HEARING OF THE EMERGING THREATS, CYBER SECURITY AND SCIENCE AND TECHNOLOGY SUBCOMMITTEE OF THE HOUSE HOMELAND SECURITY COMMITTEE
SUBJECT: DO THE PAYMENT CARD INDUSTRY DATA STANDARDS REDUCE CYBERCRIME?
CHAIRED BY: REP. YVETTE D. CLARKE (D-NY)
WITNESSES PANEL I: RITA GLAVIN, ACTING ASSISTANT ATTORNEY GENERAL, CRIMINAL DIVISION, DEPARTMENT OF JUSTICE; PANEL II: ROBERT RUSSO, DIRECTOR, PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS COUNCIL; JOSEPH MAJKA, HEAD OF FRAUD CONTROL AND INVESTIGATIONS, GLOBAL ENTERPRISE RISK, VISA INC.; MICHAEL JONES, CHIEF INFORMATION OFFICER, MICHAELS STORES INC.; DAVE HOGAN, SENIOR VICE PRESIDENT AND CHIEF INFORMATION OFFICER, NATIONAL RETAIL FEDERATION
Copyright ©2009 by Federal News Service, Inc., Ste. 500, 1000 Vermont Ave, Washington, DC 20005 USA. Federal News Service is a private firm not affiliated with the federal government. No portion of this transcript may be copied, sold or retransmitted without the written authority of Federal News Service, Inc. Copyright is not claimed as to any part of the original work prepared by a United States government officer or employee as a part of that person's official duties. For information on subscribing to the FNS Internet Service at www.fednews.com, please email Carina Nyberg at cnyberg@fednews.com or call 1-202-216-2706.
REP. CLARKE: The subcommittee will come to order. The subcommittee is meeting today to receive testimony on whether the payment card industry data standards reduce cybercrime. Good afternoon.
In recent years, a number of well-known companies have experienced massive data breaches in their internal computer networks, resulting in the compromise of sensitive customer data. The criminals who perpetrated these intrusions targeted the credit and debit card account information held by merchants or third-party data processors as the result of retail transactions.
With a thriving black market that rapidly packages and sells stolen cardholder data, the information compromised during these breaches may ultimately aid in a number of criminal organizations. We know that some percentage of the fraudulent charges and illicit businesses from these activities is used to fund terrorist activity throughout the world.
In his 2002 autobiography, the Bali nightclub bomber specifically referred to online credit card fraud and carding as a means to fund terrorist activities and encouraged his followers to use this method to obtain financing. More recently, a British case involving three jihadis alleged that the men used stolen credit card numbers obtained through phishing scams and Trojan horses to make more than ($)3.5 million in fraudulent charges. The jihadis reportedly used the numbers at hundreds of online stores to purchase equipment and other items, including prepaid cell phones and airline tickets, in order to aid jihadi groups in the field.
The subcommittee is holding this hearing today to voice our concern about the growing number of data breaches and to understand what is being done to curb this activity and to suggest that both merchants and the pay card industry have significant work ahead to meet our expectations.
The payment card industry, Visa, MasterCard, Discover, American Express and JCB, requires every business that stores, processes or transmits computer data to comply with specific data security standards. The intent of these standards is to reduce the likelihood of successful data security breaches.
On an annual basis, this merchant -- these merchants must certify that they are compliant with the payment card industry data security standards, known as PCI standards. The PCI standards contain a number of security controls that businesses must implement. The PCI standards allow smaller businesses to self-certify compliance, while larger merchants must be validated by a qualified security assessor. Enforcement comes through the card companies themselves, who can levy funds and/or prohibit noncompliant merchants from using their services.
To be clear, the PCI standards are not government regulation and are not enforced by the government. This committee supports industry created and managed security standards, as long as they are strong and effective. In light of the rising number of publicly reported data breaches, Chairman Thompson launched an investigation to determine whether the PCI standards have been effective in reducing cybercrime. The results of this investigation suggest that the PCI standards are of questionable strength and effectiveness.
The effort to become PCI-compliant is a daunting challenge for merchants whose core competency is the selling of merchandise, rather than expertise in security. The cost for the largest merchants can be as high as $18 million a year.
Many believe that if they complete this arduous task, they will be rewarded with a secure system. But the committee's investigation confirms what many analysts have known for years. In the words of one credit card company, "Full compliance with the PCI standards does not guarantee that the merchant or vendor will not be the victim of a data breach."
Take last year's data breach of Hannaford Brothers Company, for example. Hackers installed malicious code or servers to every one of the grocery stores in the Hannaford chain. The malware intercepted the data stored on the magnetic strip of payment cards as customers used them at the checkout counter.
Hannaford received certification that they were PCI-compliant on February 28th of 2008. But on February 27th of 2008, according to the documents obtained by the committee, Hannaford was notified that a number of the credit card numbers from its network were stolen and being used on the black market. In other words, Hannaford was being certified as PCI-compliant while an illegal intrusion into its network was in progress.
I do not believe that PCI standards are worthless. In the absence of other requirements, they do serve some purpose. But I do want to dispel the myth once and for all that PCI compliance is enough to keep a company secure. It is not. And the credit card companies acknowledge that. The bottom line is that if we care about keeping money out of the hands of terrorists and organized criminals, we have to do more and we have to do it now.
Specifically, we must improve our policies and our technology. First, the standards have to be better because they are inadequate to protect against the methods being used by modern hackers and attackers. Despite what the credit card companies say, for millions of small and large businesses out there, the PCI standards are the ceiling and not the floor. The bar must be raised.
In this dynamic threat environment, attackers are constantly ahead of defenders. And yet, the PCI standards are updated only by unanimous consent every two years. But part of the problem is that the standards do not require more frequent penetrating -- penetration testing. The only way to reduce breaches is by continuously testing and attacking a system through penetration testing and timely mitigation.
Second, the payment card industry and issuing banks need to commit to investing in infrastructure upgrades here in the United States.
In a response to the committee's investigation, one breached company noted that the effectiveness of data security standards is inherently limited by the technology base of U.S. credit and signature debit card processing networks. Credit and signature debit transactions are not protected by encrypted PINs. Implementation of encrypted PINs for all credit and debit transactions could be useful.
Countries in Europe and Asia are deploying new technologies, like chip and PIN, to fight fraud that could lead to organized crime and terrorism. And it is working. According to the U.K. Payments Association, three years after beginning the migration to chip-card technology, losses on transactions had reduced by 67 percent, from 219 million pounds in 2004 to 73 million pounds in 2007.
However, despite card fraud dropping 32 percent domestically between 2006 and 2007, overall counterfeit card fraud affecting U.K. customers was up 46 percent. Why? The cards are being used by malicious actors in countries that had not yet implemented the technology.
The U.S. is being blown away by security investments overseas and our 1950s-era system is making us a weak link in the security chain. Magnetic strip-based technology is outmoded and inherently less secure when compared to smart cards or other developing technologies. While I'm deeply concerned about our security, the payment card industry and issuing banks should be ashamed about the current state of play and doing everything possible to immediately institute improvements in infrastructure.
I know that our witnesses care about keeping financial information out of the hands of terrorists and other organized crime elements. And I know that the payment card industry cares. I know that the merchant community cares. But the time for waiting is over. The time for shifting risk is over. Today the responsibility is yours to make this situation better.
