PCI DSS Version 4.0: Managing Your Scope for “Significant Change”

After a few delays, PCI DSS version 4.0 was finally announced publicly on March 31, 2022. While entities may still use PCI DSS v3.2.1 until its retirement date on March 31, 2024, there are some notable changes that should be given consideration in advance. Since the initial evolution of PCI …

PCI DSS Version 4.0: Responding to Sensitive Data Discovery Incidents

At the end of March, the PCI Standards Security Council (PCI SSC) publicly released the most recent update to the PCI Data Security Standards (DSS), version 4.0. While much speculation has occurred as to the contents of the new standards—and much of that speculation turned out to be correct—now it’s …

Data Breaches Are A “When,” Not An “If.” Here’s How You Can Prepare.

Cyber attackers have spent considerable time and resource to develop cyberattack methods that evade detection. Which means a focus on complete attack prevention may be unattainable—or if attainable, not sustainable for very long. Cyber criminals are becoming increasingly organized, with increasingly sophisticated attack methods. For most organizations, this means it’s …

CDE Scoping and Future Data Compliance Requirements: Why Data Discovery Is Crucial to PCI DSS

Last month I shared a post about prioritizing data security in the uncertain future that is 2022, whether that uncertainty pertains to existing or net new privacy laws, expansions of security controls, or other regulatory factors. One thing is for certain, this year brings with it a lot of potential …

The Season of Travel: Securing Endpoints for Remote Work

Summer is here, and with many organizations still allowing employees flexibility in where they work, it’s expected that some of them will take their job on the road. Many are itching to travel while the weather’s nice and COVID restrictions are light, and the remote work model affords the opportunity …