Skip to content
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
Book a demo
Contact Us
Book a DemoContact Us
  1. Resources
  2. Collateral

PCI DSS Compliance Comes Under the Spotlight in Verizon’s 2020 Payment Security Report

Oct 19, 2020
Graphic containing the cover of Verizon's 2020 Payment Security Report in a circle, and the title_ PCI DSS Compliance Comes Under the Spotlight in Verizon's 2020 Payment Security Report
  • Copied!

Verizon’s 2020 Payment Security Report makes for rather sober reading, particularly if you’re a CISO responsible for designing, implementing and executing data security compliance programs.

High-Level Overview

The report found that in 2019, only 27.9% of organizations assessed for the report had maintained PCI DSS compliance during their interim compliance validation.  This means that nearly three quarters of companies who were previously assessed as fully compliant with PCI DSS, were not compliant when they had their interim validation.

This is the third consecutive year that compliance rates have fallen, with fewer and fewer organizations demonstrating the ability to keep a minimum baseline of security controls in place. It’s clear from the 140-page report that the Retail, Financial and Hospitality sectors are particularly bad at staying compliant.

Whilst it is still Requirement 11 – Security Testing – that causes companies the most difficulty, Verizon point to a general lack of leadership and strategic support at management level as the major contributing factor.

Were The Results The Same Across The World?

When considering a breakdown by country for companies’ interim compliance validation, the 2020 Payment Security Report found that US organizations are far behind counterparts in other global regions when it comes to being fully compliant at this interim stage following a prior compliance with PCI DSS requirements. In fact, the report identified that just 8.5% of those examined maintained their compliance with the standard in full.  EMEA followed at 40.5%, while Asia Pacific leads the way of companies maintaining compliance with an 87% compliance rate.

What is clear is that CISOs are facing a raft of challenges. The report highlights how CISOs are being drawn into responding to reactionary security incidents – firefighting– rather than having the time to take a broad, proactive and planned strategic stance.

RELATED: AUTHOR OF VERIZON 2020 PAYMENT SECURITY REPORT, CISKE VAN OOSTEN, PRESENTS PAYMENTS 2021 CLOSING KEYNOTE

Plus, with workforces transitioning to remote working environments almost overnight, an additional layer of security management was added to organizations’ action lists to ensure any potential vulnerabilities are dealt with.

Does this imply that companies are not investing enough in expanding their security teams at the rate required to support the increasing risks facing organizations today?

Not All Bad

A positive trend identified in the 2020 Payment Security Report states that around 4 out of 10 firms are expected to increase IT budgets – predominantly to replace outdated infrastructure, escalate security concerns or support an increase in employee numbers.

Whilst these investments will naturally have a positive impact on an organization’s security, the report also found that only 7% of these budgets had been earmarked for security specifically.

When you consider the potential risks to a business’s reputation and revenues, should a security breach or hack occur, it seems somewhat disproportionate.

With technology evolving, digital transformation occurring across many industry sectors, and the huge shifts we’ve seen following the onset of the Coronavirus pandemic, CISOs have had to identify the priority security components – those considered ‘most critical’ in this ever-changing landscape – and react accordingly.

The 2020 PAyment Security Report OFfers A Reminder

Ultimately, the 2020 Payment Security Report shows that maintaining once-achieved PCI compliance is a significant challenge. Further, continued compliance has been generally slipping.

Of course, there is still a long way for many organizations to go to achieve full PCI DSS compliance in the first place.

In today’s uncertain world where cybercriminals are increasingly taking advantage of the fallout from the pandemic, the report offers a timely and detailed reminder. There are steps CISOs – and the organizations they serve – need to take to keep payment security front of mind. In taking them, they will benefit from safeguarding reputations and building trust with consumers.

View our 2020 payment security Report infographic

Verizon's 2020 Payment Security Report found that only 27.9% of assessed organisations had maintained full PCI DSS compliance through the year — the fourth consecutive annual decline. Retail performed worst of any sector at 8.5%, while Asia Pacific led the regions at 87%, well ahead of the US and EMEA. This infographic pulls out the figures that matter most to contact centre and payment security teams. The gap between achieving compliance and sustaining it is the central finding, and the strongest argument for reducing scope rather than maintaining more controls.

Verizon_2020_Payment_Security_Report_Infographic_NA.pdfDownload Infographic

Like what you see? Share with a friend.

  • Copied!
Tags: Compliance Contact Center PCI DSS

Lastest News, Blogs, Events and More

  • Pause and Resume Call Recording: Calculating the Risk
    Collateral

    Pause and Resume Call Recording: Calculating the Risk

    Learn More
  • Starting Your PCI Compliance Journey
    Collateral

    Starting Your PCI Compliance Journey

    Learn More
  • Keep Calm and Simplify: Contact Center Best Practices in the Era of PCI DSS 4.0
    Collateral

    Keep Calm and Simplify: Contact Center Best Practices in the Era of PCI DSS 4.0

    Learn More
  • This is Canada 2022: The State of Security through the Eyes of Canadian Consumers Today
    Collateral

    This is Canada 2022: The State of Security through the Eyes of Canadian Consumers Today

    Learn More

Discover the Power of PCI Pal. Trust When It Matters Most.

Book a Demo
  • X
  • LinkedIn
  • YouTube

Products

  • Platform
  • Key to Pay
  • Click to Pay
  • Speak to Pay
  • Customer Authentication
  • Fraud Management
  • Services and Support

Outcomes

  • Financial Services
  • Retail
  • Government
  • Utilities
  • Healthcare
  • Travel & Leisure
  • BPO / Outsourced
  • Logistics & Shipping
  • Not For Profit

Partner Ecosystem

  • Partner Directory
  • Partner Hub

Resources

  • Blogs
  • Collateral
  • Events
  • Media Library
  • News
  • Success Stories
  • PCI Pal Glossary

Company

  • About Us
  • Careers
  • Investors
  • Trust Center

© 2026. PCI Pal. All rights reserved. Company Registration Number: 3869545

  • Cookie Policy
  • Privacy Policy
  • Terms of Use
  • Modern Slavery Act
  • Carbon Reduction Plan
  • Recruitment Data Protection Notice