search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Best Practices for a First Time Audit.
7 Common Mistakes to Avoid During Your First PCI Audit
PCI Audit

Drawing on decades of experience in PCI auditing, SecurityMetrics VP, Gary Glover, and Audit Director, Matt Halbleib, share the seven most common pitfalls organizations encounter, and how to navigate them successfully.

'PCI Basics' text on a blue background.
PCI Fundamentals for SMBs
PCI

PCI compliance doesn’t have to be a headache. The process can actually be broken down into four manageable steps.

PCI Requirement 7 Restrict Access.
PCI Requirement 7: Limiting Employee Access
PCI

PCI requirement 7 requires you to restrict employee access to only the data they absolutely need. It might sound simple, but it’s actually one of the most important requirements for preventing a data breach and commonly overlooked.

PCI Requirement 8 Combating Weak Passwords and Usernames.
PCI Requirement 8: Strengthen Your Passwords and Usernames
PCI

If you’re wondering what this means for PCI requirement eight, this blog will cover key updates, how to strengthen your organization’s passwords and usernames, and how to implement MFA (Multi-Factor Authentication).

Simplify Your PCI Audit.
How to Make PCI Assessments for Complex Environments Much Easier
PCI Audit

We'll show you the real-world difference between a chaotic, unprepared PCI effort and a strategic, streamlined process, and how to get there.

Blue background of attempting to enter the password 'Louvre.'
What the Louvre Heist Teaches Us About Cybersecurity in 2025
Data Security Trends

Here are the key takeaways from the breach and the essential cybersecurity best practices your business needs to implement in 2025 to combat threat actors.

A Culture of HIPAA Compliance
Designing API Connections That Meet HIPAA and PCI Requirements
HIPAA

This is a guest post from Keragon, a healthcare platform that specializes in building HIPAA-compliant automations without code.

Spectre AI on blue background.
How Spectre AI Identifies Merchant Fraud and Attrition to Secure Your Portfolio
PCI Partner

With the launch of Spectre AI in the SecurityMetrics Partner+ portal, you can scan the e-commerce websites of non-compliant and unenrolled merchants within your portfolio to identify those at the greatest risk of a security breach.

Blue background with text 'Don't Be Cheap' with pink piggy bank.
Why Cheap PCI Compliance Software Can Cost Your Small Business More
PCI

Small business owners have to save money wherever they can. But when it comes to cybersecurity, cheaping out on your PCI compliance software can actually end up costing you more.

Blue background with '7 Requirements' text.
Top 7 PCI DSS v4.0.1 Requirements Enterprises Must Prioritize in 2026
PCI Audit

With the major update of PCI DSS v4.0.1, businesses are facing a fundamental shift in how they need to approach payment security.

Image of shaking hands on a blue background.
Should You Stay with Your PCI QSA? [Pros, Cons & Testimonials]
PCI Audit

Read more to hear expert advice from VP of Enterprise Sales Jason Leland about the pros and cons of renewal, how to evaluate your first experience, and what to establish for a successful, long-term partnership.

Ascii art showing two clinking beer mugs with froth at the top on a black background.
A Buyer's Guide to Code Free PCI Requirement 6.4.3 and 11.6.1 Solutions
PCI

Choosing a code free solution for PCI Requirements 6.4.3 and 11.6.1 can be complicated.

'How do hackers hack?' Blog
How Do Hackers Hack?
Forensics

Hackers don’t care who you are. They just care how rich you can make them.

CMMC Phase II Under Review: What It Actually Means for Your Compliance Timeline
CMMC

DoW paused CMMC Phase II C3PAO assessments for 60 days. Learn what this means for Level 1 & 2 entities and prime contractors and why now isn't the time to slow down.

Traffic light displaying yellow light with text asking if HTTPS websites are secure on the left.
Are HTTP Websites Insecure?
Data Security

There are two website prefixes: One shows the site you are on is secure (HTTPS), and the other does not (HTTP). Which one is safe?

PCI DSS FAQ inside: Learn the basics of PCI compliance
PCI DSS Compliance FAQ: What is PCI Compliance?
SMB

Learn about the fundamentals of PCI DSS compliance.

What are 12 Requirements PCI DSS Compliance
What are the 12 Requirements of PCI DSS Compliance?
PCI

The PCI DSS (Payment Card Industry Data Security Standard) is a security standard developed and maintained by the PCI Council. This article will serves as a “jumping off point” to understanding the 12 requirements of the PCI DSS.

Stylized numbers 1 to 5 in overlapping shades of blue and gray on a light background.
5 Things Your Incident Response Plan Needs
Forensics

Find out some of the essentials to include in your incident response plan.

Blue radar screen with gridlines, circular markers, and a sweeping line indicating detected signals.
What is Vulnerability Scanning?
Vulnerability Scanning

This blog explains how automated vulnerability scanning proactively identifies security weaknesses to meet PCI compliance and protect your network.

Multiple copies of a book titled SecurityMetrics Guide to PCI DSS Compliance on a blue background.
The SecurityMetrics Guide to PCI DSS Compliance
PCI

What you need to know about the SecurityMetrics Guide to PCI DSS Compliance.

Graphic of Phishing with an orange background.
7 Ways to Recognize a Phishing Email: Examples of Phishing Email Scams
Data Security

Here are seven email phishing examples to help you recognize a malicious email and maintain email security.

5 Steps to Configure a Firewall
How to Configure a Firewall in 5 Steps
Data Security

The following guidance will help you understand the major steps involved in firewall configuration.

Pen Test vs Vuln Scan
Pentesting vs Vulnerability Scanning: What's the Difference?
Penetration Testing

Discover what the difference is between a penetration test and a vulnerability scan.

Circuit boards, a screwdriver, and a processor chip on white surface with digital tech icons overlay.
5 Ways Your Mobile Device Can Get Malware
Data Security

While convenient, mobile devices on your network can pose a risk to your business.