No one is perfect, and certainly no business is executing their cybersecurity without mistakes. But what are the top reasons businesses fail to be secure?
Sloth: Treating PCI DSS as an Annual Event
A lazy approach to PCI DSS compliance means letting security controls slide for the rest of the year and scrambling to meet requirements just before an audit.
The Consequence
Treating PCI casually or as only a once-a-year requirement creates a window of opportunity for attackers. In fact, one report found that companies that don’t maintain continuous compliance efforts face a28% higher chance of experiencing a data breach.
The "one and done" approach also makes your next audit more difficult and costly, as you have to re-establish controls from scratch.
How to Avoid This Cyber-Sin
Embrace continuous effort. Treat PCI compliance as a year-round operational process, not just an annual event.
Perform regular checks. This includes quarterly vulnerability scans, daily log monitoring, and an annual penetration test.
Maintain situational awareness. Continuously monitor all systems in your Cardholder Data Environment (CDE) and ensure a robust change control process is in place. After any significant change, rescope your environment to ensure it remains accurate.
Empower your team. The team responsible for PCI compliance needs ongoing support from senior management, regular training, and the resources to succeed. Make sure they document all PCI-related activities throughout the year to prove their continuous efforts.
Pride: Inadequate Employee Training and Security Awareness
A prideful, overconfidence that your employees inherently understand their role in protecting sensitive data can leave your organization vulnerable to the most common attack vector: the human element.
The Consequence
A lack of security awareness leads to careless mistakes and an overall weak security posture. Employees can become the weakest link, susceptible to phishing, social engineering, and other attacks.
Conduct regular training. Provide annual security training covering critical topics like recognizing social engineering, proper data handling, and how to report security incidents.
Make it relevant. Go beyond general training by providing targeted lessons based on each employee's specific responsibilities in handling sensitive data.
Keep it fresh. Supplement annual training with ongoing reminders, such as monthly security newsletters or brief security tips. This keeps security top-of-mind throughout the year.
Foster a security culture. Shift the mindset from viewing training as a chore to seeing it as a vital part of everyone's job. When employees are invested in security, they become your first line of defense.
Gluttony: Underestimating Your PCI DSS Scope
Businesses often bite off more than they can chew by allowing cardholder data to spread throughout their environment.
Many organizations fall prey to this by incorrectly identifying all the systems, networks, and applications that handle cardholder data, leading to a false sense of security and problems down the road.
The Consequence
An indulgent approach to cardholder data and underestimating your scope means your audit is actually incomplete. In fact, 75% of companies fail their initial PCI DSS assessment, often due to these kinds of oversights.
Your unassessed systems become easy targets for cybercriminals, and a breach could result in millions of dollars in fines and reputational damage.
How to Avoid This Cyber-Sin
Create a detailed data flow diagram that maps every point where cardholder data is stored, processed, or transmitted—from call centers to backup servers.
Search for hidden data. Use data discovery tools to actively scan for unencrypted card data you might have forgotten about.
Segment your network. Isolate your CDE to minimize your compliance scope. This makes it easier to manage and secure.
Question everything. If you don't need to store a Primary Account Number (PAN), then stop. The less data you handle, the smaller your scope and the lower your risk.
Wrath: Insufficient Documentation and Policy Management
Many organizations understand (or soon will) the frustration that arises from a lack of proper documentation. It’s the painstaking scramble for evidence during an audit because policies and procedures weren't properly maintained.
This cyber-sin turns a routine assessment into a chaotic and time-consuming nightmare.
The Consequence
If you want to hate your job all you need to do is fail to keep up with documentation. Without up-to-date documentation, an audit becomes a punishing, evidence-gathering expedition. This can lead to significant delays and increase the risk of non-compliance findings.
How to Avoid This Cyber-Sin
Create a central repository for all PCI-related documentation. This includes network diagrams, risk assessments, and incident response plans.
Regularly review and update all documentation to reflect changes in your environment. Treat it as a living document, not a one-time task.
Make it part of your culture. Documentation shouldn't be seen as a chore. Integrate it into your daily security and operational processes. Use checklists to ensure you have all required evidence readily available.
Maintain clear evidence of your controls, such as change control tickets and account management activities. This provides a clear, defensible record of your security efforts.
Greed: Neglecting Third-Party Service Provider Compliance
In cybersecurity, greed is the desire to save time and money by offloading your security responsibilities.
Many organizations mistakenly believe that by outsourcing their payment processing or data storage, they can also outsource their PCI compliance obligations. This is a costly and dangerous assumption that can have devastating financial consequences.
