It beats encryption. Encryption leaves your data vulnerable if thieves steal the key. Tokenization replaces protected data with a digital placeholder that applications use just as they would real Social Security or credit card numbers. But if you\u2019re hacked, the data is useless to criminals. \u201cAny business storing card numbers today should be looking at tokenization,\u201d says Lucas Zaichkowsky, a senior compliance technologist with Mercury Payment Systems.\n \n Tokens can look like your legacy data. One of the good things about tokenization is that you can be flexible in how you create your tokens. They can have the same data structure as the credit card or Social Security numbers you\u2019re already storing, making it easier to reprogram your legacy applications to handle tokens. And there\u2019s a pretty good chance you\u2019ll end up using both tokenization and your legacy systems in combination at first.\n \n \nFor some, it reduces your pci compliance burden. Another of the great benefits of tokenization is that if you set it up using an outside vendor and are not storing card data, you can skip the very long PCI Self-Assessment Questionnaire D in favor of the smaller and easier-to-complete Questionnaire C. However, if you set up a tokenization server on your network, you\u2019re still storing the data, so you still have to fill out the longer compliance questionnaire.\n \n It\u2019s tricky to deploy. If you switch from credit card numbers to tokens, you may find unexpected places where those credit card numbers are used. If you\u2019re issuing a new token every time someone hands over a credit card number, for example, that could mess up your fraud-detection systems. You\u2019ll need to map out all applications using this data beforehand. But even after you do this, don\u2019t expect to be able to move every system to tokens immediately.\n \n Payment options vary. How do you want to pay for tokenization? Akamai offers a service that prevents Web users from ever entering their credit card numbers into a merchant\u2019s system. They charge a flat rate. You can probably get tokenization as a service for about 10 cents per transaction from a payment-processing vendor, but that could lock you in to their system. You can manage your own tokenization servers, but some vendors charge per record.