search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Smartphone with a chain and padlock icon on screen symbolizing security or locked device.
Securing Mobile Devices with Mobile Encryption
Data Security

How do you secure data on mobile devices? Physical security and mobile device policies are good at protecting the device itself, but another way to protect the data on the device is mobile encryption.

Text reading Auditor Tips PCI DSS on a dark geometric patterned background with a blue underline.
Auditor Tips: PCI DSS Scope
PCI Audit

To discover your PCI scope and what must be included for yourPCI compliance, you need to identify anything that processes, stores, or transmits cardholder data, and then evaluate what people and systems are communicating with your systems.

Connecting dots illustration.
What are the HITRUST Requirements? 3 Steps To Get HITRUST Certified
HITRUST

Specific HITRUST requirements are available through HITRUST’s MyCSF portal and will include various implementations of foundational security measures and controls depending on your organization and the type of HITRUST assessment you are performing.

Security Q: Stored Data
The Dos and Don'ts of Storing Credit Card Information
PCI

An example of insecure credit card number storage comes from one of our PCI assessors, where a company explained how they processed their credit cards.

Illustration of a key with white background.
What is a Managed Firewall and Do You Need One?
Data Security

What is a Managed Firewall and Do You Need One?

Graphic of circles with numbers 1 to 18 and a large V8 circle on the left side.
What’s changed in CIS Controls (v8)?
Security Consulting

Overview of key changes in the CIS controls update. See what’s new in the CIS Controls (v8) and how this free resource can help maximize your security.

Illustration of stacked numbered boxes with text.
Improve Your Security Posture with NIST Cybersecurity Framework
Security Consulting

The NIST cybersecurity framework can help guide small-to-medium sized organizations improve their cybersecurity posture.

Illustration of a workspace with a desk, computer, chair, and plant.
Top 10 Types of Phishing Emails
Data Security

Criminals have countless methods and types of phishing emails to trick email users.

HIPAA Firewalls
Why You Need Both a Hardware and Software Firewall
Data Security

How do you block access to your systems (and sensitive data) from hackers in the outside world?

Illustration of a blue laptop with an Event Logger on the screen.
What Are HIPAA Compliant System Logs?
HIPAA

System logs are part of HIPAA compliance and specifically mentioned in two different requirements.

The Importance of Log Management
Data Security

Log management and regular log review could help identify malicious attacks on your system.

Drawing tools with ruler, pencil, and geometric circle sketch on a blue grid background.
System Hardening Standards: How to Comply with PCI Requirement 2.2
Data Security

Merchants must “address all known security vulnerabilities and [be] consistent with industry-accepted system hardening standards.”

Cartoon thief climbing out of laptop screen holding a credit card with numbers visible.
Social Engineering Training: What Your Employees Should Know
Training

Learn how to help your employees be better prepared to fight against social engineering tactics.

Laptop screen shows a shopping cart and checkout button with text 'Learn more about SAQ A-EP'.
SAQ A-EP: The What and the How
SMB

The biggest difference between SAQ A and SAQ A-EP is based on how cardholder data is handled.

Text saying hello PCI 4.0 on a dark background with scattered blue squares and circles.
PCI DSS Version 4.0 SAQ Changes
PCI Trends

There are some key changes to the PCI DSS 4.0 SAQ questionnaires you will want to be aware of.

Illustration of secure online shopping with credit card, lock icon, and checkmark icon.
Key PCI DSS 4.0 Requirement Updates
PCI Trends

You will need to be compliant with PCI DSS 4.0 by March 31, 2025. We recommend starting your transition to 4.0 by reading the documents that explain the new PCI standard, including the executive summary, which has a lot of good information in it.

How Much Does HIPAA Compliance Cost?
HIPAA Audit

Lack of budget is a plague that affects risk and compliance officers at health organizations of all sizes. This post will give you the information you need to more accurately plan your HIPAA budget.

HIPAA and PCI logos.
HIPAA vs. PCI DSS Compliance
HIPAA

Why do you need to comply with PCI if you’ve already taken care of HIPAA?

Illustration of a clipboard with paper and pen listing three names.
Are Patient Sign-In Sheets a HIPAA Violation?
HIPAA

My stance on patient sign-in sheets is that unless there is a valid business reason for having them, don’t do it.

HIPAA Violations: Who is Responsible?
HIPAA

Is it your responsibility to ensure that your clinic is HIPAA compliant?

Megaphone with five icons on white background.
5 Tips to Implement Security Awareness at Your Company
Data Security

Whether you’re a CIO, the head of IT, or in a non-security-related position, if your data security practices are unclear, your company is at a greater risk to a data breach.

Repeated book cover titled SecurityMetrics Guide to PCI DSS Compliance with blue and black design on gray background.
How to Perform a PCI v4.0 SAQ A Self-Assessment
PCI Trends

Performing an SAQ A version 4.0 Self-Assessment: Several new requirements, both existing in version 3.2.1 of the standard and some newly created for version 4.0, have been added to increase the security of outsourced ecommerce environments.

Illustration of a web browser on a computer screen.
Are HTTP Websites Insecure?
Data Security

There are two website prefixes: One shows the site you are on is secure (HTTPS), and the other does not (HTTP).

Three numbered circles 1, 2, 3 above a striped rectangle next to an open door with blue outline.
Your Crash Course To HITRUST CSF Assessment Types
HITRUST

This blog will cover the three types of HITRUST CSF certifications. It will also cover what you can expect to achieve upon completion of each type of assessment and general guidelines of which assessment is best for your organization.