The Consequence
If a breach occurs with a third-party service provider (TPSP) that handles your cardholder data, your business can still be held liable. You can't transfer the risk without verifying the provider's security.
According to the Verizon Business Data Breach Investigations Report (DBIR), 1 in 4 data breaches involve a third party. Your business is only as strong as its weakest link, and a non-compliant third party can be the entry point for a devastating attack.
How to Avoid This Cyber-Sin
Conduct due diligence. Before you sign a contract, thoroughly vet all third-party service providers.
Obtain their AOC. Always get a copy of their current Attestation of Compliance (AOC) to verify their certified status.
Define responsibilities. Clearly outline each party's PCI compliance responsibilities in a contract. Create a "good" responsibility matrix to ensure there are no gaps in coverage.
Monitor continuously. Don't just check once. Regularly (at least annually) monitor their compliance status to ensure they remain a secure partner. Remember, their security is your security.
Lust: Not Enforcing Proper Access Controls
An uncontrolled desire for convenience can lead organizations to grant excessive and unnecessary access to sensitive data.
By failing to implement the principle of least privilege, businesses become open to both internal and external threats.
The Consequence
Did you know that stolen credentials and compromised access are involved in 49% of all data breaches?
Granting too much access increases your attack surface exponentially. Compromised accounts—whether through phishing, social engineering, or a disgruntled employee—can give attackers a clear path to your most sensitive data.
How to Avoid This Cyber-Sin
Embrace least privilege. Ensure that employees are granted access to the Cardholder Data Environment (CDE) only on a "need-to-know" basis. This limits the potential damage of a compromised account.
Enforce strong passwords and MFA. Require a minimum password length of 12 characters and forbid shared credentials. Implement multi-factor authentication (MFA) for all access to the CDE to create a robust barrier against unauthorized entry.
Use role-based access control (RBAC). This makes it easier to manage access by grouping users with similar job functions and providing them with only the permissions they need.
Review and revoke access promptly. Regularly review and update access controls, and be sure to revoke access for terminated employees immediately to prevent unauthorized data access.
Envy: Lack of Preparation for New Requirements
Instead of envying a competitor's security success, take a proactive approach to your own security.
This cyber-sin is the failure to update your policies and technical controls to meet the latest standards, like PCI DSS v4.0.1.
The Consequence
Procrastinating on new requirements leaves you exposed and vulnerable. If you fail to implement the latest controls, you risk failing your assessment and becoming an easy target for a data breach.
The cost of non-compliance can be massive, including fines, loss of merchant accounts, and reputational damage.
How to Avoid This Cyber-Sin
Conduct a gap analysis. Thoroughly compare your current security posture against the new, more prescriptive requirements of PCI DSS v4.0.1.
Prioritize remediation. Focus your efforts on high-impact areas such as Multi-Factor Authentication (MFA) implementation, increased password length requirements, and secure coding for e-commerce payment pages.
Update your tools. Ensure your security tools can fulfill new requirements like detecting and alerting on changes to payment pages (6.4.3) and detecting and alerting on unauthorized file changes on payment systems (11.6.1).
Stay ahead of the curve. Your competitors are likely already working toward these new requirements. By being proactive, you can turn a potential risk into a competitive advantage.
Don’t Fall for the Seven Deadly Cybersecurity Sins
Luckily, you can overcome the seven deadly cybersecurity sins with some simple adjustments to your security approach. Strive to:
Master Sloth (Annual Compliance) by treating PCI compliance as an ongoing process with regular checks and assessments to prevent vulnerabilities from emerging.
Deny Lust (Poor Access Controls) by implementing the principle of least privilege and multi-factor authentication (MFA) to limit access to your most sensitive data.
Avoid Gluttony (Underestimating Scope) with a thorough, continuous scoping process to steer clear of an incomplete and costly audit.
End Wrath (Inadequate Documentation) by keeping your policies and procedures up-to-date and easily accessible to streamline your process.
Defy Greed (Neglecting Third Parties) by performing due diligence and continuous monitoring of third-parties you do business with.
Conquer Pride (Lack of Training) by investing in targeted, ongoing security awareness training to prevent careless mistakes that lead to data breaches.
Overcome Envy (Ignoring New Requirements) by proactively preparing for new standards like PCI DSS v4.0.1 to avoid failing your assessment and becoming a target for attack.
If you can avoid falling for these seven deadly cybersecurity sins, you will be able to secure your business year-round, instead of just during your annual audit.