Gareth Bowker

Explore articles by Gareth

Data Governance & Privacy

What Your Data Privacy Program Can’t See (But Should)

Privacy compliance has come a long way. Most organizations today have data maps, consent management platforms, vendor assessments, and governance frameworks in place, which is genuinely good progress. But there’s…

Read more
Compliance Enforcement

Navigating the New 2026 CCPA Rules: Turning Intent Into Demonstrable Compliance

The California Privacy Protection Agency (CPPA) recently issued updates to the California Consumer Privacy Act (CCPA) regulations, which became effective on January 1, 2026, bringing the era of “compliance by…

Read more
Compliance Enforcement

One Year of 6.4.3 and 11.6.1: A QSA’s Guide to Vendor Approaches

It’s been a year since PCI DSS requirements 6.4.3 and 11.6.1 became mandatory. By now, most QSAs are well acquainted with what these requirements entail. The challenge isn’t understanding the…

Read more
Security Research

Payment Iframes Now Proven Susceptible to Silent Skimming

Attackers are constantly finding new ways to evade defenders’ protections. Whether it’s through obfuscating their code, compromising plugins, poisoning content delivery networks (CDNs), or through supply chain compromises, these attacks…

Read more
Compliance Enforcement

SAQ A’s New Eligibility Criteria: More on What It Means

Since my last blog post, I’ve spoken to many of Jscrambler’s customers, potential customers, ISAs, and QSAs about what the changes to SAQ A mean to them. I’ve been following…

Read more
Compliance Enforcement

The Assessor’s Guide to Understanding SAQ A Changes

Unless entities have measures in place to protect their site, not just their payment pages, it is unlikely that they will be able to use SAQ A from 31 March…

Read more