Blog

PCI DSS 3.2 & 3.2.1 New PCI Requirements for Service Providers: What You Should Know

Here’s a quick look at the requirements service providers are expected to do for PCI DSS 3.2 and 3.2.1.

PCI DSS Requirement 12: Leverage Policy to Improve Security

If your organization has ever had a Payment Card Industry Data Security Standard (PCI DSS) assessment, you’ve probably noticed the big emphasis on having documented security policies and procedures.

How to Start a HIPAA Risk Analysis

A risk analysis is the first step in an organization’s Security Rule compliance efforts.

Lessons from Data Breaches in 2017 and What to Expect in 2018

Which data breach predictions came true in 2017 and what to expect for 2018. SecurityMetrics' Forensic Investigations Team has been helping business recover from data breaches and theft for over eighteen years.

IT Checklists for PCI Compliance

We include an PCI IT Audit checklist PDF in our PCI Guide to give IT teams the support they need to fulfill each PCI DSS requirement, one by one.

How to Maintain Security When Employees Work Remotely

Helping employees work from home securely is important for all businesses, but with this post we especially want to support SMBs and those companies without large staff or in-house security professionals.

How to Prevent Ransomware Attacks

Ransomware attacks are a type of malware. Malware means “malicious software” or “malicious executable.” On the evil scale, ransomware is near the top. It’s nasty stuff that you don’t want any part of.

How to Prevent Formjacking and E-commerce Skimming (Magecart Attacks)

The online payments ecosystem is plagued by formjacking attacks that siphon credit card data and other protected information from shopping cart pages.

Magento 1 End of Life: What You Should Do

Ecommerce business owners using Magento 1x need to be aware. All Magento 1 shops are at the end of life. What does that mean?

Implementing a PCI-Compliant Remote Workforce Setup

To protect the health of employees from the coronavirus (COVID-19) pandemic and to minimize the risk of financial losses due to productivity concerns, many companies are making plans to allow for employees to work from home.

HIPAA Social Media Compliance

Employees who irresponsibly use social media can potentially invite some serious HIPAA violations.

HIPAA Security Tip: Understand Your Data Flow

Fully understanding where PHI resides takes a lot of interdepartmental communication.

HIPAA Training Video: Essential Healthcare Compliance Training

Would it surprise you to learn that most breaches originate from healthcare workforce members?

HIPAA Security vs. EHR Security

Privacy and security are much more than simply having a HIPAA compliant EHR.

How to Find Time for HIPAA Compliance

Work on these small HIPAA compliance steps for at least 10 minutes per day for an entire month.

How Do New Penetration Test Requirements Affect You?

An industry-recognized methodology must be used when conducting a penetration test.

How to Confront Hospital Ransomware

Don’t let your patients’ medical records be taken hostage.

How do PCI Merchant Levels Determine PCI Compliance?

Learn more about PCI merchant levels and how they affect PCI requirements.

How Healthcare Security Complacency is Killing Your Organization

Far too many healthcare organizations are losing data and they don’t even know it.

How Prepared are UK Businesses for GDPR?

The EU General Data Protection Regulation (GDPR) will come into effect on May 25, 2018.

How to Become PCI Compliant: The 2020 Guide to PCI DSS Compliance

Payment Card Industry (PCI) compliance is required for any organization that takes payment cards.

HIPAA Compliant Passwords

Maintaining HIPAA compliant passwords is a key step towards protecting ePHI.

HIPAA Alphabet Soup: Unjumbling the Jargon

HIPAA includes many such acronyms, mostly security-related.

HHS HIPAA Audit Requirements

Don’t forget to document every HIPAA compliance effort as evidence to present to the OCR if your entity is chosen for auditing.