Live Webinar, May 20th, 3PM GMT

Beyond PCI DSS Compliance: Who Owns Payment Risk in 2026

Register Today

Join us for a live panel discussion on May 20th, 3pm UK Time — an expert panel uniting the standards body, the payments industry, and enterprise security to confront the accountability gap that PCI DSS 4.0.1 compliance alone can’t close.

Speakers

Una Dillon, Regional Director Europe, PCI Security Standards Council

Una brings the standards perspective — what PCI DSS 4.0 requires, where interpretation matters, and what the Council sees as the next frontier for payment security.

Deepak Kumar Ramanujam, Head of Information Security at APEXX Global

Deepak offers a payments industry view — how orchestration layers, acquirers, and PSPs think about risk distribution and where technical accountability sits in modern payment stacks.

Leor Eliashiv, UK & I Country Manager at Reflectiz

Leor brings the vendor perspective – working closely with enterprise security and compliance teams in the UK and Ireland to bridge the gap between PCI DSS 4.0 requirements and the reality of supply-chain risk, where third- and fourth-party scripts operate in the browser beyond the visibility of traditional controls.

Christina Dell, Head of Security Operations at Staysure

Christina shares the enterprise security perspective — what it takes to operationalise payment security requirements at scale, and where gaps between policy and practice emerge.

About the executive panel discussion

PCI DSS 4.0.1 introduced requirements designed to close critical security gaps in the payment ecosystem — but certification does not equal protection. Third-party scripts, invisible redirect chains, and real-time data exposure on checkout pages continue to put cardholder data at risk, often outside the boundaries of what any single team owns or monitors.

This panel brings together three senior voices — from standards, payments, and enterprise security — to examine where formal compliance ends and genuine accountability must begin.

What You’ll Learn

  • Where PCI DSS 4.0.1 draws the line — and where risk does not follow it
  • How third-party scripts and pixel tracking create exposure that compliance tools miss
  • Who bears accountability when payment data is compromised through the client side
  • What security and compliance leaders should be doing now to close the gap

Take control

Stay up to date with the latest news and updates