This is the first step in the committee's review of the payment card industry's effort, a review that I believe the chairman plans to continue. We look forward to hearing about your plans to improve America's cybersecurity posture and working with you in all the weeks and months ahead.
The chair now recognizes the ranking member of the subcommittee, the gentleman from California, Mr. Lungren, for an opening statement.
REP. DANIEL E. LUNGREN (R-CA): Thank you very much, Madame Chair. I want to compliment you for scheduling this important data security hearing. It is an issue that most people are aware of but few seem to understand the full extent of this threat or the remedies required to eliminate it as much as possible.
The new information age created by computers, the Internet, instant communication offers many benefits to the nation, particularly our economy. Transacting business in the Internet is one of the key benefits of the information age. Utilizing, obviously, credit cards today is the way people normally transact business. It's the new currency of our age. A lot of people don't even carry cash around anymore.
In fact, sometimes you try and pay with cash and people look at you, trying to figure out what scam you've got going on. I was at one place where I actually had a 50 cent piece that I was trying to utilize and the woman would not recognize it as an American currency. I was trying to explain to her the image on the surface and she just evidently missed that history lesson about that president.
The Internet has acted as a powerful economic engine for the U.S. economy. Unfortunately, these new business opportunities carried via the Internet have also transformed the landscape for the criminals, making available a wide array of new methods that identity thieves can use to access and exploit the personal and financial information of others. Today's skilled computer hackers are capable of perpetrating large-scale data breaches that leave tens of millions of individuals at risk of identity theft.
I recall my wife and I were at dinner one night. I gave the card to the waiter. After five minutes, the waiter came back kind of embarrassed and said, "Well, Mr. Lungren, this card doesn't seem to be working." So I turned to my wife and said, "Why don't you give him the card?" She gave him the card, the same account and he came back later and said, "Not working." Luckily, my wife had another card. If I had been in Chicago changing planes and needed to stay overnight there, I would have been up the creek without a paddle, as we say.
I went home that night, called in to the credit card company and they informed us there had been a credit card compromise. Our account had been compromised. They would tell us nothing more than that. My wife went online to see what our account was. At that point in time, there was no such account. It was as if it had vanished.
The point I'm making is we were never notified by the credit card company. And we have a number of automatic payments that are made against the card. And we tried to track every one of them down, missed one of them and got a notice that we had not paid that month for something.
So we are putting a tremendous obligation on the entire industry, in this case. One is to try and secure things. The other one is when there is a breach, what is your requirement to notify people? And under what circumstances do you notify people? And if you're not giving that information to those of us who are the consumers, is that information being given to law enforcement to follow up in all circumstances? Those are just some of the questions.
The key to this Internet economic engine running smoothly is data security. There's no doubt about it. If we're unable to secure our online financial transactions from cybercriminals, even those that are not involved with terrorism, then our economic growth will be jeopardized. And maybe actually we fulfill the terrorist dreams of pulling down our country through an economic attack.
Customers will reject online purchases if they can't be assured their payment card transactions are protected. Without consumer or customer confidence in the safety of the payment card transaction, Internet commerce would dry up and we could have problems with people just using the card when they're actually at brick-and-mortar stores.
We know it was a huge problem in the early days of the Internet when it was unknown frontier. Unchecked criminal activity will bring back those Wild West days, undermine customer confidence and cripple Internet commerce.
I applaud the payment card industry for investing their resources and personnel to develop and promote a universal data security standard. As was mentioned, it is voluntary. We understand that. A lot of work has gone into it. We understand that. There's always a challenge. It's easy for those of us in government to say we can do a better job. Thank God we haven't had any security breaches on the part of the federal -- oh, excuse me, I guess we have had a couple of them here and there.
All that points out is that it is a real challenge to stay ahead of the bad guys. I mean, you've got mischievous hackers, you've got individual criminal hackers, you've got criminal enterprise hackers, you've got transnational organization hackers, you've got nation state hackers, and frankly, you've got to try and protect against all of that.
The PCI Security Standards Council, that includes all of the major card brands, has at least understood that there is a need for a set of comprehensive requirements for enhancing payment account security. One of the questions I would ask is, is there any place for the retailers to be involved in discussion of those standards and part of that?
Another question I would ask is, I know you have some flexibility within the standards as they exist now, but is it still too much of one size fits all? In other words, I know you have a demarcation between mom and pop stores and the big retailers, but in between does it make sense? Are the standards flexible enough to be effective on the one hand and, at the same time, allow for different business models to operate in a reasonable fashion for that?
So I realize that the first standard was developed in 2006 to improve the standard and the security of the payment card industry.
To improve the situation more needs to be done. We're trying to identify those areas that need to be done. We're trying to make sure that all the parties are brought to bear on the question and we're looking to see if government regulation is needed.
The last thing I would say is this: The challenge for us in government is to try and ensure that we don't interfere with the ingenuity of the private sector in being able to put the fixes into the security system that are necessary. And if you can help us in that regard, not only will you benefit, but we will benefit as well.
And thank you very much, Madame Chair.
REP. CLARKE: The chair now recognizes the chairman of the full Committee on Homeland Security, the gentleman from Mississippi, Mr. Thompson, for an opening statement.
REP. BENNIE G. THOMPSON (D-MS): Good afternoon and thank you, Madame Chair, for holding this very critical hearing on the effectiveness of the PCI standards.
From our personal computers to government networks to our critical infrastructure, the United States is under attack in cyberspace. This adversary ranges in scale from unsophisticated to highly capable, from lone hackers to organized crime and nation states. Their intent ranges from nuisance and disruption to theft, espionage and warfare. Their successes are varied, but every hacker that we've caught and prosecuted, thousands continue to work unabated.
In December 2008, the Center for Strategic and International Studies concluded that the battle for cyberspace is one that we are not winning. Willie Sutton was rumored to have said he robbed banks because that's where the money is. In today's world of payment card transactions, the money is now located on computer networks.
On any given day, billions of dollars flow back and forth between merchants and payment card networks which process credit card numbers for transaction in an area that is ripe for hackers to exploit. And they are taking advantages of weaknesses in the system.
We are here today to learn about the private sector's efforts to combat data breaches and cybercrimes and to assess the quality of the payment card industry security standards. The standards have been around for several years, but massive, ongoing data breaches at some of America's largest merchants suggests that the standards are inadequate to prevent breaches.
The essential flaw with the PCI standards is that it allows companies to check boxes but not necessarily be secure. Checking boxes makes it easier to assess compliance with a standard, but compliance does not equal security. We have to get beyond check-box security. It provides a false sense of security for everyone involved and is ineffective in reducing the real threats.
Companies need to understand that even if 100 percent compliance with PCI standards is achieved, hackers will continue to develop techniques to exploit the computer systems of companies holding cardholder data. You are not safe unless you continually test your system.
Today we are calling for change. I call on the payment card industry and the thousands of merchants and vendors who have to comply with the standards to rededicate themselves to the goal of securing their networks. For the payment card industry and the issuing banks, this is going to mean significant investment in infrastructure upgrades.
As the chair has pointed out, these investments are already ongoing overseas. I'm puzzled and disappointed that we are not seeing similar upgrades here domestically and I hope our witnesses can explain why the card industry appears not to be moving quickly to address these issues.
I'm also deeply troubled by the testimony that suggests credit card companies are less interested in substantially improving their products and procedures than they are reallocating their fraud costs. The payment card industry effort to shift risk appears to have contributed to our current state of insecurity. And I am concerned that as long as the card industry is writing the standards, we will never see a more secure system.
