As the saying goes: buy cheap, pay twice. In the case of cyber security, that second payment can include a hefty fine, legal action and long-term reputational damage.

We see this all the time as Payments Forensic Investigators (PFIs), called in to investigate the cause of data breaches in Australian organisations.

On one occasion, an organisation received a renewal of their compliance certificate during our investigation of a data breach in their systems! The vendor that gave it to them promised a certificate attesting to their compliance with the Payment Card Industry Data Security Standard (PCI DSS). That certificate cost less than AU$1000 and was a self-assessment only. It might have satisfied their bank, who are required to ensure their card-accepting customers are PCI DSS compliant. It might have made the organisation feel good and even look good in front of prospective customers. But the breach proved what their board likely feared: compliance doesn’t mean security. They’d bought cheap and self-assessed without any objective, independent review.

As a result, they were hit with large fine over a thousand times the cost of their cheap certificate. Under revised Australian regulations now in place, that could have been up to AU$50 million or 30% of adjusted turnover during the breach period – whichever figure is larger. 

That’s what happens when you just buy compliance rather than build security.

Why Some Organisations Cut Corners: The Problem with Compliance Frameworks

PCI DSS is one of the world’s most recognised data security standards. It’s expected of every organisation that accepts payment cards and is enforced to varying degrees and rigour by Australian banks.

PCI DSS is binary. You either meet the requirements, or you don’t. What the standard doesn’t tell you is whether the specific PCI DSS requirements (controls) that you think you are meeting  that got you over the line on your own compliance sign off will actually stop an attacker. A control can be technically satisfied and operationally useless. Evidence gets pulled together at “self-attested” audit time, the certificate arrives, and then nothing happens until the next assessment rolls around. Meanwhile, controls aren’t actively managed. Monitoring lapses and patches stop happening on time – creating vulnerabilities that make you an easy target for cyber criminals.

As a Payment Forensic Investigator, we’ve seen the aftermath. We’ve investigated breaches at organisations that were self-attesting and could demonstrate they were compliant on paper. The self-attested third-party certificate was real, but actual compliance was not, and it didn’t stop a breach from happening.

Cyber security is a 24/7/365 job. And long as you’re in business, it’s never “complete”.

Regulators and the card brands will come down hard on any organisation they deem hasn’t done enough to prevent a data breach. Compliance on paper isn’t enough evidence anymore. In our PFI investigations, we have never found any breached organisation that was subject to a data breach that actually was PCI DSS compliant even if they had a self-assessment certificate stating they were.

When we come into an organisation after they’ve been breached, we get them compliant within 90 days. It’s not the fast and frictionless option. But that’s the point. The work we do results in a security posture that will actually prevent the next breach.  And often the perpetrators /cyber criminals will come back for another try within 12 months if they think you are a soft target.

Here’s how:

The Security Framework Some Vendors Don’t Want You to Know

A rural holiday home doesn’t need the same security system as a large office building in the middle of a major CBD. What they both need is security that is systematically and actively managed, in line with their environment and risk profile. There’s no point installing the most expensive security system if no one’s paying attention to it – meaning that if someone bypasses it, they go undetected until long after the damage is done.

That same logic applies to cyber security. Small organisations don’t need an enterprise-grade security stack. They need a fit-for-purpose security program they can actively manage. That’s what our PCI DSS Maturity Framework measures. We guide organisations through five security Stages – reactive, repeatable, defined, measured, and optimised. We tailor the framework to suit the organisation’s environment, industry and risk profile, not the other way around.

Most organisations achieve PCI DSS compliance while sitting at the first two maturity stages. That’s a risky trade-off. Lower maturity costs less to maintain, but the price you pay is fragility. Controls built to pass an assessment may not hold up against a determined attacker.

What Makes a Mature Cyber Security Posture?

No matter your organisation, a mature cyber security posture looks something like this: strong, always-on controls that stop most cyber-attacks before they happen, and an equally strong response to contain an incident on the off-chance those controls fail. Most importantly, it should be just as reliable at 2am on a Sunday as it is at 10am on a Tuesday.

Getting to this step means knowing what controls actually matter to your organisation, rather than enterprise-grade “industry best practices” that keep risk alive if you don’t have the resources to actively manage them. That’s the real security real trade-off. If you’re looking to enhance your cyber security in the most efficient, effective and sustainable manner, we can help.

Contact us for a security review.

How secure is your organisation? Find out more about our PCI DSS maturity framework and take the self-assessment to see where you stand.