PANscan Trends

See how you rank against other organizations and how they handle the storage of unencrypted payment card data over the years.

Findings from SecurityMetrics' Credit Card Discovery Tool

SecurityMetrics PANscan® is a card data discovery tool that businesses use to search for unprotected credit card data and to help confirm their PCI DSS audit scope.

Using automated card data discovery tools helps businesses find primary account numbers (PAN) on computer systems, networks, hard drives, and attached storage devices. Many businesses experience compromise because simple steps are not taken to ensure security. PANscan is a simple tool that helps limit business liability.

How much unencrypted card data has PANscan® found?

Since 2010, SecurityMetrics PANscan® discovered over 3.1 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach.

In 2023, the results of SecurityMetrics’ PANscan showed that of users scanned, 84% had unencrypted payment card data on their devices and system–adding up to over 114 million cards found. While a few results are false positives, many businesses have successfully used the tool to remove unencrypted card data unintentionally stored on devices and systems, which could have been vulnerable to data breaches, data theft, and data leaks.

The percentage of businesses that improperly stored PAN has usually gone up each year, starting at 61% in 2015, 67% in 2016, 69% in 2017, rising sharply in 2018 to 85%, 88% in 2019, but 2020 saw a slight decrease with 74% storing unencrypted PAN data, with the trend increasing again 77% in 2021, 86% in 2022, and 84% in 2023.

Alarmingly, 6% of businesses store magnetic full-track data, which is never permitted by the PCI DSS.

2024 PANscan Data Analysis:

FINDINGS FROM SECURITYMETRICS' CREDIT CARD DISCOVERY TOOL

SecurityMetrics PANscan® is a card data discovery tool that businesses use to search for unprotected credit card data and to help confirm their PCI DSS audit scope.

Using automated card data discovery tools helps businesses find primary account numbers (PAN) on computer systems, networks, hard drives, and attached storage devices. Many businesses experience compromise because simple steps are not taken to ensure security. PANscan is a simple tool that helps limit business liability.

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® has discovered over 3.1 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2023 and compares it to previous years.

2023 Statistics

  • 309.65 TBs scanned
  • 84% of PANscan® users discovered unencrypted PAN data
  • 6% store track data (data inside magnetic stripe)
  • Over 114.5 million cards found

PERCENTAGE OF USERS STORING UNENCRYPTED CARD DATA

Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2020: 74%
  • 2021: 77%
  • 2022: 86%
  • 2023: 84%

The majority of networks scanned do not adequately protect stored credit card numbers.

2023 PANscan Data Analysis:

FINDINGS FROM SECURITYMETRICS' CREDIT CARD DISCOVERY TOOL

SecurityMetrics PANscan® is a card data discovery tool that businesses use to search for unprotected credit card data and to help confirm their PCI DSS audit scope.

Using automated card data discovery tools helps businesses find primary account numbers (PAN) on computer systems, networks, hard drives, and attached storage devices. Many businesses experience compromise because simple steps are not taken to ensure security. PANscan is a simple tool that helps limit business liability.

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® has discovered over 3 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2022 and compares it to previous years.

2022 STATISTICS

  • 296.75 TBs scanned
  • 86% of PANscan® users discovered unencrypted PAN data
  • 5% store track data (data inside magnetic stripe)
  • Over 3.7 million cards found

PERCENTAGE OF USERS STORING UNENCRYPTED CARD DATA

Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2019: 88%
  • 2020: 74%
  • 2021: 77%
  • 2022: 86%

The majority of networks scanned do not adequately protect stored credit card numbers.

COMMON PAYMENT CARD DATA HIDING PLACES

Due to poor processes and/or misconfigured software, payment card data can leak into networks, even those that shouldn't store sensitive data. Here are common places to look for hiding payment card data:

  • Error logs
  • Accounting departments
  • Sales departments
  • Marketing departments
  • Customer service representatives
  • Administrative assistants

7 TIPS TO FIND AND SECURE CARD DATA

INTERVIEW EMPLOYEES

Find out how your various departments interact with card data.

CARD FLOW DIAGRAM

Know where and how card data interacts through your system.

