search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Penetration Testing FAQs: What Is a Pentest and How Does It Work?
Penetration Testing

A penetration test is a simulated cyberattack that finds exploitable security weaknesses before real attackers do. Get answers to the top pentest FAQs like cost, process, compliance, and how to choose a firm.

World map with blue circles indicating data points and arcs showing connections between continents.
Update: COVID-19 Cyber Threats and Attacks
Data Security

Current COVID-19 Cyber Threats The UN Agency WHO has reported a 500% increase in cyber security incidents over the same period last year.

Blue open padlock with circuit lines extending from it on a light gray background.
SecurityMetrics Podcast: The Latest in Cybersecurity and Compliance
Compliance

The SecurityMetrics Podcast is a weekly podcast with regular host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA), along with a variety of experts in the data security and compliance space.

Blue virus-like shapes with connecting lines on a light gray background, resembling a digital network.
COVID-19 Cyber Attacks Security Update Center
Pulse

Amid the chaos and uncertainty, SecurityMetrics remains steadfast in our mission to help you close compliance gaps and prevent data breaches. We stand ready to help with your security concerns, education, and content needs at this time.

World map with blue circles indicating data points and curved lines connecting North America to Europe, Africa, and Asia.
COVID-19 Cyber Attacks: Threat Report and Best Practices
Forensics

We caution all SecurityMetrics customers, merchants, and businesses to remain extra vigilant around cyber threat actors who are exploiting this global crisis to their advantage.

Computer monitor with a lock icon and a loading progress bar indicating security or encryption process.
Top 15 ASV Scan Vulnerabilities and How to Fix Them

Vulnerability scans search your network and provide a logged summary of alerts you can review and act on. Here are the top 15 ASV scan vulnerabilities and how to fix them.

Brad Caldwell, CEO of SecurityMetrics
SecurityMetrics COVID-19 Coronavirus Update
Data Security

With the upheaval and uncertainty many are experiencing around the world during the COVID-19 pandemic, we are more committed than ever to our mission.

Blue silhouette of home office with desk, chair, computer, lamp, books, cat by window, and trash bin.
Implementing a PCI-Compliant Remote Workforce Setup
PCI

To protect the health of employees from the coronavirus (COVID-19) pandemic and to minimize the risk of financial losses due to productivity concerns, many companies are making plans to allow for employees to work from home.

Blue credit card labeled CC# and payment terminal with a checkmark on the screen.
PCI DSS v4.0: Future of the PCI Security Standard
PCI Trends

While the PCI v4 standard is not expected to be finalized and released until the end of 2020 or the beginning of 2021, the PCI Security Standards Council has made some information available to the general public on what some of the changes might be.

Stack of three white report documents with blue outlines titled 'REPORT CVE Disclosure'.
CVE-2020-5497 - MITREid Connect Cross-site Scripting
Data Security

MITREid Connect Cross-site Scripting Vulnerability: CVE-2020-5497 Here's the situation: I was performing a penetration test that integrated with MITREid Connect for authorization.

Computer components and tools on a white desk with blue line art of smartphone, card, and magnifying glass.
2020 Data Breach Predictions and What We Learned in 2019
Forensics

It’s important to note that the number of victims in each reported breach is not cumulative, these are each individual incidences, bringing the total between these three breaches to upwards of 1.4 billion victims.

Blue credit card with a chip and name Mrs. Brown, card number masked with stars.
5 Steps of a PCI DSS Audit
PCI Audit

PCI DSS assessments, also called PCI audits, may seem daunting for you and your business. But, we’ve broken down the process into 5 steps to help you understand what the process will be like and how you can better optimize your time.

2020 SecurityMetrics guide to HIPAA Compliance for healthcare covered entities and business associates.
Guide to HIPAA Security Rule, Privacy Rule, and Breach Rule
HIPAA Audit

Did you know that protected Health Information (PHI) is extremely valuable to hackers, even more so than credit card data?

Blue clipboard icon with text inside outlined cloud shape on light background with small clouds.
PCI Compliance in the Cloud
PCI

Learn how PCI compliance in the cloud affects your organization. "The cloud" brings up an idea of something mysterious and far away, but in reality, “the cloud” is a third-party-managed physical server.

Abstract numbers 1-5 with white background.
5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year
PCI

Here are 5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year. We cover formjacking, penetration tests, PCI DSS checklists, PCI DSS audits, as well as preparing for incident response.

Cover of 2020 SecurityMetrics guide to HIPAA Compliance for healthcare entities and business associates.
SecurityMetrics' 2020 Guide to HIPAA Compliance Has Launched
HIPAA Audit

We create and publish our HIPAA Guide each year: to give healthcare IT and HIPAA leaders an up-to-date resource to direct and focus their HIPAA compliance efforts to the areas that are quick and impactful.

Outline of California with a blue padlock symbolizing security or privacy.
What is CCPA (California Consumer Privacy Act) Compliance?
Privacy

Like other privacy laws, CCPA includes some basic tenets of data protection as well as provisions to notify data subjects about the uses of their data, like who is going to see their data and when.

Blue credit card with chip, labeled CC#, showing masked number and name Mrs. Brown.
PCI Assessment FAQs
PCI Audit

To address some of the most common questions we receive about PCI assessments, we sat down with Lee Pierce, a PCI assessment expert with over 15 years in the industry.

Stack of report documents with the cover titled 'REPORT CVE Disclosure' in blue text.
WiKID 2FA Enterprise Server Cross-Site Scripting
Data Security

A stored and reflected cross-site scripting vulnerability, CVE-2019-17114, was identified on WiKID Systems 2FA Enterprise Server version 4.2.0-b2047 and earlier.

Stack of report documents with the top one titled REPORT CVE Disclosure in blue text.
WiKID Systems 2FA Enterprise Server SQL injection
Data Security

A SQL Injection vulnerability, CVE-2019-16917, was identified on WiKID Systems 2FA Enterprise Server through version 4.2.0-b2047.

Stack of documents with the cover titled REPORT CVE Disclosure in blue text and lines.
WiKID Systems 2FA Enterprise Server CSRF
Data Security

Multiple Cross-Site Request Forgery issues, CVE-2019-17118, were identified on WiKID Systems 2FA Enterprise Server through version 4.2.0-b2053.

Stack of report papers titled CVE Disclosure with circuit board design background.
Something from Nothing; a Pentest Story
Penetration Testing

While performing an external network layer penetration test I encountered a host that presented a single page that was essentially blank...

Blue cloud icon connected to light blue circuit-like lines on a gray background.
HIPAA Compliance: Storage in the Cloud
HIPAA Audit

HIPAA Compliance in “the cloud” Cloud data storage is a common and convenient option for healthcare organizations.

Jen Stone
Jen Stone: Principal Security Analyst
PCI Audit

Jen Stone is a Principal Security Analyst for SecurityMetrics. In her 4 years at SecurityMetrics, she has completed over 100 security assessments that include PCI, HIPAA, CIC CSC (SANS Top 20) and 23 NYCRR 500.