We in Congress must seriously consider whether we can continue to rely on industry-created and enforced standards, particularly if they are inadequate to address the ongoing threats. I look forward to working with my colleagues on both sides of the aisle and across committee lines to further explore whether government action is necessary to protect against these threats. One thing is certain: The current system is not working.
Madame Chair, I thank you for your work in this area. And I look forward to the testimony of both panels.
REP. CLARKE: Thank you very much, Mr. Chairman.
Other members of the subcommittee are reminded that under the committee rules, opening statements may be submitted for the record.
We're going to take a break right now for votes. They've come up and we are scheduled for three votes, which puts us at about 25 minutes. Well, now it's less than 25 minutes, maybe about 15. So please excuse us as we go and recess for votes.
(Recess.)
REP. CLARKE: (Sounds gavel.) I welcome our only panelist on the federal panel, Ms. Rita Glavin, acting assistant attorney general, Criminal Division, Department of Justice.
In June of 2008, Ms. Glavin joined the Criminal Division as the acting principal deputy assistant attorney general. Ms. Glavin began her service to the department in 1998, through the department's honors program as a trial attorney in the Public Integrity Section, where she worked until 2003. Since 2003, Ms. Glavin has been an assistant U.S. attorney with the United States Attorney's Office for the Southern District of New York.
Without objection, this witness's full statement will be inserted into the record.
I now ask you to introduce yourself and summarize your testimony for five minutes.
MS. GLAVIN: Good afternoon, Chairwoman Clarke, and thank you for the invitation to address the subcommittee.
As you know, identity theft is not a new problem. However, in recent years, identity thieves have begun to capitalize on a variety of new methods to access and exploit the personal information of others. Skilled hackers are now capable of perpetrating large-scale data breaches that leave hundreds of thousands of individuals -- and, in some cases, millions of individuals -- at risk of identity theft.
The Department of Justice, along with our law enforcement partners, has been aggressively investigating and prosecuting these data breaches and other criminal activity associated with them. And we're committed to continuing our efforts.
We have historically had tremendous success in identifying, investigating and prosecuting the perpetrators of these acts. But as always, we can and we will do more. To that end, the continued and improved coordination with our partners in the international community and in the private sector will be critical to ensuring our success. And we're glad to have this opportunity to discuss these issues with your subcommittee.
The department has a responsibility for the investigation and prosecution of a wide range of cybercrime cases. But large-scale breaches are of significant concern to us because their effects can be amplified exponentially when criminals use the Internet to quickly and widely distribute vast quantities of information stolen during these breaches.
This threat we face is wide and it's varied, ranging from very sophisticated individual hackers to international criminal organizations. The resulting losses, as you know, can be devastating. And the criminals perpetrating these acts may be motivated by any number of factors, including personal financial gain and the desire to use this illegal activity to fund and facilitate other dangerous crime.
The department's benchmark prosecutions of large-scale data breaches and the criminal activity that results from such breaches highlight the range of our efforts that we've been using to address the growing problem. And I want to give you a couple of examples.
Most recently, the FBI announced the result of a two-year undercover operation that targeted members of the online carding forum known as Dark Market. At its peak, the Dark Market website had over 2,500 registered members around the world. This operation has resulted in 60 arrests worldwide and has prevented what we estimate to be approximately $70 million in economic loss.
In another example, in August of 2008 the department announced the largest hacking and identity theft case ever prosecuted, in which charges were brought against 11 members of an international hacking ring. Now, these various defendants, who were from the United States, Estonia, the Ukraine, People's Republic of China, Belarus, were charge with, among other things, the theft and sale of more than 40 million credit and debit card numbers obtained from various retailers.
Another example, in 2004 the U.S. Secret Service and several components of the Justice Department coordinated the search and arrest of more than 28 members of the ShadowCrew criminal organization, located in eight states in the United States and six foreign countries. Members of the group were later charged in a 62-count indictment with trafficking in at least 1.5 million stolen credit and bank card numbers that resulted in losses in excess of $4 million. The ShadowCrew website was disabled, which we believe prevented hundreds of millions of dollars in additional losses to the credit card industry. This was known as Operation Firewall and this early effort paved the way for our more recent successes in this area.
Now, while investigation and prosecution are important, prevention and detection are key elements in the fight against this criminal activity. Keeping credit, debit and other financial account information out of the hands of criminals in the first place is an essential step in reducing the frequency and minimizing the impact of large-scale data compromises.
We suggest that all entities that store, process or transmit credit, debit and other financial account information should take steps, including complying with the payment card industry data security standards, to improve the security of their computer systems and decrease the vulnerability of the information they handle.
Of course, even 100 percent compliance with the PCI DSS, if that were achieved, it's likely that hackers will continue to develop techniques to exploit the computer systems of companies holding cardholder data. For instance, in those instances where the hackers have succeeded, efforts by the department and efforts by the investigative agencies to look into and prosecute and punish those hackers and carders have been critical to deterring future criminals.
For us to have continued success on those fronts, it's imperative that, one, the victim companies embrace new measures to swiftly detect data breaches, system compromises; two, that the victim companies immediately and consistently report detected data breaches to law enforcement; and finally, that the U.S. builds on its existing relationships with our international partners to strengthen law enforcement cooperation channels internationally.
Thank you, Ms. Chairwoman. I'm prepared to answer your questions.
REP. CLARKE: I thank you for your testimony.
I will remind each member that he or she will have five minutes to question the panel. I will now recognize myself for questions.
Are we seeing more massive data breaches today or is the media simply reporting more?
MS. GLAVIN: I think you have a little bit of both. You're seeing what -- the media is reporting on it, but what we've seen over the last several years and in some of the operations that -- specifically that I've referred to in our testimony, the ShadowCrew organization, where you have hundreds of thousands, if not millions, of personal financial information and identity thefts occurring -- the Operation Firewall, which was both the ShadowCrew organization and the carder market forum, to demonstrate that for a number of years this type of data breach has been happening and that there are hackers all over the world that are looking to get into systems and slowly take the information out. It can be over a course of months if not over a course of years.
So yes, the data breaches are occurring and we know that because of undercover operations we've done and because of the publicly reported takedowns that we've done that I mention in my testimony. And yes, the media is reporting on those breaches.
REP. CLARKE: Ms. Glavin, to what extent does the fact that a company is PCI-compliant help to mitigate criminal activity? And how effective are PCI standards in lowering the risk of being breached?
MS. GLAVIN: Having any security system and uniform standards are going to help. All right? It's a floor and it's a way to begin the process in preventing breaches.
That said, what we look at in terms of those PCI DSS standards, you've got to do continual monitoring; you have to do the testing, because you may have adopted those standards but people may already be in your computer system by the time you've already adopted those standards. And it's the monitoring and the testing that's going to help companies see where they've been breached. And we know that hackers are always coming up with new ways to get into your system, so it's going to be the monitoring and the testing.
The second thing that the department would suggest is that there should be notification to federal law enforcement when breaches occur. And I know that something -- that has been under subject of much discussion. But that would be an effective way of dealing with the data breaches on a number of levels because we have a sense from our investigations and prosecutions around the country as to the means that the hackers use to do this, and if we get early reporting, it helps us get a sense of what's going on such that we can stop it, that we can stamp out, you know, websites that are doing this and help get in front of the problem.
