Blog

7 Ways to Recognize a Phishing Email: Examples of Phishing Email Scams

Here are seven email phishing examples to help you recognize a malicious email and maintain email security.

PCI Requirement 10: Logging and Log Monitoring

PCI requirement 10 is all about logging and log monitoring.

PCI Requirement 11: Vulnerability Scans and Penetration Tests

PCI Requirement 11 discusses vulnnerability scanning and penetration testing.

How to Manage a Healthcare Data Breach

Data breaches can be devastating. Here are 5 steps that will help you manage a healthcare data breach.

CMMC Basics: A Practical 2026 Roadmap for CMMC Compliance

The time to implement the Cybersecurity Maturity Model Certification (CMMC) has finally arrived. Read to learn the timelines and best practices.

What is Tokenization and How Can I Use it for PCI DSS Compliance?

There are common pitfalls in implementing tokenization correctly, so it’s critical to partner with a vendor who understands how to implement tokenization across technology, security, compliance, and risk.

You’ve Been Hacked, Now What? A Step-By-Step Guide

If you aren't careful, you might destroy the very evidence needed to stop the attacker for good.

PCI Requirement Nine

PCI DSS Requirement 9 covers all aspects of physical security. Here are a few tips to make sure your physical security is PCI compliant.

7 Common Mistakes to Avoid During Your First PCI Audit

Drawing on decades of experience in PCI auditing, SecurityMetrics VP, Gary Glover, and Audit Director, Matt Halbleib, share the seven most common pitfalls organizations encounter, and how to navigate them successfully.

PCI Fundamentals for SMBs

PCI compliance doesn’t have to be a headache. The process can actually be broken down into four manageable steps.

The Top Five PCI Resources for Enterprise Organizations

To help your organization stay proactive and ahead of threat trends, I’ve curated the five most critical resources for managing enterprise-level risk in 2026. Read on to discover which PCI resources deserve your attention the most.

PCI Requirement 7: Limiting Employee Access

PCI requirement 7 requires you to restrict employee access to only the data they absolutely need. It might sound simple, but it’s actually one of the most important requirements for preventing a data breach and commonly overlooked.

PCI Requirement 8: Strengthen Your Passwords and Usernames

If you’re wondering what this means for PCI requirement eight, this blog will cover key updates, how to strengthen your organization’s passwords and usernames, and how to implement MFA (Multi-Factor Authentication).

Designing API Connections That Meet HIPAA and PCI Requirements

This is a guest post from Keragon, a healthcare platform that specializes in building HIPAA-compliant automations without code.

How to Make PCI Assessments for Complex Environments Much Easier

We'll show you the real-world difference between a chaotic, unprepared PCI effort and a strategic, streamlined process, and how to get there.

What the Louvre Heist Teaches Us About Cybersecurity in 2025

Here are the key takeaways from the breach and the essential cybersecurity best practices your business needs to implement in 2025 to combat threat actors.

How Spectre AI Identifies Merchant Fraud and Attrition to Secure Your Portfolio

With the launch of Spectre AI in the SecurityMetrics Partner+ portal, you can scan the e-commerce websites of non-compliant and unenrolled merchants within your portfolio to identify those at the greatest risk of a security breach.

Why Cheap PCI Compliance Software Can Cost Your Small Business More

Small business owners have to save money wherever they can. But when it comes to cybersecurity, cheaping out on your PCI compliance software can actually end up costing you more.

Should You Stay with Your PCI QSA? [Pros, Cons & Testimonials]

Read more to hear expert advice from VP of Enterprise Sales Jason Leland about the pros and cons of renewal, how to evaluate your first experience, and what to establish for a successful, long-term partnership.

Top 7 PCI DSS v4.0.1 Requirements Enterprises Must Prioritize in 2025

With the major update of PCI DSS v4.0.1, businesses are facing a fundamental shift in how they need to approach payment security.

Top PCI Resources for Small Businesses

Here are my top PCI resources for small businesses, based on what your business needs help with.

Top Five Most Important Things to Ask Before Hiring a Pentest Company

It’s never been more important to truly know if your organization is secure against threats.

PCI Requirement 5: Protecting Your System with Anti-Virus

PCI Requirement 5 deals primarily with installing and maintaining an anti-malware software.

Why Many Merchant PCI Programs Fail: Common Pitfalls for Acquirers

Most acquirers know their current PCI program isn’t working as well as it should. Knowing the cause of the problem is key.