
Episode #14
How to Pass your PCI Assessment in 2027: Targeted Risk Analysis, MFA, and the E-Commerce Gap: (ep. 14)
PCI DSS 4.0.1 has been the standard for a while now, but a lot of organizations are still stuck on the same handful of requirements. In this episode, Jen Stone sits down with Matt Halbleib, Director of Assessments at SecurityMetrics, to break down where SMBs keep getting tripped up — and how to fix it. Key topics covered: Why you need to read the actual standard (not just the summary of changes) — and why the PDF version matters Getting senior management buy-in and putting a real project manager behind your PCI program Scoping: what's actually in scope, and why it's worth revisiting What replaced the old org-wide risk assessment, and how to build one Why MFA got bigger in 4.0.1, and where it now applies New service provider requirements, including the responsibility matrix Logging and alerting: what's changed, and where AI actually helps Password requirements, including the jump to 12 characters, and why a password manager beats a memorized passphrase Compensating controls: what they're for, and why they should never be permanent Matt’s honest take on the customized approach E-commerce and payment page security (Req. 6.4.3 / 11.6.1) Matt Halbleib has worked in information security for nearly 19 years, almost all of it at SecurityMetrics, where he now leads the assessments team. A note from Jen: We built Practical Cybersecurity because we were tired of the fear-mongering in this industry. Security shouldn't be a secret club. Whether you're trying to figure out PCI compliance or need a pen test, my team at SecurityMetrics can help you out: https://www.securitymetrics.com/contact/lets-get-you-to-the-right-place But if you just want to learn how to protect yourself for free, start here: https://academy.securitymetrics.com/

