search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Auditor Tips: Requirement 3: Protect Cardholder Data
PCI

It is important to know what data you actually store, process, and/or transmit.

Auditor Tips: PCI DSS Responsibilities and Challenges
PCI

As you implement your cybersecurity program, make sure you understand why a security control is required so you can structure tools and processes around the protection each control offers.

Auditor Tips: Requirement 2: System Configuration
PCI

You are required to use industry-accepted configuration and hardening standards when setting up systems that are part of your PCI scope.

Performing an SAQ B-IP version 4.0 Self-Assessment
PCI Trends

The Self-Assessment Questionnaire (SAQ) B-IP is intended for payment channels where cardholder data is processed using IP-connected PTS-approved point-of-interaction terminals.

2023 Forensic Predictions
Forensics

In 2023, we've got three predictions of cyber attacks that we think will be the most prevalent this year

Who Owns Third-Party Security Risk Management
Data Security

Third-party security risk management (TPRM) is the process of analyzing and addressing risks associated with outsourcing to third-party vendors or service providers.

5 Minimum Necessary HIPAA PHI Tips
HIPAA

The HIPAA minimum necessary rule helps covered entities manage healthcare information by requiring them to limit access to and disclosure of PHI.

How Much Does a HIPAA Risk Management Plan Cost?
Risk Assessment

Many healthcare entities haven’t yet separated the difference between the HIPAA Security Rule and HIPAA Privacy Rule.

SecurityMetrics Vulnerability Scanning Process FAQ

The most commonly asked customer questions about the vulnerability scanning process.

How to Permanently Delete Files with Sensitive Data
Data Security

When delete doesn’t actually delete, it can increase your vulnerability.

What is HIPAA Compliance, and How Long Will It Take?
HIPAA

HIPAA compliance is a process, not a destination . . . but it doesn’t hurt to know your timeframe.

Vulnerability Scanners 101: What, Why, and How to Comply

Learn the fundamentals of vulnerability scanning, especially for PCI compliance requirements.

Configure and Maintain Your Firewall
Data Security

Learn why your firewall may make you vulnerable and how SecurityMetrics Managed Firewall can help.

PCI Requirement 8: Combatting Weak Passwords and Usernames
PCI

In order to comply with PCI Requirement 8, you need to practice proper password and username management.

SAQ D: What's Required for Service Providers
PCI Audit

If you are a service provider who stores credit card data, PCI SAQ D likely applies to you.

How Does Network Segmentation Affect PCI Scope?
PCI

Segmentation is important for preventing breaches and hacks, as well as a method to reduce PCI scope.

Kaseya VSA Software SecurityMetrics Response
Forensics

We are strongly encouraging all SecurityMetrics clients that use Kaseya VSA software in their environment to follow the recommended guidance provided by CISA and the FBI provided below.

What is the HIPAA Privacy Rule?
HIPAA

The HIPAA Privacy Rule is crucial for protecting PHI and ensuring patient privacy. Learn about HIPAA PHI compliance with our free guide.

What is Formjacking?
Ecommerce Security

Formjacking is a type of cyber attack where hackers inject malicious JavaScript code into a webpage form–most often a payment page form.

SAQ A: What to Know, and What to Do
SMB

Learn what’s required to fill out SAQ A.

Incident Response: 10 Things to Do if You Have a Data Breach
Forensics

Learn how to effectively respond to security breaches and prevent future attacks.

PCI Compliance in the Cloud
PCI

Learn how PCI compliance in the cloud affects your organization. "The cloud" brings up an idea of something mysterious and far away, but in reality, “the cloud” is a third-party-managed physical server.