search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Password Updates and Requirements in PCI 4.0.1
PCI

Complying with PCI DSS Requirement 8 deals with user accounts, passwords, and password management. This requirement is all about having unique, difficult-to-discover account information.

HITRUST Assessment Basics
HITRUST

This blog answers common questions about HITRUST Assessments and why a HITRUST assessment might be a good choice for your organization.

2025 Forensic Predictions
PCI Trends

Each year, SecurityMetrics releases a blog post featuring our major cybersecurity predictions, featuring insights from our veteran team of cybersecurity, audit, and compliance staff.

Cybersecurity Lessons from 2024
Data Security Trends

Read this blog to discover what SecurityMetrics forensic analysts got right and wrong about 2024 cybersecurity breaches and what we can learn from this past year.

Further Clarification on SAQ A Updates: Requirements 6.4.3 and 11.6.1
SMB

Recently two requirements that were part of SAQ A were removed, namely PCI DSS 6.4.3 and 11.6.1. 

Security Academy: Free Compliance and Cybersecurity Resource for Your Small Business
Data Security

Security Academy is a beginner-level, free course that you can return to if you have cybersecurity questions.

Web Application Firewall Fundamentals: PCI v4.0.1 Requirement 6.4.2
Compliance

Find out about the latest about PCI DSS v4.0.1 requirement 6.4.2, which mandates that ecommerce merchants implement a Web Application Firewall (WAF) or equivalent security measures to protect their online payment environments.

Announcing the 2025 SecurityMetrics HIPAA Guide
HIPAA

This year’s HIPAA guide includes an easy-to-understand introduction that covers how to read the guide, an executive summary, and an overview of this year’s new trends and stats.

2024 HIPAA Trends and Statistics
HIPAA Trends

Read this blog to learn how 2024 compared to 2023 regarding HIPAA Security, Breach Notification, and Privacy Rules trends.

Big Changes for SAQ A: What You Need to Know About 2025 Updates for 11.6.1 & 6.4.3
PCI

The PCI Council just announced a big change for merchants that use SAQ A, regarding specific PCI requirements.

How to Comply with the 12 Requirements of PCI Compliance
PCI

Complying with the 12 requirements of PCI can be complicated for those who must meet PCI compliance. Read this blog to get an in-depth description of each requirement, tips for achieving requirements, and answers to frequently asked PCI questions.

How Much Does a Data Breach Cost Your Organization?
Forensics

Let’s take a look at some of the different costs your business could incur as a result of a data breach.

The Top Ten SecurityMetrics Data Security Resources of 2024
Data Security

Discover the most important resources of 2024 so you don’t miss out.

HITRUST FAQs: Your Top HITRUST Questions Answered
HITRUST

HITRUST is becoming increasingly required by organizations to ensure robust protection of sensitive data. Manage third-party risk effectively.

Top FAQ’s For Acquirers Answered
PCI Partner

Discover the answers you need as an acquirer to navigate new PCI updates, PCI program questions, and merchant concerns.

Mobile Pen Testing 101
Penetration Testing

The main purpose of a penetration test is to stay one step ahead of the bad guys by finding your weaknesses with the help of experts exploring your mobile app and supporting systems.

How to Pass Your PCI Audit in 2025
PCI Audit

Get quick and important advice for tackling PCI audits in 2025.

FAQs for ISOs (Independent Sales Organizations)
PCI Partner

Understanding the role of an ISO in the payment process can be tricky. This blog outlines the most frequently asked questions surrounding ISOs and their pros and cons.

External Pen Testing Basics
Penetration Testing

This blog post is for anybody who's interested in external pen testing basics, the types of things found when pen testing, and the process that you go through when completing them.

Improving Your Small Ecommerce Business Network Security to Protect from E-Skimming
Ecommerce Security

This blog explores the main ideas from the webinar “How to Protect Your Ecommerce Website Against Eskimming,” and the latest threats attacking the e-commerce space.

Seven Tips to Avoid PCI Audit Fatigue
PCI Audit

When it comes to your business, choosing the right, knowledgeable partner can make all the difference in preventing audit fatigue.

How to Protect Your Ecommerce Website Against Skimming
Data Security

This blog is a summary and compendium to the SecurityMetrics’ Webinar “How to Protect Your Ecommerce Website Against Skimming”, hosted by Matt Heffelfinger and Aaron Willis.

Your Guide To Understanding Web Application Penetration Testing
Penetration Testing

Read this blog to understand the methodology, scope, and best practices for conducting effective web application penetration testing.