Home » Archive

Articles in the Alerts Category

Alerts, PCI News »

[18 Sep 2009 | | ]

I’m posting this up here again - I realize that a lot of people have already seen this, so it’s not new, but since some very detailed questions popped up in a conversation this week regarding wireless and PCI I thought I’d put it out there again…
Information Supplements - PCI Security Standards Council.

Alerts, Conferences / Webinars, headline »

[18 Sep 2009 | | ]
Heading out to PCI Community Meeting

If anyone is heading out to the PCI Community Meeting in Las Vegas next week and wants to connect, let me know (best way to connect is via email. Several of us from NetSPI are heading out to participate in the meeting and I’m looking forward to an informative meeting.
I’ll be at the meeting Tuesday through Thursday evening so let me know. I’ll also try post after getting back from the meeting with anything interesting or useful that I find out. One of the other …

Alerts, Interesting, PCI Philosophy / Approach »

[22 Jul 2009 | | ]

Sorry - I have been a bit out-of-pocket lately and I haven’t been able to post as frequently as I would like (I’m shooting for basically once per week at least and hopefully a good bit more.)
That being said- this isn’t going to be much of a post - just a quick note to mention that NetSPI’s corporate blog is finally up!   Yeah!
It went live this week, so the volume of content is minimal, but the first posts that are up are very informative and will help to provide some …

Alerts »

[11 Jun 2009 | | ]

Changed the template today (needed something different) and I have some stuff to do still - the Archives are currently not accessible and the RSS feed needs to come back to the top…  Otherwise I think it’s a little easier to read…

Alerts, Interesting, PCI News, PCI Philosophy / Approach, Retailers »

[31 Mar 2009 | | ]

So the council sat down in front of Congress today…
Cybersecurity hearing highlights inadequacy of PCI DSS.

Alerts, Interesting, PCI News, PCI Philosophy / Approach, Vendors »

[13 Mar 2009 | | ]

Quick statement from RBS in response to a request for information from the Office of Inadequate Security Blog.
RBS WorldPay statement | Office of Inadequate Security.

Alerts, Interesting, PCI News, PCI Philosophy / Approach, Vendors »

[5 Mar 2009 | | ]

I’m glad to see that the Council is following through on their commitment to hold assessors to a certain level of work and expertise.
Sadly we run into low-balling competition all the time and it’s sometimes hard to explain to potential clients that there is, really, a difference between what NetSPI provides and what the low-balling competition is actually delivering.
PCI QSA assurance program penalizes assessors.

Alerts, Conferences / Webinars, PED / Payment Terminals, Vendors »

[3 Mar 2009 | | ]

The webinar that NetSPI put on with VeriFone is up on the VeriFone webex repository.  It requires registration, but they have been very careful with the use of the registration information that they have gathered, so I’m not concerned about it.
The webinar was built to answer some questions for merchants in particular, so this isn’t an overly technical presentation, but it should help shed some light on how PA-DSS differs from PABP and why retailers and online merchants should care about the standard.  It also showcases some of VeriFone’s solutions …

Alerts, PCI News »

[24 Feb 2009 | | ]

Visa and MasterCard Issue New Breach Warning | Threat Level from Wired.com.
I wonder who it’s going to be….

Alerts, Interesting, PCI News, Vendors »

[21 Jan 2009 | | ]

Here’s another article on the Heartland breach - this one from the NYT.  It’s interesting as Heartland’s founder gave a presentation at the VeriFone payments conference in the fall pushing for some of the end-to-end encryption technology that companies (like VeriFone) are starting to implement.
I wonder if that solution would have successfully addressed this attack.
It is interesting how, at the end of this article, they start to call into question the effectiveness of the whole PCI effort.  Now, if you have read anything that I’ve put up on this blog, …