PCI London

Adapt or die: payment security programmes for the age of Al 

20th January 2027 •  Park Plaza Victoria, London, UK

The payments ecosystem left credit card data behind long ago. Can PCI DSS compliance deliver true payment security?

 

Bridging the gap between attestation and risk management 

PCI DSS v4.0.1 has been fully in force since March 2025, and the first full assessment cycle has taught hard lessons: scope was broader than expected, the customised approach was harder to operationalise, evidence demands grew, and third-party contracts proved the weakest control. 

The Council has begun work on v5.O — with Al systems and modernised validation among its stated goals, but no publication date — and the PTS POI vs device deadline has slipped to April 2027. The standard is moving from a point-in-time audit to continuous assurance faster than most compliance teams can staff it. 

Meanwhile, the payment environment has moved beyond a neat cardholder-data perimeter. Modern payment journeys rely on JavaScript, hosted fields and iframes, mobile SDKs, APls, cloud platforms, token vaults, fraud engines, digital wallets, orchestration layers and multiple third-party processors. Scope can be reduced, but dependency cannot. A merchant may outsource the checkout and remain exposed to compromised scripts, weak integrations or failures elsewhere in the payment chain. 

Agentic commerce — Al agents authorised to shop and pay on a customer's behalf — is arriving and raises a question the standard has yet to answer: who is the cardholder when an agent pays? And the criminals have not gone away: browser-side skimming still harvests card data from checkout pages that passed their last scan, and the social­engineering playbooks that dismantled major retailers in 2025 bypassed every compliance control en route to payment systems. 

That makes payment security a visibility problem as much as a compliance problem: what can touch a payment, who can change it, which systems and suppliers can influence authorisation, and how quickly will a control failure be detected? 

The schemes and regulators add urgency. Enforcement of v4.0.1 is now real; reimbursement rules for authorised push-payment fraud have moved cost onto payment firms; and operational­resilience and third-party regimes on both sides of the Channel are pulling processors, cloud providers and managed service providers into the same conversation. But compliance is not security, and an attestation is not a control. 

Compliance leaders face an external challenge (a payments ecosystem changing shape beneath the standard) and an internal problem: how to fund continuous assurance for one small dataset in organisations that believe the box is ticked — and how to get the same outcome for the small and medium-sized merchants making up most of the ecosystem. 

Their case for action is not that PCI DSS has failed, but that the gap between attestation and exposure is widening: more suppliers, more channels, more automation, less human line of sight. Waiting for the next breach to reopen the budget conversation may be the mistake. 

Where do PCI leaders see genuine assurance, where is a clean attestation masking hidden scope, and what practical steps should organisations take before v5.O makes them mandatory? Is PCI DSS keeping up with payments — and are compliance teams keeping up with PCI DSS? 

PCI DSS is at a crossroads: payment security is moving from proving compliance once a year to demonstrating control every day, across systems, suppliers and agents the compliance team does not own. PCI London will look at how compliance must deliver real security. 

 

Key Themes

From point-in-time to continuous assurance 
v4.0.1 moved the standard from annual audits towards ongoing monitoring and evidence, and the first full cycle showed how much that costs. Compliance teams need tools and processes that prove security every day, not once a year, with implications from basic workflow to risk management. Can you help? 

Third-party and service-provider risk 
Processors, gateways, cloud providers and MSPs all carry PCI obligations, and weak contracts, unclear SLAs and limited audit rights create blind spots that v4.0.1 exposes. Operational-resilience and critical-third-party regimes are now asking the same questions. Any success stories in continuous supplier assurance? 

Automation, Al and evidence at scale 
Manual evidence gathering and fragmented monitoring do not scale. Al and automation can streamline assessments, monitor scope, detect anomalies and embed PCI DSS into daily operations — but the Council is clear that human accountability and traceability are non-negotiable. So, what is best practice here? 

Reducing the cost of compliance 
Most organisations have limited resources, and the ecosystem is mostly small and medium-sized merchants completing self-assessment questionnaires. They need automation, solutions that apply more widely, and pro-business answers. How do you derive PCI DSS compliance from the security processes you already run? 

Agentic commerce: who is the cardholder when an agent pays? 
Schemes are building rails for Al agents that shop and pay on a customer's behalf, with delegated credentials and tokens. Authentication, consent, liability and scope were all designed for humans. What does compliance look like when the customer is software, and can you help merchants prepare? 

Dealing with regulations 
Teams now must build a single coherent security program that simultaneously satisfies divergent regulatory demands; they must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret differently later; they face unrealistic expectations around incident reporting; and they face personal liability. Can RegTech help? 