RUN SOFTWARE

Run a card data discovery tool to search for unencrypted card data.

PROTECT DATA

Properly remove and/or encrypt card data.

LIMIT ACCESS

Only authorized personnel should have system access.

CONSIDER DATA STORAGE

If you don't need to, stop storing card data.

NETWORK SEGMENTATION

Reduce the number of systems that store, process, or transmit card data.

2022 PANscan Data Analysis:

FINDINGS FROM SECURITYMETRICS' CREDIT CARD DISCOVERY TOOL

SecurityMetrics PANscan® is a card data discovery tool that businesses use to search for unprotected credit card data and to help confirm their PCI DSS audit scope.

Using automated card data discovery tools helps businesses find primary account numbers (PAN) on computer systems, networks, hard drives, and attached storage devices. Many businesses experience compromise because simple steps are not taken to ensure security. PANscan is a simple tool that helps limit business liability.

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® has discovered over 3 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2021 and compares it to previous years.

2021 STATISTICS

  • 208,444 GBs scanned
  • 77% store unencrypted PAN data
  • 5% store track data (data inside magnetic stripe)
  • Over 105 thousand cards found

PERCENTAGE OF USERS STORING UNENCRYPTED CARD DATA

Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2018: 85%
  • 2019: 88%
  • 2020: 74%
  • 2021: 77%

The majority of networks scanned do not adequately protect stored credit card numbers.

COMMON PAYMENT CARD DATA HIDING PLACES

Due to poor processes and/or misconfigured software, payment card data can leak into networks, even those that shouldn't store sensitive data. Here are common places to look for hiding payment card data:

  • Error logs
  • Accounting departments
  • Sales departments
  • Marketing departments
  • Customer service representatives
  • Administrative assistants

7 TIPS TO FIND AND SECURE CARD DATA

INTERVIEW EMPLOYEES

Find out how your various departments interact with card data.

CARD FLOW DIAGRAM

Know where and how card data interacts through your system.

RUN SOFTWARE

Run a card data discovery tool to search for unencrypted card data.

PROTECT DATA

Properly remove and/or encrypt card data.

LIMIT ACCESS

Only authorized personnel should have system access.

CONSIDER DATA STORAGE

If you don't need to, stop storing card data.

NETWORK SEGMENTATION

Reduce the number of systems that store, process, or transmit card data.

CLICK HERE TO LEARN MORE ABOUT PANSCAN®

2021 PANscan Data Analysis:

https://www.securitymetrics.com/content/dam/securitymetrics/PDF-files/2021_PANscan_Trends_Infographic.pdf

2021 Panscan data analysis

2021 PANSCAN® DATA ANALYSIS

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® discovered about 2.9 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2020 and compares it to previous years.

2020 PANscan Statistics

  • 237,279 GBs scanned
  • 74% store unencrypted PAN data
  • 5% store track data (data inside magnetic stripe)
  • Over 429 million cards found

Percentage of Users Storing Unencrypted Card Data

Storage of unencrypted PANs and the amount of track data stored increased. Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2017: 69%
  • 2018: 85%
  • 2019: 88%
  • 2020: 74%

Common Payment Card Data Hiding Places

Due to poor processes and/or misconfigured software, payment card data can leak into networks, even those that shouldn't store sensitive data. Here are common places to look for hiding payment card data:

  • Error logs
  • Accounting departments
  • Sales departments
  • Marketing departments
  • Customer service representatives
  • Administrative assistants

7 Tips to Find and Secure Card Data

  1. Interview Employees: Find out how your various departments interact with card data.
  2. Card Flow Diagram: Know where and how card data interacts through your system.
  3. Run Software: Run a card data discovery tool to search for unencrypted card data.
  4. Protect Data: Properly remove and/or encrypt card data.
  5. Limit Access: Only authorized personnel should have system access.
  6. Consider Data Storage: If you don't need to, stop storing card data.
  7. Network Segmentation: Reduce the number of systems that store, process, or transmit card data.

