As said at an event I've recently been to by people that do the post breach investigation in the payment industry - almost all breaches are the cause of failing to do the basics, number one is running unpatched web servers and then having routes from those servers to things beyond the DMZ, then unpatched desktop estates, mail servers, etc.

Also another interesting thing was of companies investigated post breach over the last decade none were PCI compliant at the time of breach - even though all had managed to pass at a given point in time.