Aligning PCI with the wider security and resilience stack 
Compliance chiefs are under pressure to show that PCI DSS maps into NIST, ISO, GDPR, operational resilience and regulatory expectations. Integrating PCI into the enterprise risk stack turns compliance from burden into advantage. But is PCI DSS really the right standard for this? 

Preparing for PCI DSS v5.O 
The Council has signalled work on v5.0, with Al systems and modernised validation documents among its goals and no date yet. The cryptographic inventory now required under v4.0.1 is also the starting point for post­ quantum migration. What should compliance teams do now that will still be right when v5.O lands? 

Scope: finding the COE you did not know you had 
Backup servers, monitoring tools, contact-centre recordings and data lakes have all turned out to be in scope. Discovery tooling, tokenisation and P2PE shrink the environment; late discovery is the most expensive remediation of all. How do you find, reduce and keep control of scope continuously? 

Post-quantum readiness — really? 
How do organisations improve cryptographic visibility and prepare for migration without creating operational risk? The new KMO standard provides a concrete development to examine: it addresses lifecycle key management and cloud-based or remote HSM use. But is post-quantum readiness a practical planning discussion or pie-in-the-sky? 

Securing the contact centre and the human channel 
The 2025 retail attacks went through help desks and identity, not zero-days. Voice deepfakes, pause-and-resume and phishing-resistant authentication for operators are now part of the payment perimeter. How do you keep agents, and their credentials, out of scope and out of reach? 

Browser-side skimming 
Securing e-commerce isn't just about payment card data or even pure payments. Script inventories, integrity checks and tamper detection are now mandatory, yet checkout pages that passed their last scan are still harvested through third-party and supply-chain scripts. Content security policies help; monitoring is what catches the change. What actually works at scale, and at what cost? 


Who attends

Job titles

Head of Digital Security
Head of Infrastructure Service Delivery
Information Security Officer
Senior GDPR & PCI Specialist
Senior Infosec Specialist
Principal Security Analyst
Lead Equity Research Analyst
Data Protection GDPR Manager
Compliance Officer
Security Architect, Senior Vice President
CISO
Programme Manager
Director of Financial Operations
Data Compliance Manager
Financial crime Executive
Assistant Director of IT
PCI DSS Support Function Manager
Digital Criminal Justice Lead
Senior Customer Success Manager
Global PCI Analyst
Director of Security
Card Scheme Compliance Manager
Data Protection Officer
PCI ISA - Compliance Consultant
Head of Compliance / MLRO (SMF16/17)
Senior InfoSec Compliance Analyst - Payment, Governance, Risk & Compliance
Senior Information Security Analyst
Senior Project Manager
Senior Information Technology Security Analyst
PCI Assurance Manager
Director of Security & Trust
Information Security Governance, Risk and Compliance Lead
CISO
Information Security Officer
Senior Information Compliance & Control Manager
Director of Technology & Information Security
HoD Information Security, Governance and Compliance
Manager - International, Payment Security & Governance
Operational Audit Manager
Information Security Officer
Group Information Security Manager
Head of IT Risk Governance
Principal Enterprise Architect
Information Technology Compliance Manager
Information Security Analyst
Security & Compliance Manager
Senior Security GRC Analyst
IT Security
Cyber Security Project Manager
Infosec Lead
Senior Tech Manager, Info Sec, Risk & Compliance
IT Security Administrator
Scheme Compliance Analyst
Head of Payments, Consumer Finance and Fraud
Chief Information Security Officer
Cyber Security Manager
Senior Systems Support Specialist
Senior Solution Engineering Manager
Director - Fraud Risk, Payments & Digital
Compliance and Security Analyst
Cyber Defence Manager
Security and Compliance Officer
Director of Information Security
Compliance Manager
Information Security Policy and Standards Manager
Payment Security Manager
Head of Solution Engineer Zoom Phone
Compliance and Audit Manager
IT Security Assurance & Compliance Senior Lead
Card Systems Specialist
Security Operations
Senior Network and Security Specialist
Global head of Security Compliance
Information Security Manager
Cyber Security Risk and Compliance
Payment Operations and Assurance Manager
International Director
Cyber Security Specialist | PCI ISA
Data Protection Officer
Digital Safety Compliance Analyst
Head of IT Security, Risk and Compliance
Principal Product Manager
Cyber Security and Compliance Manager
PCI Assurance Professional
Network Engineer
Cyber Security Analyst
Head of Data Protection and Privacy
Data Protection Compliance Manager
Security Design and Assurance Specialist
Schemes Compliance Manager
PCI Compliance Manager
PCI DSS Compliance Support Coordinator
Data Security Compliance Officer
IT Risk and Compliance Analyst
Compliance and Security Officer
PCI Compliance & Risk Manager
Senior Security Architect
Governance and Compliance Manager
Head of Product Compliance
Information Security, Risk and Compliance Manager
Team Lead, Card Systems UK and Ireland
Senior IT Risk Manager
PCI DSS Compliance Lead
Senior Cyber Security Analyst
Data Compliance Assistant
Head Of Billing
Information Security Auditor
Senior Security Architect
ICT Audit manager & Data Protection Officer
Head of IT Programme Management & Information Security
Senior Security GRC Expert
Group Data Protection Officer
Information Security Specialist
Cyber Security Assurance Specialist
Information Security Manager
Head of Information and Cyber Security
Information Security Analyst
Senior Information Security Analyst
Senior Risk Manager
Risk & Compliance Director
Director of Customer Data Security
Head of Compliance
Systems Consultant
CISO, Compliance Manager
CISO, Compliance Manager
Payments Compliance Product Owner
Global PCI Compliance lead
Solutions Architect
Program Specialist
Banking & Income Systems Manager
Vice President, EMEA & UK/I for Cyber Hygiene
Information Security Officer
Detective Superintendent Head of Economic Crime
Information Security Analyst
Information Security Officer and Infosec Lead
Director of Finance
Director of Compliance
Senior Compliance Officer - Finance
Head of Compliance, Director and MLRO
Senior Information Security Analyst
GRC Analyst
Data Protection Manager
Fraud & Payments Manager
Senior Special Agent - Global Security
Director of Cyber Security & Compliance
CISO
Head of Audit
Global PCI Lead
Head of Technology
Lead Security Architect
Security Compliance Manager
PCI Compliance Analyst
Senior Security Consultant
Cyber Security Architect
Project Manager
Information Security Risk and Assurance Specialist
IT Manager
PCI Manager
Senior Manager Security Governance & Compliance
Accounting Manager
Global Cybersecurity Lead
Head of IT Audit (Tech & Cyber Security) - UK HUB
Security, Risk and Compliance Director
Group Information Security Officer
Project Manager - Cyber Security
Head of Risk and Compliance
Information Security Analyst
Communications and Product Manager
IT Manager
Senior Analyst Developer

