
AI Didn't Change the Rules, It Raised the Stakes (ep.13)
You can pass your PCI assessment and still be leaking cardholder data. In e-commerce, compliant and secure are not the same thing — and AI just made the gap between them a lot harder to ignore. In t...
4 Aug 38min

Your PCI Scope is Too Big (and how to fix it) Ep.12
How much of your business actually needs to be PCI compliant? Almost always less than you think. Every system inside your PCI scope is something you have to secure, document, and prove — year after ye...
21 Juli 21min

You're Probably Behind on CMMC. Here’s What To Do Next. (ep 11)
About 100 authorized assessors. An estimated 118,000+ companies that need to be assessed. That math is the reason CMMC can't wait — and it's where this conversation starts. Brett Cox, lead CMMC Certif...
7 Juli 17min

Which PCI SAQ Do You Actually Need? (ep. 10)
First time filling out a PCI SAQ? In this episode, two QSAs who've scoped hundreds of payment environments walk you through how to pick the right one—so you don't end up with the wrong form, the wrong...
23 Juni 34min

Passkeys: An Upgrade You Didn't Know You Needed (ep. 9)
Passwords were built for a different era of the internet. It’s time to move past shared secrets to close your organization's largest threat vector for good. Traditional passwords and legacy Multi-Fact...
9 Juni 28min

The Expert Guide to Defeating eSkimmers (ep. 8)
We can't keep turning a blind eye to e-commerce skimming. It's a real threat that demands real attention—regardless of how compliance checklists evolve. Eighteen months ago, our panel met to break dow...
26 Maj 29min

Cybersecurity Priorities for 2026: The Two Vulnerabilities to Focus on in the AI Era (ep. 7)
Is your organization prepared for an autonomous AI bot? Roger Grimes joins Jen Stone to discuss the shifting landscape of cybersecurity. This episode moves past the hype to look at the hard data: AI s...
12 Maj 10min

The SAQ A Deep Dive: Two QSAs Set the Record Straight (ep. 6)
This episode of Practical Cybersecurity moves past the standard PCI checklist to focus on the operational realities, common misconceptions, and "stealth" requirements that define SAQ A in the PCI DSS ...
28 Apr 20min




