REP. CLARKE: And Ms. Glavin, how successful do you think the Department of Justice's efforts to combat credit card fraud will be in the long run if neither improved standards nor technology in infrastructure changes are realized and there's no reduction in the amount of cardholder data being lost or stolen?
MS. GLAVIN: This is going to have to be an ongoing partnership. Law enforcement has been there and we're always going to be there. And it's not just within the prosecution of the Department of Justice. FBI is always looking at this. Secret Service is always looking at this. We're working with our international partners around the world to have an international presence such that we're sharing information. We can't do that alone, and having help from private industry when they know that there have been breaches and reporting that to us, it's going to help everybody in the long run.
So we can do what we do in terms of watching the technology, trying to stay on top of hackers, continually looking out for these websites and carding forums, but we can't do everything alone. And to the extent we get help from the private sector to stay on top of that, that's important. And I think that the industry that's had -- adopting the PCI DSS, that's a laudable effort. The question is, can they continue to evolve from there?
REP. CLARKE: And then just finally, can you please explain the roles of the Secret Service, FBI and ICE in investigating cybercrime, and what are the distinctions between those investigative units?
MS. GLAVIN: Sure. The Secret Service has always been involved in looking at financial crimes and hackers. What the FBI brings to the table in addition to the Secret Service is that they have your counterintelligence databases, which the Secret Service may not have. So they can be also checking on a much more international level what's going on around the world, and they also have a presence through their legal attaches in other countries. And so the Secret Service and the FBI both play critical roles, and they both bring different tools to the law enforcement effort.
REP. CLARKE: Well, thank you very much.
I now recognize one of our new members on the committee, new member to the Congress, the gentleman from New Mexico, Mr. Lujan, for his questions at this time.
REP. BEN RAY LUJAN (D-NM): Thank you very much, Madame Chair.
And Ms. -- is it Glavin?
MS. GLAVIN: It's "Glay-vin."
REP. LUJAN: Ms. Glavin, thank you very much for being with us today.
MS. GLAVIN: Thank you.
REP. LUJAN: In your testimony you highlight many instances where there's projects or programs, recent successes, investigations that the Department of Justice has engaged in -- Dark Market carding forum, international hacking ring Operation CardKeeper, Iceman, Operation Firewall.
With that being said and with the level of concern that the Department of Justice has with the level of crime that's taking place, and in this case cybercrime, what standards exist today for keeping this data secure?
MS. GLAVIN: In terms of private industry, the standards that are out there are the PCI DSS, plus whatever state laws there are. I mean, there are -- a number of states have consumer notification laws that require financial entities to report data breaches. Some have law enforcement notification laws.
In terms of federal regulation, there's not a lot other than you're speaking to someone from the Criminal Division, and I know that we have the Title 18 criminal statutes that we use to prosecute. But in terms of standards across the industry federally such that people are required by law to comply with a certain set of standards, that's not out there.
REP. LUJAN: And with that being said, so it sounds like what states have done is they have a reporting mechanism that when there is a breach in security and data is compromised that they're required to notify the consumer that may have been impacted. But with that being said, in your opinion, are these standards working the way that they're -- they are being put together today?
MS. GLAVIN: Which standards? Do you mean the --
REP. LUJAN: The industry standards.
MS. GLAVIN: The industry standards. You're going to -- in terms of whether or not they're working, we know what reports we get when there's been data breaches and when industry chooses to tell us. Or sometimes we learn about it from our own investigations and we choose to tell them. Whether or not they're working, I think the industry representatives are in the best position to tell you that.
What I can say from the department's perspective is that there does have to be some cooperation between -- if we're going to do criminal investigations there's going to have to be some cooperation between us and private industry so that we can do those investigations, get a sense of the data breaches and have cooperation such that they let us know what's going on, we have a sense of how it happened, what's out there and who may be responsible.
As for whether or not they're working, I think they're a great bottom line to start with. But you have to be constantly watching, testing them, checking them to make sure they work because the hackers are sophisticated people and they try to stay one step ahead of the industry. The industry tries to get one step ahead of them. And it's in everyone's interest that you keep moving ahead.
REP. LUJAN: And Ms. Glavin, did you hear you correctly where -- did you say that sometimes the Department of Justice will notify the companies that there has been a breach as opposed to the other way?
MS. GLAVIN: Yes. But sometimes that can happen, you know, if we get information that they may not have that we may have access to through the course of our criminal investigations. And it could be a company that maybe PCI DSS-compliant but there was already something in the system before they got brought up to compliance.
But yes, there have been instances that I know of investigations where we've learned about information and that we have informed the company about that you may want to check X, Y and Z.
REP. LUJAN: Thank you very much, Ms. Glavin.
Madame Chair, you know, I know that we had a lot of briefings and discussions with the committee as a whole, also with the various subcommittees on the importance and the attention that's needed when it comes to data breaches, especially when the attacks that we know that are occurring on a regular basis, national security as well as financial institutions.
And I think that in the same regard when we're talking about what the expectations are of the American public with feeling secure about the data that could exploit them and expose them to these types of crimes, oftentimes without then ever knowing, is something that we have to take seriously.
So I thank you very much, Madame Chair and Chairman Thompson, for bringing this to the attention and allowing us to have a hearing on this today.
REP. CLARKE: Thank you very much, my colleague. And I just want to correct the record at least vocally that my colleagues name is Mr. Lujan.
REP. LUJAN: (Off mike.)
REP. CLARKE: Very well.
And some of your response to my colleague's questions were a bit troubling to me. The fact that it could take some time before there's communication around a vulnerability that's existing within the system and in that amount of time transactions can take place that can lead to financial support for criminal endeavors is something we should always be concerned about.
Time is of the essence, right? And if you're not getting the level of transparency, for whatever reasons, from the private side -- in other words, maybe someone is ashamed that, you know, they've met these PCI standards and now they've found a vulnerability. And as you said, it could have been one that existed there prior to them coming up to code. It's still important for that information to be shared, notwithstanding whatever reasons may inhibit someone from doing so.
And because, again, these transactions take place so quickly, what would you say could expedite the transfers of information? What do you think would open up private enterprise to really working with law enforcement on a much more timelier (sic) basis once something is detected to address it? And do you think that perhaps some modernization or some introspection about the PCI standards would help put them on a higher platform for detection?
MS. GLAVIN: The PCI DSS standards -- again, I'll say what I said before -- I think one of the key components of those standards are going to be they're regularly monitoring and testing. Sometimes these breaches aren't readily apparent and are hard to detect.
As I've had it described to me, the breaches can sometimes occur such that the best analogy could be that the front door of your house gets open and you don't know it, and slowly over a period of time someone may take piece by piece out of your house. And it could happen over a course of months and an entity may not be aware of it. So immediate notification could be hard in that type of instance, but regularly monitoring, testing we hope would be a way that they'd detect it sooner.
In terms of the information sharing, we support an effort such that there be some type of notification to federal law enforcement.
How's that done and what particular entity that it's reported to is something that we're happy to work with this committee on such that it can happen faster and it gets to the law enforcement entities that have been in the forefront of this such as the FBI and the Secret Service. But it's immediate notification when you see the data breach -- yes, that's something that we would like. But sometimes it's not always easy that you're going to find that data breach right away.
