VZ Verizon Communications Inc.

2022 Verizon Business Payment Security Report: Preparing to navigate PCI DSS v4.0

2022 Verizon Business Payment Security Report: Preparing to navigate PCI DSS v4.0

What you need to know:

  • To help organizations interpret the new Payment Security Standard, Verizon launches the 2022 Payment Security Report (PSR) in conjunction with the PCI SSC’s 2022 introduction of the PCI DSS v4.0
  • The 2022 PSR includes a step-by-step, logical systems approach to managing complex security problems in advance of the PCI DSS v4.0 2024 deadline
  • Organizations emphasized security management and governance, resulting in significant gains (43.4 percent compliance in 2020, up from 27.9 percent in 2019). Conversely, the security control gap improved substantially in 2020, from a high 7.7 percent in 2019 to a low 4.0 percent in 2020
  • The 2022 PSR continues to advise organizations on best practices for negotiating PCI DSS v4.0 during a time of increased vulnerability

NEW YORK, Sept. 08, 2022 (GLOBE NEWSWIRE) -- Despite Payment Card Industry Data Security Standard (PCI DSS) compliance improving significantly in 2020, the cybersecurity threats organizations face are more cunning and evasive than they were even two years ago, the reveals. As organizations prepare to implement PCI DSS v4.0, the 2022 PSR provides valuable insights to pivot and adapt to the new Standard.

Verizon's logical approach to the strategic management of complex compliance challenges appears to be making a positive difference for businesses. This year’s report found that, overall, PCI DSS compliance improved significantly in 2020, with 43.4 percent of organizations maintaining full compliance, compared to 27.9 percent in 2019. Additionally, while over half (56.7%) of organizations failed their interim validation assessment due to one or more security controls omissions, the security control gap still improved substantially, from a high 7.7 percent in 2019 to a low 4.0 percent in 2020.

“Despite compliance improvements, we know that bad actors are still out there and stronger than ever,” said Sampath Sowmyanarayan, CEO, Verizon Business. “Our own (2022 DBIR) found the financial sector continues to be victimized by motivated organized crime, with servers being involved in 90 percent of financial breaches. As a result, working harder on your current strategy is unlikely to move the needle,” Sowmyanarayan continued. “To remain safe in today’s heightened cybersecurity climate, organizations will need to approach their objectives and goals at a project, program and strategic level.”

The COVID-19 pandemic escalated online business activities and payment card transactions, but it also enabled the skillful exploitation of both existing and emerging threats and weaknesses within payment systems and processes. Further complicating the payment security landscape for Chief Information Security Officers (CISOs) and other security practitioners, the PCI SSC recently instituted the most significant rewrite of the DSS since its release in 2004. While a significant step forward, security leaders need to focus their attention and resources on getting up to speed with these new requirements. Released earlier this year, PCI DSS v4.0 will go into effect in 2024.

“Substantial industry feedback drove changes to PCI DSS v4.0,” said Lance Johnson, Executive Director of the PCI Security Standards Council. “Key changes to the standard focus on meeting the evolving security needs of the payments industry, continuously promoting security processes, increasing flexibility for organizations using different methods to achieve security objectives, and enhancing validation procedures.”

Design priorities for PCI DSS v4.0

CISOs and their teams will need to apply a logical, coordinated process to evaluate requirements and constraints of PCI DSS v4.0, while navigating their way through the changes. To help organizations within the payment industry simplify the complexity of these new measures and ensure data security, the 2022 PSR includes a “toolbox” of management models and frameworks useful for negotiating PCI DSS v4.0.

As the report highlights, the challenges organizations encounter with data security and compliance management have identifiable cause-and-effect relationships. The key to achieving ongoing growth and stability of security and compliance program performance is to find a way to focus resources on only the parts within the security environment that are currently limiting or blocking further improvement—the weakest links, system constraints or leverage points. As such, strategic planning, coordination and execution at an operational level is paramount for averting costly data breaches.

Potential impact of 5G on payment card compliance

The appeal of emerging technologies, such as 5G and edge computing, gained significant momentum when the COVID-19 pandemic exposed the weakest links of the financial services industry. The speed and stability of 5G will continue to enhance the mobile experience for the payments industry—providing greater customer security through advanced biometric-based identification and verification methods. It also will provide more secure connections for video conferencing, with participants such as financial professionals and loan counselors.

Financial institutions and merchants will continue to find innovative ways to benefit from 5G-enhanced features, open architecture and Multi-access Edge Computing (MEC) technologies. At the same time, security practitioners need to explore how these new innovations might impact the PCI DSS compliance posture.

