Blog

Security Insights

Practical guidance on PCI DSS, vulnerability management, security posture and compliance from the Radical Security team.

All posts120PCI DSS25Vulnerability Management35Security Posture25Compliance35
2026
Vulnerability Management
Choosing a Vulnerability Scanner: What to Look For
Choosing a vulnerability scanner? The criteria that matter, from asset coverage and credentialed scans to KEV and EPSS data, integrations and pricing.
April 14, 2026 · 9 min readRead →
Compliance
Data Retention Policies: Keeping What You Need and Nothing More
How to build a data retention policy: set a schedule, meet GDPR, PCI DSS and HIPAA rules, handle legal holds, backups and logs, and prove deletion.
March 10, 2026 · 9 min readRead →
Vulnerability Management
Vulnerability Management for OT and IoT Devices
How to run OT and IoT vulnerability management safely: passive discovery, vendor-approved patches, ISA/IEC 62443, segmentation and consequence-based priorities.
February 24, 2026 · 9 min readRead →
Compliance
Answering Vendor Security Questionnaires Without Losing Your Mind
How to answer vendor security questionnaires faster: use standard formats, build an answer library, share SOC 2 and ISO reports, and answer precisely.
January 13, 2026 · 8 min readRead →
2025
Security Posture
Building a 12-Month Security Roadmap
Build a 12-month security roadmap for 2026: baseline against NIST CSF 2.0, prioritize by risk and effort, plan quarterly phases and keep the plan alive.
December 9, 2025 · 8 min readRead →
Compliance
HITRUST Certification: Is It Worth the Effort?
Is HITRUST certification worth the effort? Compare the e1, i1 and r2 assessments, see what drives the work, and learn when SOC 2 or ISO 27001 is enough.
November 18, 2025 · 8 min readRead →
Compliance
Writing Security Policies Auditors Will Accept
How to write security policies auditors will accept: structure, ownership, review cycles, control mapping, acknowledgment evidence and an exceptions process.
October 21, 2025 · 8 min readRead →
Vulnerability Management
Living With End-of-Life Software You Can't Retire
Windows 10 support ends October 14, 2025. How to manage end-of-life software you can't retire: inventory, isolation, ESU, compensating controls and sign-off.
October 7, 2025 · 8 min readRead →
Compliance
PCI DSS vs. SOC 2 vs. ISO 27001: Which Framework Do You Need?
PCI DSS vs. SOC 2 vs. ISO 27001: who requires each, what you get, how they overlap, and which order to pursue them in based on your customers and your data.
September 16, 2025 · 8 min readRead →
Vulnerability Management
Shifting Left: Catching Vulnerabilities in the CI/CD Pipeline
How to shift left with CI/CD vulnerability scanning: SAST, SCA, secrets, IaC, container and DAST checks, plus gating policies developers will actually accept.
September 2, 2025 · 8 min readRead →
PCI DSS
Segmentation Testing: What Requirement 11.4.5 Actually Requires
What PCI DSS Requirement 11.4.5 requires for segmentation testing: how often to test, who can test, what to cover, and how 11.4.6 differs for service providers.
August 12, 2025 · 7 min readRead →
Security Posture
System Hardening With CIS Benchmarks
How to harden systems with CIS Benchmarks: Level 1 vs. Level 2 profiles, hardened images, automated rollout, testing, documenting exceptions and catching drift.
July 15, 2025 · 8 min readRead →
Security Posture
Building an Incident Response Plan That Works at 2 a.m.
Build an incident response plan people can use at 2 a.m.: contact lists, severity levels, decision rights, short runbooks and notification clocks.
June 17, 2025 · 9 min readRead →
Vulnerability Management
Taming False Positives in Vulnerability Scans
Why vulnerability scan false positives happen and how to cut them with validation, credentialed scanning, tuning and an exception process with expiry dates.
June 3, 2025 · 8 min readRead →
PCI DSS
Preparing for Your QSA Assessment: Evidence Collection Tips
How to prepare for a PCI DSS v4.0.1 QSA assessment: evidence types, how the ROC Template works, organizing evidence, targeted risk analyses and vendor AOCs.