Companies

Royal Society for the Protection of Birds (RSPB)
Sky
Boden
Soho House Group
Just Eat
First Rate Exchange Services
Arete Research
HM Courts & Tribunals Service (HMCTS)
Village Hotel Club
Citigroup
Domino's Pizza
Sky
BBC
Taylor Wimpey
CIMB
Millennium Hotels & Resorts
NatWest Group
Metropolitan Police Service
CashFlows
BP
Feeld
CashFlows
Caravan and Motorhome Club
The Access Group
Persia International Bank plc
Live Nation International
Travis Perkins
Sky
MarkerStudy
Barclaycard
Reed & Mackay
pladis Global
Footasylum
Formula 1
Driver and Vehicle Licensing Agency (DVLA)
Atcore Technology
Currys plc
Live Nation International
Sky
Collinson Group
Ocado
Bupa Global
BT
SSP
WHSmith
SilverRail Technologies
Sky
Anderson Zaks
Greene King
CashFlows
Just Eat
The Appointment Group
Paysafe Group
OVO Group
WHSmith
Tesco Mobile
Atcore Technology
EVO Payments
Standard Chartered Bank
Transport for Greater Manchester (TfGM)
Travelex Holdings
HSS Hire Service Holdings Limited
Reward Gateway
FIS Global
Hutchison 3G UK Ltd t/as Three UK
Vodafone
Zoom Technologies
South Western Railway
Mars
Valero Energy Corporation
Cancer Research UK (CRUK)
Public Health England
Reed Exhibitions
National Trust
Manchester Airports Group (MAG)
Transport for London (TfL)
PCI Security Standards Council
Santander
Imperial Brands Plc
easyJet
Homebase
Paysafe Group
Tate
BT
CertSure
First Rate Exchange Services
Manchester Airports Group (MAG)
Driver and Vehicle Licensing Agency (DVLA)
Cancer Research UK (CRUK)
Paysafe Group
Direct Line Group
Imperial College London
Caravan and Motorhome Club
The Walt Disney Company
Kent County Council
Transport for London (TfL)
John Lewis Partnership
Whitbread PLC
Kindred Group
Airwair International Ltd - Dr Martens
Valero Energy Corporation
Diligenta
Virgin Media
Sky
Taylor Wimpey
Glow Financial Services
Paragon Customer Communications
Amazon Web Services
Publica Group
Azzurri Group
Wise
Quintessentially
Vanquis Bank
Howdens Joinery
London North Eastern Railway
Diligenta
Ocado Technology
Dunelm Group plc
Transaction Network Services
ERGO Travel Insurance Services Ltd
Elavon
Moneyboat
Atcore Technology
Direct Line Group
Direct Line Group
British Airways
The TJX Companies
Parliament UK
PCI Security Standards Council
Oxfordshire County Council
Deutsche Bank Group
Anderson Zaks
Metropolitan Police Service
JD Sports Fashion plc
Specsavers
WSH Group
Starling Bank
King's College
Payabl.
Marie Curie Cancer Care
NEXT
Phoenix Group
FitFlop
American Express
Lumanity
Ted Baker
Waterstones
BP
ClearCourse LLP
BP
Pennon Group
Anglian Water Services
Co-operative Bank plc
The University of Manchester
The Travel Corporation
Hutchison 3G UK Ltd t/as Three UK
Mayflower Theatre Trust LTD
RSA Insurance Group
BT
CertSure
HSBC
BNP Paribas Group
ZEAL Network
Harvey Nichols Group Limited
Sky
Thredd
National Trust
Barclaycard
DorisIT
Royal Holloway University of London