About the Verizon Business 2022 Payment Security Report

Verizon published the industry’s first global analysis of PCI DSS assessments in the 2010 Verizon PCI Compliance Report, now called the Payment Security Report (PSR). Based on global data gathered by PCI DSS qualified security assessors (QSAs) from Verizon and four other external contributors, with additional comparisons between geographic regions (Americas, EMEA and APAC), the report explores why some companies accomplish more than others in their efforts to achieve sustainable and effective data security. Since its inception, the PSR has tracked compliance ups and downs, while keeping a finger on the pulse of the changing payment security landscape.

Read the full , and learn more about what the Verizon Cyber Security Consulting Payment Security Practice is doing to help organizations prepare for PCI DSS v4.0.

Additional Resources:

  • Verizon will be speaking Wednesday, September 14, 2022 at the PCI Security Standards Community Meeting in Toronto, ON, Canada on “.” Learn more about the event, and .

Verizon Communications Inc. (NYSE, Nasdaq: VZ) was formed on June 30, 2000 and is one of the world’s leading providers of technology and communications services. Headquartered in New York City and with a presence around the world, Verizon generated revenues of $133.6 billion in 2021. The company offers data, video and voice services and solutions on its award-winning networks and platforms, delivering on customers’ demand for mobility, reliable network connectivity, security and control.

VERIZON’S ONLINE MEDIA CENTER: News releases, stories, media contacts and other resources are available at . News releases are also available through an RSS feed. To subscribe, visit .

Media contacts:

Erin Cheever



EN
08/09/2022

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Verizon Communications Inc.

 PRESS RELEASE

Verizon announces a $5B commitment to continue investing in America an...

Verizon announces a $5B commitment to continue investing in America and supporting small businesses What you need to know: Verizon announces a substantial $5 billion commitment over the next five years with the launch of a new Small Business Supplier Accelerator.Verizon Small Business Digital Ready launched a new grant cycle where eligible small businesses can apply for $10,000 grants (open until June 30, 2025). NEW YORK, May 13, 2025 (GLOBE NEWSWIRE) -- Verizon today announced a commitment to invest $5 billion over the next five years in US small business suppliers with the launch...

 PRESS RELEASE

Verizon anuncia compromiso de $5 mil millones para seguir invirtiendo ...

Verizon anuncia compromiso de $5 mil millones para seguir invirtiendo en EE.UU. y apoyar a las pequeñas empresas  Lo que debes saber: Verizon anuncia un importante compromiso de $5 mil millones de dólares durante los próximos cinco años con el lanzamiento del nuevo programa, Verizon Small Business Supplier Accelerator.Verizon Small Business Digital Ready lanzó un nuevo ciclo de subvenciones en el que las pequeñas empresas elegibles pueden solicitar subvenciones de $10,000 (abierto hasta el 30 de junio de 2025). NUEVA YORK, May 13, 2025 (GLOBE NEWSWIRE) -- Hoy, Verizon anunció su compro...

 PRESS RELEASE

Verizon to speak at MoffettNathanson conference May 15

Verizon to speak at MoffettNathanson conference May 15 NEW YORK, May 13, 2025 (GLOBE NEWSWIRE) -- Sowmyanarayan Sampath, executive vice president for Verizon (NYSE, Nasdaq: VZ), and CEO for Verizon Consumer, is scheduled to speak at the MoffettNathanson Media, Internet & Communications Conference on Thursday, May 15, at 8:00 a.m. ET. His remarks will be webcast, with access instructions available on Verizon’s Investor Relations website, . For details on Verizon's most recent financial results, . Verizon Communications Inc. (NYSE, Nasdaq: VZ) was formed in 2000 and is one of the ...

 PRESS RELEASE

Introducing Samsung Galaxy S25 Edge on Verizon

Introducing Samsung Galaxy S25 Edge on Verizon Get a Verizon 3-year price-lock guarantee and a new Galaxy S25 Edge on us with myPlan and any trade-in from Apple, Google or Samsung NEW YORK, May 12, 2025 (GLOBE NEWSWIRE) -- [What’s new] Introducing the Samsung Galaxy S25 Edge: where unparalleled elegance meets uncompromising power. This groundbreaking device, available at Verizon, offers the advanced capabilities of the Galaxy S25 Ultra in an exceptionally thin and light smartphone. Verizon preorders start May 13 in Titanium Silver, Icyblue and Jetblack, with 256GB or 512GB storage s...

 PRESS RELEASE

Buffalo Bills Announce Verizon as Official 5G Network and a Founding P...

Buffalo Bills Announce Verizon as Official 5G Network and a Founding Partner of New Highmark Stadium Verizon partnership to include: Ownership of the Distributed Antenna System (DAS)Integration of Verizon Business Services and Solutions to drive sustainability, operations and fan experiencesPremium programming, sweepstakes and onsite activations; unique access and experiences will be available for Verizon customersVerizon to donate to Buffalo-based Veterans One Stop NEW YORK, May 12, 2025 (GLOBE NEWSWIRE) -- The Buffalo Bills today announced Verizon will be the exclusive wireless teleco...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch