Welcome to our podcast series, Coffee with the Council. I'm Bryli Muse, Marketing and Communications Analyst for the PCI Security Standards Council. In today's episode, I'm excited to celebrate the 20th Anniversary of the Council.
Listen to the full episode on Spotify or on your favorite podcast player.
When the PCI Security Standards Council was created in 2006, the goal was to create a forum for the ongoing development, enhancement, and implementation of security standards for account data protection. Since then, the Council has not only achieved that goal but also created a space for industry leaders to come together and shape the direction of the industry.
Throughout our conversations with stakeholders, we explored a variety of topics about the Council’s journey and the evolution of the payments industry. To begin, we asked them to share their memories of how the Council, or the payments industry itself, has evolved over the last 20 years. Their responses offer a look back at the milestones, partnerships, and progress that have shaped the journey.
First, let’s hear a few words from Gary Glover, Vice President of Assessments at SecurityMetrics, and PCI SSC GEAR member, about his past 20 years involved in the Council.
Gary Glover: I think the thing that comes most to my mind when considering the past 20 years - which has allowed me to see the change from working individually with the card brands through the formation of the Council - I remember in the early days writing assessment reports that QSA’s didn’t have a whole lot of training in that area so we just did our best, reports probably didn’t have quite enough detail. We knew about cybersecurity and were implementing the standard as best we knew with our clients, but writing was not the fun part and did not get enough attention. Over the years it is interesting to see how the Council has evolved in the training and direction given to QSAs. That training both in assessment techniques and how to better document our results has improved the QSA community as a whole. I guess another fun part has been the experience of seeing how not only the PCI DSS standard has been evolving and incorporating important cybersecurity controls, but also how the Council has become more attentive to the QSA community by forming the GEAR. We have felt more “seen”, and that feels good.
Bryli Muse: Andy Barratt, Vice President of Coalfire, reflects on his involvement with the Council over the past 20 years.
Andy Barratt: The 20 years of PCI is kind of the last 20 years of my career. I spent the early start of my career working in card production assessments for the brands directly. I became a QSA as the program started. So, I've been a QSA, for what feels like since time began! And then I've adopted every other program in its infancy. So, I was one of the first P2PE Assessors, I became a PFI, and I'm now in a really fortunate position that I lead one of the most well-established QSA companies in the world. So that's a personal privilege having been through that journey. I think one of the things that was always fun is seeing the international variances. So, watching EMV roll out in Europe, I remember being a teenager working in a grocery store while chip and pin were being rolled out in the UK. And then rolling forward like 20 years and working with major US retailers who want to see how it was done in other parts of the world because just the adoption was different.
Bryli Muse: Sam Pfanstiel, Principal Technical Compliance Analyst at Toast, came to know PCI SSC a little later than some. However, he still was able to share the value and evolution he has seen over the years.
Sam Pfanstiel: I was a little bit late to PCI. I love to catch up with some of the generations that have been around from the beginning. But some of my favorite memories around PCI when I first became active in the community, I think we were just moving from PCI DSS v2 to v3. Of course, now we're on v4.0.1. At that time, we were seeing the evolution of recognizing all of the threats associated with malware, associated with lateral movement, and authorization. There's just a lot of complexity to addressing all the risk. And that's created a lot of exciting opportunities to see both the standards evolve but also seeing the way that the PCI Security Standards Council is invested in the solutions that really address these for merchants. I love what I do for Toast because we offer solutions, but it's really democratized that capability to the financial technology industry, really setting the stage for any technology company or innovator to build payment solutions that will not just satisfy the customer or merchant's needs, but also do it in a way that's secure. That's been really exciting from P2PE, to the SPoC and now the MPoC standards. These standards really are exciting to really build a roadmap or design a path for technology innovators to provide those secure solutions.
Bryli Muse: We also heard from Jacob Ansari, Security Governance Partner of Square, and his memories of PCI SSC over the years.
