Company Profile
- Company
- Large Enterprise Financial Services Company
- Size
- Large Enterprise
- Industry
- Financial Services
A large enterprise financial services organization uses PKWARE to keep sensitive data out of PCI DSS audit scope. Remediation is the mechanism: data that has been discovered and masked no longer counts as cardholder data in scope for assessment. The organization has maintained compliance this way for one to three years, and also reports obligations under GDPR, HIPAA and SOX.
Background
This case study of a Global 500 professional services company is based on a December 2021 survey of PKWARE customers by TechValidate, a third-party research service. The profiled company asked to have their name blinded to protect their confidentiality.
The study is a December 2021 TechValidate survey and the organization is unnamed. Its answers describe an ongoing compliance posture rather than a single project, which is the more useful signal in this category, because PCI DSS is reassessed every year and the real question is whether an approach survives that cycle.
Challenges
The business challenges that led the profiled company to evaluate and ultimately select PKWARE include experiencing issues with:
- PCI DSS compliance
- Other data compliance mandates (i.e., GDPR, CCPA, etc.)
- The surveyed organization has found it somewhat difficult to achieve or maintain PCI DSS compliance year over year.
- They must also comply with the following regulations:
- GDPR
- HIPAA
- SOX
The support team has done a great job of keeping us informed and the product has good functionality.
Finding PCI DSS somewhat difficult to maintain year over year is the most candid line in this study, and it describes the normal case rather than an unusual one. Scope grows quietly. A new report, an extract for a partner, a test environment refreshed from production, and cardholder data is sitting in a system nobody assessed last year. The difficulty is rarely the controls themselves. It is knowing where the data went.
Our Approach
PKWARE specifically helps achieve and/or maintain PCI DSS compliance by removing sensitive data from the audit scope via remediation.
Use Cases
The surveyed company utilizes the following to achieve and/or maintain PCI DSS compliance:
- PK Discovery
- PK Masking
Reducing scope is a structurally different strategy from strengthening controls. Every system in scope has to be assessed, documented and reassessed each year, so the cost of compliance scales with the number of places the data is allowed to exist. Removing the data, rather than hardening every location that holds it, lowers that cost permanently instead of annually.
Results
PKWARE specifically helps achieve and/or maintain PCI DSS compliance by:
- Removing sensitive data from the audit scope via remediation
- The surveyed organization has worked with PKWARE solutions to maintain PCI DSS compliance for 1 – 3 years.
- The surveyed organization is confident that their current cybersecurity setup can scale with company growth and can adapt to fit the updates involved in future PCI DSS updates.
Four regimes at once is the wider point. PCI DSS, GDPR, HIPAA and SOX ask different questions and share one prerequisite, which is knowing what data exists and where it lives. An organization that can answer that once can answer it for each of them, and that is why discovery tends to be the component that pays for itself across an entire compliance program. The organization also reports confidence that its current setup will scale with growth and absorb future PCI DSS revisions, which is a statement about the approach rather than about the current version of the standard.
