Although PCI-DSS is a well know security compliance standard for payment cards, this research is asking whether or not PCI is sufficient, either because it doesn't go far enough, or because it is not enforced. Either way, more needs to be done to protect the banks' customers.