Industries

Charity
Media
Retail
Travel/Leisure/Hospitality
Retail
Banking
Other Industry
Central Government
Travel/Leisure/Hospitality
Banking
Retail
Media
Media
Real Estate
Banking
Travel/Leisure/Hospitality
Banking
Regional Law Enforcement
Security Product Vendor
Oil/Gas
Other Industry
Security Product Vendor
Travel/Leisure/Hospitality
Software
Banking
Travel/Leisure/Hospitality
Construction
Media
Insurance
Banking
Travel/Leisure/Hospitality
Manufacturer
Retail
Automobiles/Parts
Central Government
Travel/Leisure/Hospitality
Retail
Travel/Leisure/Hospitality
Media
Insurance
Transportation/Shipping
Healthcare Services
Telecommunications
Food/Beverage/Tobacco
Retail
Software/Hardware
Media
Banking
Food/Beverage/Tobacco
Security Product Vendor
Retail
Travel/Leisure/Hospitality
Software/Hardware
Electricity
Retail
Telecommunications
Travel/Leisure/Hospitality
Banking
Banking
Transportation/Shipping
Banking
Household/Personal Products
Media
Banking
Telecommunications
Telecommunications
Security Product Reseller
Transportation/Shipping
Food/Beverage/Tobacco
Oil/Gas
Charity
Central Government
Other Industry
Charity
Transportation/Shipping
Transportation/Shipping
Regulator
Banking
Manufacturer
Transportation/Shipping
Household/Personal Products
Software/Hardware
Education
Telecommunications
Construction
Banking
Transportation/Shipping
Central Government
Charity
Software/Hardware
Insurance
Education
Travel/Leisure/Hospitality
Media
Regional Government
Transportation/Shipping
Retail
Travel/Leisure/Hospitality
Casinos/Gaming
Retail
Oil/Gas
Consultancy
Media
Media
Real Estate
Banking
Software
Security Product Vendor
Central Government
Retail
Banking
Travel/Leisure/Hospitality
Banking
Retail
Travel/Leisure/Hospitality
Consultancy
Software
Retail
Software
Insurance
Software
Banking
Travel/Leisure/Hospitality
Insurance
Insurance
Transportation/Shipping
Retail
Central Government
Regulator
Regional Government
Banking
Banking
Regional Law Enforcement
Retail
Retail
Real Estate
Banking
Education
Banking
Charity
Retail
Banking
Retail
Banking
Research
Retail
Retail
Oil/Gas
Software/Hardware
Oil/Gas
Water/Sewage
Water/Sewage
Banking
Education
Travel/Leisure/Hospitality
Telecommunications
Other Industry
Insurance
Telecommunications
Construction
Banking
Banking
Casinos/Gaming
Retail
Media
Banking
Charity
Banking
Education
Education


Venue

Park Plaza Victoria, London

vpp

Location:
Park Plaza Victoria
239 Vauxhall Bridge Road, London, UK, SW1V 1EQ
Telephone: 0333 400 6140

Directions:
Please click here