Card Groups Need New Approach to Data Security

Aug 11, 2008 12:00 PM, By MICHAEL GARRY Technology Editor michael.garry@penton.com


         Subscribe in NewsGator Online   Subscribe in Bloglines

The Hannaford Bros. data security breach, which exposed 4.2 million credit and debit cards earlier this year, was certainly a teachable moment for the food retailing industry.

As detailed in an article beginning on Page 28, data thieves, who have yet to be identified, were able to seize consumer card data that was “in transit” along its private network between the POS card reader and Hannaford's centralized payment switch. This happened despite Hannaford's being Payment Card Industry-compliant.

Michael Garry

Thus it became immediately clear that compliance with PCI's 12 data security standards is no guarantee of security. Of course, retailers are still expected by the card associations to be certified as PCI-compliant or face stiff financial penalties. But now retailers need to invest in security technology and services that go beyond PCI compliance.

Meanwhile, the urgency of the data security issue was underscored last week when federal prosecutors brought criminal charges against 11 individuals allegedly involved in the theft of more than 40 million credit and debit card numbers from nine retailers.

The PCI Security Standards Council, Wakefield, Mass., set up by the card associations (Visa, MasterCard, et al.) to manage the standards, declines to say if it was influenced by the breach at PCI-compliant Hannaford. Yet the council has been notably busy in recent months. Not long after Hannaford revealed its security break-in, the council announced that a new version of PCI will be coming in October, among other moves.

But those efforts have not done much to calm retailers. As Dave Hogan, chief information officer for the National Retail Federation, Washington, puts it, “Every year they make the guidelines tougher, but it's like building a bigger wall around your data center. The bad guys just bring a bigger ladder to get over it.”

And building the wall is an increasingly expensive proposition. Hannaford has acknowledged spending millions of dollars post-breach to ensure that it doesn't happen again.

The industry is already grappling with the card associations over the interchange rates they apply to transactions, but it may not be too long before it will need to challenge them to do more about data security than just impose PCI standards. For example, it makes little sense for the associations to make signatures, rather than PINs, the vehicle for authenticating credit card purchases. PINs, already widely accepted by consumers for debit and ATM cards, are a far more secure method.

Moreover, the magnetic stripe on credit cards is now an antiquated technology, dating back to the 1980s. Far more secure technologies, such as the microchip embedded in credit and debit cards used in the United Kingdom, should be employed. But that would require a financial investment by the card associations, which would rather have retailers do the investing.

Subscribe / Renew to Supermarket News

Supermarket News

The most reliable source of industry news and insight...in print and online.

Most Viewed News

Read More News

Retail Analytics
Brian Ross

View All Questions

Refresh: A Whole Health Blog

Bob Vosburgh

Bob Vosburgh:

Read More Refresh

Articles by Market
Retail/Financial
Executive Changes
Grocery/Center Store/
Brands
Health & Wellness
In-Store Bakery/Deli/Meals
Logistics
Marketing
Meat/Seafood/Dairy
Nonfoods/Pharmacy/HBC
Produce/Floral
Specialty/Ethnic
Technology
Key Issues
Food Safety/Recalls
Legislation/Regulations
Sustainability/Green
Resources
Profiles & Rankings
Webinars
White Papers/Studies
Whole Health Blog
Total Access Blog: Expo East
Photo Galleries
RSS
SN Data
Campbell: Innovate
for Impact

Back to Top

Subscribe to SN

Latest Cover

IRI Fast Trends

Not much remains the same in the food-distribution industry, whether it's the marketing of supermarket departments, the advent of new formats or rapidly changing consumer preferences. See what's changing now in the latest IRI Time and Trends report.

SN Daily Update

newsletter image

The food trade’s leading daily news service. Register Here

Upcoming Events

2009 Midwinter Executive Conference,
Jan. 11-13,
Food Marketing Institute,
The Ritz-Carlton, Grande Lakes,
Orlando, Fla.;
202.452.8444.

NRF 98th Annual Convention & Expo,
Jan. 11-14,
National Retail Federation,
Jacob K. Javits Convention Center,
New York;
800.673.4692

View All Upcoming Events

Jobs/Classifieds

View All Classifieds

Premium Content

Cool Running

Cool Running

With the entire country as its laboratory, Wal-Mart Stores has been conducting step-by-step experiments to create the ultimate “green store.”

Changing Diapers

Changing Diapers

At a time when the economy in shambles has been a boon for many store-brand categories, private-label diapers are sporting a serious sag.

Supermarket News Casting Lifelines

Casting Lifelines

For 23 years Food For All, through its checkout register drives at sponsoring supermarkets, has raised funds for countless nonprofit organizations both in the United States and abroad.

Little Luxuries

Little Luxuries

Whether it's cupcakes or cookies, mini-tarts or gourmet brownies, small desserts have become a big draw in many supermarket bakery departments.

Supermarket News Secret's Out

Celebrating Cheese

Specialty cheese is expected to hold its own this holiday season even as shoppers trim their entertaining budgets.