---
title: Four Insights from Day 1 of the PCI NACM
description: Read this blog post for key payment security takeaways from the PCI NACM.
image: https://blog.pcisecuritystandards.org/hubfs/NACM%20Recap%20Day%201.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm#)

# [Four Insights from Day 1 of the PCI NACM](https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm)

 Posted by [Lindsay Goodspeed](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed) on 13 Sep, 2023 in [Skimming](https://blog.pcisecuritystandards.org/topic/skimming) and [Community Meetings](https://blog.pcisecuritystandards.org/topic/community-meetings) and [PCI DSS](https://blog.pcisecuritystandards.org/topic/pci-dss) and [Participation](https://blog.pcisecuritystandards.org/topic/participation)

![NACM Recap Day 1](https://blog.pcisecuritystandards.org/hs-fs/hubfs/NACM%20Recap%20Day%201.jpg?width=800&name=NACM%20Recap%20Day%201.jpg "NACM Recap Day 1")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm&url=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm&source=tweetbutton&text=Four%20Insights%20from%20Day%201%20of%20the%20PCI%20NACM> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm)

 

The 2023 North America Community Meeting convened in Portland, OR this week, bringing together thousands of payment security experts from across the globe. The three-day program is jam-packed with dozens of presentations and panel discussions covering a broad range of payment security topics.

The following are just a few of the takeaways from the first day of the conference.

Security is a Journey, Not a Destination

Lance Johnson, Executive Director of PCI SSC, reminded the audience that proper security requires ongoing vigilance. As payment technology evolves and new attack vectors emerge, the Council relies on industry feedback and insights to help keep global payment data secure. In reaction to industry shifts, the Council recently updated its Participation Program to enable broader industry participation. Learn more here: [New Opportunities for Collaboration with the Council](https://blog.pcisecuritystandards.org/new-opportunities-for-collaboration-with-the-council-coming-in-2023)

Resources Abound to Help the Industry Understand PCI DSS v4.0

The Council presented a series of discussions focused on common industry questions to help the industry understand the latest version of PCI DSS v4.0. With the 2024 March retirement of PCI DSS v3.2.1, the transition is top of mind in the payment security industry.

Council-created PCI DSS v4.0 resources that were highlighted on stage included:

- [Dozens of New and Updated Frequently Asked Questions (FAQs) related to PCI DSS v4.0](https://www.pcisecuritystandards.org/faqs/all/)
- [Newly Published SAQ Instructions and Guidelines](https://www.pcisecuritystandards.org/document_library/)
- [Eight Steps to Take on the Journey to PCI DSS v4.0](https://blog.pcisecuritystandards.org/eight-steps-to-take-toward-pci-dss-v4-0)

AI Technology Provides Both Opportunities and Risks to Payment Security

There are both opportunities and risks when considering AI’s role in payment security. While AI provides opportunities to automate mundane tasks, over reliance can lead to issues. Organizations may become overly reliant on AI for payments, leaving little room for human judgment and intuition. AI tools can produce biased results based on the data they were trained on. Be aware of this potential bias and take it into account when interpreting the output. The more you understand about how an AI tool works, the better you can evaluate its reliability.

Breached Card Data is Trending Downward

[A Verizon survey](https://www.verizon.com/business/resources/reports/dbir/) shows that since 2018, payment card data is being featured less and less in data breaches. Effective security controls - such as those defined in PCI DSS v4.0 - are helping organizations keep their payment data secure. However, organizations are still being attacked, so vigilance is crucial. As new payment technologies emerge and as criminals find new ways to steal data, it’s the role of the Council - in close partnership with the payments industry - to develop and evolve standards to keep pace with criminal activity. 

[![Subscribe to the PCI Perspectives Blog for More Payment Security Insights](https://no-cache.hubspot.com/cta/default/281302/33786b6b-e067-48c0-b7cf-d5f3274e66a6.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/33786b6b-e067-48c0-b7cf-d5f3274e66a6)

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Lindsay Goodspeed](https://blog.pcisecuritystandards.org/hubfs/Headshots/lindsay-goodspeed.jpg)

[ Lindsay Goodspeed ](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed)

[Twitter ](https://twitter.com/PCISSC) [LinkedIn](https://www.linkedin.com/in/lindsaygoodspeed) [Email](mailto:blog@pcisecuritystandards.org) [Website](https://www.pcisecuritystandards.org/)

 As Senior Manager, Corporate Communications for the Council, Ms. Goodspeed drives awareness of PCI Security Standards and resources for the protection of payment card data.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/four-insights-from-day-1-of-the-pci-nacm#)