May 13, 2025 · 8 min readRead →
Compliance
FedRAMP 20x: What's Changing for Cloud Providers
FedRAMP 20x aims to replace narrative paperwork with automated validation and faster authorizations. Here's what cloud providers know so far and what to do now.
April 22, 2025 · 7 min readRead →
Security Posture
Data Classification: Knowing What You're Protecting
A practical guide to data classification: a simple four-level scheme, data owners, labeling, handling rules, and linking it to DLP and access controls.
April 8, 2025 · 7 min readRead →
Vulnerability Management
Writing a Vulnerability Disclosure Policy
How to write a vulnerability disclosure policy: scope, safe harbor, reporting, timelines, security.txt, ISO/IEC 29147 and the EU Cyber Resilience Act.
March 25, 2025 · 9 min readRead →
Security Posture
Shadow AI: Managing Employee Use of Generative AI Tools
How to manage shadow AI: discover the generative AI tools staff use, offer approved options, set data rules for prompts, and back it with DLP and training.
March 11, 2025 · 8 min readRead →
PCI DSS
SAQ A Changes in 2025: Why 6.4.3 and 11.6.1 Were Removed and What Replaced Them
The January 2025 SAQ A drops requirements 6.4.3 and 11.6.1 and adds a script eligibility criterion. Here's what changed and what merchants should do now.
February 18, 2025 · 7 min readRead →
Compliance
Navigating the Patchwork of U.S. State Privacy Laws
U.S. state privacy laws now cover about 19 states. See 2025–2026 effective dates, how the laws differ, and how to build one program to the strictest rules.
February 4, 2025 · 8 min readRead →
Security Posture
Post-Quantum Cryptography: Why You Should Start Your Crypto Inventory Now
Post-quantum cryptography migration starts with a cryptographic inventory. Here's what NIST and NSA have set out, and how to inventory and plan now.
January 28, 2025 · 8 min readRead →
Compliance
The Proposed HIPAA Security Rule Overhaul: What Healthcare Should Expect
HHS proposed the biggest HIPAA Security Rule update in over a decade: mandatory encryption, MFA, asset inventories and annual audits. Comments close March 7.
January 21, 2025 · 8 min readRead →
Compliance
The EU Cyber Resilience Act and Products With Digital Elements
The EU Cyber Resilience Act sets security rules for products with digital elements. Key dates, product classes, Annex I requirements, SBOMs and reporting.
January 7, 2025 · 9 min readRead →
2024
Compliance
DORA: Operational Resilience Requirements for EU Financial Entities
DORA applies from January 17, 2025. Learn its five pillars, the oversight of critical ICT providers, which RTS and ITS are final, and a readiness checklist.
December 3, 2024 · 9 min readRead →
Security Posture
Secrets Management: Getting Credentials Out of Your Code
A practical guide to secrets management: move credentials into a vault, use short-lived secrets and OIDC federation, scan repos, rotate keys and handle leaks.
November 12, 2024 · 8 min readRead →
Compliance
CMMC 2.0 Final Rule: What Defense Contractors Need to Know
The CMMC 2.0 final rule takes effect December 16, 2024. Learn the three levels, assessment types, POA&M limits, annual affirmations and the phased rollout.
November 5, 2024 · 9 min readRead →
Vulnerability Management
An Emergency Patching Playbook for Zero-Days
A zero-day emergency patching playbook: triggers, triage, exposure lookup, interim mitigations, emergency change, compromise checks, validation and updates.
October 29, 2024 · 8 min readRead →
PCI DSS
The March 31, 2025 Deadline: A Checklist of PCI DSS 4.0 Future-Dated Requirements
A checklist of every PCI DSS 4.0 future-dated requirement due March 31, 2025, grouped by theme and split between all entities and service providers.
October 15, 2024 · 8 min readRead →
Compliance
Continuous Compliance: Moving Beyond the Annual Audit Scramble
Continuous compliance replaces the annual audit scramble with automated evidence collection, continuous control monitoring and policy-as-code. Here's how.
October 1, 2024 · 8 min readRead →
Security Posture
Passkeys for the Enterprise: Are You Ready to Go Passwordless?
Are passkeys ready for the enterprise? How FIDO2 works, synced vs. device-bound passkeys, attestation for admins, recovery, shared devices and a phased rollout.
September 24, 2024 · 9 min readRead →
Compliance
The EU AI Act: What Security Teams Need to Know
The EU AI Act entered into force on August 1, 2024. What security teams need to know: risk tiers, Article 15 cybersecurity, logging, deadlines and fines.
September 17, 2024 · 9 min readRead →
Vulnerability Management
Agent-Based vs. Agentless Scanning: Pros and Cons
Agent-based vs. agentless scanning compared: network scans, endpoint agents and cloud snapshot scanning, with pros, cons and why most programs use a mix.
August 27, 2024 · 8 min readRead →
PCI DSS
Automating Log Review to Meet Requirement 10.4.1.1
PCI DSS requirement 10.4.1.1 makes automated log review mandatory on March 31, 2025. Learn what it requires, which tools fit and what evidence to keep.
August 13, 2024 · 8 min readRead →
Security Posture
Third-Party Risk Management Without the Spreadsheet Nightmare
A practical guide to third-party risk management: tier vendors, right-size assessments, reuse SOC 2 and ISO 27001 evidence, and tighten contracts.
July 30, 2024 · 9 min readRead →
PCI DSS
What PCI DSS 4.0.1 Clarified (and What It Didn't)
PCI DSS 4.0.1 is a limited revision with no new requirements. What it clarified on patching, MFA and payment page scripts, and what stays exactly the same.
July 16, 2024 · 8 min readRead →
Vulnerability Management
Edge Devices Are the New Front Door: Patching VPNs and Firewalls
Why VPNs and firewalls are prime targets, and how to handle edge device patching: firmware discipline, config backups, off-box logging and end-of-life hardware.
June 18, 2024 · 9 min readRead →
Compliance
NIS2 Directive: Who's in Scope and What's Required
The NIS2 Directive covers medium and large firms in 18 sectors. Learn who is in scope, essential vs. important entities, Article 21 measures and fines.
June 4, 2024 · 8 min readRead →
PCI DSS
MFA for All Access Into the CDE: Requirement 8.4.2 Explained
PCI DSS requirement 8.4.2 extends MFA to all access into the CDE from March 31, 2025. How it fits with 8.4.1, 8.4.3 and 8.5.1, and ways to implement it.
May 21, 2024 · 7 min readRead →
Vulnerability Management
The NVD Backlog: What It Means for Your Vulnerability Program
The NVD backlog leaves many new CVEs without CVSS scores or CPE data. Here's how it affects scanners and prioritization, and how to keep your program working.
May 7, 2024 · 8 min readRead →
Compliance
CIRCIA: Upcoming Incident Reporting Rules for Critical Infrastructure
CISA's proposed CIRCIA rule would have critical infrastructure entities report substantial cyber incidents within 72 hours. Who's covered and what to expect.
April 30, 2024 · 8 min readRead →
Compliance
ISO 27001:2022 Transition: What Changed and the October 2025 Deadline
The ISO 27001:2022 transition deadline is October 31, 2025. See what changed in the clauses and Annex A, and how to plan a smooth move off the 2013 version.
April 23, 2024 · 8 min readRead →
Vulnerability Management
Vulnerability Management vs. Continuous Threat Exposure Management (CTEM)
Vulnerability management vs. CTEM explained: how Gartner's five-stage model differs from scan-and-patch, and how small teams can adopt it without a platform.
April 16, 2024 · 8 min readRead →
PCI DSS
Authenticated Internal Scanning: What Requirement 11.3.1.2 Means for You
PCI DSS requirement 11.3.1.2 makes authenticated internal scanning mandatory from March 31, 2025. What sufficient privileges, exceptions and scan accounts mean.
