Trustwave Sued in Target Breach: Should Security Vendors Be Worried?
The PCI-DSS assessor for Target is named in a lawsuit. Where does responsibility sit?
With all IT data breaches there is a common cycle. First there is the fear over who is at risk, then theories on how the breach occurred, and finally the blaming and lawsuits start to roll in. In the breach of retailer Target, the lawsuits are now coming in, but in a surprising move, one lawsuit isn't just going after Target; it's also going after security vendor Trustwave.
Target first revealed that it had been breached by attackers on Dec. 9, 2013, and ever since, there have been lots of speculation on what went wrong. All U.S retailers are required to be compliant with the Payment Card Industry Data Security Standard (PCI-DSS), in order to securely process credit card transactions. The question of Target's PCI-DSS compliance status has been an important part of the conversation surrounding the data breach, and now the company that conducted the PCI-DSS compliance testing for Target is being named in a legal action.