2020 PANscan Data Analysis:

https://info.securitymetrics.com/2020-panscan-data-analysis

2020 PANscan Data Analysis

2020 PANSCAN® DATA ANALYSIS

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® discovered about 2.5 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2019 and compares it to previous years.

2019 PANscan Statistics

  • 259,304 GBs scanned
  • 88% Store unencrypted PAN data
  • 7% store track data (data inside magnetic stripe)
  • Over 511 million cards found

Percentage of Users Storing Unencrypted Card Data

Storage of unencrypted PANs and the amount of track data stored increased. Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2016: 67%
  • 2017: 69%
  • 2018: 85%
  • 2019: 88%

Common Payment Card Data Hiding Places

Due to poor processes and/or misconfigured software, payment card data can leak into networks, even those that shouldn't store sensitive data. Here are common places to look for hiding payment card data:

  • Error logs
  • Accounting departments
  • Sales departments
  • Marketing departments
  • Customer service representatives
  • Administrative assistants

7 Tips to Find and Secure Card Data

  1. Interview Employees: Find out how your various departments interact with card data.
  2. Card Flow Diagram: Know where and how card data interacts through your system.
  3. Run Software: Run a card data discovery tool to search for unencrypted card data.
  4. Protect Data: Properly remove and/or encrypt card data.
  5. Limit Access: Only authorized personnel should have system access.
  6. Consider Data Storage: If you don't need to, stop storing card data.
  7. Network Segmentation: Reduce the number of systems that store, process, or transmit card data.

2019 PANscan Data Analysis:

https://info.securitymetrics.com/panscan-infographic-2019

2019 PANscan infographic

2019 PANSCAN® DATA ANALYSIS

How much unencrypted payment card data do users of PANscan store?

Since 2010, SecurityMetrics PANscan® discovered about 2 billion unencrypted primary account numbers (PAN) on business networks. Storage of unencrypted payment card data increases your organization's risk and liability in the event of a data breach. This infographic examines user results of PANscan from 2018 and compares it to previous years.

2018 PANscan Statistics

  • 7,011,170 GBs scanned
  • 85% Store unencrypted PAN data
  • 5% store track data (data inside magnetic stripe)
  • Over 330 million cards found

Percentage of Users Storing Unencrypted Card Data

Storage of unencrypted PANs and the amount of track data stored increased. Storing any unencrypted card data, especially track data, is a violation of the Payment Card Industry Data Security Standard (PCI DSS) and makes it easier for a criminal to steal data.

  • 2015: 61%
  • 2016: 67%
  • 2017: 69%
  • 2018: 85%

Common Payment Card Data Hiding Places

Due to poor processes and/or misconfigured software, payment card data can leak into networks, even those that shouldn't store sensitive data. Here are common places to look for hiding payment card data:

  • Error logs
  • Accounting departments
  • Sales departments
  • Marketing departments
  • Customer service representatives
  • Administrative assistants

7 Tips to Find and Secure Card Data

  1. Interview Employees: Find out how your various departments interact with card data.
  2. Card Flow Diagram: Know where and how card data interacts through your system.
  3. Run Software: Run a card data discovery tool to search for unencrypted card data.
  4. Protect Data: Properly remove and/or encrypt card data.
  5. Limit Access: Only authorized personnel should have system access.
  6. Consider Data Storage: If you don't need to, stop storing card data.
  7. Network Segmentation: Reduce the number of systems that store, process, or transmit card data.

2018 PANscan Data Analysis:

https://info.securitymetrics.com/panscan-infographic-2018

2018 PANscan Infographic

2017 PANscan Data Analysis:

http://info.securitymetrics.com/2017-panscan-data-analysis

2017 PANscan infographic

2016 PANscan Data Analysis:

http://info.securitymetrics.com/whats-causing-you-to-store-unencrypted-payment-cards

2016 PANscan infographic

2015 PANscan Data Analysis:

http://info.securitymetrics.com/learning-center-panscan-infographic-2015

2015 PANscan infographic

2014 PANscan Data Analysis:

http://info.securitymetrics.com/learning-center-what-you-don't-know-can-hurt-you

2014 PANscan infographic