• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'

2

Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won

3

A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'

1

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'

2

Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won

3

A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'
Tech

Why system testing, a critical aspect of data security, is worsening

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
March 23, 2015, 2:34 PM ET
Computer Technician in Server Room
Computer Technician in Server RoomPhotograph by Getty Images/Fuse
Add Fortune on Google for similar content.

Verizon (VZN) recently issued its 2015 compliance report for the payment card industry, and the 84-page tome reveals some surprising findings.

The most striking result? While many aspects of data security are improving for companies that deal with major card brands like American Express, MasterCard, and Visa, one key element has backslid over the past year: Regular system testing.

This is what’s known as “requirement 11” in the world of PCI DSS—as in Payment Card Industry Data Security Standard—a continually updated set of guidelines devised by an industrywide council founded in 2006. According to the report, regular system testing is the only category to experience a drop.

In order for companies to achieve compliance—or meet the minimum mandate for security—they are required to run quarterly vulnerability scans and at least one annual penetration test. “Pentesting,” as the latter is known, is the practice of inviting whitehat hackers to breach your network, reveal the chinks in its armor, and draw up a report. “Vulnscans,” on the other hand, rely on automated tools to expose known weaknesses—for instance, all the server side vulnerabilities discovered last year, including the infamous “Heartbleed,” “Shellshock,” and “POODLE” bugs—rather than the wiles of crafty humans.

Despite both pentesting and vulnscans being essential components of enterprise IT security, only a third of companies undertook adequate system testing, according to the report.

“You would expect a lot of executives asking their teams and suppliers to test their systems,” says Rodolphe Simonetti, managing director of payment card industry services at Verizon. “In reality only 33% of them did that. That’s a definite surprise when you consider the number of breaches we’ve seen last year.”

Companies improved on 11-out-of-12 compliance indicators—averaging an 18 percentage point increase in areas such as data access restrictions, authentication schemes, encryption of sensitive information, and strong passwords—but regular testing dropped seven percentage points from last year, the sole compliance indicator to worsen.

Why the drop at a time when the threats seem to be coming in faster than ever? The report ranks a lack of accountability and poor record keeping as partial explanations. That means businesses are simply losing track of their work—what Art Gilliland, head of HP’s enterprise security products, has described to Fortune as a “people and processes” problem.

In other words, it doesn’t matter if you have a topnotch scanner if you’re unable to manage its findings effectively. (Hackers-for-hire also pose an issue since it can be difficult to know who offers a quality service.)

In general, more companies are becoming compliant, stepping onto the bottom-rung of a ladder leading up toward that lofty concept of security. But in terms of proactively prodding their networks and findings cracks, companies have taken a step backward.

“The lesson is clear,” the report exhorts, “as an industry, breached and non-breached organizations alike, we all need to do better at testing our defenses.”

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

d
EnvironmentConsumer electronics
Almost 4 in 10 Americans have a ‘junk drawer’ full of their old electronics. It’s because of a very specific anxiety
By Eric Williams, Payam Saeedi, Stacey Watson and The ConversationJune 21, 2026
16 hours ago
b
InnovationInfrastructure
Over 40,000 American bridges have structurally deficient ratings. Why aren’t we using quantum sensors on them?
By Alex Krasnok and The ConversationJune 21, 2026
17 hours ago
zak
CybersecuritySocial Media
The U.K. just banned social media for kids under 16. The founder of ‘safe TikTok’ says the U.S. is next
By Nick LichtenbergJune 21, 2026
18 hours ago
Sam Altman thinks AI will surpass human intelligence by 2030.  His rival AI billionaires say it’ll be even sooner
AISam Altman
Sam Altman thinks AI will surpass human intelligence by 2030. His rival AI billionaires say it’ll be even sooner
By Marco Quiroz-GutierrezJune 21, 2026
21 hours ago
ace
AIEconomics
Nobel Laureate Daron Acemoglu on the ‘brainless’ AI discourse, the myth of capitalism and the Gen Z revolution risk
By Nick LichtenbergJune 21, 2026
22 hours ago
Patricia Camden is EY Studio+ Customer Experience and Loyalty Leader
CommentaryConsulting
EY: we found your biggest AI blind spot. It’s called the ‘tempo gap’
By Patricia Camden and John DuboisJune 20, 2026
2 days ago

Most Popular

Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
Success
Former U.S. Secret Service agent says bringing your authentic self to work stifles teamwork: 'You don’t get high performers, you get sloppiness'
By Sydney LakeJune 21, 2026
21 hours ago
Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won
Success
Former VP Kamala Harris says she went through a nine-hour interview to land the job—but she couldn’t escape ‘gold medal depression’ even when she won
By Emma BurleighJune 21, 2026
21 hours ago
A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'
Economy
A new trade war may be brewing. This time, Europe is taking a page from Trump's playbook — 'We no longer live in a world of pink ponies and rainbows'
By Jason MaJune 20, 2026
1 day ago
'I literally was crying last night because I’m nervous about what I’m going to find out': a record 51% of Americans aren't 'cost secure' on health
Health
'I literally was crying last night because I’m nervous about what I’m going to find out': a record 51% of Americans aren't 'cost secure' on health
By Ali Swenson, Amelia Thomson-Deveaux and The Associated PressJune 20, 2026
2 days ago
NBC’s Tom Llamas climbed from 15-year-old intern to the top anchor chair—and still isn’t satisfied: ‘If you're not growing, you're dying'
Success
NBC’s Tom Llamas climbed from 15-year-old intern to the top anchor chair—and still isn’t satisfied: ‘If you're not growing, you're dying'
By Preston ForeJune 21, 2026
20 hours ago
Tenzin Seldon: The GLP-1 boom is the biggest climate story no one is pricing in
Commentary
Tenzin Seldon: The GLP-1 boom is the biggest climate story no one is pricing in
By Tenzin SeldonJune 21, 2026
20 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.