Member-only story
Cybersecurity Tightens with PCI DSS v4
Do you remember when the CEO of Equifax said:
And when Dido Harding — the then CEO of Talk Talk — said:
“[Our data] wasn’t encrypted, nor are you legally required to encrypt it. We have complied with all of our legal obligations in terms of storing of financial information.”
Well, then, we perhaps have to admit that the general understanding and implementation of encryption within the industry is weak, and often, those at a board level have very little understanding of what actually happens on the ground. But, as cybersecurity professionals, we should be pushing for improved standards, and in a way that a bridge engineer would push for improved ways to build bridges if it was found that bridges kept falling down.
PCI DSS
So, in cybersecurity, it’s very much a carrot — doing encryption because you want to protect your customer’s details — or a stick — doing it because you will lose a licence to trade if you do not comply. One of the biggest sticks in the finance industry is PCI DSS, which is generally seen to follow good cybersecurity standards.
