
Join TCT at the PCI-NACM in Vancouver - Episode 233
Om avsnittet
PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain risk, and operational compliance are reshaping payment security. They explain why continuous evidence beats annual screenshots, what the PCI Community Meeting in Vancouver can offer, and how teams can turn compliance into practical, measurable risk reduction. Ideal for security leaders and compliance professionals worldwide.
Episode Transcript:
Adam, join us at the PCI North American Community Meeting in Vancouver, British Columbia, Canada. 20 years later, I have to ask you, Adam, has PCI actually made payments more secure?
Adam Goslin:
Oh, I mean, there’s no doubt it had a dramatic impact. You got to remember back in the day, it was the absolute Wild West. The card brands were just getting their asses handed to them, and something needed to be done.
The level of change from when this whole adventure first started to now is pretty startling. I think in many ways it was necessary.
I think that the card industry as a whole forced a lot of organizations to start leveling up, start taking this stuff seriously. I believe it was astronomically helpful as we’ve headed into this arena.
Certainly, we’re seeing a lot of shifts in the marketplace where we’re moving away from a checkbox approach, etc.
It’s hard to remember. I was looking up, when did PCI V1 officially get released? It was middle of December in 2004.
Todd Coshow:
Oh, wow.
Adam Goslin:
It was like the first version of it, type of a deal. It was 2006 that the PCI SSC was officially formed.
Then they started to make enhancements. But there have been a whole myriad of different changes and modifications to the standards over that time.
The payments arena really has made a fairly startling shift from just checking the box, annual validations, into more of a continuous security or, as we here at TCT like to call, operational mode, type of a deal.
The acceleration of AI, both for the white hats and black hats, has enabled attackers to move as quickly as defenders.
So it remains a very, very vibrant and exciting arena.
Todd Coshow:
No doubt. Well, what do you think the biggest conversations at this year’s community meeting will be?
Adam Goslin:
Yeah, I think there’s a lot.
New and exciting things happening in the payment space will certainly be one.
Bar none, a big participant will be a lot of topics surrounding AI. AI, its use and benefits and all that fun stuff. Honestly, I’m kind of hoping that somebody whips a little bit of realism in there about the dangers of AI as well.
I think I’ve mentioned once or 80 times about AI zombie walk.
I think there’s a lot of signs in the marketplace right now that the AI zombie walk mentality isn’t necessarily the best idea in the grand scheme of things. I think there’s a lot more reasonability starting to enter into the mix. That’s what I’m hoping at least.
Certainly, a lot of discussions around operational compliance, automation of evidence collection, various ways to streamline your engagements, looking at threat intelligence and attack trends as they’re going.
Certainly, one of the cool parts about being at the conference is getting updates direct from the council, what’s happening, what’s coming soon to a theater near us, all of that fun stuff.
We’ve got all that coming our way as well.
Todd Coshow:
Indeed. What’s one thing every first-time attendee should do in Vancouver?
Adam Goslin:
Well, number one, I’m just gonna underscore this big time.
Compliance Unfiltered With Adam Goslin med Total Compliance Tracking finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.