search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Scanning Updates.
Updates to Vulnerability Scanning Requirements for PCI Requirement 11
PCI

Complying with PCI DSS requirement 11 deals with vulnerability scanning and penetration testing, with additional requirements to scan your ecommerce sites being introduced with PCI v4.0.

PCI Documentation Updates.
Updates to Documentation Requirements for PCI DSS Requirement 12
PCI

PCI DSS requirement 12 deals with documentation, training, and risk assessments. This blog will cover the changes made to the documentation requirements in v4.0.

Security Awareness Training
New PCI Requirements: Security Awareness Training
Compliance

Human error remains one of the biggest threats to an organization’s security. This makes adequate security training more important than ever.

Vintage computer displays a blue brain with nearby black envelope holding a blue A.I. tag.
Recognizing a Phishing Email in the Age of Artificial Intelligence
Forensics

Phishing remains one of the most effective methods for hackers to breach organizations.

Stylized numbers 1 to 5 in blue shades above diagonal light blue lines on a white background.
What To Include In An Incident Response Plan
Forensics

Creating an incident response plan can seem overwhelming. To simplify the process, develop your incident response plan in smaller, more manageable procedures.

Illustration of a question mark.
Password Updates and Requirements in PCI 4.0.1
PCI

Complying with PCI DSS Requirement 8 deals with user accounts, passwords, and password management. This requirement is all about having unique, difficult-to-discover account information.

Blue icon of an FAQ folder with documents flying out against a light background with blue circles.
HITRUST Assessment Basics
HITRUST

This blog answers common questions about HITRUST Assessments and why a HITRUST assessment might be a good choice for your organization.

2025 Forensic Predictions.
2025 Forensic Predictions
PCI Trends

Each year, SecurityMetrics releases a blog post featuring our major cybersecurity predictions, featuring insights from our veteran team of cybersecurity, audit, and compliance staff.

Panel illustration .
Cybersecurity Lessons from 2024
Data Security Trends

Read this blog to discover what SecurityMetrics forensic analysts got right and wrong about 2024 cybersecurity breaches and what we can learn from this past year.

Further Clarification on SAQ A Updates: Requirements 6.4.3 and 11.6.1
SMB

Recently two requirements that were part of SAQ A were removed, namely PCI DSS 6.4.3 and 11.6.1. 

Security Metrics Academy Cybersecurity Resource.
Security Academy: Free Compliance and Cybersecurity Resource for Your Small Business
Data Security

Security Academy is a beginner-level, free course that you can return to if you have cybersecurity questions.

Shopping Cart Castle illustration.
Web Application Firewall Fundamentals: PCI v4.0.1 Requirement 6.4.2
Compliance

Find out about the latest about PCI DSS v4.0.1 requirement 6.4.2, which mandates that ecommerce merchants implement a Web Application Firewall (WAF) or equivalent security measures to protect their online payment environments.

2025 HIPAA Guide on white background.
Announcing the 2025 SecurityMetrics HIPAA Guide
HIPAA

This year’s HIPAA guide includes an easy-to-understand introduction that covers how to read the guide, an executive summary, and an overview of this year’s new trends and stats.

'HIPAA Trends + Statistics' on a blue background.
2024 HIPAA Trends and Statistics
HIPAA Trends

Read this blog to learn how 2024 compared to 2023 regarding HIPAA Security, Breach Notification, and Privacy Rules trends.

What You Need To Know SAQ A.
Big Changes for SAQ A: What You Need to Know About 2025 Updates for 11.6.1 & 6.4.3
PCI

The PCI Council just announced a big change for merchants that use SAQ A, regarding specific PCI requirements.

PCI 12
How to Comply with the 12 Requirements of PCI Compliance
PCI

Complying with the 12 requirements of PCI can be complicated for those who must meet PCI compliance. Read this blog to get an in-depth description of each requirement, tips for achieving requirements, and answers to frequently asked PCI questions.

Text stating a data breach costs more than you think with stacks of bundled cash on a blue background.
How Much Does a Data Breach Cost Your Organization?
Forensics

Let’s take a look at some of the different costs your business could incur as a result of a data breach.

Blue stylized number 10 with text Top Ten Resources for 2024 on a light background.
The Top Ten SecurityMetrics Data Security Resources of 2024
Data Security

Discover the most important resources of 2024 so you don’t miss out.

HITRUST is a team effort, so you often need a lot of help from your entire team to manage your efforts
HITRUST FAQs: Your Top HITRUST Questions Answered
HITRUST

HITRUST is becoming increasingly required by organizations to ensure robust protection of sensitive data. Manage third-party risk effectively.

Man walking up blue stairs with a large arrow indicating forward direction.
Top FAQ’s For Acquirers Answered
PCI Partner

Discover the answers you need as an acquirer to navigate new PCI updates, PCI program questions, and merchant concerns.

Hand holding a phone showing an eye icon, with text Mobile Pen Testing 101 on left side.
Mobile Pen Testing 101
Penetration Testing

The main purpose of a penetration test is to stay one step ahead of the bad guys by finding your weaknesses with the help of experts exploring your mobile app and supporting systems.

Binoculars projecting beams with text 'How to Pass Your PCI Audit 2025' on beige background.
How to Pass Your PCI Audit in 2025
PCI Audit

Get quick and important advice for tackling PCI audits in 2025.

Blue text FAQs for ISOs with pointing hands and circular arrows on light background repeating the phrase.
FAQs for ISOs (Independent Sales Organizations)
PCI Partner

Understanding the role of an ISO in the payment process can be tricky. This blog outlines the most frequently asked questions surrounding ISOs and their pros and cons.

Blue outline of a computer monitor displaying a scanning progress bar about halfway complete.
External Pen Testing Basics
Penetration Testing

This blog post is for anybody who's interested in external pen testing basics, the types of things found when pen testing, and the process that you go through when completing them.