March 19, 2024 · 7 min readRead →
Compliance
NIST CSF 2.0: What the New 'Govern' Function Means for You
NIST CSF 2.0 adds a sixth function, Govern. Learn what the Govern function covers, why NIST added it, and how smaller teams can put it into practice.
March 12, 2024 · 9 min readRead →
Security Posture
Getting a Handle on SaaS Sprawl
How to get SaaS sprawl under control: discover apps from SSO, expense and OAuth data, add SSO and SCIM, set consent policies, fix offboarding and assign owners.
March 5, 2024 · 8 min readRead →
PCI DSS
PCI in the Cloud: Understanding Shared Responsibility
How PCI DSS shared responsibility works in the cloud: provider AOCs, responsibility matrices under 12.8.5 and 12.9.2, IaaS vs. SaaS, containers, segmentation.
February 20, 2024 · 9 min readRead →
Compliance
NYDFS Part 500 Amendments: Key Deadlines and Requirements
The NYDFS Part 500 amendments phase in new cybersecurity requirements through November 2025. Here are the key deadlines, Class A rules and what's due next.
February 13, 2024 · 9 min readRead →
Security Posture
Hardening Your Identity Provider Against Account Takeover
How to harden your identity provider against account takeover: strong admin MFA, conditional access, token lifetimes, fewer admin roles, logging, safe resets.
February 6, 2024 · 9 min readRead →
PCI DSS
Securing Payment Page Scripts: Requirements 6.4.3 and 11.6.1 Explained
PCI DSS 4.0 requirements 6.4.3 and 11.6.1 cover payment page scripts and tamper detection. Learn what each requires and how to prepare before March 2025.
January 23, 2024 · 9 min readRead →
Security Posture
Reporting Security Posture to the Board
How to report security posture to the board: frame it as business risk, track a few metrics over time, tie spend to risk reduction and fit it on one page.
January 16, 2024 · 8 min readRead →
Vulnerability Management
Compensating Controls When You Can't Patch
Compensating controls for systems you can't patch: segmentation, virtual patching, disabling services, access limits, monitoring and documented risk acceptance.
January 9, 2024 · 7 min readRead →
2023
Security Posture
Google and Yahoo's Bulk Sender Rules: Getting DMARC Right
Google and Yahoo's bulk sender rules start in February 2024. Here's what they require and a practical DMARC rollout plan from p=none to p=reject.
December 12, 2023 · 8 min readRead →
PCI DSS
PCI Compliance for Call Centers and Phone Payments
PCI compliance for call centers: how phone payments bring VoIP, call recordings and agent desktops into scope, and how pause-and-resume and DTMF masking differ.
December 5, 2023 · 8 min readRead →
Vulnerability Management
CVSS 4.0: What's New and Should You Switch?
CVSS 4.0 brings new metrics, drops Scope and replaces Temporal with Threat. Here's what changed from CVSS 3.1 and how to plan a sensible switch to version 4.0.
November 28, 2023 · 8 min readRead →
Compliance
FTC Safeguards Rule: New Breach Reporting for Non-Bank Financial Institutions
The amended FTC Safeguards Rule requires non-bank financial institutions to report breaches affecting 500 or more consumers within 30 days, from May 13, 2024.
November 21, 2023 · 8 min readRead →
PCI DSS
PCI DSS 3.2.1 Retires March 31, 2024: Are You Ready for the Switch?
PCI DSS 3.2.1 retires March 31, 2024. Learn what changes for your next assessment, what stays best practice until 2025, and how to prepare for v4.0.
November 14, 2023 · 8 min readRead →
Security Posture
Least Privilege and Just-in-Time Access in Practice
How to put least privilege and just-in-time access into practice: role design, access reviews, removing standing admin rights, cloud IAM and service accounts.
October 24, 2023 · 8 min readRead →
PCI DSS
Annual Scope Confirmation: Why Card Data Discovery Matters
PCI DSS 4.0 requirement 12.5.2 makes annual scope confirmation mandatory. Learn what it covers and how card data discovery finds PAN outside your expected CDE.
