Posts

Showing posts from January, 2014

PCI London: How the Payment Card Industry could kill PCI DSS

Image
Today (23rd Jan 14) I was a panellist at PCI London 2014, quite a few people were interested in what I had to say, on removing the need for PCI DSS compliance completely by securing the payment cards further. What I said was nothing new, I have been bleating on about this since attending the first PCI SSC meeting back in 2007. Still it is a bold thing to say, especially at a conference where Visa Europe and the PCI Security Standard Council are promoting PCI DSS compliance in the UK, and with event sponsoring vendors promoting their PCI DSS compliance servicing wares.  I'll summarise the views which I expressed at PCI London, which I believe could draw an end to PCI DSS compliance. Introduce Global Chip & Pin (EMV) Chip & Pin provides two-factor authentication, this means in order for the cardholder to make a payment,  the cardholder requires knowledge of a 4 digit number, and possession of the payment card. This is known as a 'cardholder present' transac...

UK Information Security Threat Horizon 2014

I was asked for my views on the Threat Horizon, specifically what attacks and trends do I expect to impact UK businesses in 2014, so I thought I'd share my thoughts.  The following are my own views, and they are not based on any specific studies or reports, but on what I've generally read, discussed and trends I have seen affecting UK businesses in the last couple of years. Cloud Data Protection UK businesses continue the 'Cloud Rush', meaning more and more confidential data is going into the cloud. I don't think this is so much a Snowden privacy revelation issue with government spying, but I see the problem is that UK businesses are being  taken in by the marketing cost saving glitz, and so  are blindly trusting cloud service providers. At the end of the day a cloud service provider is a third party service provider. A cloud service purchased by a business, where the third party is charged with adequately  protecting confidential info...