search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
CSF HITRUST Breakdown: FAQs & Guidance
HITRUST

In this blog, you’ll learn about the fundamental aspects of HITRUST Certification, as well as receive answers to frequently asked questions about CSF HITRUST.

How Infosend Became PCI DSS Compliant with SecurityMetrics
Data Security

Since 2014, Infosend has partnered with SecurityMetrics to meet their PCI compliance needs, ensuring their processes remain secure and their clients’ data is protected.

Top Cybersecurity Data Insights: a Breakdown of Our 2024 PCI DSS Guide
PCI Trends

For 2024, our guide remains one of the best resources to use as you achieve PCI DSS compliance for your organization. It covers each requirement with clarity and thoroughness.

Vita Companies HITRUST Certification Journey using SecurityMetrics and Privaxi
HITRUST

About four years ago, Vita Companies decided to pursue HITRUST certification to differentiate themselves in the market.

Updates to Multi-Factor Authentication Requirements in PCI v4.0.1
PCI Trends

Learn how to comply with PCI DSS 4.0 Requirement 8, focusing on multi-factor authentication (MFA) and password management.

6 Common Problems Merchants Face in PCI Compliance Programs
PCI Partner

Merchants that rely on a PCI compliance program to stay compliant and protect their business often find themselves dissatisfied or frustrated by all kinds of problems including lack of support, expensive contracts, and many more.

Why You Need to Know About PCI Requirements 6.4.3 & 11.6.1: Eskimming Findings from SecurityMetrics Investigations
Ecommerce Security

SecurityMetrics has seen a dramatic increase in attacks specifically on ecommerce sites using iFrames to host a payment page from a 3rd party service provider.

PCI Compliance & Cybersecurity: Anedot's Journey with SecurityMetrics
PCI Audit

In this case study, Anedot works with SecurityMetrics to better secure their cybersecurity infrastructure and to reach PCI DSS 4.0 compliance.

Internal Penetration Testing 101: Where to Start
Penetration Testing

While there are various types of penetration tests like external, web application, or mobile, this blog will focus on internal tests and why they matter.

Understanding the New PCI SAQ Type: SAQ SPoC
Data Security

This article covers the Self-Assessment Questionnaire (SAQ) for Software-based PIN entry.

Updates to PCI DSS v4.0.1
PCI Trends

The PCI Security Standards Council (PCI SSC) recently published a limited revision to the PCI DSS in the form of v4.0.1.

External Vulnerability Scanning FAQ: What is External Vulnerability Scanning?

External vulnerability scanning is a security practice that involves scanning and assessing the external-facing network infrastructure, systems, and applications of an organization for potential vulnerabilities.

Why Partner with SecurityMetrics for Data Security and Compliance?
Compliance

We want to remove you from being the low-hanging fruit to hackers by improving your overall security posture. Our mission statement is to “close data security and compliance gaps to avoid a data breach.”

10 Misconceptions about Endpoint Security and Why You Need It
Data Security

Endpoint security generally refers to cybersecurity tools or services that can help alert you on devices that may be compromised.

Artificial Intelligence and Cybersecurity: What Businesses Don't Know
Data Security

AI or artificial intelligence can be used safely by businesses that are concerned about their cybersecurity.

Navigating AI Safely in Your Small Business: an AI Cybersecurity Perspective
Data Security

A number of other interesting AI cybersecurity issues are hitting our radar as customers begin taking advantage of new AI tools in their small businesses.

New Ecommerce Security Tool: Shopping Cart Monitor
Ecommerce Security

Shopping Cart Monitor has the potential to save online retailers a significant amount of money and frustration since content providers can be held liable for damages—damages that can cost retailers hundreds of millions of dollars every year.

Cost Effective Data Security Best Practices in the Workplace
Data Security

Don't let cyber threats compromise your sensitive information. Follow these simple, cost-effective data security best practices for a secure workplace.

GDPR FAQs
GDPR

Find out the most commonly asked questions about GDPR.

Understanding the HIPAA Application of Firewalls
HIPAA

Like a security guard, firewalls control what goes in and what comes out.

HIPAA Compliance Best Practices
HIPAA

With over 20 years in the industry, we have found that these HIPAA compliance best practices are most helpful in securing your organization.

Blogengine.net Directory Traversal & Listing; Login Page Unvalidated Redirect
Data Security

A directory traversal, CVE-2019-10717, was identified on BlogEngine.NET applications versions 3.3.7 and earlier through the /api/filemanager endpoint.

Authorization Bypass: CVE (2020-11679, 2020-11680, 2020-11681)
Data Security

Attackers: Known or Unknown? That is the question.

Performing an SAQ C-VT version 4.0 Self-Assessment
PCI Trends

This post will highlight changes made to the SAQ C-VT version 4.0 and provide guidance on how to comply with newly added requirements.