Blog

SecurityMetrics Announces the 2025 Guide to PCI DSS Compliance

The SecurityMetrics PCI Guide helps you reach PCI compliance with the newest stats, advice, and checklists.

PCI Requirement 2: Apply Secure Configurations to All System Components

Read this blog to learn what the requirement entails, how to harden your systems, and manage your system configurations.

PCI DSS Requirement 3: What You Need to be Compliant

PCI DSS Requirement 3 involves protecting card data storage.

PCI Standards: Which PCI SAQ is Right for My Business?

PCI Standards: Which PCI SAQ is Right for My Business? A PCI Self-Assessment Questionnaire (PCI SAQ) is a merchant’s statement of PCI compliance.

What are the 12 Requirements of PCI DSS Compliance?

The PCI DSS (Payment Card Industry Data Security Standard) is a security standard developed and maintained by the PCI Council. This article will serves as a “jumping off point” to understanding the 12 requirements of the PCI DSS.

5 Steps of a PCI DSS Audit

PCI DSS assessments, also called PCI audits, may seem daunting for you and your business. But, we’ve broken down the process into 5 steps to help you understand what the process will be like and how you can better optimize your time.

PCI Validation: How to Simplify Your Annual PCI Validation Process

No matter how small your business is or how daunting this task is, it’s important to ensure that you’re doing all you can to protect your data.

Updates to Vulnerability Scanning Requirements for PCI Requirement 11

Complying with PCI DSS requirement 11 deals with vulnerability scanning and penetration testing, with additional requirements to scan your ecommerce sites being introduced with PCI v4.0.

Updates to Documentation Requirements for PCI DSS Requirement 12

PCI DSS requirement 12 deals with documentation, training, and risk assessments. This blog will cover the changes made to the documentation requirements in v4.0.

New PCI Requirements: Security Awareness Training

Human error remains one of the biggest threats to an organization’s security. This makes adequate security training more important than ever.

Recognizing a Phishing Email in the Age of Artificial Intelligence

Phishing remains one of the most effective methods for hackers to breach organizations.

What To Include In An Incident Response Plan

Creating an incident response plan can seem overwhelming. To simplify the process, develop your incident response plan in smaller, more manageable procedures.

Password Updates and Requirements in PCI 4.0.1

Complying with PCI DSS Requirement 8 deals with user accounts, passwords, and password management. This requirement is all about having unique, difficult-to-discover account information.

HITRUST Assessment Basics

This blog answers common questions about HITRUST Assessments and why a HITRUST assessment might be a good choice for your organization.

2025 Forensic Predictions

Each year, SecurityMetrics releases a blog post featuring our major cybersecurity predictions, featuring insights from our veteran team of cybersecurity, audit, and compliance staff.

Cybersecurity Lessons from 2024

Read this blog to discover what SecurityMetrics forensic analysts got right and wrong about 2024 cybersecurity breaches and what we can learn from this past year.

Further Clarification on SAQ A Updates: Requirements 6.4.3 and 11.6.1

Recently two requirements that were part of SAQ A were removed, namely PCI DSS 6.4.3 and 11.6.1. 

Security Academy: Free Compliance and Cybersecurity Resource for Your Small Business

Security Academy is a beginner-level, free course that you can return to if you have cybersecurity questions.

Web Application Firewall Fundamentals: PCI v4.0.1 Requirement 6.4.2

Find out about the latest about PCI DSS v4.0.1 requirement 6.4.2, which mandates that ecommerce merchants implement a Web Application Firewall (WAF) or equivalent security measures to protect their online payment environments.

Announcing the 2025 SecurityMetrics HIPAA Guide

This year’s HIPAA guide includes an easy-to-understand introduction that covers how to read the guide, an executive summary, and an overview of this year’s new trends and stats.

2024 HIPAA Trends and Statistics

Read this blog to learn how 2024 compared to 2023 regarding HIPAA Security, Breach Notification, and Privacy Rules trends.

Big Changes for SAQ A: What You Need to Know About 2025 Updates for 11.6.1 & 6.4.3

The PCI Council just announced a big change for merchants that use SAQ A, regarding specific PCI requirements.

How to Comply with the 12 Requirements of PCI Compliance

Complying with the 12 requirements of PCI can be complicated for those who must meet PCI compliance. Read this blog to get an in-depth description of each requirement, tips for achieving requirements, and answers to frequently asked PCI questions.

The Top Ten SecurityMetrics Data Security Resources of 2024

Discover the most important resources of 2024 so you don’t miss out.