REP. CLARKE: Ms. Glavin, I want to thank you for sharing with us your perspective on the PCI standards and the payment card industry and its relationship to cybercrime. We want to thank you for sharing your expertise with us, and we look forward to working with you further as we look for ways to strengthen this part of our concern with regards to the threats that exist, the vulnerabilities that may exist within the payment card industry. Thank you very much.
MS. GLAVIN: Chairwoman Clarke, thank you very much, and we look forward to working with you.
REP. CLARKE: Thank you.
I would like to acknowledge the work, Ms. Glavin, of your senior counsel, Kim --
MS. GLAVIN: Kim Peretti.
REP. CLARKE: -- Peretti in this field. And I'd like to thank her and her colleagues for their service. Thank you very much.
MS. GLAVIN: They've done excellent work.
REP. CLARKE: We appreciate it.
The members of the subcommittee may have additional questions for the witness, and we will ask you all to respond in writing to those questions. At this time, the first panel is dismissed and the chair calls up the next panel.
I welcome the second panel of witnesses. Our first witness is Robert Russo, director of the Payment Card Industry Data Security Standards Council.
Welcome.
Our second witness is Joseph Majka, head of fraud control and investigations, global enterprise risk, for Visa. Our third witness is Michael Jones, chief information officer for Michaels Stores. Our fourth witness is Dave Hogan, senior vice president and chief information officer for the National Retail Federation.
I thank you all for being here today.
Without objection, the witnesses' full statements and written statements of Andrew Cochran, an expert on terrorism financing, and Kirsten Trusko on behalf of the Network Branded Prepaid Card Association, will be inserted into the record. Hearing no objection, so ordered.
I now ask each witness to introduce yourself and summarize your statement for five minutes, beginning with Mr. Russo.
MR. RUSSO: Thank you, Chairwoman Clarke. Thank you for the opportunity to testify on the critical issue of payment card data security.
Payment card fraud concerns every American and in a global economy every consumer worldwide. The payment card system is one that manages billions of transactions representing trillions of dollars moving across a global network. Reducing payment card fraud and constantly innovating to stay ahead of it is a critical challenge.
The PCI Security Standards Council was formed in 2006 just for that purpose. Our mission is to protect cardholder data from criminal elements who constantly manufacture new and inventive ways to compromise security systems. At the center of our efforts to do this are three standards. Let me tell you about each.
First, the PCI Data Security Standard, or the DSS, is a set of 12 security practices based on six core principles. The DSS covers everything from securing applications to networks to their perimeters to maintaining an incident response plan.
Second, our payment application data security system is designed to ensure that payment applications which are found in many retailers are not storing sensitive payment card data.
And third, that (PIN ?) security requirements ensure that the PIN entry devices, devices that you may see at a checkout line to enter your PIN number, have been designed to properly encrypt the customer's PIN and are tamperproof.
But new threats continue to emerge. That's why development and review of the PCI standards is a critical process and why the PCI Security Standards Council takes it seriously. We engage our community of participating organizations -- more than 500 merchants, processors, financial institutions, technology companies, government, academia and trade associations worldwide -- to ensure our standards meet the latest threats. And when new threats emerge, we have mechanisms to take swift action. These include regular updates to our testing procedures, monthly "webinars" with both assessors and merchants, flash bulletins on emerging threats as well as ongoing updates to the standards themselves.
Our goal is simple, to have every organization that stores, processes or transmits cardholder data do so in accordance with the PCI standards. I have no doubt that compliance with the PCI standards are an entity's best line of defense against payment card data compromise. In fact, we have never found a breached entity to have been in full compliance with the PCI standard at the time of a breach.
But we also recognize that the dynamic nature of any organization can render a validated system noncompliant almost immediately after a satisfactory compliance report has been issued. Effective security is not a one-time snapshot but really a full-length feature film where the organization is compliant at each and every frame. No standard is perfect, but the PCI security standards have proven to be the most effective means of preventing data breaches and protecting consumers.
One final point: In order to assist organizations with maintaining and achieving compliance with our standards, the council provides a wide range of resources, for example, the ongoing training, approval and quality assurance of qualified security assessors, a worldwide network of professionals that conduct on-site compliance assessments, the validation of worldwide network of approved scanning vendors who do remote scanning of networks, secure them against network threats and, finally, an education program that includes printed materials, online resources, webinars and face-to-face training sessions.
Payment card fraud is a serious concern demanding a serious, continuous and vigorous response. The PCI Security Standards Council has made its sole mission the securing of cardholder data.
Thank you and I look forward to answering your questions.
REP. CLARKE: Thank you for your testimony.
I now recognize Mr. Majka to summarize his statement for five minutes.
MR. MAJKA: Chairwoman Clarke and members of the committee, my name is Joe Majka. I'm head of fraud control and investigations for Visa Inc. I've been with Visa for over 12 years and have over 28 years experience in corporate security investigations and law enforcement, specializing in the area of financial crimes.
I want to thank the committee for this opportunity to appear at today's hearing and to explain who Visa is and our role as a leader in global data security.
It is important to note that Visa's fundamental role is to facilitate transactions between millions of consumers and businesses. Visa is not a bank and we do not issue payment cards. Visa is a network that connects 1.6 billion global payment cars, 29 million worldwide merchants and over 16,000 financial institutions in 170 countries. Through electronic payment networks like Visa, the entire economy benefits from a more transparent, cost-effective and secure commercial activity.
I'm pleased to be here to talk with you about data security and about the payment card industry data security standard in particular.
In our view, the best way to secure payments is by applying to core principles. First, security must be a shared responsibility among all relevant parties -- law enforcement, payment companies, regulatory agencies, retailers and others. Only together can we protect all parts of our shared system.
Second, we must collectively apply multiple layers of security to protect the system. That includes measures applied at the card level such as card verification values or transaction alerts. It includes measures supplied at the point of sale such as standards for secure devices and best practices for data storage. And it includes measures applied at the network level, including neural networks and fraud monitoring.
One of the most effective layers we have collectively applied to date is the PCI data security standard. Visa requires all entities that store, transmit or process Visa card data to comply with the standards. To our knowledge, no organization that has fully implemented and maintained compliance with the standard has been a victim of a data compromise event. We believe full compliance with the standard is a valuable component of a comprehensive security program and greatly reduces the risk of data compromise.
While there have been a few instances where an entity previously validated compliance was the victim of a compromise, in all cases our review concluded gaps in the compromised entity's PCI DSS controls were major contributors to the breach. Approximately 90 percent of the U.S. merchants and 80 percent of third-party processors have validated PCI compliance. These organizations, like Michaels, deserve credit to enhancing their security practices to meet the minimum industry standard and for validating their compliance on at least an annual basis.
This month in Washington, D.C., Visa held our third global security symposium, a symposium on payment security where Visa called on system participants for continued industry investment, collaboration and innovation to keep the electronic payment system secure for the future. At this summit we heard from numerous individuals and organizations who reaffirmed the importance of ongoing compliance with the PCI standards.
Visa has maintained a long-standing relationship with law enforcement agencies over the years supporting efforts to investigate and prosecute criminals committing payment card fraud. This relationship continues and is stronger than ever today as Visa and law enforcement agencies work together to combat cyber criminals in today's high-tech world.
Visa was a founding member of the U.S. Secret Service Electronic Crimes Task Force in San Francisco and continues to actively participate in U.S. Secret Service task force groups. Visa also works closely with the FBI's Cyber Division, U.S. Postal Inspections Service, state attorneys general and the Department of Justice Computer Crime and Intellectual Property Section.
