During a recent investigation, we discovered that a major e-commerce company had a critical misconfiguration on its web server. This vulnerability enabled attackers to inject malicious code into the website, allowing them to intercept customer payment data during transactions. The root cause? It missed a quarterly ASV scan, which would likely have identified the issue before it was exploited.
Misconfigurations like this are not unique to one company; they may pose a serious risk to any organization handling cardholder data.
The Payment Card Industry Data Security Standard (PCI DSS) mandates that organizations carry out and document recurring security activities, which must be reviewed by a Qualified Security Assessor (QSA) during the annual compliance assessment. A key part of these activities is the ASV (Approved Scanning Vendor) scan that is performed quarterly. These scans are intended to protect cardholder data by periodically identifying and addressing vulnerabilities in internet-facing systems. They are a clearly defined requirement under the PCI DSS standard.
As per the payment security standard council, the expectation is straightforward, requiring organizations to conduct a scan using an ASV every 90 days, or after significant changes are done in the CDE environment, to identify and remediate any issues and submit a passing report. Additionally, it is necessary that organizations must pass the ASV scan activities to maintain compliance. A failed scan is not acceptable for compliance purposes; therefore, if the initial scan fails, the organization is required to perform remediation and conduct subsequent rescans until a passing result is achieved.
Despite these well-defined requirements, many organizations consistently fail to conduct these scans on time. Failure to perform these tasks results in non-compliance or an unsuccessful/invalid Report on Compliance (RoC).
This situation highlights a deeper disconnect between compliance intention and operational reality.
While PCI SSC enforces strict requirements, with assessors requiring clear evidence for PCI DSS v4.0.1 , many organizations struggle to keep up due to competing priorities. As per the PCI DSS Requirement 11.3.2, organizations are required to perform external ASV scan at least quarterly and after any significant changes are done to the cardholder data environment (CDE). However, we found many organizations not following this important requirement.
In addition, organizations lack streamlined processes because they did not fully understand the technical and logistical nuances of ASV scanning.
This results in:
This gap not only poses challenges for PCI DSS compliance but also heightens overall security risk, providing ample opportunity for attackers.
Usually, ASV scans focus on:
These help organizations detect vulnerabilities or weaknesses in applications, infrastructure, configurations, as well as software components.
However, the challenge arises when it comes to understanding them technically and their deeper issues. Eventually, this leads to failed ASV scans as well as recurring vulnerabilities.
Some of the common pitfalls are:
The need to balance a strict compliance schedule with daily operational demands and technical missteps often leads to missed or failed quarterly ASV scans.
For organizations aiming to maintain PCI DSS compliance, selecting the right ASV is more than a checkbox. The right ASV not only helps the organization meet PCI DSS requirements but also acts as a strategic partner by eliminating the hassle of quarterly scans and providing in-depth expertise.
When evaluating potential ASVs, organizations must look beyond basic scanning capabilities. These include:
Maintaining PCI DSS compliance can be overwhelming, especially when it comes to managing quarterly ASV scans. Ampcus Cyber offers a comprehensive and partner-driven ASV service, helping organizations avoid common pitfalls, streamline compliance, and strengthen their overall security posture.
Here’s how the Ampcus Cyber ASV solution stands out:
With Ampcus Cyber as your ASV partner, you gain more than a compliance tool. You gain a cybersecurity advisor focused on helping you pass every scan with confidence, while also boosting your real-world security.
An ASV scan is a specialized type of external vulnerability assessment mandated by PCI DSS. It focuses specifically on identifying vulnerabilities that could be exploited by external attackers to compromise cardholder data, thereby ensuring PCI DSS compliance. In contrast, general external vulnerability assessments may cover a broader range of internet-facing assets and assess various types of security weaknesses.
ASV scan must be performed at least once every 90 days (quarterly), or after any significant changes are made to the CDE.
There is no standard timeline for performing and completing the ASV scan. The scanning process depends on the organization’s size and infrastructure in the scope, such as number of IPs or servers. The larger the size of the organization, the more time it can take for ASV scan.
These are the prerequisites for conducting an ASV scan• Defining and validating the scan scope (internet-facing assets in the PCI environment)• Scheduling and coordinating the scan with the ASV• Ensuring systems are ready and accessible for scanning• Collaborating with a qualified, PCI-certified ASV vendor• Client attestation and verification of scan scope
Prices vary from one service provider to another. Typically, factors such as company size, number of servers, IP addresses, and the overall scanning scope are considered when calculating the cost. For Ampcus Cyber customers, the pricing is 25% lower than standard market rates.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
This website uses the following additional cookies:
(List the cookies that you are using on the website here.)
More information about our Cookie Policy