Understanding PCI Compliance with Jerry Hughes at QSC24
PCI compliance is crucial for maintaining security in organizations. Jerry Hughes discusses the recent rollout of PCI version 4.0, which includes 64 major changes. Continuous compliance and targeted risk assessments are essential as security challenges evolve. He critiques current password security measures and raises concerns about breach disclosures and consumer protection laws.
Transcript
This is Textron tv. Hey everyone. We're back in San Diego.
It's been a crazy two days here. I, I don't even know how many interviews we've done, but it it's a lot. And we've had a real, a good spectrum of different topics, but this is one we haven't spoken about.
It's more than I haven't spoken about probably in two, three years to be real. PCI. Right?
The original big stick in security, getting people to actually do something about their security. I want to introduce you to Jerry Hughes of Compass IT Compliance. And first of all, Jerry, welcome to Text Drunk You, man.
It's great. Appreciate it you here. I appreciate it.
Thank you for having us. No, it's our pleasure. Jerry, did I tell our audience a little bit about your personal story?
Oh, sure, sure. So I'm an IT security kind of a geek, right? I was IT security professional my whole life, you know, and I've been working with different organizations helping them become compliant, right?
And over the years before the hair was gray, uh, I At least you got here, man. Be happy. We've seen changes.
We've seen changes, right? You know, sooner you get controls in place and the threat landscape changes everything. So PCI, what a good time for the topic.
This is the biggest change in the 17 years I've been a qualified security assessor. Really? Oh, it's unbelievable.
I, I want to jump into that, but before we do, tell us a little bit about Compass. Sure. So, uh, compass IT compliance, I'm one of the co-founders, my business partner, uh, bill Palm and I started this thing really over 20 years ago.
We ended it as Lighthouse Computer Services and we, we rebranded 15 years ago. Now is Compass. And it's been a great ride.
I mean, all the changes out there in the world, if ev you know, we've grown the team and, you know, been through two banking crisis, uh, COVID-19, you know, what, what else could you, what more challenges And we've, we've grown to about 45 employees. Well, but You know, if you had two wars going on on your scorecard, you might have Right. Might have win some money there.
Yeah. Yeah. Uh, where are you guys based?
So We're based out of North Providence, Rhode Island. Oh, I love it. Good, good people.
There's a great Place. Yeah. Yeah.
Providence. Sure. Providence is nice too.
I, we were up in the summer. Nice. Um, alright.
Actually before we go further too, if people want to go look up the website, what's the website? Yes, It's sure. com.
com. com encompasses with two S's. Alright, Jerry, let's jump in.
So, big changes, big changes. The pci, I tell us about it. Big changes.
0. Yes. And it is significant.
64 major changes. And of those 13 went right into effect and the other 51 are going to go into effect by March 31st, 2025, All, all 51 will go in or it's phased in. Yeah, nope.
Uh, it jumps right from the 13 going in immediately and then the additional, uh, uh, 51 will jump right in. So it's, I, you know, uh, organizations need to start early planning and preparing for, we perform a number of different gap analysis to see where you are relative to where you need based on the changes that PCI brings forward. So it's, it's a lot.
And if you start late Yeah, it is. Yeah. If you start late, Why, why, why all 51 at that time?
That's kind like arbitrary. Yeah. So actually start with 13 right away and then they gave you, give you almost a year really from the time it was rolled out.
You got a year to kind of get your arms around it. And, and some of those are really big though. So we always, the council's always recommended that you get with A-Q-Q-S-A company.
That's what we do. And we consult with organizations, say, Hey listen, these changes are big. Lemme show you them and show you where you need to be again, with based on the changes.
And we try to help you get there. And it's, uh, it's fun. I like what we do.
We help organizations. Yep. So there was a time where I did a lot of work in the PCI space and one of the things I remember most about it is, you know, you had level one merchants, level four merchants, and a level four merchant.
They were small guys. They just had to fill out their self-assessment questionnaire and go on their way level one guys needed a QSA to get their ACT together's. Correct.
Is that still, That is still in, in, in place. And that's covered by the brands, right? So yeah.
