Blog

search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Microsoft Exchange Server Zero-Days and SEO Cyberattack
Data Security

Directive to patch Microsoft Exchange server zero-days immediately SEO Cyberattack: hackers use strategy to push malicious web pages up the rankings Are password managers safe? Experts compare LastPass vs. 1Password

SolarWinds and FireEye
Forensics

In this SecurityMetrics News episode, Heff and Forrest analyze recent cybersecurity news, including the unprecedented SolarWinds security breach and the FireEye compromise.

How to Protect Your Organization From the Log4j Vulnerability
Data Security

For clients of the SecurityMetrics Threat Intelligence Center, we are actively scanning and informing clients of outbound Log4j indicators of compromise.

Western Digital Vulnerability Causes Data Loss in Hard Drives
Forensics

Join Heff this week as he dives into the Western Digital hard drive vulnerability, the recent bad news from Microsoft, and breach #2 of this year for LinkedIn.

Storing Unencrypted Credit Card Data: 2021 PANscan® Data Analysis
Data Discovery

Card data discovery is an important part of payment data security and complying with PCI DSS requirement 3. If you are going to store credit card data, you’ll need to know where it is captured, where it is stored, where it is transmitted, and where it is received.

What Is Social Engineering? Social Engineering Examples
Data Security

Protect sensitive data from social engineering attacks.

Does Your Third Party Vendor Put You At Risk?
Data Security

The role of the third party is evolving.

HIPAA Security Rule Requirements and Healthcare Security
HIPAA

While most healthcare entities follow the Privacy Rule fairly well, many aren’t compliant in the HIPAA Security Rule.

SecurityMetrics Summit: A Cybersecurity and Compliance Conference
SMB

In 2020, we hosted the first annual SecurityMetrics Summit; a virtual data security and compliance conference on September 23rd and 24th.

2021 Forensic Predictions and What Happened in 2020: Part 3
Forensics

Learn how to maximize security through simple practices and employee training.

How to Choose a Safe and Secure VPN
Data Security

VPNs are a popular tool that helps businesses make sure outside users are authorized and that transmitted data is encrypted.

2021 Forensic Predictions and What Happened in 2020: Part 1
Forensics

The year 2020 was surprising in many ways and the digital forensics industry offered some surprises as well as some more predictable outcomes.

Boost Your E-commerce Security Against Eskimming Attacks
Ecommerce Security

With ecommerce attacks on the rise, it's crucial for businesses to learn how to strengthen their ecommerce security.

Performing an SAQ C version 4.0 Merchant Self-Assessment
PCI Trends

Merchants using the SAQ C to validate their PCI DSS compliance should be aware of changes that were introduced into this questionnaire during the publication of the SAQ C version 4.0.

How to Prepare for a HIPAA Audit in 3 Steps
HIPAA Audit

Learn the three essential steps to help you effectively prepare for a HIPAA audit.

5 Simple Ways to Get PCI Compliant
PCI

Learn 5 basic practices to get PCI compliant, even if you're new to PCI or a compliance veteran.

How Does a Firewall Protect a Business?
Data Security

Get answers to the most common firewall questions.

PCI 6.6: Why You Need a Web Application Firewall and Network Firewall
Data Security

Web application firewalls rest in front of public-facing web applications to monitor, detect, and prevent web-based attacks.

A Snapshot of Firewalls, HIPAA, and Healthcare Security
HIPAA

See how healthcare organizations are managing their firewalls.

How to Comply with PCI Requirement 1: Manage Your Firewall
PCI

PCI Requirement 1 deals with setting up and configuring firewalls to protect your business data.

Auditor Tips: Requirement 5: Implement And Update Your Anti-Malware
Pulse

PCI DSS requires anti-malware software to be installed on all systems that are commonly affected by malware (e.g., Windows).

Achieving lift-off with PCI DSS v4.0
PCI Trends

With March 31, 2025 as a target destination, managed security service providers and enterprises from across the digital commerce chain are taking a measured approach to implementing PCI DSS version 4.0.

Changes and Updates to the 4.0 SAQ
PCI Trends

This blog will discuss changes to the PCI DSS 4.0 SAQ questionnaires and is based on our Webinar "PCI DSS 4.0: What's New and How It Affects You."

Performing an SAQ P2PE version 4.0 Self-Assessment
PCI Trends

This blog will discuss changes made to the SAQ P2PE version 4.0 and will review the process of performing a self-assessment using the SAQ P2PE.