Shavlik POS Patch Underscores Challenge of PCI Compliance

Shavlik POS Patch Underscores Challenge of PCI Compliance

Nemertes Impact Analysis:

Privately held Shavlik Technologies now offers automated, agentless patching of embedded Microsoft (NASDAQ:MSFT) Windows XP (XPe) devices. XPe is a stripped-down Windows XP and is the OS for many Point of Sale (PoS) terminals. Regular patching of POS terminals is a compliance requirement and compliance drives security spending for 60% of organizations. Any PoS terminal handling credit card data must comply with the Payment Card Industry Data Security Standard (PCI-DSS) which stipulates regular patching. As a streamlined OS, a patch client is often not an option so the only choices are an agentless solution or labor-intensive manual patching.

Impacts::

Enterprises: Automated patching of PoS terminals can save significant person-hours for both patching and report generation.

Vendors: Opportunity for POS manufacturers Fujitsu (TYO:6702), IBM (NYSE:IBM), NEC (TYO:6701) and Symbol Technologies (NYSE:MOT) to integrate Shavlik agentless patching.

Investors: Potential opportunity for agentless patch companies such as privately held Dorado Software and ScriptLogic to follow Shavlik.

-Ted Ritter, Senior Research Analyst

Sign Up To Receive Nemertes Impact Analysis By E-mail

Follow Nemertes Research on Twitter