Blog

GDPR and CCPA Overview: Your Role in Data Protection

This post covers the General Data Protection Regulation (GDPR) and the California Consumer Protection Act (CCPA), as well as fees for data breaches, changes in privacy attitudes, and the future of the standards.

Magento 1 End of Life: What You Should Do

Ecommerce business owners using Magento 1x need to be aware. All Magento 1 shops are at the end of life. What does that mean?

Recap: SecurityMetrics’ 2020 Cybersecurity and Compliance Conference

From COVID-related challenges to firewall configuration to e-commerce web skimming, SecurityMetrics Cybersecurity Conference and Summit 2020 provided cybersecurity content and sessions for everyone in the data security and compliance industry.

Garmin Ransomware Attack: SOC Threat Analysis and 10 Lessons Learned

The global pandemic has created more opportunities for ransomware threat actors to create mayhem and chaos across the threat landscape.

Top Cybersecurity Conferences 2020

Whether you’re a small business owner or the CISO at a large enterprise, finding good cybersecurity conferences is a necessary task to continue security education and explore the latest technology and innovative solutions.

How to Prevent Formjacking and E-commerce Skimming (Magecart Attacks)

The online payments ecosystem is plagued by formjacking attacks that siphon credit card data and other protected information from shopping cart pages.

SecurityMetrics Summit: A Cybersecurity and Compliance Conference

In 2020, we hosted the first annual SecurityMetrics Summit; a virtual data security and compliance conference on September 23rd and 24th.

What is a Business Continuity Plan?

A business continuity plan (BCP) provides a way for organizations to deal with the business impact of any disruptive event and carry on with business.

Remote PCI DSS Audits During COVID-19: FAQs

The COVID-19 crisis has presented a variety of challenges to merchants and service providers around the world. We’ve received many questions about the impact of COVID-19 on PCI DSS audits, as well as PCI compliance in general.

How to Maintain Security When Employees Work Remotely

Helping employees work from home securely is important for all businesses, but with this post we especially want to support SMBs and those companies without large staff or in-house security professionals.

Update: COVID-19 Cybersecurity and Threats

As plans to reopen economies move forward around the world, the entire cybersecurity industry–including the SecurityMetrics Security Operations Center (SOC)–is being challenged in new and unexpected ways.

Where Did that Request Come From? CVE-2020-11682 (CSRF)

What is CSRF? Cross site request forgery, commonly referred to as CSRF (pronounced sea-surf), is an attack in which a user who is authenticated to an application is tricked into unintentionally performing a state-changing action.

Authorization Bypass: CVE (2020-11679, 2020-11680, 2020-11681)

Attackers: Known or Unknown? That is the question.

Penetration Testing FAQs

We outline the penetration testing process in detail and answer some of the most frequently asked questions related to this important security test.

Update: COVID-19 Cyber Threats and Attacks

Current COVID-19 Cyber Threats The UN Agency WHO has reported a 500% increase in cyber security incidents over the same period last year.

SecurityMetrics Podcast: The Latest in Cybersecurity and Compliance

The SecurityMetrics Podcast is a weekly podcast with regular host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA), along with a variety of experts in the data security and compliance space.

COVID-19 Cyber Attacks Security Update Center

Amid the chaos and uncertainty, SecurityMetrics remains steadfast in our mission to help you close compliance gaps and prevent data breaches. We stand ready to help with your security concerns, education, and content needs at this time.

COVID-19 Cyber Attacks: Threat Report and Best Practices

We caution all SecurityMetrics customers, merchants, and businesses to remain extra vigilant around cyber threat actors who are exploiting this global crisis to their advantage.

Top 15 ASV Scan Vulnerabilities and How to Fix Them

Vulnerability scans search your network and provide a logged summary of alerts you can review and act on. Here are the top 15 ASV scan vulnerabilities and how to fix them.

SecurityMetrics COVID-19 Coronavirus Update

With the upheaval and uncertainty many are experiencing around the world during the COVID-19 pandemic, we are more committed than ever to our mission.

Implementing a PCI-Compliant Remote Workforce Setup

To protect the health of employees from the coronavirus (COVID-19) pandemic and to minimize the risk of financial losses due to productivity concerns, many companies are making plans to allow for employees to work from home.

PCI DSS v4.0: Future of the PCI Security Standard

While the PCI v4 standard is not expected to be finalized and released until the end of 2020 or the beginning of 2021, the PCI Security Standards Council has made some information available to the general public on what some of the changes might be.

CVE-2020-5497 - MITREid Connect Cross-site Scripting

MITREid Connect Cross-site Scripting Vulnerability: CVE-2020-5497 Here's the situation: I was performing a penetration test that integrated with MITREid Connect for authorization.

2020 Data Breach Predictions and What We Learned in 2019

It’s important to note that the number of victims in each reported breach is not cumulative, these are each individual incidences, bringing the total between these three breaches to upwards of 1.4 billion victims.