search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Blue computer monitor with a lock icon inside a hexagon network of connected dots symbolizing cybersecurity.
Which Pentest is Right for You?
Penetration Testing

Determining which type of pentests are best for your organization depends on concerns or needs that are generated from real life security incidents or concerns about security posture for business critical systems or environments.

6 Steps Penetration Test
6 Steps to a Penetration Test
Penetration Testing

Getting a penetration test can seem overwhelming, but following these steps can help ensure that your penetration test goes as smoothly as possible.

Three numbered circles 1, 2, 3 above a striped rectangle next to an open door with blue outline.
Your Crash Course To HITRUST CSF Assessment Types
HITRUST

This blog will cover the three types of HITRUST CSF certifications. It will also cover what you can expect to achieve upon completion of each type of assessment and general guidelines of which assessment is best for your organization.

Blue icon of an FAQ folder with documents flying out against a light background with blue circles.
HITRUST Assessment Basics
HITRUST

This blog answers common questions about HITRUST Assessments and why a HITRUST assessment might be a good choice for your organization.

Blue 3D number 10 with striped top surfaces casting a shadow on a light background.
Ten Mistakes in HIPAA Security Rule Compliance
HIPAA Audit

The HIPAA Security Rule requirements are vast. To help you prioritize your security, we’ve put together the ten mistakes that organizations make when it comes to HIPAA security compliance.

Blue rocket icon launching upward with smoke, inside a blue circle with striped circles behind it.
What is it like working with SecurityMetrics on PCI Compliance?
PCI Audit

What is it like working with SecurityMetrics? SecurityMetrics’ central objective is to help companies secure their data, not just meet compliance standards. We love working with organizations who have that same vision for security.

Blue storefront with large window, entrance door with awning, and a sign reading SHOP.
How to Start a Cybersecurity Program For Your Small Business
SMB

For many small business owners, cybersecurity budgets can be very limited. Finding a cybersecurity program can help you get the most value for your money.

Light bulb with medical caduceus symbol inside, symbolizing medical innovation or ideas.
The SecurityMetrics HIPAA Portal Helps Streamline Your Compliance
HIPAA Audit

This blog discusses how the SecurityMetrics HIPAA Portal can help with your HIPAA requirements.

Laptop displaying a skull and crossbones symbol on the screen, indicating malware or danger.
Ransomware Trends: Don't Panic, Prepare
Data Security

This blog discusses ransomware trends and what to do about ransomware.

White thought bubble with a blue question mark inside on a light background with diagonal blue stripes.
Responding to 5 Common PCI Questions from Franchisers and Franchisees
PCI Partner

Here are the top 5 PCI questions we get from franchisers and franchisees about PCI compliance.

Blue scales balancing a lock symbol on one side and a dollar sign on the other.
Cost Effective Data Security Best Practices in the Workplace
Data Security

Don't let cyber threats compromise your sensitive information. Follow these simple, cost-effective data security best practices for a secure workplace.

Blue 3D question mark with striped top and shadow on light gray background.
Partner with SecurityMetrics for Data Security and Compliance
Compliance

Why Partner with SecurityMetrics for Data Security and Compliance?

Text saying hello PCI 4.0 surrounded by blue circles and squares on dark background.
Performing an SAQ C version 4.0 Merchant Self-Assessment
PCI Trends

Merchants using the SAQ C to validate their PCI DSS compliance should be aware of changes that were introduced into this questionnaire during the publication of the SAQ C version 4.0.

Illustration of PCI 4.0
Performing an SAQ-D version 4.0 Merchant Self-Assessment
PCI Trends

Merchants who do not qualify to assess their PCI DSS compliance using any of the simpler self-assessment questionnaires are required to use the SAQ D to validate their compliance.

Blue outlined computer monitor displaying a scanning progress bar partially filled.
External Vulnerability Scanning FAQ: What is External Vulnerability Scanning?
Vulnerability Scanning

External vulnerability scanning is a security practice that involves scanning and assessing the external-facing network infrastructure, systems, and applications of an organization for potential vulnerabilities.

Illustration of a laptop screen showing binary code with a magnifying glass highlighting part of the code.
Forensic FAQs
Forensics

If you've experienced a data breach, you will probably need a forensic investigation to determine the cause of the breach. Here are some forensic faqs to help you understand the process of a forensic investigation.

3D blue block letters spelling FAQ with striped faces casting shadows on white background.
PCI Program FAQs: What is a PCI Program?
PCI Partner

A PCI program is a system that acquirers use to keep track of their merchants PCI compliance, and for merchants to receive the training and tools they need to achieve PCI compliance and remain PCI compliant.

Text saying PCI 4.0 with layered blue shadow outlines and scattered geometric shapes on light background.
PCI DSS 4.0 SAQ Questionnaires Q&A
PCI Trends

PCI DSS 4.0 SAQ Questionnaires Q&A: While future-dated requirements are not mandatory until March 31, 2025, it's recommended to implement them early for enhanced security.

Blue outlined 3D text saying 'PCI 4.0' with stacked line effect on a light gray background.
PCI 4.0 Summary of Changes
PCI Trends

PCI 4.0 summary of changes including new requirements that have been added to the standard.

Stylized numbers 1 to 5 in blue shades above diagonal light blue lines on a white background.
What To Include In An Incident Response Plan
Forensics

Creating an incident response plan can seem overwhelming. To simplify the process, develop your incident response plan in smaller, more manageable procedures.

Illustration of secure online shopping with a lock, shopping cart, credit card, and checkmark icons.
How to Test Your Incident Response Plan
Forensics

How to test your incident response plan and conduct tabletop exercises.

Small blue shop with large window and door under striped awning and sign reading SHOP.
Scoping for PCI Compliance: What You Need To Know
PCI Audit

Scoping is determining what systems are covered or need to be assessed or included as part of your PCI compliance.

Text 'Auditor Tips PCI DSS' on a dark geometric patterned background with a blue underline.
Auditor Tips: Requirement 10: Audit Logs and Log Monitoring
PCI Audit

It’s critical that you configure the log monitoring solution correctly so that the appropriate directories, files, security controls, and events are being monitored.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background.
Auditor Tips: Requirement 11: Testing Security
Penetration Testing

If your organization is required to be PCI compliant, don’t procrastinate beginning the penetration test process.