VZ Verizon Communications Inc.

Payment security compliance declines – Only 1 in 3 companies globally make the grade and just 1 in 5 in the Americas

Payment security compliance declines – Only 1 in 3 companies globally make the grade and just 1 in 5 in the Americas

Verizon’s 2019 Payment Security Report highlights why compliance matters, and offers measures to combat the downward compliance trend

What you need to know:

  • Companies that maintain full compliance with the Payment Card Industry Data Security Standard (PCI DSS) decrease for the second year in a row to 36.7 percent worldwide.
  • Only 1-in-5 organizations in the Americas maintain full compliance; Companies in Asia-Pacific dominate.
  • Verizon’s 9-5-4 Framework addresses elements to help develop and improve capability and process maturity across an entire data protection compliance program (DPCP).

BASKING RIDGE, N.J., Nov. 12, 2019 (GLOBE NEWSWIRE) -- Payment security compliance has declined for the second year in a row, with organizations based in the Americas lagging behind worldwide counterparts, (2019 PSR) flags.

When Visa Inc. initially launched the PCI DSS in 2004, many assumed that organizations would achieve effective and sustainable compliance within five years. Now, 15 years on, the number of businesses achieving and maintaining compliance has dropped from 52.5 percent (2018 PSR) to a low of just 36.7 percent worldwide. Geographically, organizations in the Asia-Pacific (APAC) region show a stronger ability to maintain full compliance at 69.6 percent, compared to 48 percent in Europe, Middle East and Africa (EMEA) and just 20.4 percent (1 in 5) in the Americas.



PCI DSS helps businesses that offer card payment facilities protect their payment systems from breaches and theft of cardholder data, as shown in the . Compliance is measured on an organization’s ability to meet — and importantly, maintain — the standard.

 

“After witnessing a gradual increase in compliance from 2010 to 2016, we are now seeing a worrying downward trend and increasing geographical differences,” said Rodolphe Simonetti, global managing director for security consulting at Verizon. “We see an increasing number of organizations unable to obtain and maintain the required compliance for PCI DSS, which has a direct impact on the security of their customers’ payment data. With the latest version of the PCI DSS standard 4.0 launching soon, businesses have an opportunity to turn this trend around by rethinking how they implement and structure their compliance programs.”

New Verizon framework helps businesses navigate payment security compliance



Data protection and compliance present daily challenges. Many organizations believe they can use a one-size-fits-all script to achieve effective and sustainable data protection. However, in the real world, security is more complicated.



Simonetti continues, “Many organizations spend a lot of time and money creating data protection compliance programs, but often these are ineffective — looking good on paper but not able to withstand the scrutiny of a professional security assessment. We still see Chief Information Security Officers focusing on how to maintain baseline control activities rather than looking at data protection competency and maturity. What is needed is a clear and easy-to-understand navigational guide to help them deliver measurable results and predictable outcomes.”



In previous , Verizon developed methodology to help organizations manage their Data Protection Compliance Programs (DPCPs). These have now been combined to form the Verizon 9-5-4 Compliance Program Performance Framework — a guideline which helps develop and improve capability and process maturity.



The 9-5-4 Framework is designed to help organizations achieve repeatable, consistent and predictable outcomes by offering guidance on how to map, monitor and report the status of sustainability and effectiveness for each of the 9 Factors of Control Effectiveness and Sustainability — including control environment, control design, control risk, control robustness, control resilience, control lifecycle management, performance management, maturity measurement and self-assessment. This is across each of the essential 4 lines of assurance — individual accountability, risk management and compliance teams, internal audit, external audit and regulators — and is achieved by evaluating the 5 Constraints of Organizational Proficiency  — capacity, capability, competence, commitment and communication.

Link reinforced between lack of compliance and breaches



The report also includes data from the Verizon Threat Research Advisory Center (VTRAC), which demonstrates that a compliance program without the proper controls to protect data has a more than 95 percent probability of not being sustainable and is more likely to be a potential target of a cyberattack.



“For years, we have discussed the close correlation between the lack of PCI DSS compliance and cyber breaches,” concludes Simonetti. “In this year’s report, we included even more data from the Verizon VTRAC team, the authors of Verizon’s Data Breach Investigation series, to add more depth to this discussion. Our data shows that we have never investigated a payment card security data breach for a PCI DSS compliant organization. Compliance works! ”

About the Verizon 2019 Payment Security Report



This year's report focuses on performance visibility, control and maturity of DPCPs. It includes results from 302 PCI DSS engagements for a range of organizations, including Fortune 500 and large multinational firms in more than 60 countries. The assessments were conducted by Verizon's team of PCI Qualified Security Assessors (QSAs), as well as large third-party QSAs, including ControlScan, Foregenix, MegaplanIT and Schellman. 