So the primary vans, visa, MasterCard, American Express, discover, jcb Discover, yeah. And J ccb. Yep.
And those are still driving the, the, the DSS but the enforcement comes from the acquiring banks, not the council. Yes. So Visa has the, they're the ones who set the limit of 6 million transactions and over by any one brand and you're level one and that's where the big, the big Work comes in.
That's it comes into, Oh yeah. So if I asked you to summarize, you know, look, there's 64 Big ones, But give me the top five. I will, I'll tell you one of the biggest ones, and this is great for this con uh, conference because we've been partners with Qualys since, gosh, for 17 years as well.
And, and one of the biggest ones is the requirement for authenticated scans. So that's a big, that's a big game changer. And, and they've got a great platform that they've had out for a little while now, which allows us to deal with cloud computing.
So you essentially installing agents on systems, not to go too geeky, but installing agents on Systems. No, it's just geeky talk. Yeah.
Because really the problem is yeah. Scanning cloud systems, unless you got an agent on there for sure, you're not getting in. That's right.
That's right. And it's the cloud provider who controls That. Sure.
And and, and honestly, as you look at it, it makes sense, right? You, you need these big providers, these cloud solutions takes a lot of the other risk away. It shifts the risk to them to a degree.
Well, it's a hyper scale. That's right. That's right.
And so I can't, I probably can't name a client or two. There's not too many clients that aren't using any kind of a cloud Solution For sure. For some part of it.
For sure. Yeah. So that's, that platform is phenomenal.
And I tell you what, it was exciting too. One of the new ones that I missed, I had some business calls, but I'll tell you what I'm excited about the AI uh, solution. Was it total, total ai?
Have you guys seen this thing? Yes. Unbelievable.
I, uh, I was talking to folks over dinner last night about it. It is, it's gonna be a game changer. Because when, when I was asked before like, Hey, what do you see for new technologies, new challenges and ai, everybody's using it.
It sucks. The oxygen addict, oh my gosh. Conversation.
Right? But people use, it's like with any technology people use and misuse it. 'cause you know why?
Here's why you're very excited. You got a new product, new offering, new delivery channel. I wanna get it out there.
But, but I'm, I'm a, I'm a buzzkill 'cause I'm like, well, slow down. We wanna do it. We wanna do it in a safe, secure way.
So we wanna risk assess before we go live. We wanna data classify it appropriately so we know what, what kind of data it's gonna have, what kinda risk it brings to the Table. Where did that data come from?
Exactly, Exactly. So the full life cycle of the data. So you're mapping data flows and encryption at rest and emotion.
It's, it's huge. It is it exciting. It's gonna be a big thing.
It really is. So we've got accredited skins. Yes.
What are some of the other big Points? Uh, so, and this is unfortunately a long time in coming. I'm like, you know, passwords, they, they only required a length of seven for a while until just now.
Finally they say, let's go to 12. You know, I mean that, this should have been like that forever. But, And look, I I, so I've been in security 30 years.
You said that I'm not always one of these people, but um, for the life of me, I don't understand why we still use passwords. Right. Pass.
I know. I don't know. I I tell you it's, I can't answer that either.
We need stronger pass phrases. At least One of the changes. Your pain in the end.
Oh, for sure. Look, there's no, the average person, forget the average company. Yeah.
The average per person has 150 plus passwords. Yes. They want you to have a unique password for all 150.
Change 'em every 90 days. They gotta be 12 characters plus loans. Oh.
And Don't write 'em down. Don't write 'em down and don't write 'em down. You gotta use a password manager, which got hacked three times already.
That's I I've got. And, and so Yeah. There's gotta be a better mouse trap here.
I'll tell you what, one of the big changes that came in they bring up too, is well they've had MFA forever multifactor authentic issues. Yes. And now they finally enforce it on all user access to the cardholder data.
Amen. It's time. It's about time.
Right. Uh, the other Thing I like that I like pass keys. Sure.
Yep. And pass phrases, long pass phrases. Yep.
I think these things are gonna help us protect those environments. 'cause you're right, password is useless. I mean, it's too easy to hack and it's been done a million times.