In 2004, Visa provided investigative support to law enforcement which resulted in the indictment and extradition of Roman Vega, one of the most significant high-level cyber criminals at the time. And Visa continues to support high-profile investigations, including the arrest of criminals responsible for hacking into Dave & Busters and T.J. Maxx. Visa values our partnership with law enforcement and is committed to continuing to work closely with law enforcement to bring cyber criminals to justice.
Protecting cardholders is always a primary goal in responding to data compromise incidents. After learning of a data compromise, Visa immediately begins to work with the compromised entity, law enforcement and the affected client financial institutions to prevent card-related fraud.
In closing, securing consumer data within the U.S. economy is a shared responsibility, and every industry should deploy focused resources to protect consumer information within its care. We look forward to working with all participants to continue to develop tools to minimize the risk and the impact of data compromise events.
Thank you for the opportunity to be here today. I'd be happy to answer any questions.
REP. CLARKE: Thank you for your testimony.
I now recognize Mr. Jones to summarize his statement for five minutes.
MR. JONES: Good afternoon, Madame Chair, members of the committee.
I've been in retail for 30 years, 20 in retail IT, the last four with Michaels, a $4 billion merchant. I wish I could say that attempting to follow the PCI mandates made me confident that credit card data is completely safe, but unfortunately that is not the case. This is because the mandates have been developed from the perspective of the card companies rather than from those who are expected to follow them.
The PCI data security standards are an extraordinarily complex set of requirements. They are very expensive to implement, confusing to comply with, and ultimately subjective, both in their interpretation and in their enforcement. The program is rife with ambiguity and complexity. As an example, must every company associate acknowledge the security policy of a company -- all 40,000 of our associates or just those involved with credit transactions? This one PCI mandate has been imposed by compliance vendors differently at retailers all across the country.
We have been questioned by customers, legislators and even the credit card companies themselves, why do you keep credit card information at all? One reason we keep the information is related to another credit card company procedure designed to protect their banks from loss; it's called a chargeback. It can be initiated by a bank on its own or it can be initiated at the request of the bank's customer.
For example, if a customer spots a charge on their credit statement that they don't recognize they can initiate a chargeback by contacting the issuing bank. The retailer is then charged with retrieving the sales media by card number. If the retailer is unable to produce that sales media or something on that sales media does not match, the retail sale is reversed and the cost of the transaction is charged back against the retailer. This is true even if the transaction may have actually been made. This could have been fairly easily solved using a unique approval ID for each transaction, thus eliminating the need for credit card number storage by the retailer.
PCI states that all credit card data must be encrypted. There is an exception to this requirement, however. PCI states that data traveling over a private network need not be encrypted. While a private network is more secure, I still would not choose to send credit card numbers through this network unencrypted. Why? Because it adds unnecessary risk. However, the credit card companies' financial institutions do not accept encrypted transactions.
We at Michaels have asked for the past three for the ability to send encrypted information to the bank. To date, this has not happened.
Why is this an issue? One might ask the consumers affected by the Heartland Payment System's data breach or TJX Corporation for that matter. It has been suggested that methods used in those breaches capitalized on this flaw.
What can be done to improve this situation? First, many of the PCI requirements are covered by the Sarbanes-Oxley audits. This causes a lot of duplicative work around proof of compliance and is arguably unnecessary. Second, the requirements are one-sided against merchants; the very financial institutions that impose them are not subject to the mandates themselves.
Third, the PCI Data Security Standards Council was allegedly spun off from the credit card companies and set up as an independent governing body of credit card company, bank and merchant representatives. In fact, the council is set up so that credit card companies and banks retain all power over the ultimate mandates, fines and anything else connected to PCI. It is not an industry standards body.
When a breach occurs and card data is stolen, clearly the consumer potentially suffers the most inconvenience. Fortunately, the law provides that promptly reporting consumers must be held financially harmless. However, the largest financial impact is on the retailer, especially if the credit card company's data, which by and large we do not want, is seized from a retail location. The retailer is in the press. The retailer is demonized. The retailer is threatened with damages and sanctions. The retailer pays the costs of the fraudulent transactions. All of this arises from rules that initially grew from a card monopolist that we have no choice but to do with business with or risk the loss of a large portion of our business.
We do not need more laws. The existing, sometimes misguided enforcement and proliferation of state regulations around these issues have created a difficult if not impossible environment for retailers.
In conclusion, I'm proud to report that Michaels has never had evidence of a breach of consumer data. Regardless of the outcome here, we will continue to do what is necessary to keep card data safe. But in the future we would be more secure and the risks to us all far lower were the card companies to take greater responsibility for the inadequate system of payment they have created and asked us to use.
Thank you and I'm happy to answer any questions.
REP. CLARKE: Thank you for your testimony.
I now recognize Mr. Hogan to summarize his statement for five minutes.
MR. HOGAN: Thank you, Chairwoman Clarke and members of the committee, for this opportunity to appear on behalf of National Retail Federation, the world's largest retail trade association. I've been with the NRF for almost seven years and have spent my entire 25-plus- year career in retail information technology.
Whether it be by cash, check or plastic, the payment mechanism is really just a means of accomplishing business. Retailers accept credit cards for payment in part because they have been assured by the credit card companies that if they follow a limited number of steps they will be given a guarantee of payment. Most retailers are not in the payment acceptance business any more than their customers are in the payment delivery business.
There have been two big developments in the last decade or so that have changed the playing field. The first has been the rapid proliferation of general-purpose credit cards. With over 80 percent of the market share, Visa and MasterCard are two primary examples -- these cards issued broadly by banks in the hopes that each card will generate income for them.
The second change has been society's increased computerization. Globally, there have been numerous instances of hackers from outside of our borders accessing computer systems, stealing credit card information and then using this data to commit fraud. In several cases, these have targeted companies that process or store credit card data.
As with the growth of online shopping fraud, these developments presented the card industry with a challenge. In response they introduced what they called the Payment Card Industry Data Security Standard, or also called PCI.
PCI is an attempt to prevent large stockpiles of credit card data from getting into the wrong hands. However, the PCI guidelines are onerous, confusing and constantly changing. Indeed, PCI is little more than an elaborate patch. The premise behind PCI -- that millions of retail establishments will systematically keep pace with the ever- evolving sophistication of today's professional hacker -- is just not realistic.
Our industry has spent billions on compliance programs related to data security. PCI protocols have required many merchants to scrap good, existing data security programs and replace them with a different security program that meet PCI rules that aren't necessarily any better. Even companies that have been certified as PCI-compliant have been compromised.
Unfortunately, the economic incentives for the card companies to remedy these flaws in their system have been diminished. It appears to our industry that credit card companies are somewhat less interested in improving their product and procedures than they are in reallocating their fraud costs. In our view, if you peel back the layers around PCI you will see it for it really is, a tool to shift risk off the banks and credit card's balance sheets and place it on others. It is their payment card system, and retailers, like consumers, are just users of their system.
And what is really ironic here is that merchants are forced to store and protect credit card data that many don't want to keep anyway. The credit card companies' own rules around retrieval requests essentially require merchants to keep credit card data for an extended period of time. As I mentioned, all of us -- merchants, banks, credit card companies and our customers -- want to eliminate credit card fraud. But if the goal is to make credit card data less vulnerable, the ultimate solution is to stop requiring merchants to store credit card data in the first place.
