Aug 5th, 2026

LHC Advisors: Turning PCI From Checkbox Theater Into Evidence

TL;DR

LHC Advisors helps organizations build practical cybersecurity, PCI, risk, and compliance programs that hold up when customers, banks, processors, card brands, auditors, or lawyers start asking for evidence. The company provides advisory leadership, virtual and fractional CISO support, security program development, maturity and gap assessments, PCI advisory and assessment services, penetration testing, vulnerability management, and framework-aligned readiness support across areas like PCI, NIST, ISO, CIS, CMMC, privacy, and cloud. The Cents Chat episode with Steve Levinson highlights the core problem for ISVs and payments service providers: PCI is not only about whether you store card data. If your software, integrations, redirects, access, vendors, or deployment processes can impact the security of cardholder data, you may have service-provider responsibilities. LHC Advisors helps companies define scope, understand responsibility, validate controls, and build the evidence trail before the incident, enterprise customer, or procurement team asks for it the hard way.

LHC Advisors: Cybersecurity Guidance for Companies That Need More Than a Checkbox

Security programs have a funny way of looking simple until someone asks for evidence.

A prospect wants an AOC. A bank partner asks for a responsibility matrix. A processor asks what was actually included in the assessment. A customer wants to know whether the product named in the sales deck is the same product covered by the compliance documentation. Then suddenly the folder named PCI_Final_Final_2024_Old does not feel like a strategy.

LHC Advisors exists for that moment, preferably before it becomes an emergency.

LHC Advisors is a cybersecurity advisory and assessment firm focused on practical security outcomes. Its work spans executive advisory leadership, virtual, fractional, and interim CISO support, cybersecurity program development, maturity assessments, PCI advisory and assessment services, penetration testing, vulnerability management, and security audit preparation. The company’s website frames the work around pragmatic recommendations built for the client’s environment, operating model, and risk profile, not generic security theater.

That matters because many organizations do not need a 300-page security roadmap that looks impressive and dies in a shared drive. They need help understanding what risk actually matters, which framework applies, what controls are missing, what evidence exists, what evidence does not exist, and what has to change operationally for the program to mature.

LHC Advisors supports a broad set of security and compliance needs. Its advisory services include cybersecurity strategy, roadmap creation, program management, and preparation for audits and certifications like SOC 2, PCI, ISO 27001, CMMC, and FedRAMP. Its assessment work is aligned to frameworks and regulatory environments such as PCI, NIST, ISO 27x, CIS20, CMMC, HIPAA, HITRUST, FedRAMP, GDPR, and CCPA. Its PCI services include assessments, readiness, remediation consulting, trusted advisor support, and security program governance. Its penetration testing and vulnerability management services help organizations identify exploitable conditions, prioritize remediation, and keep hardening after the assessment is over.

In plain English, LHC Advisors helps companies answer the uncomfortable security questions before someone else asks them with leverage.

That is especially relevant for ISVs, fintech operators, payment platforms, marketplaces, service providers, and software companies that live near payments. These companies often move quickly. They integrate with payment providers, embed checkout flows, configure redirects, manage vendors, and deploy software into workflows that merchants rely on. They may not think of themselves as part of the cardholder data environment, especially if they do not store card numbers.

But in payments, “we do not store card data” is not the end of the conversation.

That is where LHC Advisors’ PCI and advisory experience becomes valuable. The company helps organizations define scope, understand control responsibilities, prepare for assessments, validate the right services, and build a security program that can survive procurement questions, customer diligence, and post-incident scrutiny.

The Pain Point: PCI Scope Does Not Stop Where Card Storage Stops

The Cents Chat episode with Steve Levinson focused on one of the most dangerous assumptions ISVs make: “Our payment provider is PCI compliant, so we are good.”

That may be comforting. It may even be partially true.

But it is not complete.

PCI DSS does not only apply to entities that store, process, or transmit cardholder data. It can also apply to entities that could impact the security of cardholder data. For ISVs and payments-adjacent software companies, that phrase changes everything.

A software platform may never store a primary account number. It may never transmit raw card data. It may send the cardholder to a hosted payment page, iFrame, or compliant payment provider. Those tools can absolutely reduce scope, and scope reduction matters. But scope reduction is not the same thing as responsibility elimination.

Steve’s redirect example makes the issue clear. If the ISV controls where the customer is sent, how the integration is configured, who can change the endpoint, how the code is deployed, which scripts load, or which vendors sit in the payment path, then a compromise in the ISV’s environment could still affect the security of the payment flow. The payment provider may remain compliant while the ISV-controlled experience sends the customer to the wrong place, mirrors transaction data, or introduces malicious code.

That is the PCI scope trap.

Many ISVs think the only question is whether they touch cardholder data. The better question is what they could change, break, misconfigure, fail to monitor, or fail to secure that could impact the payment environment.

LHC Advisors helps companies work through that question in a structured way. That starts with scoping: defining the service, mapping relevant data and control flows, understanding redirects, tokens, refunds, support access, configurations, vendor relationships, and the technical paths that could affect security. From there, companies can determine which PCI requirements may apply, what evidence is needed, what belongs to the ISV, what belongs to the customer, and what belongs to a third-party provider.

The responsibility matrix is a major part of that work. A current AOC is useful, but it does not always explain the granular split of responsibility. A responsibility matrix shows which controls belong to the service provider, which belong to the customer, and which are shared. Without it, a sales promise like “our solution handles PCI” can turn into a very uncomfortable conversation when a customer learns it still owns controls nobody explained.

The episode also highlights why QSA-led assessment can matter commercially. A Level 2 service provider may be under the applicable transaction threshold, but a sophisticated enterprise customer, bank partner, or processor may still want stronger independent validation. A self-assessment may satisfy one requirement, but it does not carry the same weight as a QSA-led assessment when procurement, risk, or legal teams are looking for defensible evidence.

That is the broader lesson LHC Advisors brings to the table: PCI is not a once-a-year trophy. It is a point-in-time validation of a security program that has to keep operating after the assessment date. Software changes. Vendors change. Access changes. Infrastructure changes. AI tools and downstream providers add fourth- and fifth-party risk. If change management, logging, monitoring, vulnerability management, vendor review, and documentation are not part of the operating model, compliance can drift quickly.

LHC Advisors’ value is helping companies avoid treating PCI as checkbox theater.

The real goal is evidence. Evidence that scope was understood. Evidence that controls were implemented. Evidence that responsibilities were assigned. Evidence that vendors were reviewed. Evidence that logs were monitored. Evidence that changes were managed. Evidence that the company did what it said it would do.

That evidence is much easier to build before something breaks.

For ISVs and payments service providers, the takeaway is simple: if your software can impact the security of cardholder data, you need to understand your role. A compliant payment vendor is a starting point, not a force field.

LHC Advisors helps companies figure out what is actually in scope, what needs to be controlled, and what has to be documented before the hard questions arrive.