October 10, 2023 · 8 min readRead →
Vulnerability Management
Cloud Misconfigurations Are Vulnerabilities Too
Cloud misconfigurations are vulnerabilities too. See the common ones and how to manage them with owners, SLAs, CIS Benchmarks and policy-as-code guardrails.
October 3, 2023 · 8 min readRead →
Security Posture
Logging and Monitoring: Building Visibility You Can Actually Use
A practical guide to security logging and monitoring: what to log first, time sync, retention, high-value detections, alert tuning and keeping SIEM costs down.
September 26, 2023 · 9 min readRead →
Vulnerability Management
Using SBOMs to Find Vulnerable Components Faster
Learn how to use an SBOM to find vulnerable components faster: generate SBOMs, store them centrally, match them against vulnerability data and apply VEX.
September 12, 2023 · 9 min readRead →
PCI DSS
Building a PCI Responsibility Matrix With Your Service Providers
How to build a PCI responsibility matrix with your service providers, covering PCI DSS v4.0 requirements 12.8.1 to 12.8.5 and 12.9, owners and evidence.
August 22, 2023 · 8 min readRead →
Compliance
The SEC's Cyber Disclosure Rules: What Public Companies Must Report and When
The SEC cybersecurity disclosure rules require an 8-K within four business days of finding an incident material, plus new 10-K disclosures. Key dates inside.
August 15, 2023 · 9 min readRead →
Security Posture
Security Awareness Training That Actually Changes Behavior
Security awareness training that changes behavior: build a blame-free reporting culture, tailor content by role, use short formats and measure real habits.
August 8, 2023 · 9 min readRead →
Vulnerability Management
Setting Remediation SLAs That Teams Actually Meet
How to set vulnerability remediation SLAs your teams will meet: risk-based tiers, clear clock rules, exceptions that expire, escalation and useful reports.
July 18, 2023 · 9 min readRead →
Security Posture
API Security: Protecting the Connections Between Your Systems
An API security guide for IT teams: the OWASP API Security Top 10 2023, API inventory, object-level authorization, rate limiting, gateways, schemas and testing.
July 11, 2023 · 8 min readRead →
PCI DSS
How to Perform a Targeted Risk Analysis Under PCI DSS 4.0
A practical guide to the PCI DSS 4.0 targeted risk analysis: which requirements need one under 12.3.1, what it must contain, and how to do one step by step.
June 13, 2023 · 9 min readRead →
Vulnerability Management
Vulnerability Management Metrics That Matter
The vulnerability management metrics that show real progress: time to remediate by tier, SLA compliance, scan coverage, KEV fix time and risk trend.
June 6, 2023 · 8 min readRead →
Security Posture
Zero Trust in Practice: First Steps for Mid-Sized Companies
Practical zero trust first steps for mid-sized companies: MFA everywhere, device checks, per-app access, segmentation and logging, mapped to CISA's ZTMM v2.0.
May 23, 2023 · 8 min readRead →
Vulnerability Management
Using EPSS to Decide What to Patch First
EPSS estimates how likely a CVE is to be exploited in the next 30 days. Learn how to read EPSS scores and combine them with CVSS and KEV to prioritize patching.
May 9, 2023 · 7 min readRead →
Compliance
Control Mapping: Satisfying Multiple Frameworks With One Control Set
Control mapping lets one control set satisfy SOC 2, ISO 27001, PCI DSS and NIST CSF. How to build a common control framework, reuse evidence and avoid gaps.
May 2, 2023 · 9 min readRead →
Compliance
What Cyber Insurers Now Require Before They'll Write a Policy
The cyber insurance requirements underwriters now expect, from MFA and EDR to tested backups and patching, and how to answer applications accurately.
April 25, 2023 · 8 min readRead →
PCI DSS
The New PCI Password Rules: 12 Characters and Beyond
PCI DSS 4.0 password requirements raise the minimum to 12 characters by 2025. Here's what 8.3.6, 8.3.9, 8.3.7, 8.3.10.1 and 8.6 require and when.
April 11, 2023 · 8 min readRead →
Vulnerability Management
Managing Vulnerabilities in Container Images and Kubernetes
A practical guide to container vulnerability management: image scanning, base images, rebuilds, the CIS Kubernetes Benchmark and admission control.
