Latest
How Much AI Is Too Much in Writing? 83 Writers Drew the Same LinePost an AI Image and Unfriend MeShe Asked How to Publish Her Bedtime Story. They Called Her a Thief.The AI Hype Cycle: Why the Crash Is Coming, and Who’s Causing ItSix Claude Prompts That Get You Unstuck, and Why the Order MattersDogpiled Over AI Art at the Renaissance FaireClaude Opus 5.5: What the New Release Means for WritersTrump’s AI Force Is a Fire Department With No Fire CodeMonthly or Milestone: How Ghostwriting Gets BilledThe Hugging Face AI Agent Attack: An Operations ReadingWhat It Costs to Fix an AI-Written ManuscriptWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthThe Quotation Marks That Get Authors SuedThe One-Hour Call Before I Quote Your BookWhen Your Own Memoir Sounds Like BraggingThe Work You Would Never Have StartedWhen a Client Thinks the Ghostwriter Used AIBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreBlack Tuesday: The Web Ring War Nobody Outside It NoticedThe Web Got Fenced: What AI Search Costs Small Sites
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Eight Years of PCI Audits: The Most Thankless Heroics in IT

This entry is part 51 of 53 in the series Technology
TL;DR: Pass a PCI audit and you’re furniture. Fail one and the company loses the ability to take credit cards. I ran infrastructure through eight consecutive years of PCI audits at a major national retailer. Every one passed, on time and on budget. Nobody ever put us on a stage for it, and that asymmetry, invisible when you succeed, catastrophic when you fail, is the defining experience of compliance work.

For at least eight years straight, I lived an annual ritual: the PCI audit. I ran the infrastructure group at a major national retailer. The networking group ran the network. Between us, with development pulled in wherever the audit touched their code, we carried the company through an assessment that decided whether it could keep accepting credit cards.

Most of our business came through cards. If we failed, we’d lose the ability to process certain brands, and the revenue impact would have been immediate and severe. Every audit season carried that weight, and every audit season ended the same way: we passed, the business kept running, and nobody outside IT ever knew anything had happened.

What does a PCI audit take?

The audit was IT-wide. Not company-wide; the rest of the business was untouched. But inside IT it reached everything: my entire infrastructure staff, the full networking group, and slices of development wherever cardholder data flowed through their systems.

We usually got a couple of months of notice. Two months sounds like time until you understand what has to happen inside it: every system scanned, every finding triaged, every fix implemented and verified, every document current, all while the day job of keeping a retailer’s systems running continues at full speed.

The load wasn’t evenly distributed. My team handled a stream of specific, farmed-out fixes: firewall this machine, correct that SQL configuration, patch this server. Manageable, discrete work. The crushing weight landed on me and on the network side, especially the network manager. The network was where cardholder data lived and moved, so the network was where the audit lived too. Those were tense months, every year, for eight years.

What does preparing for a PCI audit involve?

From the outside, audit prep sounds like paperwork. From the inside, the two months broke down roughly like this. The first stretch was discovery: scanning every system in scope, which for us meant everything, because we scanned comprehensively instead of sampling. That comprehensiveness wasn’t bureaucratic zeal; it once turned up a password-cracking tool a consultant had planted on a server, a story I tell elsewhere in this series, and we’d never have found it by sampling.

The middle stretch was triage and remediation. Every finding from the scans got sorted: quick fixes farmed out to the teams, structural problems escalated to me and the network manager, and the stuck cases worked into mitigating controls. The last stretch was verification and documentation, proving that what we said we fixed was fixed, because an auditor who grades on the spirit of the standard also checks the letter of your claims.

Running underneath all of it was the day job. A retailer’s infrastructure doesn’t pause for audit season. Systems still failed, projects still shipped, and the same people doing the audit work carried their normal load. The two-month figure hides that, and it’s why audit season had a particular texture of exhaustion that the people who lived it’ll recognize instantly.

Pass a PCI audit and you’re furniture. Fail one and the company loses the ability to take credit cards.
Share on X

The people problem inside the audit

My team wasn’t trained in security. Most infrastructure teams aren’t. They saw the audit as something they shouldn’t have to worry about, an interruption to their real work, a specialty that belonged to someone else. Getting them engaged was a yearly negotiation.

They did fine, every time. But the lesson stuck with me: in most IT organizations, security is a thing that happens to the staff once a year instead of a thing they practice. The audit passed because a few people carried it, not because the organization had absorbed it. If I were advising that company today, that’s the first thing I’d change.

Furniture

When you pass, nothing happens. No stage, no bonus announcement, no all-hands recognition. You’re furniture. The systems keep taking credit cards, which they were already doing, so from the outside it looks like nothing occurred.

What occurred was two months of near-heroic effort by people under real pressure, delivered on time and on budget, eight years running. The only version of the audit anyone outside IT would ever have noticed is the version where we failed. Success was designed to be invisible.

That’s a shame, because the work matters enormously, and the people who do it burn out on exactly this asymmetry. If you run a company that passes its audits every year, the correct response isn’t silence. Somebody earned that silence for you.

Why should executives care about PCI audit stories?

Because audits show where security depends on a few people doing thankless work, and that’s where a company is most exposed.

Heard elsewhere

The recurring problem in cybersecurity is communication before technology, leaders seeing it as a cost center because the people explaining it speak in bits and bytes instead of risk. Richard discussed the reframe on Tequila and Tech Talk.

When leaders write books about security and compliance, they tend to write about structures. The structure isn’t the story. The story is the network manager under two months of pressure, the team that thinks security is someone else’s job, the pass that nobody celebrates. Readers who have lived an audit recognize the truth of it instantly, and readers who haven’t learn what their own IT departments never tell them.

And if I could send one instruction back to myself at the start of those eight years, it would be this: don’t let security live only in audit season. The yearly scramble existed because security was an annual event instead of a standing practice. Teams that patch, scan, and verify continuously walk into audits with weeks of work instead of months, and their audits stop being heroics. Heroics are what you need when the system is wrong. We were very good at heroics.

For more from this series, see The Cybersecurity Hub: breaches, audits, and hard-won security lessons from four decades in the trenches.

Frequently Asked Questions

What happens if a company fails a PCI audit?
When I ran infrastructure at a major national retailer, most of our revenue came through credit cards, so a failed audit would have meant losing the ability to process certain brands. That kind of failure hits revenue immediately and severely, not gradually. It’s also the only version of a PCI audit that anyone outside IT ever notices. Passing keeps everything running exactly as it was. That’s why nobody outside the department knew the stakes each year. Failing is the scenario that turns invisible compliance work into a visible business crisis.
How long does PCI audit preparation take?
In my eight years running infrastructure through these audits, we typically got about two months of notice before the assessment began. That time had to cover scanning every system in scope, triaging and fixing every finding, and then verifying and documenting that the fixes held. All of that happened on top of the normal day job, since a retailer’s infrastructure doesn’t pause for audit season. Two months sounds generous until you’re inside it, watching the same people who keep the business running also carry the entire remediation load.
Who carries the workload during a PCI audit?
In my experience, the crushing weight fell on me and on the network manager, because the network was where cardholder data lived and moved. My infrastructure staff handled a stream of specific, farmed-out fixes like firewalling a machine or correcting a SQL configuration, which was manageable, discrete work. Development got pulled in only where the audit touched their code. The audit passed every year because a few people carried it under real pressure, not because the whole organization had absorbed security as a routine practice.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.