Jacob Ansari: It's been really interesting to just sort of see the transition of how we think about risk and how we think about where to prioritize our efforts and the development, the proliferity even of different standards across the payment ecosystem. So, it's changed a lot, but it's still kind of fun to see some of the through lines that have been through all of the history of the standards and to remember the obscure little bits of history that still show up if you know where to look for them.
Bryli Muse: Adam Bush, Managing Director at Schellman Compliance, spoke particularly about the dramatic advancements in technology over the last 20 years and the role the Council played in those changes.
Adam Bush: Over the last 20 years, we've seen more advancement in technology than in the previous hundred years. And the way we process payments and the way we just exchange currency, the way trade happens today just has adapted and has changed so drastically that man, it feels like a different century. And so, the speed at which we operate has changed really drastically. And, it would be impossible for a single entity in a bubble to keep up with an industry that has a pace of play and a rate of change that is so drastic. So having a true community and a Council that's involved with the community has, I think, kept them current and allowed them to stay on the bleeding edge, on the cutting edge, of information security and a broader compliance ecosystem.
Bryli Muse: These advancements are not limited to one region either. All across the globe, technology is advancing at a rapid rate. Tomoe Sakurai, Executive Director at Sun Partners Corporation, highlights the value the Council provided to her region of the world.
Tomoe Sakurai: My story is when I started attending the Community Meeting, I found it to be a lot smaller, especially the Asian-Pacific Community Meetings. Over the years, I found that there are more people from different countries, and I think the PCI community itself has become more global, as people often say these days. It's great that there is a strong awareness for cardholder data protection, especially in our country. I think the Council has done a very good job of laying the foundation for protecting cardholder data and raising awareness, which I think is very important. I have great respect for them and their work in setting the standards. It's great to see how the standards evolve over the years. In many ways, it's very flexible. I am glad to see the growth and hope it continues to spread across the world.
Bryli Muse: We also heard from Royston Ballard, Chief Information Security Officer of PCI PAL and his appreciation for the Council, and how it has continued to adapt to the continually changing payment industry.
Royston Ballard: What has been very clear, and abundantly clear, is the Council's willingness to basically take the feedback that's coming from the wider community itself of the importance and having to adapt accordingly for this next transformative technological change that we're about to see that is going to impact pretty much everything across the payment industry. Traditional ways of making payments are evolving, so where you did have to rely on traditional credit card numbers, now obviously, that is coming into the realm of tokenization. There are various other sorts of means and methods of making payments that will continue to evolve. I think the one thing that is good to see is the pace in terms of which the Council itself is basically being appreciative of these changes that need to come into effect very, very soon. Primarily on the basis that this isn't something that is a science fiction project, it is something which is now. I think those evolutions and how we collectively, as an industry, address those is going to be very important in sort of the next evolutionary chain of the journey of payments and processing thereof going forward.
Bryli Muse: Vivian Cullen, CEO of Comply B4, had so many memories of PCI SSC over the years, that he comprised it all into a small eBook.
Vivian Cullen: Quite frankly, I've written a small eBook of my memories and my journey watching PCI grow from its infancy to its maturity today. Yeah, the evolution of the standard is quite profound, purely because I've seen it go from infancy. And it has put us in a situation now that we've seen it grow from something very, very small and in some way parochial to something very global and widely accepted. To the point that even I think some countries that, I know of one in particular, that use it as a standard, as a baseline standard to work from. That's an important thing. And that shows the quality and the depth that is available within the standard.
Bryli Muse: Head of Cyber Security Services at Schwarz Digits IT, Tomas Perlines, looks back to a time before the Council and the unthinkable transformation of security through the years.
Tomas Perlines: Looking back into the times when the PCI Council was founded and the technologies which were out there to implement card payment solutions, we see that there is a massive evolution going on right now. And consumers in the past were even giving away their cards for payments. This is unthinkable today. So, we have been able to create a lot of awareness into the whole society even without explicitly mentioning that this is part of the PCI Council’s work.
