<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Why Do PCI Scanning Companies Make Things So Difficult?</title>
	<atom:link href="https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/</link>
	<description>All about e-Commerce, ShopSite, and Web Hosting</description>
	<lastBuildDate>Thu, 16 Dec 2021 19:59:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.2.1</generator>
	<item>
		<title>By: Robert Mangiafico</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-27790</link>
		<dc:creator><![CDATA[Robert Mangiafico]]></dc:creator>
		<pubDate>Wed, 17 Oct 2012 17:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-27790</guid>
		<description><![CDATA[Thanks for the real world feedback Paul. We work with all the major vendors every day. I&#039;ve found TrustWave and McAfee to be the two easiest ones to work with in terms of getting things resolved.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the real world feedback Paul. We work with all the major vendors every day. I&#8217;ve found TrustWave and McAfee to be the two easiest ones to work with in terms of getting things resolved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul van Woensel</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-27786</link>
		<dc:creator><![CDATA[Paul van Woensel]]></dc:creator>
		<pubDate>Wed, 17 Oct 2012 16:35:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-27786</guid>
		<description><![CDATA[We currently are using Security Metrics and extrememly unhappy with the service. The same false positives over and over. Sites that are hosted by the same servers as other site fail, while the other passes. 

There are still 3 months left on our contract, but I would love to suggest a different / better experience. 

Who switched to what and how are you liking similar priced options?]]></description>
		<content:encoded><![CDATA[<p>We currently are using Security Metrics and extrememly unhappy with the service. The same false positives over and over. Sites that are hosted by the same servers as other site fail, while the other passes. </p>
<p>There are still 3 months left on our contract, but I would love to suggest a different / better experience. </p>
<p>Who switched to what and how are you liking similar priced options?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Galloway</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-24839</link>
		<dc:creator><![CDATA[John Galloway]]></dc:creator>
		<pubDate>Thu, 28 Jun 2012 12:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-24839</guid>
		<description><![CDATA[Security Metrics have a number of products that are used for PCI compliance. However none of them perform a quality job and are typically lagging behind competing products. This included their vulnerability scanning, their pan scan tool and their online pci portal.

After working with their products and with other alternatives, it seems the security metrics model is to  create basic products  then push these through large banks onto small merchants who are not technical and will just accept whatever is put in front of them.

This is a typical business case where you can take an ordinary product, spend lots of money on sales and marketing and squeeze as much revenue as possible from it.]]></description>
		<content:encoded><![CDATA[<p>Security Metrics have a number of products that are used for PCI compliance. However none of them perform a quality job and are typically lagging behind competing products. This included their vulnerability scanning, their pan scan tool and their online pci portal.</p>
<p>After working with their products and with other alternatives, it seems the security metrics model is to  create basic products  then push these through large banks onto small merchants who are not technical and will just accept whatever is put in front of them.</p>
<p>This is a typical business case where you can take an ordinary product, spend lots of money on sales and marketing and squeeze as much revenue as possible from it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SteveG</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16562</link>
		<dc:creator><![CDATA[SteveG]]></dc:creator>
		<pubDate>Fri, 20 May 2011 17:08:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16562</guid>
		<description><![CDATA[&quot;My main suggestion is, stop whining about things you can’t change and be grateful for what you have!&quot;

Wow, excellent response.. Except it&#039;s wrong.. There is no whining, not even on my part I&#039;ve been taken for a few hundred bucks because of this.. I want change.. I want accountability.. And I want a FAR more transparent process than we have had to date.. Then when you add what certainly looks like a back door agreement between processors and compliance companies, the whole thing simply reeks of a money grab with no real intention to resolve the issues..

But that may just be me being cynical..]]></description>
		<content:encoded><![CDATA[<p>&#8220;My main suggestion is, stop whining about things you can’t change and be grateful for what you have!&#8221;</p>
<p>Wow, excellent response.. Except it&#8217;s wrong.. There is no whining, not even on my part I&#8217;ve been taken for a few hundred bucks because of this.. I want change.. I want accountability.. And I want a FAR more transparent process than we have had to date.. Then when you add what certainly looks like a back door agreement between processors and compliance companies, the whole thing simply reeks of a money grab with no real intention to resolve the issues..</p>
<p>But that may just be me being cynical..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Mangiafico</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16561</link>
		<dc:creator><![CDATA[Rob Mangiafico]]></dc:creator>
		<pubDate>Fri, 20 May 2011 16:52:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16561</guid>
		<description><![CDATA[Thanks for the feedback Jason. I&#039;m not knocking the standards (besides a little dig at the industry as a whole) and adhering to them. But, there are other PCI scanning companies out there that we work with that do the job more efficiently and better than SecurityMetrics. They make our (and our clients) life easier when issues pop up.

