AI Didn't Change the Rules, It Raised the Stakes (ep. 13)
SecurityMetrics, Inc.
0:00 / 0:00
AI Didn't Change the Rules, It Raised the Stakes (ep. 13)
109 просмотров · 2 месяца назад
SecurityMetrics, Inc.
5,41 тыс. подписчиков
109 просмотров · 2 месяца назад
You can pass your PCI assessment and still be leaking cardholder data. In e-commerce, "compliant" and "secure" are not the same thing — and AI just made the gap between them a lot harder to ignore.
In this episode of Practical Cybersecurity, SecurityMetrics Principal Security Analyst Jen Stone sits down with forensic investigator Aaron Willis and host Hef (SOC & threat hunting lead) for a real-world panel on what AI is actually doing to PCI compliance. No hypotheticals — just what auditors and forensic investigators are seeing in the field right now under PCI DSS 4.0.1.
What you'll learn:
Why passing PCI (especially SAQ-A) doesn't mean your checkout is safe
Why PCI DSS 4.0.1 already governs AI — even though it never uses the word
How e-commerce skimmers hide in third-party scripts, browser local storage, and the checkout page
A real case study: the skimmer that defeated a premier agent-based detection tool
What requirements 6.4.3, 11.6.1, and SAQ-A FAQ 1588 actually require (and where merchants get it wrong)
Why payment redirects create a false sense of security — and why attacks against them are up 300%
What counts as a "payment page script" (analytics, marketing pixels, tag managers, and more)
How AI changes your targeted risk analysis, MFA, and third-party (12.8) obligations
The three-tier framework for treating compliance as real security
Chapters:
0:00 — Welcome back: why we're running the AI panel
0:29 — Meet the panel + AI as a force multiplier
1:08 — 2026 forensic & cyber predictions: how they held up
1:53 — Agentic AI bots and credential attacks
2:46 — The vulnerability firehose: zero-days and mass CVEs
3:42 — Inside 2,000+ e-commerce forensic cases
4:54 — Shopping Cart Monitor: one skimmer a week, hiding in the browser
6:35 — What Specter AI actually does
8:06 — Case study: the skimmer that beat a premier detection agent
10:19 — How the threat landscape changed: real-time & agentless
11:52 — PCI DSS 4.0.1 & AI: it doesn't say "AI" — and doesn't have to
14:05 — Script security decoded: 6.4.3, 11.6.1 & FAQ 1588
17:30 — The payment-redirect trap (up 300%)
19:56 — AI-impacted requirements: risk analysis, MFA, 12.6.3, 12.8
24:18 — Compliance isn't security: the three-tier framework
26:28 — Script inventory: 3,400 scripts on one checkout page
27:35 — Q&A: SAQ-A and the "legally required" myth
29:14 — Q&A: iframes and the script protection rule
30:09 — Q&A: do agent-based tools satisfy 6.4.3 / 11.6.1?
30:58 — Q&A: what counts as a payment page script
31:50 — Q&A: notification obligations under 11.6.1
33:35 — Q&A: does an AI chatbot trigger a risk assessment?
34:13 — Q&A: evidence assessors want on AI training
35:45 — Q&A: public vs. private AI tools
37:51 — Final tip: AI didn't change the rules, it raised the stakes
Resources:
Forensic Predictions webinar: • Zero Trust is Failing and other 2026 Cyber...
Shopping Cart Monitor: https://www.securitymetrics.com/shopp...
Spectre AI: https://securitymetrics.wistia.com/me...
PCI DSS 4.0.1 script security (6.4.3 / 11.6.1 / FAQ 1588): https://blog.pcisecuritystandards.org...
More episodes: • Practical Cybersecurity with Jen Stone
About SecurityMetrics:
SecurityMetrics helps organizations secure payment data and meet PCI DSS. We're a certified PCI Qualified Security Assessor (QSA), Approved Scanning Vendor (ASV), PCI Forensic Investigator (PFI), and P2PE Assessor.
#PCIDSS #Cybersecurity #Compliance #Ecommerce #AISecurity #PCIDSS401