Bryli Muse: Aidan Corcoran, Product Owner for Verisec International, spoke on his excitement to see where the standards will go in the next 20 years.
Aidan Corcoran: That has been fantastic to be able to watch the organization grow and evolve and move from just a handful of standards to the whole family of standards that we have now. And then under the new leadership, the iteration of those standards into the family groups has been a real bonus to be able to have more consistency and an interesting future for these standards.
Bryli Muse: Finally, Naveed Islam, Chief Information Security Officer at Paymentsense Limited, shares the value of the Council moving at the same pace as the payment industry and the achievement it is to have done so for the last 20 years.
Naveed Islam: Wow. So, the payment industries evolved so much in the last 20 years. So, I remember working with the PCI Council on the very early standards, and I was one of the recipients. So, I used to be a QSA back in 2006-2007, whenever it was, and working on the early standards and the ecosystem has moved on so much. A lot of it was very much face-to-face payments back then, but payments itself, card payments weren't as ubiquitous as they are now. And the Council has done a really good job in terms of moving with the times. Over time, what the Council has done is, as I said, is moved along with the technologies and made sure that they stay at times in front of it, but if not in front of it, alongside us, to enable all of these payment methods to happen face-to-face, virtual, over the phone, etcetera, etcetera, for these payments to take place, but in a secure and a trusted manner so that when I'm making a payment using my Android or Apple phone, I don't even think about the security. When I'm making an online payment, I'm not thinking about the security because I know there's an ecosystem behind it. So, I work in the industry, so I kind of know about it by speaking to people who have no clue about payment security when they're using these, they just have an inherent trust that all of these technologies and the payment aspects is just going to work. It's going to work, it's going to be secure, and their details are not going to get leaked. That's all enabled through what PCI Council has done over the last 20 years and said, the biggest achievement for me is keeping abreast of all the changes and staying ahead or alongside it.
Bryli Muse: As we bring this episode to a close, we asked our stakeholders to leave a congratulatory message for the Council in honor of its 20th anniversary. Let’s end by hearing their words of celebration, appreciation, and best wishes for the future.
Bryli Muse: ControlCase Director of Business Development, Karolien Holsters, is proud to have been a part of the PCI SSC journey and is looking forward to the years to come.
Karolien Holsters: I would like to say congratulations to the Council! ControlCase has been very grateful to be part of your journey. And we are here to continue on the same path with you.
Bryli Muse: Dustin Rich, Director of PCI at Align, acknowledged how quickly 20 years have gone by and is thankful for the greater payment industry.
Dustin Rich: Wow! It's already been 20 years? It’s hard to believe and I feel it really ages me. I was in the first QSA class there in Foster City at the Visa offices back in the day. I still remember that day, still interact with a few others in that class, and we have all really have come a long way. A lot in the industry has grown and matured over the last years. There’s been a lot of changes and new threats, but the industry is definitely in in a better security posture today than it was then. Congratulations to the Council and thank you for the past 20 years! Also, thank you to all those who've worked diligently and contributed within this industry over the last 20 years. We've all come a long way!
Bryli Muse: And Richard Kisley, Chief Engineer for IBM HSM, shared our final celebratory message.
Richard Kisley: PCI SSC, congratulations! 20 years. Fantastic! What are we doing next?
Bryli Muse: Thank you for sharing your wonderful memories over the last 20 years and your heartfelt congratulatory messages for the Council. We look forward to all that is to come in the next 20 years! To hear more great memories of 20 years of PCI SSC, visit our 20th anniversary landing page on the PCI SSC website. 
Like what you’ve heard? Subscribe to PCI SSC’s “Coffee with the Council” podcast by visiting any of the following platforms: Apple Podcasts, Spotify, Amazon Music, Anchor, Castbox, Google Podcasts, iHeartRadio, Pocket Casts, RadioPublic, or Stitcher.


