Security Over Critical Payment Systems

Issued Date
August 06, 2026
Agency/Authority
Olympic Regional Development Authority

Objective

To determine whether the New York State Olympic Regional Development Authority complies with the Payment Card Industry Data Security Standard and whether its access controls and vulnerability management over payment systems are sufficient to minimize the various risks associated with unauthorized access to systems and data.

Background

The New York State Olympic Regional Development Authority (ORDA) was established by the New York State Legislature to operate, manage, and maintain the facilities used during the 1932 and 1980 Olympic Winter Games in Lake Placid. Its main objective is to safeguard the public’s investment in these Olympic sites, as well as the venues that have been added to the list of ORDA facilities since 1980.

ORDA’s mission is to bring economic and social benefits to the Adirondacks and Catskills by managing venues that offer recreational and athletic opportunities. ORDA operates and manages three downhill ski areas, including Gore Mountain and Belleayre Mountain, and Whiteface Mountain, which is just 15 minutes from Lake Placid. Additionally, ORDA operates and manages the Olympic Center, Olympic Oval, and Olympic Training Center in Lake Placid, and the Olympic Jumping Complex and Mount Van Hoevenberg Olympic Sports Complex in the town of North Elba.

As a part of its operations, ORDA accepts credit card payments. In general, all organizations that accept credit cards as a method of payment must comply with the Data Security Standard (DSS) established by the Payment Card Industry (PCI) Security Standards Council. The PCI DSS is intended to help an organization proactively protect customer credit card data stored, processed, or transmitted on its network. As part of this, organizations must complete a self-assessment of their compliance with said standards. Additionally, as a public benefit corporation, ORDA must adhere to the Office of Information Technology Services’ (ITS) policies, including ITS Information Security Policy and ITS’ Standards over: Account Management and Access Control, Authentication Tokens, and Vulnerability Management.

Key Findings

We identified areas where ORDA could improve overall governance of information technology, compliance with PCI DSS requirements, and certain security controls in place to minimize the various risks associated with unauthorized access to its systems and data. Due to the confidential nature of our audit findings, we communicated the details of these findings with seven recommendations in a separate, confidential report to ORDA officials for their review and comment.ORDA officials agreed with our findings and have already begun actions to implement our recommendations. ORDA has proactively implemented changes to increase cybersecurity awareness and controls across the organization.

Key Recommendation

Implement the seven recommendations included in our confidential draft report.

Nadine Morrell

State Government Accountability Contact Information:
Audit Director
: Nadine Morrell
Phone: (518) 474-3271; Email: [email protected]
Address: Office of the State Comptroller; Division of State Government Accountability; 110 State Street, 11th Floor; Albany, NY 12236