In fact, we proposed such changes to the PCI Security Standards Council back in 2007. The card industry dismissed our proposal without addressing it and its merits. There have been numerous suggestions made over the years that would significantly reduce the chances of major data breaches, but none of them have been adopted yet. Here are just a few.
First: go on record and stop requiring merchants to store credit card data and eliminate any penalties they impose for not doing so. Another: change the system and allow consumers to enter in a PIN, or personal identification number, for credit card transactions just like you do with debit card transactions. Third: quickly develop and rollout the next generation of credit card and give merchants the hardware and software necessary to handle these new products.
In conclusion, once the payment system itself becomes a burden, commerce inevitably suffers. We believe any one of these recommendations would significantly reduce credit card fraud.
Thank you for the opportunity for appearing in front of this committee, and I'll be happy to answer any of your questions.
REP. CLARKE: I thank the witnesses for their testimony.
I will remind each member that he or she will have five minutes to question the panel. I will now recognize myself for questions.
My first question goes to both Mr. Russo and Mr. Majka. Since the PCI standards have become mandatory there's been no shortage of massive data breaches. Is there any hard evidence to suggest that the standards have actually reduced the number of data breaches or the amount of credit card fraud? And what metrics are in place to judge the effectiveness of these standards?
MR. RUSSO: Chairwoman Clarke, let me answer first. The council's purview does not include keeping statistics on breaches on who is compliant as we do not have that relationship with the merchants. I can tell you, as I stated earlier, that based on what we've seen in forensics and what our information has given us by reaching out to these breached entities that they were in fact not compliant at the time of the breach.
Very similar to Ms. Glavin, who mentioned locking your doors, you don't lock your doors on Monday, Wednesday and Friday and not on Tuesday, Thursday, Saturday and Sunday. So it's constant vigilance that must be there when it comes to protecting this data. It's everyone's responsibility, including the merchant, including the consumer, to be looking after their own data.
MR. MAJKA: Madame Chair, I'd like to say that, you know, entry into these data systems while the criminals are very complex, we found that the entry methods have been very simple and that they were -- would have been addressed by the PCI data security standard in all cases. And even those entities where they've had validated compliance, our review of those incidents found that either they hadn't maintained compliance and there were significant gaps that allowed the breach to occur.
I'd also like to say that the standard itself has been improved over the years. And one of the success stories of the standard is the removal of prohibited data from merchants' servers. And this has led to incidents where we no longer have a breached entity who's been storing data for three or four five years that the criminals can access five years' worth of data. So I think those are things that the standard itself has addressed and has helped.
I'd also like to say that I think that we don't know how many breaches have been prevented by those entities that have in fact gone as far as implementing and maintaining the standard properly.
REP. CLARKE: I think that's really at the core of the issue here is that we can't get some tangible evidence of how effective this is in actually eliminating the breaches.
It's clear that if people aren't following the protocol that opens them up in terms of more vulnerability, but it would seem to me that as a part of the build-out and the -- of I guess the floor of the PCI standards that we would develop some sort of metric that gives us an ability to objectively judge the effectiveness of these standards. Are you saying that those don't exist right now?
MR. RUSSO: No, Madame Chairwoman, they do exist in various entities, those entities being the acquiring banks as an example which own the relationships with the merchants. They require PCI compliance. They track PCI compliance. They have those numbers. Again, the council does not have any input into that or any view into that because we do not have the relationships with the merchants. The banks, the acquirers, have the relationship with the merchants. But there are tens of thousands -- hundreds of thousands that are going through programs every day and validating their compliance on a regular basis.
REP. CLARKE: Mr. Russo, do you have a relationship with the banks?
MR. RUSSO: The council does not have a relationship with the banks other than to put the standard out there and make sure that they are creating awareness among their constituents that they need to be compliant with the standard.
REP. CLARKE: Thank you.
The next question then is both to you, Mr. Russo, and Mr. Majka. The PCI standards include requirements for encrypting data at rest and data that travels over the Internet. But the Heartland breach, for instance, involved data in transit between terminals and hosts on nonpublic networks. As Mr. Jones notes in his testimony, there are no PCI standards for this. Is this a fundamental weakness in the standards? And why doesn't PCI require end-to-end encryption including internal encryption? And how are you going to address this?
MR. RUSSO: There are provisions within the standard now that address this data and address the inside network that should, in fact, either stop this from happening or at least give you a warning that something is happening so that you can immediately stop it and cut the breach off.
We do go out to, as I mentioned, all of our participating organizations, one of whom is sitting at the table with me today, the NRF, and we do ask them for their feedback on the standard and what needs to be done. One of the things that we are in the process of doing right now is we've issued a proposal to a number of technology companies to give us an independent study on what we're calling emerging technologies, one of which is end-to-end encryption, another of which is tokenization, another of which is chip and PIN. So we are looking at these technologies and how they make the standard more robust, but it's important to say that there really is no silver bullet here.
REP. CLARKE: I'd like to get -- and I'm a bit over my time -- but I'd like to get Mr. Jones' and Mr. Hogan's response to this end- to-end encryption dilemma. Please -- answers?
MR. JONES: First, I think on encryption I'm not sure I would call it an emerging technology. It has been around for, you know, for some time. And obviously since it is a requirement for anything traveling outside the private network, I think that not having it as part of something that travels on your internal network was something originally to reduce some of the costs involved with implementing the standards because it costs money to implement encryption end to end, and that would have involved a lot of cost to merchant banks all across the country as well as retailers. Every retailer would have had to implement encryption on their side. But we've already had to do it from -- and most retailers do transact across the Internet in one way or another, so we've had to do that.
So, you know, that -- I would separate that out from a chip and PIN discussion as far as what, you know, what we should be looking at going forward. And as far as, you know, whether it should be in the standard or not, you know, I feel that it should have been in the standard long ago as part of something simply because there are things that may have caught the Heartland Payment thing. But when we talk about very sophisticated thieves, the Heartland Payment software that was used was so sophisticated that it was virtually impossible for highly technical, highly sophisticated people to pick up and most of the existing scanning technologies would not have even picked it up but, had it been encrypted, wouldn't have mattered. And that's the way that I think of looking. So why not lock your front door? Why leave it open?
REP. CLARKE: Mr. Hogan, do you concur?
MR. HOGAN: (Off mike.) I think it's very interesting that the merchants, universities, doctors' offices, you know, anybody who accepts credit card and processes credit card data has to go through extraordinary hoops to adhere to a PCI standard. However, when it's convenient the information is sent open in the free and clear when it's transmitted to the banks, so on and so forth. So I think you've got a double standard going on here where in one case, you know, you have to, you know, adhere to a standard and spend a lot of time, effort and money to do it, and then all of a sudden you send it back out wide open that anybody could potentially read unencrypted downstream.
REP. CLARKE: Thank you. My time has expired.
Let me now acknowledge the gentleman from New Mexico, Mr. Lujan.
REP. LUJAN: Thank you, Madame Chair. I know that we have some votes I think we have to get to, if I'm not mistaken, so I'll try to keep this brief.
Mr. Russo, what recommendations on standards have been made that have not been implemented by those that follow your standards?
MR. RUSSO: Congressman, we have a feedback process in place, which Chairwoman Clarke mentioned a little earlier. Actually I'm a little perplexed because Mr. Hogan earlier said that this is constantly changing, yet Chairwoman Clarke indicated it was a two-year process that we go through.