March 28, 2023 · 8 min readRead →
PCI DSS
Protecting Stored Account Data: A Guide to PCI DSS Requirement 3
A practical guide to PCI DSS Requirement 3 in version 4.0: data retention, sensitive authentication data, PAN masking, encryption, hashing and key management.
March 14, 2023 · 9 min readRead →
Security Posture
Network Segmentation Beyond Compliance
Network segmentation beyond compliance: macro vs. microsegmentation, east-west controls, management networks and cloud VPC design, starting from mapped flows.
February 28, 2023 · 7 min readRead →
PCI DSS
Choosing the Right SAQ: A Plain-English Guide for Merchants
Choosing the right PCI SAQ comes down to how you take card payments. Compare the PCI DSS v4.0 SAQ types, their eligibility rules and common selection mistakes.
February 14, 2023 · 9 min readRead →
Vulnerability Management
Securing Your Open-Source Dependencies
How to secure open-source dependencies with SCA, lockfiles, update bots, OpenSSF Scorecard and SLSA, and how to handle malicious packages and license risk.
February 7, 2023 · 9 min readRead →
Security Posture
How to Run a Tabletop Exercise That Isn't a Waste of Time
How to run a tabletop exercise that finds real gaps: set objectives, pick participants, design scenarios and injects, facilitate well and follow up.
January 31, 2023 · 9 min readRead →
PCI DSS
Point-to-Point Encryption (P2PE): How It Cuts Your PCI Scope
How point-to-point encryption (P2PE) cuts PCI scope for card-present merchants: listed solutions, SAQ P2PE, the PIM, and handling and inspecting devices.
January 17, 2023 · 8 min readRead →
2022
Vulnerability Management
Building a Patch Tuesday Process That Scales
Build a Patch Tuesday process that scales: a monthly cadence, triage, test-pilot-broad rings, out-of-band updates, reboot windows and reporting that works.
December 13, 2022 · 9 min readRead →
Security Posture
EDR vs. MDR vs. XDR: Which Does Your Organization Need?
EDR vs. MDR vs. XDR: what each one does, how they compare, and how to choose based on staff, 24/7 coverage, existing tools, budget and response authority.
December 6, 2022 · 7 min readRead →
Security Posture
Attack Surface Management: Seeing Your Organization Like an Attacker
Attack surface management finds the domains, IPs, cloud assets and exposed services attackers see first. Here's how to discover, prioritize and own them.
November 29, 2022 · 9 min readRead →
Compliance
GDPR's 72-Hour Breach Notification Rule in Practice
How the GDPR 72-hour breach notification rule works in practice: when the clock starts, what to report, when to tell individuals, and a workable response plan.
November 15, 2022 · 9 min readRead →
PCI DSS
Tokenization vs. Encryption: Which Reduces PCI Scope More?
Tokenization vs. encryption for PCI scope: why encrypted PAN usually stays in scope, when token-only systems fall out, and where P2PE fits in the picture.
November 8, 2022 · 8 min readRead →
Vulnerability Management
Vulnerability Scanning vs. Penetration Testing: What's the Difference?
Vulnerability scanning vs. penetration testing: how they differ in purpose, depth, frequency and cost, when you need each, and how they work together.
October 25, 2022 · 8 min readRead →
PCI DSS
ROC, SAQ, and AOC: Making Sense of PCI Compliance Documents
ROC, SAQ and AOC explained: what each PCI compliance document is, who completes and signs it, how merchant levels apply, and where ASV scan reports fit.
October 18, 2022 · 7 min readRead →
PCI DSS
Scoping and Segmentation: How to Shrink Your Cardholder Data Environment
How PCI DSS scoping works, which systems fall into your cardholder data environment, and how network segmentation can shrink scope and assessment effort.
September 20, 2022 · 9 min readRead →
Vulnerability Management
Asset Inventory: You Can't Patch What You Don't Know About
Why asset inventory is the foundation of vulnerability management, what CIS Controls v8 Controls 1 and 2 require, and how to build and reconcile an inventory.
