While PCI DSS applies to every organization that accepts payment cards, many education institutions have been slow to achieve campus-wide compliance. The situation is particularly unfortunate since education institutions – whether because of their open networks or inadequate security procedures – are particularly vulnerable to hacking and other compromises of confidential consumer data. As a result, financial institutions and card issuers increasingly view education institutions as risky merchants.