search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Sending Credit Card Info Over Email
PCI

The way you handle emailing credit card info might just change your scope for PCI DSS compliance.

The Risks of Emailing Credit Card Data: 2026 Compliance Standards
Compliance

Did you know that if your server receives, transmits, or stores primary account numbers (PAN), it is officially in scope for PCI security requirements?

2026 Cybersecurity Outlook & Lessons
Data Security Trends

Looking back on the previous year’s cybersecurity lessons isn’t just a nostalgic exercise, it could be a peek into anticipating 2026’s threats.

Question mark illustration on white background.
Common PCI DSS Questions for SMBs
SMB

This blog is intended for small to medium sized-merchant businesses and attempts to answer common PCI DSS questions.

PCI Requirement 12
PCI DSS Requirement 12: Policies and Documentation
PCI

Without a formal policy, technical controls are just isolated tools. Requirement 12 ensures those tools are part of a consistent, repeatable, and legal framework.

Two hands holding white masks with text Protect Your Identity Online on blue grid background.
10 Ways I’m Protecting My Professional Identity in 2026
Ecommerce Security

Your professional identity has never been more exposed. Read this blog to discover ten tips for protecting your identity online in 2026.

Cracked glass over text reading DATA BREACH with healthcare and securitymetrics blog mention.
How to Manage a Data Breach: 5 Steps to Keep Your Business Safe
Forensics

Here are some steps to take to stop information from being stolen, prevent further damage and restore operations as quickly as possible.

Comparing PCI QSA Firms.
Comparing PCI QSA Firms
PCI Partner

In this blog, I will compare the QSA firms SecurityMetrics, Coalfire, and A-Lign by looking at what you can expect from each QSA’s assessment and what they will cost.

PCI Requirement 10: Logging, Tracking, and Monitoring text with hand handling office binders.
PCI Requirement 10: Logging and Log Monitoring
PCI

PCI requirement 10 is all about logging and log monitoring.

Requirement 11
PCI Requirement 11: Vulnerability Scans and Penetration Tests
Penetration Testing

PCI Requirement 11 discusses vulnnerability scanning and penetration testing.

Computer screen with numbers on the left side going in the computer and dollar signs on the right side exiting computer.
How to Manage a Healthcare Data Breach
Forensics

Data breaches can be devastating. Here are 5 steps that will help you manage a healthcare data breach.

CMMC Path.
CMMC Basics: A Practical 2026 Roadmap for CMMC Compliance
CMMC

The time to implement the Cybersecurity Maturity Model Certification (CMMC) has finally arrived. Read to learn the timelines and best practices.

Falling down a hole with text 'You've Been Hacked'.
You’ve Been Hacked, Now What? A Step-By-Step Guide
Forensics

If you aren't careful, you might destroy the very evidence needed to stop the attacker for good.

Paper shredder in blue background titled 'Upping Your Physical Security.'
PCI Requirement Nine
PCI

PCI DSS Requirement 9 covers all aspects of physical security. Here are a few tips to make sure your physical security is PCI compliant.

Best Practices for a First Time Audit.
7 Common Mistakes to Avoid During Your First PCI Audit
PCI Audit

Drawing on decades of experience in PCI auditing, SecurityMetrics VP, Gary Glover, and Audit Director, Matt Halbleib, share the seven most common pitfalls organizations encounter, and how to navigate them successfully.

'PCI Basics' text on a blue background.
PCI Fundamentals for SMBs
PCI

PCI compliance doesn’t have to be a headache. The process can actually be broken down into four manageable steps.

Tall building with text 'PCI Resources For Enterprise Organizations' on blue background.
The Top Five PCI Resources for Enterprise Organizations
Compliance

To help your organization stay proactive and ahead of threat trends, I’ve curated the five most critical resources for managing enterprise-level risk in 2026. Read on to discover which PCI resources deserve your attention the most.

Illustration of three blue shops in small, medium, and large sizes from left to right.
What are Service Provider Levels and How Do They Affect PCI Compliance?
PCI Audit

If you’re a service provider, you may have some different PCI requirements based on what level you are.

Illustration of three spinning gears above a technology device on a white background.
3 Projects to Get You Into InfoSec
Data Security

This blog will discuss 3 infosec projects that are under $100 to get you started in Cybersecurity or Infosecurity by giving you hands-on experience to develop your skills.

PCI Requirement 7 Restrict Access.
PCI Requirement 7: Limiting Employee Access
PCI

PCI requirement 7 requires you to restrict employee access to only the data they absolutely need. It might sound simple, but it’s actually one of the most important requirements for preventing a data breach and commonly overlooked.

PCI Requirement 8 Combating Weak Passwords and Usernames.
PCI Requirement 8: Strengthen Your Passwords and Usernames
PCI

If you’re wondering what this means for PCI requirement eight, this blog will cover key updates, how to strengthen your organization’s passwords and usernames, and how to implement MFA (Multi-Factor Authentication).

PCI DSS Compliance for Service Providers FAQ
PCI Audit

PCI DSS compliance for service providers is necessary if your organization provides services to merchants that may affect the security of their merchant payment data.

Designing API Connections That Meet HIPAA and PCI Requirements
HIPAA

This is a guest post from Keragon, a healthcare platform that specializes in building HIPAA-compliant automations without code.

Simplify Your PCI Audit.
How to Make PCI Assessments for Complex Environments Much Easier
PCI Audit

We'll show you the real-world difference between a chaotic, unprepared PCI effort and a strategic, streamlined process, and how to get there.