PCI-DSS has no meaning to them her or the people empowered to protect the data. Good news everyone the new Infosec laws on the horizon will see companies like this held accountable and if found guilty of not securing the environment to the standards set out by the guidlines , its massive fines and business going under for them.