search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Brad Caldwell, CEO of SecurityMetrics
SecurityMetrics COVID-19 Coronavirus Update
Data Security

With the upheaval and uncertainty many are experiencing around the world during the COVID-19 pandemic, we are more committed than ever to our mission.

Blue silhouette of home office with desk, chair, computer, lamp, books, cat by window, and trash bin.
Implementing a PCI-Compliant Remote Workforce Setup
PCI

To protect the health of employees from the coronavirus (COVID-19) pandemic and to minimize the risk of financial losses due to productivity concerns, many companies are making plans to allow for employees to work from home.

Blue credit card labeled CC# and payment terminal with a checkmark on the screen.
PCI DSS v4.0: Future of the PCI Security Standard
PCI Trends

While the PCI v4 standard is not expected to be finalized and released until the end of 2020 or the beginning of 2021, the PCI Security Standards Council has made some information available to the general public on what some of the changes might be.

Stack of three white report documents with blue outlines titled 'REPORT CVE Disclosure'.
CVE-2020-5497 - MITREid Connect Cross-site Scripting
Data Security

MITREid Connect Cross-site Scripting Vulnerability: CVE-2020-5497 Here's the situation: I was performing a penetration test that integrated with MITREid Connect for authorization.

Computer components and tools on a white desk with blue line art of smartphone, card, and magnifying glass.
2020 Data Breach Predictions and What We Learned in 2019
Forensics

It’s important to note that the number of victims in each reported breach is not cumulative, these are each individual incidences, bringing the total between these three breaches to upwards of 1.4 billion victims.

Blue credit card with a chip and name Mrs. Brown, card number masked with stars.
5 Steps of a PCI DSS Audit
PCI Audit

PCI DSS assessments, also called PCI audits, may seem daunting for you and your business. But, we’ve broken down the process into 5 steps to help you understand what the process will be like and how you can better optimize your time.

2020 SecurityMetrics guide to HIPAA Compliance for healthcare covered entities and business associates.
Guide to HIPAA Security Rule, Privacy Rule, and Breach Rule
HIPAA Audit

Did you know that protected Health Information (PHI) is extremely valuable to hackers, even more so than credit card data?

Blue clipboard icon with text inside outlined cloud shape on light background with small clouds.
PCI Compliance in the Cloud
PCI

Learn how PCI compliance in the cloud affects your organization. "The cloud" brings up an idea of something mysterious and far away, but in reality, “the cloud” is a third-party-managed physical server.

Abstract numbers 1-5 with white background.
5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year
PCI

Here are 5 Blogs to Help You Survive PCI DSS and Prevent Security Breaches This Year. We cover formjacking, penetration tests, PCI DSS checklists, PCI DSS audits, as well as preparing for incident response.

Cover of 2020 SecurityMetrics guide to HIPAA Compliance for healthcare entities and business associates.
SecurityMetrics' 2020 Guide to HIPAA Compliance Has Launched
HIPAA Audit

We create and publish our HIPAA Guide each year: to give healthcare IT and HIPAA leaders an up-to-date resource to direct and focus their HIPAA compliance efforts to the areas that are quick and impactful.

Outline of California with a blue padlock symbolizing security or privacy.
What is CCPA (California Consumer Privacy Act) Compliance?
Privacy

Like other privacy laws, CCPA includes some basic tenets of data protection as well as provisions to notify data subjects about the uses of their data, like who is going to see their data and when.

Blue credit card with chip, labeled CC#, showing masked number and name Mrs. Brown.
PCI Assessment FAQs
PCI Audit

To address some of the most common questions we receive about PCI assessments, we sat down with Lee Pierce, a PCI assessment expert with over 15 years in the industry.

Stack of report documents with the cover titled 'REPORT CVE Disclosure' in blue text.
WiKID 2FA Enterprise Server Cross-Site Scripting
Data Security

A stored and reflected cross-site scripting vulnerability, CVE-2019-17114, was identified on WiKID Systems 2FA Enterprise Server version 4.2.0-b2047 and earlier.

Stack of report documents with the top one titled REPORT CVE Disclosure in blue text.
WiKID Systems 2FA Enterprise Server SQL injection
Data Security

A SQL Injection vulnerability, CVE-2019-16917, was identified on WiKID Systems 2FA Enterprise Server through version 4.2.0-b2047.

Stack of documents with the cover titled REPORT CVE Disclosure in blue text and lines.
WiKID Systems 2FA Enterprise Server CSRF
Data Security

Multiple Cross-Site Request Forgery issues, CVE-2019-17118, were identified on WiKID Systems 2FA Enterprise Server through version 4.2.0-b2053.

Stack of report papers titled CVE Disclosure with circuit board design background.
Something from Nothing; a Pentest Story
Penetration Testing

While performing an external network layer penetration test I encountered a host that presented a single page that was essentially blank...

Blue cloud icon connected to light blue circuit-like lines on a gray background.
HIPAA Compliance: Storage in the Cloud
HIPAA Audit

HIPAA Compliance in “the cloud” Cloud data storage is a common and convenient option for healthcare organizations.

Jen Stone
Jen Stone: Principal Security Analyst
PCI Audit

Jen Stone is a Principal Security Analyst for SecurityMetrics. In her 4 years at SecurityMetrics, she has completed over 100 security assessments that include PCI, HIPAA, CIC CSC (SANS Top 20) and 23 NYCRR 500.

Matt Halbleib
Matt Halbleib: Director of Assessments
Data Security

Matt Halbleib holds QSA (Qualified Security Assessor), PA-QSA (Payment Application Qualified Security Assessor), and CISSP (Certified Information Systems Security Professional) security certifications and as a qualified assessor for the Payment Card Industry, has completed over 100 PCI DSS, PA-DSS and P2PE security assessments.

Network diagram with blue nodes of various sizes connected by blue lines on a white background.
HITRUST vs. HIPAA
HITRUST

The difference: HITRUST vs. HIPAA HITRUST is a compliance framework created by a private alliance of security industry experts and includes many aspects of HIPAA Security and Privacy Rules.

Laptop screen displaying skull and crossbones with search, list, and gear icons connected to it.
What is Formjacking?
Ecommerce Security

Formjacking is a type of cyber attack where hackers inject malicious JavaScript code into a webpage form–most often a payment page form.

Stack of three report pages titled 'CVE Disclosure' with blue circuit-like lines background.
Blogengine.net Directory Traversal & Listing; Login Page Unvalidated Redirect
Data Security

A directory traversal, CVE-2019-10717, was identified on BlogEngine.NET applications versions 3.3.7 and earlier through the /api/filemanager endpoint.

Illustration of a digital report with pie charts and a bar graph on a white background.
PANscan 2020 Study Shows Unencrypted Credit Card Data Storage Up
Data Discovery

Card data discovery tools help businesses find unencrypted card data and other sensitive information on systems and devices.

Stack of blue-outlined reports titled CVE Disclosure on a light background with circuit lines.
BlogEngine.NET XML External Entity Attacks
Data Security

An Out-of-band XML External Entity attack, CVE-2019-10718, exists on BlogEngine.NET versions 3.3.7 and earlier through the /pingback.axd endpoint.