September 13, 2022 · 8 min readRead →
Security Posture
Cloud Security Posture Management (CSPM) Explained
Cloud security posture management (CSPM) continuously checks cloud configurations against benchmarks. Learn what it does, its limits, and how to roll it out.
September 6, 2022 · 8 min readRead →
Compliance
SOC 2 Type I vs. Type II: Which Do You Need?
SOC 2 Type I vs. Type II explained: what each report tests, how long it takes, when a Type I is enough, and how to pick the right report for your customers.
August 30, 2022 · 8 min readRead →
Security Posture
How to Run a Security Posture Assessment in 30 Days
A week-by-week plan to run a security posture assessment in 30 days: scope, inventory, framework control review, technical validation and a roadmap.
August 23, 2022 · 9 min readRead →
PCI DSS
ASV Scans Explained: How to Pass Your Quarterly External Scan
ASV scans explained: what PCI DSS requires for your quarterly external scan, what counts as a pass, and how to handle scope, disputes and false positives.
August 9, 2022 · 9 min readRead →
Security Posture
Privileged Access Management: Locking Down Your Most Powerful Accounts
Privileged access management explained: vaulting, session recording, admin tiering, separate admin accounts, PAWs, service and break-glass accounts, monitoring.
July 26, 2022 · 8 min readRead →
Vulnerability Management
Risk-Based Vulnerability Management: Why CVSS Alone Isn't Enough
Risk-based vulnerability management goes beyond CVSS scores. Learn how to combine CISA KEV, EPSS, asset criticality and exposure to decide what to fix first.
July 12, 2022 · 9 min readRead →
Compliance
Compliance Isn't Security: Why Passing an Audit Doesn't Mean You're Safe
Compliance vs. security: why passing a SOC 2, ISO 27001 or PCI DSS audit doesn't mean you're secure, and how to treat compliance as a floor, not a ceiling.
June 28, 2022 · 6 min readRead →
Vulnerability Management
How to Use CISA's Known Exploited Vulnerabilities (KEV) Catalog
A practical guide to CISA's Known Exploited Vulnerabilities (KEV) catalog: what BOD 22-01 requires, how entries are chosen, and how any organization can use it.
June 21, 2022 · 7 min readRead →
PCI DSS
Understanding the Customized Approach in PCI DSS 4.0
The customized approach in PCI DSS 4.0 lets you meet a requirement's objective with your own control. Here's how it works, what it demands and who it suits.
June 7, 2022 · 8 min readRead →
PCI DSS
PCI DSS 4.0 Is Here: What Changed From 3.2.1
PCI DSS 4.0 was published on March 31, 2022. Here's what changed from 3.2.1, which new requirements are future-dated, and how to plan your transition.
April 12, 2022 · 9 min readRead →
2020
Vulnerability Management
Who Owns the Fix? Defining Roles in Vulnerability Management
Define roles in vulnerability management with a simple RACI: who finds, fixes, verifies and accepts risk, plus escalation paths and handling ownerless assets.
December 15, 2020 · 9 min readRead →
Compliance
NIST SP 800-53 Rev. 5: What's New in the Control Catalog
NIST SP 800-53 Rev. 5 brings outcome-based controls, integrated privacy, a new supply chain family and separate baselines. See what changed and what to do next.
December 8, 2020 · 8 min readRead →
Compliance
CPRA Passed: What California's New Privacy Law Changes
California voters approved the CPRA (Prop 24). See what changes from the CCPA, the 2022 and 2023 dates, and the new security, audit and breach liability rules.
November 17, 2020 · 9 min readRead →
Vulnerability Management
Proving the Fix: Rescanning and Verifying Vulnerability Remediation
A closed ticket isn't proof. Learn how to verify vulnerability remediation with rescans, authenticated checks, clear closure criteria and honest reporting.
October 20, 2020 · 8 min readRead →
Compliance
The DFARS Interim Rule: SPRS Scores and the NIST 800-171 Assessment Methodology
The DFARS interim rule takes effect November 30, 2020. Learn how SPRS scores work, how to calculate your NIST 800-171 score and how the SSP and POA&M affect it.
