Перейти к содержимому

AI Didn't Change the Rules, It Raised the Stakes (ep. 13)

SecurityMetrics, Inc.

0:00 / 0:00

AI Didn't Change the Rules, It Raised the Stakes (ep. 13)

109 просмотров · 2 месяца назад
SecurityMetrics, Inc.
5,41 тыс. подписчиков
109 просмотров · 2 месяца назад
You can pass your PCI assessment and still be leaking cardholder data. In e-commerce, "compliant" and "secure" are not the same thing — and AI just made the gap between them a lot harder to ignore. In this episode of Practical Cybersecurity, SecurityMetrics Principal Security Analyst Jen Stone sits down with forensic investigator Aaron Willis and host Hef (SOC & threat hunting lead) for a real-world panel on what AI is actually doing to PCI compliance. No hypotheticals — just what auditors and forensic investigators are seeing in the field right now under PCI DSS 4.0.1. What you'll learn: Why passing PCI (especially SAQ-A) doesn't mean your checkout is safe Why PCI DSS 4.0.1 already governs AI — even though it never uses the word How e-commerce skimmers hide in third-party scripts, browser local storage, and the checkout page A real case study: the skimmer that defeated a premier agent-based detection tool What requirements 6.4.3, 11.6.1, and SAQ-A FAQ 1588 actually require (and where merchants get it wrong) Why payment redirects create a false sense of security — and why attacks against them are up 300% What counts as a "payment page script" (analytics, marketing pixels, tag managers, and more) How AI changes your targeted risk analysis, MFA, and third-party (12.8) obligations The three-tier framework for treating compliance as real security Chapters: 0:00 — Welcome back: why we're running the AI panel 0:29 — Meet the panel + AI as a force multiplier 1:08 — 2026 forensic & cyber predictions: how they held up 1:53 — Agentic AI bots and credential attacks 2:46 — The vulnerability firehose: zero-days and mass CVEs 3:42 — Inside 2,000+ e-commerce forensic cases 4:54 — Shopping Cart Monitor: one skimmer a week, hiding in the browser 6:35 — What Specter AI actually does 8:06 — Case study: the skimmer that beat a premier detection agent 10:19 — How the threat landscape changed: real-time & agentless 11:52 — PCI DSS 4.0.1 & AI: it doesn't say "AI" — and doesn't have to 14:05 — Script security decoded: 6.4.3, 11.6.1 & FAQ 1588 17:30 — The payment-redirect trap (up 300%) 19:56 — AI-impacted requirements: risk analysis, MFA, 12.6.3, 12.8 24:18 — Compliance isn't security: the three-tier framework 26:28 — Script inventory: 3,400 scripts on one checkout page 27:35 — Q&A: SAQ-A and the "legally required" myth 29:14 — Q&A: iframes and the script protection rule 30:09 — Q&A: do agent-based tools satisfy 6.4.3 / 11.6.1? 30:58 — Q&A: what counts as a payment page script 31:50 — Q&A: notification obligations under 11.6.1 33:35 — Q&A: does an AI chatbot trigger a risk assessment? 34:13 — Q&A: evidence assessors want on AI training 35:45 — Q&A: public vs. private AI tools 37:51 — Final tip: AI didn't change the rules, it raised the stakes Resources: Forensic Predictions webinar:    • Zero Trust is Failing and other 2026 Cyber...   Shopping Cart Monitor: https://www.securitymetrics.com/shopp... Spectre AI: https://securitymetrics.wistia.com/me... PCI DSS 4.0.1 script security (6.4.3 / 11.6.1 / FAQ 1588): https://blog.pcisecuritystandards.org... More episodes:    • Practical Cybersecurity with Jen Stone   About SecurityMetrics: SecurityMetrics helps organizations secure payment data and meet PCI DSS. We're a certified PCI Qualified Security Assessor (QSA), Approved Scanning Vendor (ASV), PCI Forensic Investigator (PFI), and P2PE Assessor. #PCIDSS #Cybersecurity #Compliance #Ecommerce #AISecurity #PCIDSS401