Quantcast

Anti-Hacker Rule Falls Short of Security Guarantee, Ex-Heartland CTO Says

APR 9, 2012 12:37pm ET
Print
Email
Reprints
(1) Comment

Large data breaches at companies like Global Payments (GPN) are just the tip of the iceberg of the financial industry's data security woes, says Steve Elefant, who was chief technology officer at Heartland Payment Systems (HPY) during its massive 2008 data breach.

After Global Payments disclosed its breach last month, a familiar question arose: How could this happen to a company that was considered compliant with the Payment Card Industry data security standard?

"PCI compliance has done a lot of good in getting people to think more about security, but the fallacy of PCI is that it will make you more secure against breaches," says Elefant, now a consultant with Strawhecker Group. "PCI compliance is one thing, but you have to be vigilant on many other levels to prevent breaches."

The standard, which is enforced by the card networks, sets certain data security requirements for companies that handle payment card data. The processors were each determined to be noncompliant with the standard after their breaches.

As large as Global Payments' breach was, possibly exposing card account data of some 1.5 million consumers, it was "only a fraction" of Heartland's breach, which involved 100 million exposed accounts, Elefant notes.

Among the lessons Elefant learned during his term as the top information-technology exec at Heartland from November 2008 to September 2011 is that there is no sure bulwark against hackers, but widespread advanced data-encryption and rigorous PCI compliance goes a long way toward preventing break-ins.

"What we are seeing is the reality that there is no such thing as safe software, and there never will be," Elefant says.

Encryption is "very effective … if it is used properly," but it still "is not used widely enough" by payments industry players, Elefant says.

While little is known about how Global Payments' breach occurred, Elefant says  it is "disappointing" that despite four years of industry experience following Heartland's breach another major processor experienced such widespread data-exposure.

Hackers are likely to move to smaller targets, which have fewer resources to devote to defending themselves, he says.

"Hackers are still succeeding, and small processors need to be on alert more than ever before," Elefant says.

This article is adapted from a version that appeared on PaymentsSource.

JOIN THE DISCUSSION

(1) Comment

SEE MORE IN

RELATED TAGS

 

 
The Week's Best Quotes: Holder's 'Too Big to Jail' Cop, Big-Bank Influence

The most notable quotes from American Banker stories of the previous week. Readers are encouraged to add their own observations in the Comments fields at the bottom of each slide. (Image: Fotolia)

Comments (1)
It may be "disappointing" to see another big breach but nobody can be surprised by this. Stolen card data remains like pure gold for organised crime. The is nothing at all in PCI-DSS, E2EE or tokenization that prevents a concerted attack, much less an inside job. Big data breaches will continue for as long as stolen cara data remains replayable in counterfeit cards or in Card Not Present transactions. Yet we could kill two birds -- carding and CNP fraud -- with one stone if we simply deployed chip across all payments channels. See http://lockstep.com.au/blog/2012/04/01/kill-two-birds-with-one-chip
Posted by Stephen Wilson Lockstep | Monday, April 09 2012 at 6:34PM ET
Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Email Newsletters

Get the Daily Briefing and the Morning Update when you sign up for a free trial.

TWITTER
FACEBOOK
LINKEDIN
Marketplace
Fiserv is a leading global provider of information management and electronic commerce systems for the financial services industry.
Learn More
Informa Research Services is the premier provider of competitive intelligence, mystery shopping, and compliance testing services to the financial industry.
Learn More
CSC is a leader in private-label, third-party loan servicing with 30+ years of proven experience in delivering effective, cost-effective solutions.
Learn More
Already a subscriber? Log in here
Please note you must now log in with your email address and password.