search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
PCI for a Small Business
Top PCI Resources for Small Businesses
PCI

Here are my top PCI resources for small businesses, based on what your business needs help with.

Graphic with a compass with text 'Don't Get Lost' explaining 5 things to ask before hiring Pen Test.
Top Five Most Important Things to Ask Before Hiring a Pentest Company
Penetration Testing

Read this blog to discover the top five most important questions to ask a potential pentest firm and why each question is vital to your success.

Common Pitfalls for Acquirers.
Why Many Merchant PCI Programs Fail: Common Pitfalls for Acquirers
PCI

Most acquirers know their current PCI program isn’t working as well as it should. Knowing the cause of the problem is key.

Pentest Cost.
Why Some Penetration Tests Cost $10K and Others $3K
Penetration Testing

Read this blog to discover what determines the cost of a penetration test, what cheaper and more expensive penetration tests include, which fit your needs, and the major red flags to avoid.

Western Reserve
How Finding the Right Partner Helped Western Reserve Achieve HITRUST Certification
HITRUST

Explore this blog to get direct quotes from Mark about his experience working with SecurityMetrics, why Western Reserve chose to become HITRUST certified, and what you should look for in a HITRUST partner.

Multi-colored background with text 'How much will PCI compliance software actually cost me in 2025.'
Budgeting for PCI Compliance: Essential Software Costs for SMBs in 2026
SMB

Let's break down the real costs you can expect for PCI compliance software in 2026 for SMBs.

PCI Audits Cost
Why Are PCI Level 1 Audit Costs So Confusing?
PCI Audit

Read this blog to get answers from a QSA on what affects the cost of a PCI level one audit, what hidden fees might exist, and what you can do to get a more accurate quote.

Forensics Blog
You’ve Been Breached. What Should You Do Now?
Forensics

A breach doesn’t have to be the end of the world (or your business). How you respond matters more than what happened.

Blue glowing word PULSE on dark background with securitymetrics blog logo at bottom.
SecurityMetrics Pulse: Detecting Compromises in Your Network’s Gray Area
Pulse

In this blog, you will learn what attacks networks are experiencing and how SecurityMetrics Pulse can detect these threats ahead of time, so you have the knowledge you need to defend your business.

Cover of SecurityMetrics 2026 PCI DSS Compliance guide for merchants and providers, 11th edition.
Get the 2026 SecurityMetrics PCI Guide
PCI

Discover what’s inside the 11th edition of the SecurityMetrics PCI Guide and learn how to navigate the post-v4.0.1 compliance landscape with free, expert-backed insights.

Practical Cybersecurity podcast by Jen Stone.
Announcing Practical Cybersecurity With Jen Stone
Data Security Trends

Get the practical cybersecurity advice you need by subscribing to Jen Stone's new podcast Practical Cybersecurity.

Multiple black fingerprints on white background with one fingerprint highlighted in blue at center.
SecurityMetrics Uncovers a Near 700 Site Global Skimming Operation
Forensics

SecurityMetrics forensic experts have identified a near 700 site skimming operation using a sophisticated, multi-channel kit designed to lock out analysts and mimic legitimate payment providers.

A shoe stepping on a building with text Small Business Mistakes on blue grid background.
The 7 Most Common Mistakes in Small Business Security
SMB

To help you prioritize your security, here are 7 common mistakes that small business owners make and how to fix them.

Text 'CREATE STRONG PASSWORDS' in yellow highlight on a blue background with scattered letters.
How to Create (And Remember!) Strong Passwords
Data Security

Moving beyond "P@ssw0rd123" to a safer, simpler digital life.

Old computer displaying masked credit card info with text: Sending credit card information over email.
The Risks of Emailing Credit Card Data: 2026 Compliance Standards
Compliance

Did you know that if your server receives, transmits, or stores primary account numbers (PAN), it is officially in scope for PCI security requirements?

2026 Cybersecurity Lessons.
2026 Cybersecurity Outlook & Lessons
Data Security Trends

Looking back on the previous year’s cybersecurity lessons isn’t just a nostalgic exercise, it could be a peek into anticipating 2026’s threats.

SecurityMetrics blog graphic with large CMMC text over a Pentagon aerial image on blue background.
The Five Step Roadmap for Tackling CMMC
CMMC

CMMC has rolled out, and if you work with the Department of Defense, you need to be CMMC compliant to continue getting contracts. Here's five easy steps to tackle CMMC.

PCI Requirement 12
PCI DSS Requirement 12: Policies and Documentation
PCI

Without a formal policy, technical controls are just isolated tools. Requirement 12 ensures those tools are part of a consistent, repeatable, and legal framework.

Two hands holding white masks with text Protect Your Identity Online on blue grid background.
10 Ways I’m Protecting My Professional Identity in 2026
Ecommerce Security

Your professional identity has never been more exposed. Read this blog to discover ten tips for protecting your identity online in 2026.

Comparing PCI QSA Firms.
Comparing PCI QSA Firms
PCI Partner

In this blog, I will compare the QSA firms SecurityMetrics, Coalfire, and A-Lign by looking at what you can expect from each QSA’s assessment and what they will cost.

CMMC Path.
CMMC Basics: A Practical 2026 Roadmap for CMMC Compliance
CMMC

The time to implement the Cybersecurity Maturity Model Certification (CMMC) has finally arrived. Read to learn the timelines and best practices.

Falling down a hole with text 'You've Been Hacked'.
You’ve Been Hacked, Now What? A Step-By-Step Guide
Forensics

If you aren't careful, you might destroy the very evidence needed to stop the attacker for good.

Paper shredder in blue background titled 'Upping Your Physical Security.'
PCI Requirement Nine: What You Need to Know About PCI Requirements for Physical Security
PCI

PCI DSS Requirement 9 covers all aspects of physical security. Here are a few tips to make sure your physical security is PCI compliant.

Best Practices for a First Time Audit.
7 Common Mistakes to Avoid During Your First PCI Audit
PCI Audit

Drawing on decades of experience in PCI auditing, SecurityMetrics VP, Gary Glover, and Audit Director, Matt Halbleib, share the seven most common pitfalls organizations encounter, and how to navigate them successfully.