search
Search...
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Image of an open envelope with a credit card inside with a name written on the card.
Sending Credit Card Info Over Email
PCI

The way you handle emailing credit card info might just change your scope for PCI DSS compliance.

Question mark illustration on white background.
Common PCI DSS Questions for SMBs
SMB

This blog is intended for small to medium sized-merchant businesses and attempts to answer common PCI DSS questions.

Cracked glass over text reading DATA BREACH with healthcare and securitymetrics blog mention.
How to Manage a Data Breach: 5 Steps to Keep Your Business Safe
Forensics

Here are some steps to take to stop information from being stolen, prevent further damage and restore operations as quickly as possible.

PCI Requirement 10: Logging, Tracking, and Monitoring text with hand handling office binders.
PCI Requirement 10: Logging and Log Monitoring
PCI

PCI requirement 10 is all about logging and log monitoring.

Requirement 11
PCI Requirement 11: Vulnerability Scans and Penetration Tests
Penetration Testing

PCI Requirement 11 discusses vulnnerability scanning and penetration testing.

Computer screen with numbers on the left side going in the computer and dollar signs on the right side exiting computer.
How to Manage a Healthcare Data Breach
Forensics

Data breaches can be devastating. Here are 5 steps that will help you manage a healthcare data breach.

Tall building with text 'PCI Resources For Enterprise Organizations' on blue background.
The Top Five PCI Resources for Enterprise Organizations
Compliance

To help your organization stay proactive and ahead of threat trends, I’ve curated the five most critical resources for managing enterprise-level risk in 2026. Read on to discover which PCI resources deserve your attention the most.

Illustration of three blue shops in small, medium, and large sizes from left to right.
What are Service Provider Levels and How Do They Affect PCI Compliance?
PCI Audit

If you’re a service provider, you may have some different PCI requirements based on what level you are.

Illustration of three spinning gears above a technology device on a white background.
3 Projects to Get You Into InfoSec
Data Security

This blog will discuss 3 infosec projects that are under $100 to get you started in Cybersecurity or Infosecurity by giving you hands-on experience to develop your skills.

Network of gray user icons connected by lines with one blue highlighted user icon.
PCI DSS Compliance for Service Providers FAQ
PCI Audit

PCI DSS compliance for service providers is necessary if your organization provides services to merchants that may affect the security of their merchant payment data.

PCI for a Small Business
Top PCI Resources for Small Businesses
PCI

Here are my top PCI resources for small businesses, based on what your business needs help with.

Text about PCI Requirement 5 on protecting your system with anti-virus by SecurityMetrics blog.
PCI Requirement 5: Protecting Your System with Anti-Virus
Pulse

PCI Requirement 5 deals primarily with installing and maintaining an anti-malware software.

Common Pitfalls for Acquirers.
Why Many Merchant PCI Programs Fail: Common Pitfalls for Acquirers
PCI

Most acquirers know their current PCI program isn’t working as well as it should. Knowing the cause of the problem is key.

Pentest Cost.
Why Some Penetration Tests Cost $10K and Others $3K
Penetration Testing

Read this blog to discover what determines the cost of a penetration test, what cheaper and more expensive penetration tests include, which fit your needs, and the major red flags to avoid.

Western Reserve
How Finding the Right Partner Helped Western Reserve Achieve HITRUST Certification
HITRUST

Explore this blog to get direct quotes from Mark about his experience working with SecurityMetrics, why Western Reserve chose to become HITRUST certified, and what you should look for in a HITRUST partner.

HITRUST Providers.
Top HITRUST Providers and Who Should You Choose
HITRUST

Here’s my definitive ranking of top HITRUST providers, what they offer, who they’re best for, and projected costs.

Multi-colored background with text 'How much will PCI compliance software actually cost me in 2025.'
Budgeting for PCI Compliance: Essential Software Costs for SMBs in 2025
SMB

Let's break down the real costs you can expect for PCI compliance software in 2025 for SMBs.

PCI Audits Cost
Why Are PCI Level 1 Audit Costs So Confusing?
PCI Audit

Read this blog to get answers from a QSA on what affects the cost of a PCI level one audit, what hidden fees might exist, and what you can do to get a more accurate quote.

Laptop with binary code on screen zoomed by magnifying glass representing data analysis or debugging.
What To Do When You Get Hacked, Step-By-Step
Forensics

Here’s what to do when you get hacked, step-by-step.

'What Do You Do If Your Identity Is Stolen' with gray silhouette and a question mark besides text.
What to Do If Your Identity is Stolen in 2025: Essential Steps
Data Security

If you find yourself a victim of identity theft, it’s crucial to act swiftly and systematically to protect yourself and minimize the damage.

Forensics Blog
You’ve Been Breached. What Should You Do Now?
Forensics

A breach doesn’t have to be the end of the world—or your business. How you respond matters more than what happened.

Infosend Experience Getting PCI 4.0 Audit.
One IT Professional’s Experience working with SecurityMetrics for their PCI 4.0 Audit
PCI Partner

Read this blog, based on the podcast “PCI DSS 4.0: One Organization’s Experience,” to learn how Martin tackled common PCI challenges, found new solutions, and discovered that PCI doesn’t have to be a solitary effort.

The Most From Your Penetration Test.
How to Get the Most From Your Penetration Test (According to Real Ethical Hackers)
Penetration Testing

We asked two of our senior security experts—Garrett Adler (Senior Pen Tester) and Terrill Thorn (Director of Pen Testing)—to walk through how companies like yours can squeeze the absolute most value out of their pen test.