What Are the Penalties for Noncompliance with PCIDSS
If you fail to comply with the data security standards contained within CISP/PCI, the credit card company might issue a fine on your banking member, impose restrictions on your company, or both.
One requirement of PCI-DSS is that the merchant or service provider must immediately report any suspected or confirmed loss or theft of any material or data that might contain cardholder data. The merchant must also take immediate action to investigate the incident and limit the exposure of the compromise.
If a merchant fails to immediately report a suspected or confirmed security breach, the member institution can be fined up to $100,000 per incident. If, at the time of the compromise, the merchant was not compliant with the PCI-DSS requirements, the fine can increase to $500,000 per incident.
As an incentive toward compliance, PCI-DSS provides Safe Harbor to protect the merchant, member, or service provider. This means that if at the time of a compromise, the merchant, member, or service provider was fully compliant with the PCI-DSS requirements, and the incident was reported immediately, the provider is protected from fines and compliance exposure by the credit card company.
Continue reading here: Requirement 1 Install and Maintain a Firewall Configuration to Protect Data
Was this article helpful?