PCI DSS Compliance

Encryption, Hashing, and Tokenization

Challenges in Payment Card Security

After every Experian industry forecast for the last five years, the number of data breaches will continue to rise. Studies by the Ponemon Institute on data breaches show that the average cost to a U.S. company is over $200 per compromised customer record.

With an average of 29,000 compromised records per incident, the cost of a data breach in this country can exceed $5 million. In 2023 alone, the global average was $4.45 million per data breach, according to same Ponemon study, which IBM commissions annually.

In addition to the considerable financial damage caused by a data breach, there is an acute loss of trust between a company and its customers. Both the security breach and its consequences are usually widely known and long remembered.

And although the most expensive data breaches occur in healthcare, the protection of payment card data remains an important issue, as credit card numbers and personal account holder data are regularly victims of hacking, theft, fraud, and other misuse.

According to this SecurityMetrics Analysis Despite the fact that 12 documented requirements of the PCI 2.0 Data Security Standard (DSS) had been largely implemented, external (50 %) and internal (33 %) data breaches continued to occur in the payment card industry (PCI). The trend is worsening as the definitions in the 3.x and 4.x standards are being expanded to cover more forms of personal data.

PCI DSS Solutions

Data discovery and masking features in the products of IRI Data Protector Suite – or the IRI Voracity platform - help mitigate or even neutralize the impact of data breaches and support BFSI companies and other organizations managing credit card data in complying with PCI DSS requirements. They Find and protect the primary account number (PAN) and other credit card number values (as well as other sensitive data) in multiple data sources.

These IRI data masking tools support PCI DSS rules for data-centric security through Encryption, SHA-2 cryptographic Hashing and Tokenization.

In structured data sources such as well-formed relational database columns and fields in flat files IRI FieldShield-users their choice of Data classification, Suchmethoden und datenzentrischen Security features on PANs and other sensitive data in an intuitive, efficient, and flexible way within Eclipse. For example, setting an encryption cipher with a passphrase is done in a simple dialog:

Here, to comply with PCI DSS and ensure no changes to the table or database structure are required, a Format-preserving encryption used. Furthermore, retaining the original appearance of the values can trick hackers into believing they have real PANs.
 

These simple yet powerful static data masking functions can also help you limit the financial and operational impact of a data breach. For example, Steam, a platform for game distribution, was the victim of a data breach. As significant as the breach was, the overall impact on Steam was limited because the credit card values were encrypted.

FieldShield and IRI's other data masking tools (DarkShield for various forms of semi- and unstructured data and CellShield (for Excel spreadsheets) – the data classification, scanning, and data masking rules are shared – offer simplicity, affordability, and security by discovering and protecting credit card data and other personally identifiable information at rest. They help Organizations like this, to meet PCI DSS requirements for protecting stored cardholder data while mitigating the risk of data loss and secure, intelligent Test data targets to provide.

It is also possible to PAN or PII in a dynamic data masking context to encrypt/decrypt or to process, for example by an application that queries a database.