GDPR Defense
Simplify your work towards GDPR compliance.

Features
Secure your data and get on the path to GDPR compliance
The General Data Protection Regulation (GDPR) not only applies to organizations operating in the European Union (EU), but also to organizations that process sensitive data from the EU. SecurityMetrics GDPR Defense has the tools you need to secure Personally Identifiable Information (PII) and assess your compliance with GDPR requirements.
Assess your compliance
Track your compliance progress simply and quickly with SecurityMetrics’ guided GDPR checklist. This checklist breaks down important elements of the GDPR into actionable items so you are never left wondering what you need to do next. The checklist monitors your progress in real time and features an organized dashboard for reporting.
Upload GDPR policies to a central location
An additional feature of the SecurityMetrics GDPR checklist is the ability to store your policies in a central storage cloud, which makes them easily accessible if you need to provide proof of implementation. Feel at ease knowing that your policies are stored securely in the case of a hard drive crash or data loss.
Access your GDPR Implementation Report
In the event of a data breach, you can use the SecurityMetrics GDPR Implementation Report as proof of your efforts to become compliant. The report is easily accessible from the checklist dashboard and provides a pie graph of your implementation progress, as well as a report of your progress over time.
Find PII at your organization
SecurityMetrics PIIscan is a data discovery tool that assists with GDPR requirements by discovering unencrypted Personally Identifiable Information (PII). PIIscan searches computer systems, hard drives, and attached storage devices for unencrypted PII. Once PIIscan has discovered unencrypted PII, a report is generated that displays where the data is located. This makes it easy to securely delete or encrypt this data and reduce your organization’s risk. By using PIIscan, you will also save time by not having to manually search for unencrypted PII on your systems.
GDPR training
In today's data-driven society, organizations rely on the collection and processing of user data in ever-evolving ways. Employees working in these organizations share a duty to protect the rights of individuals' personal data, which includes complying with the EU General Data Protection Regulation (GDPR). This training is comprised of two lessons, including:
Lesson 1: Privacy and the GDPR
- The General Data Protection Regulation (GDPR)
- Small Mistakes, Global Impact
- Compliance Matters
- Identifying Personal Data
Lesson 2: GDPR Principles
- Individual Rights
- Global Transfers
- Privacy by Design
- Processing Data Securely
- Data Breach Notification
- Implementing GDPR Standards
Implement GDPR policies and procedures
Part of the GDPR requires businesses to update and expand their policies and procedures to meet new regulations. Rather than trying to build your own GDPR Policies and Procedures from the ground up, we provide templates that you can easily tailor to fit your business.
PCI program solutions for acquirers and ISOs
SecurityMetrics PCI programs are merchant-friendly, keeping them and you happy.
Feature
Basic
Plus
Pro
Advisor
Online Portal
Merchant PCI SAQ
SAQ Pre-Population
ASV scans (1/merch)
PCI Policy Template
24/7 Help Desk
24/7 Scan & SAQ Support
Partner+ Portal
Custom Email Campaigns
Assigned CSM
ASV scans (5/merch)
$100,000 Merchant Premium Service Warranty
Card Data Discovery
Mobile Device Scan
AI-Powered PCI Compliance (Spectre AI)
Anti-Malware Software
Get started on your PCI program, request a quote now.
Request a QuoteLite
Basic
Advanced
PCI for small businesses starting at
Price discounts available depending on merchant processor
- External Vulnerability Scan (1 IP)
- Online PCI Self Assessment Questionnaire (SAQ)
- Online compliance reporting portal
- Non-compliance notification
- Compliance reporting to merchant processor
- Compliance certificate
- PANscan® (Card discovery software for 1 machine)
- Service warranty (Up to $100,000 reimbursement in case of a breach)
- Security Awareness Training (1 seat)
*We discount our services for most merchants because of our relationship with their merchant processor.
Looking for Acquirer or PCI program pricing? Click here.
Basic
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 1 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 3 seats
- 5 Hour Technical Support (inbound tech support only)
Plus
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 3 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 15 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Pro
- Online Portal Access (Software to help you work towards HIPAA compliance)
- Security Fundamentals Checklist
- $100,000 Service Guarantee
- Monthly Perimeter Scans: 5 IPs
- Risk Analysis
- Risk Management Plan
- Monthly HIPAA Newsletter
- HIPAA Policies & Procedures (including Breach Notification Policy and Business Associate Agreement Template
- HIPAA Training: 25 seats
- Unlimited Support (specialized HIPAA support agents available for guidance on all HIPAA tools)
Basic
- Portal access
- 1 payment path supported
- User-initiated scanning process
- Fulfills req’s. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Plus
- Portal access
- 1 payment path supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Add-on consultation credits available
- Partner discounts available
Pro
- Portal access
- 3 payment paths supported (option to add on)
- Automated scanning process
- Fulfills req's. 6.4.3 & 11.6.1
- Forensic annual baseline assessment
- 12 annual consultation credits included
- Partner discounts available
Frequently Asked Questions
Resources
The following are related resources that we have prepared for you. Find more answers to your questions in our Learning Center.
Trusted by 300,000+ companies










































































































Get PCI DSS Compliant
Get ready for PCI DSS v4.0.1 with the right tools, training, and support.
Why choose SecurityMetrics?
Award-winning customer support
If you would like assistance at any point in your GDPR compliance journey, our award-winning support staff is available 24/7 to provide you with answers your questions. SecurityMetrics representatives can help guide you through the checklist and provide insight as to how to fulfill each requirement.
Full service vendor
With expertise in GDPR, PCI DSS assessments, HIPAA assessments, forensic incident response, vulnerability scanning, penetration testing, card data discovery, security appliances, SSF (PA-DSS) security assessments, P2PE assessments, HITRUST assessments, training, and consulting, we hold a myriad of credentials and can help secure your data.
Unknown storage of PII
Organizations may unknowingly store PII when: Applications (e.g., payment processing) are not configured correctlyElectronic health record systems, payment processing applications, or other applications do not meet data security standardsOld PII is not securely deleted or encrypted on newly purchased applications. Employees are not aware unencrypted card data storage is prohibited.
See how we've helped our clients succeed
When you succeed, we succeed. That's why we pay such close attention to detail and provide award-winning support. Let's work together!
Recognition for Outstanding Work
SecurityMetrics has worked hard over the years to provide outstanding products and services. Here are some of the awards the team has won.




Over 25 Years of Compliance Experience
QSA | PFI | ASV | P2PE | SSF | SLC | 3DS | QPA | PCIP | RPO

