Share this article
PCI DSS security assessor and cyber consultant, Claire Greathead, addresses some of the common issues faced by organisations seeking to achieve compliance with the payment card industry’s core standard.
Over the years, I’ve seen dozens of businesses navigating the challenges of PCI DSS compliance. Depending on the size and sector of an organisation there can be a range of different considerations to be taken into account.
Even those companies with a mature approach to risk and a highly competent security team can fall foul of some common mistakes if they are not familiar with the specific requirements of the standard. This is not to say that organisations should be terrified of the PCI DSS. Achieving compliance isn’t an impossible mountain to climb. However, it is a standard that takes resource, effort and diligence.
While every organisations is different, there are certain mistakes that I do see crop up time and again. These common errors can put sensitive card data at risk and potentially lead to failed assessments, additional costs and reputational uncertainty.
Here are five PCI compliance mistakes we see most frequently at SRM . . . along with some pointers on how to steer clear of them:
Far too many businesses treat PCI DSS compliance as a tick-box exercise that needs to be completed on an annual basis and then ignored for the next 12 months. In fact, this is an issue that can often be applied across a range of certifications and accreditations but it is a particular issue in PCI.
Typically, businesses will scramble to meet the requirements of the standard in the final weeks leading up to an assessment, only to identify issues that have arisen over the course of the year which could have left the organisation compromised.
This is a problem because PCI DSS benefits an organisation precisely because it is designed to support and enforce ongoing security best practices. Failing to maintain compliance throughout the year leaves a business vulnerable to breaches between audits. And if a breach does occur, allowing standards to drop typically means that the organisation is not protected by their compliance certificate.
The solution, not surprisingly, is to embed best practice into an organisation’s everyday processes. By automating log monitoring, scheduling regular vulnerability scanning and conducting quarterly internal reviews, compliance can be made part of a business’s culture – and not just its calendar.
Another common mistake I’ve seen on many occasions is organisations underestimating scope. This can mean failing to identify the appropriate number of systems that interact with cardholder data or a failure to isolate the cardholder data environment (CDE) correctly.
An incomplete scope immediately makes an assessment invalid – and it means that potential threat actors can take advantage of parts of the network that the business has simply ignored and failed to secure.
For those organisations seeking to gain and maintain compliance, it’s crucial to conduct a thorough network segmentation exercise. This will typically involve the creation of data flow diagrams and asset inventories that identify every system, application and process that interacts with cardholder data.
Businesses can keep the scope tight by clearly separating the CDE from the rest of the business environment.
Like virtually all information security standards, PCI DSS compliance is built on the clear presentation of policies, procedures, access logs and incident response plans. Nevertheless, organisations often lack consistency and accuracy in their paper trails.
Failure to produce evidence of the controls in place and being followed during an assessment is highly problematic, so taking the time to establish a documentation management process is an important step for organisations. Documents should also be assigned ownership – another common mistake – so that there is a designated team member tasked with keeping documents up to date and dated as records.
No business is an island in 2025. All organisations rely on third parties to a greater or lesser degree – whether it’s for processing payments, hosting or providing support.
The temptation is often to pass the buck of responsibility for these services to the third party suppliers but as part of the PCI equation it’s important to check that these vendors are compliant.
Why? Because if a third party has access to cardholder data or impacts the security of the CDE, the business is still responsible for ensuring their compliance.
In order to achieve PCI compliance, organisations should request and review vendors’ Attestation of Compliance (AOC) documents. Roles and responsibilities within contracts should be clearly defined so that suppliers form part of the overall risk management process, rather than there being a disconnect.
It’s an absolutely basic mistake but time and again it is access controls that often compromise security. Too frequently I see organisations with shared passwords, over-provisioned accounts and little to no access review.
As a leading cause of breaches, access management should be a non-negotiable within an organisation. Similarly, simple steps such as multi-factor authentication and the regular cleansing of inactive or unused accounts needs to be made part of business as usual.
Overall, my advice to businesses is to be proactive and diligent all year round when it comes to PCI DSS compliance. And, of course, get support from experienced consultants like the team here at SRM to provide a keen, objective eye over security processes and procedures ahead of an audit.
Find out more about how SRM can help you work through your next PCI compliance audit by clicking here or call us today on 03450 212151.