• retiredIdentity@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    2 days ago

    The company i work for has to go through annual PCI Compliance testing to make sure CC transactions are not leaking card information and storage is encrypted if we stored (we don’t) thus information. Even our network is scrutinized closely. We are also required to have bi-annual table top exrcises and they are talking about pentestung. What kind of Compliance do any of these companies have.

    • IphtashuFitz@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 days ago

      Same here. We also contract with HackerOne, a company of “white hat” hackers that actively attack our site and earn significant bounties if they can do something like remotely execute commands, exfiltrate data, etc. Only after they provide us with a repeatable set of steps and we close the hole do they get paid.

    • Taleya@aussie.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      2 days ago

      They don’t. The only private companies who have to monkey dance like that are cinema content handlers who want TPN status

      Must protect the IP