I don&#039;t doubt that SecurityMetrics offers value in dealing with PCI related issues. I&#039;d just like to see them improve their processes to make it easier to comply with all the rules and regulations PCI requires.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the feedback Jason. I&#8217;m not knocking the standards (besides a little dig at the industry as a whole) and adhering to them. But, there are other PCI scanning companies out there that we work with that do the job more efficiently and better than SecurityMetrics. They make our (and our clients) life easier when issues pop up.</p>
<p>I don&#8217;t doubt that SecurityMetrics offers value in dealing with PCI related issues. I&#8217;d just like to see them improve their processes to make it easier to comply with all the rules and regulations PCI requires.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16560</link>
		<dc:creator><![CDATA[Jason]]></dc:creator>
		<pubDate>Fri, 20 May 2011 16:42:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16560</guid>
		<description><![CDATA[Well, honestly, what do you expect them to do about it? They are held to certain standards by the PCI and there&#039;s absolutely nothing they can do about that... And honestly, for any merchant who has ever tried to do PCI Compliance on their own (the right way) would be more than glad to have the kind of help that SecurityMetrics offers. Yeah, it&#039;s still a pain, but it&#039;s way better than doing it on your own... 
My main suggestion is, stop whining about things you can&#039;t change and be grateful for what you have!]]></description>
		<content:encoded><![CDATA[<p>Well, honestly, what do you expect them to do about it? They are held to certain standards by the PCI and there&#8217;s absolutely nothing they can do about that&#8230; And honestly, for any merchant who has ever tried to do PCI Compliance on their own (the right way) would be more than glad to have the kind of help that SecurityMetrics offers. Yeah, it&#8217;s still a pain, but it&#8217;s way better than doing it on your own&#8230;<br />
My main suggestion is, stop whining about things you can&#8217;t change and be grateful for what you have!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Mangiafico</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16551</link>
		<dc:creator><![CDATA[Rob Mangiafico]]></dc:creator>
		<pubDate>Thu, 19 May 2011 15:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16551</guid>
		<description><![CDATA[Can&#039;t argue with that Steve.  :)

Hopefully someone with pull in the industry starts cleaning it up.]]></description>
		<content:encoded><![CDATA[<p>Can&#8217;t argue with that Steve.  <img src="https://www.lexiconn.com/blog/wp-includes/images/smilies/simple-smile.png" alt=":)" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Hopefully someone with pull in the industry starts cleaning it up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SteveG</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16547</link>
		<dc:creator><![CDATA[SteveG]]></dc:creator>
		<pubDate>Thu, 19 May 2011 03:35:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16547</guid>
		<description><![CDATA[I&#039;m switching my merchant account provider specifically because of their relationship with Security Metrics.. Well that and I know more about PCI than they do.. 

What kills me is that if you fail the PCI compliance many merchant providers do not shut you off, they don&#039;t even tell you about the failure, but they do charge you an extra $20 for being out of compliance.. 

It&#039;s the old, well, you broke the rules, but for $20 we&#039;ll look the other way.. Nudge nudge, wink wink.. 

It&#039;s wrong, and we shouldn&#039;t be forced to deal with it.. There are so many ways that they could improve the entire PCI system, but I doubt anyone has bothered to talk to the people in the trenches, the merchants..]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m switching my merchant account provider specifically because of their relationship with Security Metrics.. Well that and I know more about PCI than they do.. </p>
<p>What kills me is that if you fail the PCI compliance many merchant providers do not shut you off, they don&#8217;t even tell you about the failure, but they do charge you an extra $20 for being out of compliance.. </p>
<p>It&#8217;s the old, well, you broke the rules, but for $20 we&#8217;ll look the other way.. Nudge nudge, wink wink.. </p>
<p>It&#8217;s wrong, and we shouldn&#8217;t be forced to deal with it.. There are so many ways that they could improve the entire PCI system, but I doubt anyone has bothered to talk to the people in the trenches, the merchants..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ISO Info - Why Do PCI Scanning Companies Make Things So Difficult?</title>
		<link>https://www.lexiconn.com/blog/2011/05/why-do-pci-scanning-companies-make-things-so-difficult/#comment-16544</link>
		<dc:creator><![CDATA[ISO Info - Why Do PCI Scanning Companies Make Things So Difficult?]]></dc:creator>
		<pubDate>Wed, 18 May 2011 22:59:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.lexiconn.com/blog/?p=3899#comment-16544</guid>
		<description><![CDATA[[...] Continue reading here: Why Do PCI Scanning Companies Make Things So Difficult? [...]]]></description>
		<content:encoded><![CDATA[<p>[&#8230;] Continue reading here: Why Do PCI Scanning Companies Make Things So Difficult? [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
