RSS Amplifier

Podcast

Practical Cybersecurity with Jen Stone

Practical Cybersecurity , hosted by Jen Stone (MCIS, CISSP, CISA, QSA), is the bridge between complex security frameworks and real-world business implementation. Whether you are a "Jack of all trades" IT manager or a business leader with limited resources, this show provides the roadmap to a defensible security posture.

buzzsprout.comSource feed ↗10 episodes

Live Last read · last published · next check

Latest episodes

Saves to your Listen queue, to pick up on another day or another device.

AI Didn't Change the Rules, It Raised the Stakes (ep.13)

You can pass your PCI assessment and still be leaking cardholder data. In e-commerce, compliant and secure are not the same thing — and AI just made the gap between them a lot harder to ignore. In this episode, SecurityMetrics Principal Security Analyst Jen Stone is joined by forensic investigator Aaron Willis and [HOST NAME] for a practitioner panel on how AI is reshaping attacks on cardholder…

Play

Your PCI Scope is Too Big (and how to fix it) Ep.12

How much of your business actually needs to be PCI compliant? Almost always less than you think. Every system inside your PCI scope is something you have to secure, document, and prove — year after year. So the fastest way to cut the cost and effort of compliance isn't working harder on controls. It's making your scope smaller. In this episode, Principal Security Analysts Jen Stone and Michael…

Play

You're Probably Behind on CMMC. Here’s What To Do Next. (ep 11)

About 100 authorized assessors. An estimated 118,000+ companies that need to be assessed. That math is the reason CMMC can't wait — and it's where this conversation starts. Brett Cox, lead CMMC Certified Assessor and head of Boeing's DFARS CMMC Program Management Office, joins host Jen Stone to explain what the Cybersecurity Maturity Model Certification actually requires, why the November 2026…

Play

Which PCI SAQ Do You Actually Need? (ep. 10)

First time filling out a PCI SAQ? In this episode, two QSAs who've scoped hundreds of payment environments walk you through how to pick the right one—so you don't end up with the wrong form, the wrong security controls, and the wrong amount of risk. Choosing the right PCI DSS Self-Assessment Questionnaire (SAQ) isn't just a paperwork decision. Pick the wrong form and you can leave blind spots in…

Play

Passkeys: An Upgrade You Didn't Know You Needed (ep. 9)

Passwords were built for a different era of the internet. It’s time to move past shared secrets to close your organization's largest threat vector for good. Traditional passwords and legacy Multi-Factor Authentication (MFA) are no longer enough to protect your business. Automated, scaling phishing toolkits easily intercept shared secrets, leaving small and medium businesses highly vulnerable to…

Play

The Expert Guide to Defeating eSkimmers (ep. 8)

We can't keep turning a blind eye to e-commerce skimming. It's a real threat that demands real attention—regardless of how compliance checklists evolve. Eighteen months ago, our panel met to break down the rollout of PCI DSS requirements 6.4.3 and 11.6.1. Now, one year after PCI v4.0, we're looking at the data-backed reality of how these requirements are actually playing out in the field. With the…

Play

Cybersecurity Priorities for 2026: The Two Vulnerabilities to Focus on in the AI Era (ep. 7)

Is your organization prepared for an autonomous AI bot? Roger Grimes joins Jen Stone to discuss the shifting landscape of cybersecurity. This episode moves past the hype to look at the hard data: AI scams are yielding 4.5x more value for attackers, and traditional MFA is no longer enough to stop them. In this episode, we translate complex "vulnerability fatigue" into a clear, two-step priority…

Play

The SAQ A Deep Dive: Two QSAs Set the Record Straight (ep. 6)

This episode of Practical Cybersecurity moves past the standard PCI checklist to focus on the operational realities, common misconceptions, and "stealth" requirements that define SAQ A in the PCI DSS v4.0.1 era. The Eligibility Foundation Most merchants skip the Eligibility Criteria , which is the actual foundation of the assessment. Total Data Outsourcing: To qualify, a merchant must not store,…

Play

Protecting the House: Why Asset Management and "Storytelling" are Keys to HITRUST (ep.5)

Episode Summary In this episode of Practical Cybersecurity , we dive into the complex world of HITRUST certification. Often called the "gold standard" for healthcare security, HITRUST can be a daunting mountain to climb for small and large organizations alike. Jen Stone and experts Peter Briel (Privaxi) and Lee Pierce (SecurityMetrics) break down why scoping is your best friend, why screenshots…

Play

4 Critical Tasks for Small IT Teams (ep.4)

A single data breach now costs a business an average of $1.4 million, according to the annual IBM report. For a small or medium-sized business (SMB), this hit is often terminal—most companies that suffer a major breach struggle to stay in business longer than six months. In this episode, Matt "Heff" Heffelfinger , Director of SOC Operations at SecurityMetrics, joins us to discuss why many business…

Play