I don't need to show you that. Right? Yep.
So that's one of the other bigger, bigger changes that are out there with it. And, and I think that will help organizations reduce the, their risk to reasonable levels. You know what I mean?
Mm-Hmm. Let me give you another thing. My, these are Alan's pet peeves with PCI.
Okay, Let's go. We can talk all day on this hour, trust me. Alright.
So this whole concept of anyone who has ever breached was not PCI compliant because the fact you were breached me not PCI compliant. Oh my God. This guy's great.
Yeah. So, but that's, that's nonsense. I'm, I I'm gonna pull, I'm gonna call BS tube.
And, and when I read that, and that's truly what he said was accurate, exactly what the council said. And they said that, that if you, if you compromise, it's 'cause you weren't in PI compliant. Right.
And the theory, you can kinda see what they mean by that. I, I get it. But q in time tested.
I know it's a moment in time. So my biggest advice to anybody listening to this thing is, is remember, it's not a moment in time. You need to be continuously compliant.
It's not just 'cause I came in and I attested to your compliance at that day when I left point in time. No, it's a, it's 365 days a year. 24 hours each day.
And you have to be maintain the compliance. The other big thing you're asking to changes one of the other ones is what they're calling targeted risk assessments. And this is where I love this.
Yeah. Right. Risk based, who doesn't, I mean, I've been doing it audit in all verticals for years.
And the banking industry I came from always was using risk-based approach. And finally, the PCI is really embracing it more. They always had requirements in section 12 for having Yes.
Risk management programmed. And they just amped up and he said, look, if you're looking to roll out a new product or service, assess it in advance. Right.
Let's risk make it makes sense. Why go live? You'll get there, but do it safely.
Do it securely and then you ready to roll it out. That's just common sense. I think.
I, I I don't disagree with you at all, man. Here's a, uh, what about disclosure? Anything new at disclosure requirements?
So there, You mean there's a lot of, there's, there's Like of a, of a breach or something. Oh, Breach. That's, that's been in place for a while.
But there are, that's Much string. We do need that. Gotta be honest with you.
Absolutely. Jerry. Every week I get about these many letters.
Yeah. Hey, you've been the victim of a breach. I'm giving you a year free of experience.
I know, right. Or Equifax or there's some new one now that does all three. Great.
But meanwhile, my social security numbers up there and everything Else's one of my businesses, compass Cyber guard, the head of it, Jesse Roberts is phenomenal. He, he, he could scare us both. And I've been in this and you've been in this industry forever.
Yeah. He goes on the dark web through special browsers, brings up the businesses that do these ransomware attacks. And you could find information on almost anything.
Everything. It is Scary. It's, it is.
Yeah. You buy it and you got it. And, and, and it's, it's, But I'm, I'm concerned our company's disclosing.
Like they've made it, they've made it painless to disclose the breach. Yes. You know, but are they, it's getting better.
You think it's, I think it's getting a little better. And it's not just with PCI, it's other, you know, verticals with confidential information. So as consumers, we're not just working in the world of PCI, we're consumers too at home.
We use business, uh, you know, information and shared all the time. And I wanna know, it's protected when I, when I put information. I know you do.
And, and, and the laws have changed to protect it. These international laws on privacy like GDPR Right. They other state privacy rules.
Right. Yeah. Some states have some, it's getting don't, It's getting better.
It's getting a lot better now. So, so I, we're moving in the right direction. We're not there yet.
For sure. So, so here's another question I always had. So whether you wanna call 'em arbitrary or not, we had these thresholds that made you a level one or a level two.
And some companies, if they were smart enough, were able to skirt. Yeah. Right.
I did a couple of transactions with this processor, but I had another processor Sure. Kept me under a six level. Yeah, Sure.
Kept me under that level one. How do we, how do you, You know, so at the end of the day, it's this, um, because I'll, I'll tell you. So even, uh, uh, something that's under the threshold that requires a report on compliance audit, uh, if you care about your business and the consumers that you serve, you wanna be secure.
Absolute, absolute. The security is compliance. We can check boxes all day long.