October 13, 2020 · 9 min readRead →
Vulnerability Management
Building an Intake Process for Vendor Security Advisories
Build an intake process for vendor security advisories: pick sources, match them to your inventory, triage, assign owners and track every advisory to closure.
September 8, 2020 · 8 min readRead →
Compliance
PCI Compliance When Your Staff Work From Home
PCI compliance doesn't pause when staff work from home. See which PCI DSS 3.2.1 requirements apply to remote workers and how to keep card data off home devices.
August 18, 2020 · 9 min readRead →
Vulnerability Management
Third-Party Application Patching: The Gap in Most Patch Programs
Third-party application patching is where most patch programs fall short. Learn why browsers, readers and runtimes get missed and how to close the gap.
August 4, 2020 · 8 min readRead →
Compliance
Schrems II and the End of Privacy Shield: What Security Teams Should Do Now
Schrems II struck down the EU-US Privacy Shield. Learn what the ruling means for SCCs and the data transfer steps your security team should take right now.
July 28, 2020 · 8 min readRead →
Vulnerability Management
What CISA's 15- and 30-Day Remediation Deadlines Can Teach Private Companies
CISA's BOD 19-02 sets 15- and 30-day remediation deadlines for internet-facing systems. Here's what private companies can borrow from the federal model.
June 30, 2020 · 8 min readRead →
Compliance
HIPAA Security Risk Analysis: A Step-by-Step Guide
A step-by-step guide to the HIPAA security risk analysis: scope all ePHI, find threats and vulnerabilities, rate each risk, document it and act on the results.
June 23, 2020 · 7 min readRead →
Vulnerability Management
Managing Web Application Vulnerabilities Alongside Infrastructure Findings
Web application vulnerability management differs from patching servers. Learn how to handle DAST, SAST and SCA findings, route them to developers and retest.
May 26, 2020 · 8 min readRead →
Compliance
SOC 2 Readiness: How to Prepare for Your First Audit
SOC 2 readiness for your first audit: scope the system, pick Trust Services Criteria, run a gap assessment, gather evidence and plan the Type II window.
May 19, 2020 · 8 min readRead →
Vulnerability Management
SSVC: A Decision-Tree Approach to Vulnerability Prioritization
SSVC uses decision trees, not scores, for vulnerability prioritization. Learn its decision points and outcomes, how it compares with CVSS, and a worked example.
April 21, 2020 · 8 min readRead →
Vulnerability Management
Patching a Remote Workforce: Keeping Laptops Updated Off the Corporate Network
Patching a remote workforce: how to keep laptops updated off the corporate network with cloud update delivery, split tunneling, deadlines and reporting.
March 24, 2020 · 8 min readRead →
Compliance
NYDFS Part 500 Annual Certification: How to Prepare
How to prepare for your NYDFS Part 500 annual certification: who signs, what records to keep, and a checklist of controls to verify before February 15.
March 10, 2020 · 8 min readRead →
Compliance
CMMC 1.0 Is Here: What the New Model Means for Defense Contractors
CMMC 1.0 was released January 31, 2020. What defense contractors need to know: the five levels, third-party certification, FCI vs. CUI and how to prepare now.
February 18, 2020 · 8 min readRead →
Vulnerability Management
Building a Vulnerability Management Program From Scratch
Build a vulnerability management program from scratch: policy, asset inventory, scanning, prioritization, remediation and metrics, plus a 90-day plan.
February 4, 2020 · 9 min readRead →
Vulnerability Management
How to Read a CVSS v3.1 Score (and What It Doesn't Tell You)
Learn how to read a CVSS v3.1 score and its vector string metric by metric, what changed from v3.0, and what the number can't tell you about your risk.
January 21, 2020 · 9 min readRead →
Compliance
CCPA Is Now in Effect: What Security Teams Need to Do
The CCPA took effect January 1, 2020. What security teams must do now: map personal data, verify consumer requests and meet the law's reasonable security duty.
January 14, 2020 · 9 min readRead →