Kiwis are naturally resourceful. Kayak strapped to the car roof, chilly bin packed, trip funded by a sausage sizzle outside Bunnings, and enough confidence to figure the rest out along the way. But when it comes to PCI DSS compliance, that resourcefulness splits in three. Some businesses spend like they have hired a helicopter to fly a route they could have driven in a car. Others set off with no map, no fuel, and ‘all good, mate’ attitude. And some start the engine and never leave the car park.
Category: PCI DSS
From iced matcha tea to qualification: The rollercoaster ride to becoming a Qualified Security Assessor (QSA)

If you’re reading this blog, you probably already have some experience with security standards and certifications – maybe you even hold a few yourself. In this blog, I will shed some light on my own journey to gain the QSA qualification and break down the steps I took to make this happen.
What is the difference between masking and truncation?
We have come across a number of scenarios recently where there seems to be a bit of confusion between masking and truncation and when to use which one. The following update from the Axenic PCI department should help clear things up.
Our Journey to becoming PCI QSA Registered
What does a 1300km lockdown drive have in common with PCI?
“How does driving a 1,300km journey during the COVID-19 lockdown relate to PCI compliance?” I hear you say…
As those of you who know me, or have seen me present will know, I love a good metaphor.
Over Easter weekend I had the somewhat surreal experience of driving the 1,300km journey from home to Auckland International Airport and back again during New Zealand’s level 4 COVID-19 lockdown. On the trip home I was reflecting and couldn’t help thinking about the similarities between the lockdown, making this a safe compliant trip and PCI DSS compliance.
Highlights from the Verizon 2014 PCI Compliance Report
Verizon has published its 2014 PCI Compliance Report, which can be downloaded from here. Like their Data Breach Investigation Report (DBIR) it is an excellent piece of research and provides insight into the challenges associated with complying with the Payment Card Industry’s Data Security Standard (PCI DSS) v2.0.
