When it comes to securing payment card information, the Payment Card Industry Data Security Standard (PCI DSS) is the most widely recognised framework. It outlines clear, technical controls that significantly reduce the risk of data breaches, including encryption, access restrictions, and continuous monitoring. And it works. In many data breaches, card data is the one thing attackers don’t get access to, because it’s properly protected.

So why don’t we apply the same level of protection to other types of sensitive information?

Analysing Recent Breaches: Why Some Data Gets Stolen, and Some Doesn’t

Recent incidents involving Qantas and Medibank highlight a consistent trend. Attackers targeted and successfully gained access to personal and operational data, but payment card data was untouched. That’s not a coincidence. Payment systems are usually protected under PCI DSS with stronger controls. The rest of the environment often isn’t.

This points to a broader issue. Personal information (known in cyber security terms as Personally Identifiable Information aka PII) is just as valuable in the wrong hands. Yet, many organisations treat it with a lower standard of security. The result is identity theft, regulatory investigations, and reputational damage that takes years to repair.

Lessons From PCI DSS: The Case for Stronger Data Security

The reason PCI DSS gets attention is because it’s mandatory. If an organisation wants to accept credit card payments, they must comply. This requirement is enforced by banks, card brands, and payment platforms, and there is an annual review process. Compliance is tracked, documented, and verified. Insurers also ask for it when renewing cyber cover.

The same can’t be said for protecting other types of sensitive data, such as PII. Privacy laws vary in how they are applied and enforced. There is no consistent technical benchmark and no enforcement body reviewing security practices each year.

The lesson here is clear. PCI DSS provides critical protection of payment data, making it harder for cyber criminals to access during a data breach. But in today’s digital-first world, where identity verification often happens without face-to-face interaction, the risks go beyond payment fraud. Identity theft is now just as serious, if not more damaging. While a compromised payment card can be cancelled and replaced within hours, recovering from identity theft is far more complex. Replacing passports, driver’s licences, or addressing fraudulent accounts opened in your name can take months to resolve and may cause long-lasting financial and emotional damage.

What’s more, not holding PII to the highest data protection standards can also impact cyber insurance. As highlighted in Austbrokers Cyber Pro’s Cyber Insurance Market Update 2025, many insurers are now reviewing broader cyber security controls. If you claim your organisation follows specific cyber security best practices, but then fail to properly implement these controls resulting in a data breach, your insurer may have grounds to deny your claim.

The Benefits of Applying PCI DSS to Safeguard PII

PCI DSS compliance provides a robust framework for protecting sensitive data. By leveraging these existing requirements to cover PII, organisations can elevate their overall cyber security posture without significant additional effort or cost. Doing so offers several practical advantages:

  1. A Cost-Effective Security Add-On Organisations that process payment card transactions are required to implement PCI DSS. As such, using those same controls to protect PII is efficient and cost-effective. It’s no shortcut either. PCI DSS is still a cyber security best practice for PII.
  2. Flexible Implementation Unlike PCI DSS, which sets clear rules for protecting payment data, there are no uniform global standards for PII security. This gives organisations the flexibility to apply PCI DSS safeguards in a way that best suits their size, systems, and industry, while still maintaining a consistent, standards-based approach.
  3. Enhances Trust and Reputation Customers expect that both their payment details and personal information will be handled with care. And following recent high-profile breaches that have compromised PII, consumer awareness is at an all time high. Demonstrating that your organisation applies recognised standards like PCI DSS to broader data security builds confidence, and strengthens stakeholder trust.

Extending PCI DSS security practices to cover PII is a smart, cost-effective way to enhance your overall security posture.

Safeguard At-Risk Data with Proven Security Controls

Security should not depend on whether data falls under a specific compliance framework.

Reframing PCI DSS as a practical blueprint rather than a compliance obligation helps IT, cyber security and business leaders shift from box-ticking to proactive risk management.

Stratica PCI DSS and PII expertise helps organisations apply strong, proven controls across their entire environment. Our team works with organisations to assess risk, uplift security practices, and ensure all key data is protected — not just payment data.

To find out how secure your organisation is, book a security review or visit the Stratica website to learn more.