Privacy compliance has come a long way. Most organizations today have data maps, consent management platforms, vendor assessments, and governance frameworks in place, which is genuinely good progress. But there’s…
The California Privacy Protection Agency (CPPA) recently issued updates to the California Consumer Privacy Act (CCPA) regulations, which became effective on January 1, 2026, bringing the era of “compliance by…
It’s been a year since PCI DSS requirements 6.4.3 and 11.6.1 became mandatory. By now, most QSAs are well acquainted with what these requirements entail. The challenge isn’t understanding the…
Attackers are constantly finding new ways to evade defenders’ protections. Whether it’s through obfuscating their code, compromising plugins, poisoning content delivery networks (CDNs), or through supply chain compromises, these attacks…
Since my last blog post, I’ve spoken to many of Jscrambler’s customers, potential customers, ISAs, and QSAs about what the changes to SAQ A mean to them. I’ve been following…
Unless entities have measures in place to protect their site, not just their payment pages, it is unlikely that they will be able to use SAQ A from 31 March…