We go through two feedback periods where we get feedback from all of those participating organizations -- again, one of which is the NRF -- and we then discuss all of this information at two community meetings that we have on a yearly basis, one in North America and one in Europe. That information is then taken back from what we're getting, again, at that community meeting and gone through another feedback period before a new standard is released.
I might also mention that the difference between the initial standard that we came out with in 2006 and the 1.2 version, which we came out with in October, was not that different. There were clarifications. There were documentation changes. More guidance information was put in to make it easier to understand the intent and in fact comply with it. And these were all recommendations from these participating organizations, from our board of advisers. There are things that we put out on a regular basis based on their input. We do not create this standard in a vacuum. This is something that the entire group of participating organizations and the assessment community and our board of advisers advise us on.
REP. LUJAN: And let me narrow the question a little bit, Mr. Russo. There was some discussion about end-to-end encryption for its databases. Isn't that a recommendation that was made by the Heartland Payment Systems' CEO to implement?
MR. RUSSO: After the breach. It absolutely was, after the breach. And we agree that encryption is a good thing -- again, not a silver bullet. Encryption is a good thing. And as the gentleman from Michaels mentioned, encryption is an expensive proposition. If we make this mandatory in the standard, there will be a number of merchants who will not be able to afford this immediately, and there are provisions within the standard that actually affect what happens there.
So the need for end-to-end encryption within the internal network is really not there. If you are following the standard religiously, the need is not there. Why put these people through the expense? That being said, we are now investigating it from an independent third party and we will present that information in the form of feedback to our entire community and get their feeling on whether or not they actually want this to be part of the standard.
REP. LUJAN: And Mr. Russo, you said something earlier that I found interesting that you've never found PCI not to be in compliance at a time of breach, meaning that at a time of breach there may have been some break in compliance.
MR. RUSSO: Correct.
REP. LUJAN: But with the system that we have today, who's responsible for monitoring compliance?
MR. RUSSO: The merchant themselves. Basically, what we do is we take a snapshot. Let me give you a brief example, if I have a minute or so.
If you need fire insurance on your house and you come to me and ask me as the insurance company to give you fire insurance, I send an inspector out and you have everything in place -- smoke detectors that work, fire extinguishers, sprinklers and such. Three months later your house burns down. I send an inspector out again only to find out that there was no pressure on the sprinklers at that time, all of the batteries weren't working in your smoke detectors, and so on.
This is the responsibility not only of the counsel to make sure that you are compliant, but it's your responsibility as a merchant, your responsible to the consumers to make sure that you are doing this on a regular basis and --
REP. LUJAN: And Mr. Russo, if I could interrupt, I think that that example is a perfect illustration, because I would ask that the regulator that was responsible for monitoring the fire suppressant system and if you come back after there was a fire and you found out that my fire suppressant system wasn't adequate to be able to protect my home or my place of business, then the regulator wasn't doing their job. In this case there's no one overseeing this. It's here is a set of rules; if you want to be able to utilize our product, please follow them. And in the case if there is a breach, we depend on the Department of Justice to step in, oftentimes informing a group of people that maybe there was a breach.
Madame Chair, I know that my time has expired, but this is really interesting to see, you know, when we talk about a set of standards to truly see how we can work together to look to see where the weak points are, but also from a compliance perspective, I know that there aren't compliance efforts moving forward to truly work with the retailers if it's their responsibility to be held in compliance. But it seems to me that the system that we have today I think we all agree from different sides that it's not working.
REP. CLARKE: Thank you very much for your observations, Mr. Lujan.
And thank you for your responses.
We are in the process of votes right now, but I would like to get in one final question for this panel. And this question is for the entire panel, actually. A large part of the data theft problem is the amount of valuable data stored in the system. Mr. Hogan and Mr. Jones testified that the credit card companies are actually requiring merchants to keep more data than they would otherwise prefer.
Can the panel please explain what requirements exist for merchants to store credit card data in their systems? And why did the credit card companies dismiss the suggestion from NRF that these requirements be changed?
MR. MAJKA: Madame Chairwoman, if I may start by answering that question, Visa does not require merchants to retain cardholder data. We embarked on a campaign about three years ago to educate merchants on what data they absolutely need to maintain, and the campaign was called Drop the Data. And in those cases, they are not required to retain the account number.
We have found that some merchants do in fact retain the account number, customer name, maybe the expiration date. And in those cases, should a merchant choose to retain that data, they do have to secure it properly. But all merchants have the ability to work with their acquiring merchant bank to not store that data and use whether it's a authorization code or transaction ID as a reference number to then research a transaction that may be in question.
So from a Visa perspective, we do not require storage of that data.
REP. CLARKE: Mr. Hogan?
MR. HOGAN: This -- I mean, that statement is quite interesting because we hear from numerous, numerous merchants -- restaurants, hotels -- that if they don't keep some credit card data for a period of time to handle the retrieval or chargeback request process, they will be fined and penalized. So I would love to have, you know, somebody go on record here from Visa or so on and so forth that would basically make a statement that, again, retailers and merchants do not need to store any card -- any credit card data at all, just keep an authorization code, and they will not be penalized at all in context of the chargeback or retrieval request process. So maybe that could be a question you could pose back.
REP. CLARKE: I find this discrepancy to be very troubling -- very troubling.
Mr. Jones?
MR. JONES: I think there's -- we have to look at two entities, too. As the question was being answered there was "Visa does not require," and then the second part was we recommend they work with their acquiring merchant bank to understand what data they need to keep or don't need to keep.
Visa is not the person that we work with on a day-to-day basis. We work with our merchant bank. If your merchant bank cannot provide you back the information for you to look up among your thousands, tens of thousands, hundreds of thousands or millions of transactions, which we deal with on a basis to pull that transaction, and we have to physically pull a receipt, again -- we go from the point that we get a piece of paper with a card number on it and we have to get to the point where we pull a receipt to otherwise -- within a certain time period, otherwise we lose that transaction. So it's not a requirement. We could not do that. That's a cost -- we could say that's a cost of doing business. By doing that then, we would just automatically lose those dollars.
My brethren in places like Best Buy or big ticket, it would cost them a fortune. Places like a Marriott or a hotel or car reservation where you hold a reservation with a credit card number or they put a $400 charge on your credit card where it's being held but not charged yet, they do have to keep that; otherwise, they have no way to charge you after.
So I think we're dealing with which organization is requiring versus PCI doesn't require you; they're not a credit organization. Visa just transports it; their merchant bank is something else. The retailer is left holding the bag and has no input or say but yet is paying the transaction fee, is the one who pays for the transaction when the customer says that they are not responsible for it, and has, you know, no say in it.
There is a solution out there, but there have been no interactions, been no partnership to develop, really develop that solution I think.
REP. CLARKE: Well, let me just close by saying that this is something that we have to fix. And Mr. Majka, I look forward to speaking to you further about this.
And to all of you, thank you so much for your testimony here today. This has been very interesting, very enlightening. And I think that we've got a lot of work to do, as I said in my opening statement. Certainly, I think some things have come to light here today that should concern all of us and that we should be working together as a team to make sure that we address.
I thank the witnesses for their valuable testimony and the members for their questions. The members of the subcommittee may have additional questions for the witnesses, and we will ask you to respond expeditiously in writing to those questions.
Hearing no further business, the subcommittee stands adjourned. (Sounds gavel.)
END.