Aptean Logo

PCI Compliance Can Help Avoid Costly Data Breaches

Wednesday, September 5, 2018

card-pci-compliance-can-help-avoid-costly-data-breaches

It’s becoming crucial for companies to take seriously the regulations aimed at safeguarding customer data in this era of data breaches. Leaks of credit card data are a nightmare for customers and manufacturers alike, but luckily the major credit card companies saw the importance of cybersecurity more than a decade ago when they developed the Payment Card Industry Data Security Standard (PCI DSS).

Many of these regulations are commonsense safeguards, such as protecting sensitive data with a firewall. While compliance continues to grow, Verizon recently found that more than 40 percent of merchants have failed to adopt the standards. They change regularly, so those out of compliance can fall even further behind. Let’s examine a couple of common mistakes companies make when taking on a compliance project.

Mistake No. 1: Underestimating PCI Compliance Reach

These rules don’t just apply to major retailers. Manufacturers and distributers who process credit-card payments are subject to PCI DSS. One of the most common misconceptions about PCI compliance includes third-party credit card processing. Even if you outsource processing, you are still responsible for your customers’ transactions. Remaining compliant means ensuring that your processor is compliant, too, both at the time of hire and each year thereafter.

Mistake No. 2: Relying on Your IT Team To Manage the Entire Process

Some of the most critical PCI compliance-focused tasks will require the skills of an IT expert. However, your entire team is responsible for PCI-compliant processes. Maintaining a security policy and requiring that your employees adhere to it is a PCI compliance standard by itself.

Making sure your everyday processes protect data is important. Companies that accept credit card information over the phone and record customer service calls must be sure to edit out sensitive details that customers provide. Printed documents with credit card data need to have those numbers redacted. Email attachments should be deleted once card numbers are collected. You need the cooperation of more than just your IT team to put these requirements into practice.

Keep Access Limited

Ideally, you can invest in a Qualified Security Assessor to examine transaction processes and suggest solutions. If that’s not possible, limiting data access can make becoming PCI compliant less of a burden. Examine how credit card data flows through your organization to see if any departments can do without access to that information. At the same time, reduce the number of users who can access sensitive data. This trims down the number of processes that need to be PCI-compliant while also reducing the chances of a data breach due to employee error.

Awareness Is Your Best Defense

Falling victim to a data breach can have serious consequences. By understanding how PCI compliance affects your operations, reducing the number of departments affected and training those with access to be vigilant, your team can avoid a costly misstep.

Read the full article from Stevie Hay in Manufacturing Business Technology.

Stephen "Stevie" Hay
Author
Stephen "Stevie" Hay| Group VP of Distribution & Plant Management Product Group

As Vice President of Aptean’s Distribution & Plant Management Product Group, Stevie Hay is responsible for the strategic direction, customer satisfaction and business performance of Aptean’s distribution and plant management suite of products. Mr. Hay has worked with Aptean for over 20 years in different customer-facing roles. His most recent role was as General Manager for the Distribution Products where he managed the strategic direction of the WMS product lines along with leading several businesses successfully through the Aptean acquisition integration process.

Stephen "Stevie" Hay

By Stephen "Stevie" Hay| Group VP of Distribution & Plant Management Product Group

card-erp-migration-mistakes-5-critical-areas-to-avoid
Blog

ERP Migration Mistakes: 5 Critical Areas to Avoid

Discover 5 migration-specific mistakes that derail ERP projects. Learn how legacy system transitions differ from new implementations and avoid costly post-go-live failures.

Mar 25th, 2026
Before and After- How AI in Transportation and Logistics Enables Smarter and Smoother Operations
Blog

Before and After: How AI in Transportation and Logistics Enables Smarter and Smoother Operations

See how AI in transportation and logistics transforms daily operations—from maintenance to routing—with real before-and-after scenarios from Jim Endres.

Mar 18th, 2026
Comparing Food and Beverage ERP Solutions and Preparing Your Business for Implementation
Blog

Comparing Food and Beverage ERP Solutions and Preparing Your Business for Implementation

Learn how to evaluate ERP options based on industry fit, functionality and vendor expertise so you can select a system that supports long-term success.

Mar 12th, 2026
Logistics Trends To Act On in 2026- What’s Shaping the Industry Next Right Now
Blog

Logistics Trends To Act On in 2026: What’s Shaping the Industry Right Now

2026 won’t be a quiet year for logistics. From AI-driven planning to sustainable transportation and workforce change, see what you should have your eye on.

Feb 25th, 2026
Insights From Microsoft for Building High-Value, Scalable AI Projects
Blog

Insights From Microsoft for Building High-Value, Scalable AI Projects

Eduardo Kassner shares Microsoft’s proven framework for choosing, testing and scaling AI projects that deliver real business value.

Feb 17th, 2026