I can be compliant, but am I secure? And, and the answer probably no. If I'm just doing cutting the corners, going a bare minimum.
So, so risk based, take that risk based approach we talked about earlier. Look at all the risks in your business. Where's my confidential information at rest and in motion and the network logical world.
And then in the physical environment in my offices, do I have any hard copies? Do I have any servers or systems? Where's my cloud providers I'm utilizing, right?
And, and when you look at it that way and you map the flow, it becomes a little easier and you shrink that footprint. That's the first approach is like, do I even need that data? If I don't, let's shrink it down and then I, I have a better chance at controlling and minimizing my risk.
That's just makes good sense. I I think it does. I think where the disconnect came in is, and I'm not saying you, but for a lot of companies, the thought of calling in the QSA and going through that process was a expensive Sure.
B, really time consuming. And c, what's gonna really upset the apple cart in terms Oh, for sure. Of the way I do things.
Yeah. And, and, and they try to. Yeah.
No, of course. You see, that's what people try to do. Sure.
They avoid. It's like anything though, right. You look at this, uh, you know, different, different things that happen to an environment that these hurricanes, God bless these people, but the Changes, we live a party.
You don't have to tell me. Yeah. I'm sorry my heart goes out.
But I'll tell you, people put up protections after the fact, sadly. You know what I mean? Let's be Proactive.
That's what gets religion Know. I know. Let's, let's be, let's be proactive.
Let's look at these things before and try to anticipate, try to risk assess, try to get in front of as much as we can. We're not gonna see everything. But if we, We make that effort.
Right. You know, when I, I started my first security company in 2001 venture backed company. Nice.
Within a year I learned that my best customer was someone who had a breach. Yeah. Sadly.
Because now they got religion. They were in buying things. You are Right.
Right. And I came up with the idea of letting some of the hackers in our company maybe go breach some people, we won't make anything public. We'll just call and say, Hey, you know, uh, got your customer list.
Maybe there you Right. You should do something. You wind up in jail, dude.
Yout do that. I was gonna, That's a red Michael over here. I gotta be honest with You.
But that be a real anti flag. Yeah. But that's, that's kind of the paradox of the security industry.
It really is. That's what it takes. It, it Sadly, That's what it takes.
Takes. And you know, it, you live this far For sure. But I was say before, even though if you're below it, if I'm making a business decision and I re I recommend this when I talk with clients about when they choose, they have a choice, right?
Service providers, maybe two are almost the same one, even though they're below, below the threshold, right. Less than 6 million. They don't need a rock.
They can get away with a self-assessment. And you have one that did the self-assessment. You have one that did the audit.
Who are you going with? Come on Day long ly all day long. But part of that is, is is you remember that commercial size sims, an educated consumer, was our best customer.
Yeah. Part of that is educating the consumers to say, Hey, make sure you're merchandise Rock. For sure.
For sure. And I tell you, we we, we do a lot of work with privacy too. And I'll tell you what about that when you see about identity theft way back when people first heard about it.
Like what the, what is that? Mm-Hmm. And you see, and you see, but now that the world is more educated, people understand now.
'cause people have lost their identity. And it was, it was criminal in the sense that they were used, used it for not just money, but they also use it to committ crimes. It ruined.
And you could be, yeah. Now people And, and, but, and, and law enforcement didn't have enough education themselves. They were, they were behind eight ball.
Absolutely. So at least now they didn't know what they were doing. That's Right.
At least now the industry and the, and the agencies rather, that are involved, are educated too. And they, and they go, look, that's real. Let's see what we can do.
And they'll investigate. So it's, it's getting better. We, we got a long way to go.
And then we know sooner we get there, Hey, what's Ai? Then there's some What's AI stuff? Come on.
That's a whole nother world, man. We talk about it every day. Fun.
Anyway. Hey Jerry, man, thank you so much. You're pleasure man.
Man. Yeah. I get back into it just 'cause I don't have enough To do here.
I could do this for another couple hours. I'm sure you get, man. Thank you.
com. Jerry Hughes here on Tech Trunk tv. We're gonna take a break.
We're live at Qualis QSC.