Similar to series, the is based on actual casework with a specific focus on financial services (50.7 percent); IT services (17.5 percent), retail (19.9 percent) and hospitality (10.6 percent). Geographies include the Americas (50.0 percent), APAC (20.0 percent), and EMEA (30.0 percent).



Verizon Communications Inc. (NYSE, Nasdaq: VZ), headquartered in New York City, generated revenues of $130.9 billion in 2018. The company operates America’s most awarded wireless network and the nation’s premier all-fiber network, and delivers integrated solutions to businesses worldwide. With brands like Yahoo, TechCrunch and HuffPost, the company’s media group helps consumers stay informed and entertained, communicate and transact, while creating new ways for advertisers and partners to connect. Verizon’s corporate responsibility prioritizes the environmental, social and governance issues most relevant to its business and impact to society.

VERIZON’S ONLINE MEDIA CENTER: News releases, stories, media contacts and other resources are available at . News releases are also available through an RSS feed. To subscribe, visit .

Media Contacts:

Clare Ward (EMEA)

+44 (0) 118 905 2501



Nil Pritam (APAC)





Najuma Thorpe

+1.732.427.2304

 

EN
12/11/2019

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Verizon Communications Inc.

 PRESS RELEASE

Verizon to speak at Deutsche Bank Media, Internet & Telecom Conference...

Verizon to speak at Deutsche Bank Media, Internet & Telecom Conference on March 10 NEW YORK, March 05, 2026 (GLOBE NEWSWIRE) -- Tony Skiadas, executive vice president and chief financial officer at Verizon (NYSE, Nasdaq: VZ), is scheduled to speak at the Deutsche Bank Media, Internet & Telecom Conference on Tuesday, March 10, at 8:00 a.m. ET. The session will be webcast, with access instructions available on Verizon’s Investor Relations website, . Verizon Communications Inc. (NYSE, Nasdaq: VZ) powers and empowers how its millions of customers live, work and play, delivering on their dema...

David Barden ... (+2)
  • David Barden
  • Vikash Harlalka

Broadband Spring 2026 – A fine time for FWA

In this Broadband Spring report, we share a quick update on broadband industry trends from 4Q25 heading into 2026E. Industry net adds improved meaningfully in 4Q25 from a year ago but remained slightly below last year when we adjust for the loss of ACP. Net adds for the quarter were in line with the pre-pandemic norm but trailing twelve-month net adds remain below pre-pandemic levels. We take a deep-dive here into FWA’s continued strong momentum, by carrier, and how it fits into the overall broa...

Blair Levin
  • Blair Levin

C-Band Update: What Does the El Paso Airport Shutdown and Broadcaster ...

The El Paso Airport Shutdown does not on the surface reference FCC spectrum policy. But what happened is a tale of two agencies, that both rhymes with past conflicts between the FCC and FAA and raises questions about the wireless industry’s hope for access to the Upper C-Band. In this note, we address those questions and others raised by broadcasters seeking to limit the amount of spectrum that wireless can bid on in the upcoming C-Band auction.

Verizon Communications Inc: 1 director

A director at Verizon Communications Inc sold/sold after exercising options 225,000 shares at 49.614USD and the significance rating of the trade was 75/100. Is that information sufficient for you to make an investment decision? This report gives details of those trades and adds context and analysis to them such that you can judge whether these trading decisions are ones worth following. Included in the report is a detailed share price chart which plots discretionary trades by all the company's...

 PRESS RELEASE

Verizon to speak at Morgan Stanley Technology, Media & Telecom Confere...

Verizon to speak at Morgan Stanley Technology, Media & Telecom Conference on March 2 NEW YORK, Feb. 25, 2026 (GLOBE NEWSWIRE) -- Dan Schulman, CEO of Verizon (NYSE, Nasdaq: VZ), is scheduled to speak at the Morgan Stanley Technology, Media & Telecom Conference on Monday, March 2, at 12:20 p.m. PT / 3:20 p.m. ET. The session will be webcast, with access instructions available on Verizon’s Investor Relations website, . Verizon Communications Inc. (NYSE, Nasdaq: VZ) powers and empowers how its millions of customers live, work and play, delivering on their demand for mobility, reliable netwo...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch