---
title: PCI Council Supports Data Privacy Day with Free Training
description: In the spirit of Data Privacy Day, the PCI SSC shares educational resources on mitigating the three most common causes of merchant data breaches.
image: https://blog.pcisecuritystandards.org/hubfs/2017-Blog/2018-data-privacy-day.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training#)

# [PCI Council Supports Data Privacy Day with Free Training](https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training)

 Posted by [Lindsay Goodspeed](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed) on 25 Jan, 2018 in [Training](https://blog.pcisecuritystandards.org/topic/training) and [Patching](https://blog.pcisecuritystandards.org/topic/patching) and [Passwords](https://blog.pcisecuritystandards.org/topic/passwords) and [Awareness](https://blog.pcisecuritystandards.org/topic/awareness) and [QIR](https://blog.pcisecuritystandards.org/topic/qir) and [Data Privacy Day](https://blog.pcisecuritystandards.org/topic/data-privacy-day) and [Remote Access](https://blog.pcisecuritystandards.org/topic/remote-access)

![2018-data-privacy-day.jpg](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2017-Blog/2018-data-privacy-day.jpg?width=800&name=2018-data-privacy-day.jpg "2018-data-privacy-day.jpg")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training&url=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training&source=tweetbutton&text=PCI%20Council%20Supports%20Data%20Privacy%20Day%20with%20Free%20Training> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training)

*In support of Data Privacy Day, we’re offering FREE PCI Awareness training to the first 1,000 people who register between 25 January, noon EST – 26 January noon EST. ** PCI Awareness training helps companies educate employees who handle payment card data on payment data security essentials. Learn more about the offer ***[*here*](https://www.pcisecuritystandards.org/program_training_and_qualification/data_privacy_day_registration2018)***. *

In the spirit of Data Privacy Day, here are some educational resources on mitigating the three most common causes of merchant data breaches:

**Remote Access Vulnerabilities **

Remote access is one of the most common attack methods used by criminal hackers and is often used in combination with other attacks such as malware. For example, remote access may be used to get into a merchant’s payment system (by using a commonly known vendor default password like “password” or “123456”). Once in, the hackers place malware on a merchant system which may be used to capture data. Merchants may not even know that remote access software is present or when the remote access is being used, especially if that remote access is left permanently switched on and not monitored.

- [**More Information on Remote Access Security**](https://blog.pcisecuritystandards.org/topic/remote-access)

**Weak Password Practices**

The second area is weak password practices. Industry reports show that 81% of hacking-related breaches leveraged either stolen and/or weak passwords. Computer equipment and software out-of-the-box (including payment terminals) often come with default or preset passwords such as “password” or “admin”, which are commonly known by criminals.

- [**More Information on Secure Password Practices**](https://blog.pcisecuritystandards.org/topic/passwords)

**Outdated and Unpatched Software **

Often, software has flaws or mistakes, also known as bugs or vulnerabilities. Cybercriminals exploit these mistakes to break into a merchant’s computers and steal payment data. Software vendors provide security updates called “patches” to fix these coding errors, and need to be installed in a timely manner for maximum effectiveness.

- [**More Information on Patching and Updating Software**](https://blog.pcisecuritystandards.org/topic/patching)

Awareness starts with you and doesn’t stop with Data Privacy Day. Make it an everyday priority in 2018 and sign up for our:

[![FREE Awareness eLearning course](https://no-cache.hubspot.com/cta/default/281302/5897bc82-df39-4fc6-ad77-5d199cc491a6.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/5897bc82-df39-4fc6-ad77-5d199cc491a6)

 

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Lindsay Goodspeed](https://blog.pcisecuritystandards.org/hubfs/Headshots/lindsay-goodspeed.jpg)

[ Lindsay Goodspeed ](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed)

[Twitter ](https://twitter.com/PCISSC) [LinkedIn](https://www.linkedin.com/in/lindsaygoodspeed) [Email](mailto:blog@pcisecuritystandards.org) [Website](https://www.pcisecuritystandards.org/)

 As Senior Manager, Corporate Communications for the Council, Ms. Goodspeed drives awareness of PCI Security Standards and resources for the protection of payment card data.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/pci-council-supports-data-privacy-day-with-free-training#)