Kitty and Chris sit down with Steve Levinson of LHC Advisors to unpack PCI service-provider scope, why ISVs can have PCI responsibilities without storing card data, and why relying on a compliant payment vendor does not make responsibility disappear.




LHC Advisors helps organizations mature cybersecurity, PCI, risk, and compliance programs through advisory leadership, assessments, QSA-led PCI support, penetration testing, vulnerability management, and pragmatic security guidance.
For service providers, PCI compliance is not just a security checkbox. It is a legal, financial, and contractual defense layer when card data risk becomes real.
