Advertisement

Most Small Merchants Do Not Fear Security Breach

Only 50% of small merchants have validated their PCI compliance, according to a recent survey of 600 Level 4 merchants. In total, 79% of these retailers think there is “little to no chance a data breach will happen to them,” as noted in the report titled: A Tale of Two Merchants: The Fourth Annual Survey of Level 4 Merchant PCI Compliance Trends,” conducted by ControlScan and Merchant Warehouse. Additionally, brick-and-mortar retailers are less stringent than their e-Commerce counterparts.

As defined by Visa, Level 4 merchants are those processing less than 20,000 Visa eCommerce transactions annually; or up to 1 million transactions in the brick-and-mortar store. In total, there are approximately 5 million Level 4 merchants in the U.S.

In reality, these smaller merchants should be more concerned. In June, 2012, Visa reported that attacks against Level 4 and franchise merchants are on the rise in the U.S.; and as many as 96% of breach victims in 2012 were not PCI compliant, according to Verizon.

Advertisement

Small Businesses Offer Contradictory Security Insights

While less than half (47%) of Level 4 merchants say they are familiar with PCI DSS, those stating familiarity with compliance measures are supportive:

  • 77% say security ranks “high” or “medium” in terms of overall organizational priorities;
  • 67% believe PCI compliance would make their business more secure; and
  • 57% note that they believe PCI standards should apply to their businesses.

On the contrary…

  • Of those survey respondents who have validated PCI compliance, only 39% say they have the documentation to support their Self-Assessment Questionnaire (SAQ);
  • 43% say they took no action nor made any purchases to achieve PCI compliance; they simply “completed the paperwork;” and
  • Total overall compliance for survey respondents is 30%.


4 Recommendations For ISOs And Acquirers

ControlScan offered the following four recommendations for ISOs and merchant acquirers, to help forge a stronger partner relationship with retailers:

  1. Mine customer data to create risk-based action plans.
  2. Strengthen communications with the riskiest merchants.
  3. Equip merchant-facing representatives with the right tools.
  4. Offer technology and service solutions to facilitate a smooth transition to PCI compliance.

Click here to access the complete report.

Featured Event

View the Retail Trendcaster Webinar Series on-demand to uncover key 2025 retail trends, from AI and personalization to social commerce. Gain expert insights, data-driven predictions, and actionable takeaways to stay ahead in a rapidly evolving market.

Advertisement

Advertisement

Retail Trendcaster Webinar Series
Days
Hours
Minutes
Seconds

Uncovering What’s Next in Retail

On-Demand Limited Video Series

Q1 is a pivotal time for retail, with experts analyzing holiday sales and forecasting trends. View the full lineup of the Retail Trendcaster video series for insights on consumer spending, AI, personalization, social commerce, and more—helping you focus on what truly matters in 2025.

Brought to you by
Retail TouchPoints
Access Now
Retail TouchPoints is a brand of Emerald X LLC. By clicking the button and submitting information, you acknowledge and agree that your information may be shared with corporate affiliates of Emerald X LLC, and other organizations such as event hosts, speakers, sponsors, and partners. Please read our Privacy Policy and our Terms Of Use for more information on our policies.

Access The Media Kit

Interests:

Access Our Editorial Calendar




If you are downloading this on behalf of a client, please provide the company name and website information below: