<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Toolkit &#187; Costs of A Breach</title>
	<atom:link href="http://www.pcitoolkit.com/category/costsofabreach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcitoolkit.com</link>
	<description>Powered by CSRSI®</description>
	<lastBuildDate>Tue, 26 Apr 2011 04:20:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PCI Breach Costs</title>
		<link>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 16:26:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Costs of A Breach]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=133</guid>
		<description><![CDATA[Total direct cost to a merchant from a PCI event]]></description>
			<content:encoded><![CDATA[<p>Total direct cost to a merchant from a PCI event include:</p>
<ul>
<li> Card replacement costs now averaging about $4 per item</li>
<li>Compliance fines now ranging from about $5,000 to $50,000<br />
per event for a small merchant (III, IV)</li>
<li>Cost of forensic examination averaging between $25,000 		and $35,000 per event for Level III and IV  merchants</li>
<li>Additional fines for actual fraudulent utilization of stolen PAN 		varies</li>
</ul>
<p><span style="text-decoration: underline;">Case Study:</span></p>
<ul>
<li><span style="font-family: Arial; color: black;">A small carp present retailer was breached. The retailer had filled out a self assessment form and attested that the information was true and correct to the acquirer. </span></li>
<li><span style="font-family: Arial; color: black;">The merchant was found to have stored over 2,000 credit card numbers in an accounting system for “reference” and to bill clients “if they forgot there credit card number”. </span></li>
<li><span style="font-family: Arial; color: black;">The file was accessed and the credit card numbers were stolen when during the course of a robbery the CPU was stolen. A CPP (common point of purchase) analysis of credit cards revealed the location of the theft.</span></li>
</ul>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">Replacement Cost                 $ 5,000</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Compliance Fine                   $ 12,500</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Forensic Examination            $ 25,000</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Card Utilization Fines </span><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">$ 74,398.47</span></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> </span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> TOTAL $116,898.47</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> </span></p>
<ul>
<li><span style="font-family: Arial; color: black;">The merchant also sustained significant reputational cost due to adverse publicity, legal fees, loss of business and other expenses.</span></li>
<li><span style="font-family: Arial; color: black;">The merchant filed for protection under bankruptcy</span></li>
<li><span style="font-family: Arial; color: black;">The amounts due were assessed to the ISO by the acquirer.</span></li>
<li><span style="font-family: Arial; color: black;">Visa fined the ISO additional fees following an examination of ISO practices as it relates to PCI adoption and plan for portfolio under VBR 07508 after the initial event.</span></li>
<li><span style="font-family: Arial; color: black;">ISO sustained a financial loss of </span><span style="font-family: Arial; color: black; font-weight: bold;">$189,354.45</span></li>
</ul>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black; font-weight: bold;">Study: Maine Bureau of Financial Institutions January 2009</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">Study design</span></span><span style="font-family: Arial; color: black;">: Cost of TJX and Hannaford breach borne by Maine chartered banks and credit unions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><strong>TJX<br />
</strong></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">52 Institutions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">64,825 Accounts</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">$485,000 Recovery*</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><strong>Hannaford</strong></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">71 Institutions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">243.599 Accounts</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">$4,500,000 Recovery*</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">*</span><span style="font-family: Arial; color: black; font-style: italic;">Recovery cost: investigation, communication, reissuance and net fraud</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black; font-style: italic;"><br />
</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">Study Design</span></span><span style="font-family: Arial; color: black;">: Cost of compromise to 43 companies in 2008. Each company volunteered under the condition of anonymity.</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p><!-- tr 	{mso-height-source:auto;} col 	{mso-width-source:auto;} td 	{padding-top:1.0px; 	padding-right:1.0px; 	padding-left:1.0px; 	mso-ignore:padding; 	color:windowtext; 	font-size:18.0pt; 	font-weight:400; 	font-style:normal; 	text-decoration:none; 	font-family:Arial; 	mso-generic-font-family:auto; 	mso-font-charset:0; 	text-align:general; 	vertical-align:bottom; 	border:none; 	mso-background-source:auto; 	mso-pattern:auto;} .oa1 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:.75pt solid black; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa2 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:none; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa3 	{border-top:.75pt solid black; 	border-right:.75pt solid black; 	border-bottom:.75pt solid black; 	border-left:none; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa4 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:.75pt solid black; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa5 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa6 	{border-top:.75pt solid black; 	border-right:.75pt solid black; 	border-bottom:.75pt solid black; 	border-left:none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} --></p>
<table style="border-collapse: collapse; height: 149px;" border="0" cellspacing="0" cellpadding="0" width="853">
<col style="width: 120pt;" span="4" width="160"></col>
<tbody>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">YEAR</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">Cost per Breach</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">Cost per record</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">External Third Party</span></span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2008</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$6.6 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$202</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">44%</span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2007</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; direction: ltr; unicode-bidi: embed; vertical-align: baseline; text-align: center;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$6.3 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$193</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">40%</span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2006</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$4.7 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$186</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; direction: ltr; unicode-bidi: embed; vertical-align: baseline; text-align: center;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">29%</span></p>
</td>
</tr>
</tbody>
</table>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><br />
</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

