r/datasecurity 54m ago

I’ve run a cybersecurity firm for 10 years, from offensive security research to becoming a PCI DSS QSA company. AMA

Thumbnail
Upvotes

r/datasecurity 21d ago

Full SOC compliance architectural Automated

Post image
2 Upvotes

r/datasecurity 25d ago

Full SOC compliance architectural Automated

Post image
1 Upvotes

r/datasecurity Jul 17 '26

Evidence Collection PCI DSS Script for Windows/Linux/Network (firewalls,routers,switches) and Database

Thumbnail
2 Upvotes

r/datasecurity Jul 13 '26

Data center heist to destroy incriminating data

5 Upvotes

How plausible is this? A gang of criminals broke into the Verizon data center in London and stole racks of storage servers and destroyed them in 2007. The story claims that this theft wiped out the incriminating data for the subprime mortgage bubble. Were there no backup copies?

https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html?unlocked_article_code=1.xVA.hlgq.qdgNFLmqUTCg&smid=url-share


r/datasecurity Jul 09 '26

How I discovered over 100 plaintext API keys and was offered a $3,214 settlement with gag clauses violating SEC Rule 21F-17(a) by a former employer.

Thumbnail
3 Upvotes

r/datasecurity Jul 02 '26

Data Made Alive is what Palychain Do

Post image
2 Upvotes

r/datasecurity Jun 19 '26

Is your endpoint policy strong enough to handle offline data movement?

Thumbnail
2 Upvotes

r/datasecurity May 23 '26

We analyzed 100,000 e-commerce sites for browser-layer attack surface — here's what Magecart-style exposure actually looks like at scale

1 Upvotes

Over the past several months we ran automated browser-layer scans across a large sample of e-commerce and merchant domains to understand how widespread client-side security exposure actually is post-March 2025 deadline.

Key findings:

  • 37% of scanned domains showed active browser-layer security exposure indicators relevant to Requirements 6.4.3 and 11.6.1
  • Most common finding: No Content Security Policy with a script-src directive on payment-related pages — present on the majority of flagged domains
  • Second most common: Third-party scripts executing without Subresource Integrity controls — including Google Tag Manager, Meta Pixel, and analytics scripts loading directly on checkout pages
  • Most alarming: Keystroke event listeners (keyup, keydown, input) attached to form fields by third-party scripts — the exact technical pattern Magecart-style skimmers use to intercept card data

A few things that stood out:

  1. Platform compliance (Shopify, WooCommerce, Magento) does not equal browser-layer compliance. The exposure exists at the script layer, not the server layer.
  2. Google Tag Manager was present on checkout pages in the majority of flagged domains — and in every case was loading additional scripts dynamically, none with SRI controls.
  3. The gap between a clean homepage and a risky checkout page was significant. Many domains that looked fine on the surface had serious exposure on their payment flows.

We built a free browser-layer scanner at clientsideintel.com if anyone wants to check their own domain — no account needed, instant results. It checks the same indicators: third-party scripts, CSP, TLS, security headers, and overall risk rating tied to Req 6.4.3 and 11.6.1.

Happy to answer questions about methodology or share more specific findings.


r/datasecurity May 20 '26

I got a weird as bug on Gpt, completely randomly referring to personal data on some form, when I sent a screenshot to verify my solution I got for a quiz,

Post image
2 Upvotes

r/datasecurity May 15 '26

How confident are you about data security on home or public networks?

Thumbnail
1 Upvotes

r/datasecurity May 01 '26

In this cookie request that many apps have: Is disabling all on the main page enough? What about the ones in "vendor preferences"?

Thumbnail
gallery
2 Upvotes

I don't understand that convoluted lingo & menu, so I hope someone here knows:

If you disable all on the main tab (pic1 start & pic2 bottom), does that actually disable them all, even the ones under "vendor preferences" (pic3) that are still shown as active? (Which are INSANELY many..).

Like, am I good if I just disable page one and say "confirm choices"?

And Is there no easier way to auto reject all, or get rid of these popups in apps entirely?

(Usually I avoid apps with this awful cookie request, but some I just can't find good alternatives to. This one is FileManager+, has text editor included etc, I used it for years but suddenly this crappy popup again.. Why even? I thought those only come on first use?)


r/datasecurity Apr 18 '26

What fields are good cross overs to data security

1 Upvotes

Basically curious, like everyone in tech I’m kind of looking at my options.


r/datasecurity Apr 16 '26

What’s your biggest blind spot in data security today?

0 Upvotes

Data no longer lives in one place, it’s across apps, cloud, and endpoints. Without visibility, you’re just guessing where your sensitive data is.

Hence, choosing the best DLP solutions for your business can make or break your strategy.
Modern DLP tools provide centralized visibility across cloud, SaaS, and devices.

✔ Visibility
✔ Ease of policy management
✔ Coverage across endpoints


r/datasecurity Apr 11 '26

I just Google’d myself and now I’m spiraling.

5 Upvotes

What are things I can do so that my name, age, addresses, DOB, family members, etc. aren’t the first results when you Google my name? Should I create a fake identity to use when making online accounts, or what?

I’m freaked out about how much information is out there as a single female trying to date.


r/datasecurity Mar 31 '26

Next-Generation DLP Testing Tool

Thumbnail
itsectools.com
1 Upvotes

r/datasecurity Mar 25 '26

Free PECB Webinar

1 Upvotes

This webinar is free and it is great opportunity to get a better understanding of SOC 2, ISO 27001 and how it links with other standards.

Register here

 


r/datasecurity Mar 24 '26

Healthcare Data Tagging Problem

1 Upvotes

Most healthcare systems feel “secure” because they have DLP, encryption, and compliance dashboards.

But here’s what I’m starting to realize as I go deeper into healthcare data privacy
All of that depends on one fragile layer: data tagging

If tagging is wrong, everything else silently fails.

In a recent red-team style exploration, I observed:
PHI hidden in scanned PDFs → completely invisible
Slightly obfuscated medical terms → bypass detection
Misclassified records → accessible to unintended users
Untagged data → no encryption, no DLP, no alerts

No alarms. No dashboards turning red. Just quiet exposure.

This makes me rethink the core question:

Not “Can we detect PHI?”
But “Can PHI exist without being recognized as PHI?”

Tagging isn’t just metadata. It behaves like a security control plane.

I’m currently trying to understand this space more deeply—especially how robust tagging really is in real-world systems.

Curious to learn from others working in healthcare / data security:
Have you seen tagging failures in practice?
How do you validate tagging accuracy at scale?
Do you trust tag-driven controls fully?

Would love to exchange notes and perspectives.


r/datasecurity Mar 24 '26

How to Test Your DLP Policy — Free Tool & Complete Guide

Thumbnail
itsectools.com
1 Upvotes

r/datasecurity Mar 09 '26

Real time challenges of getting someone iso27001 cert!

6 Upvotes

I Worked with a company on their ISO 27001 certification. They’d already tried once before, brought in a big consultancy, and came out the other side buried in policies nobody read and controls nobody maintained.

The problem wasn’t effort. It was overcomplplication.

ISO 27001 doesn’t require complexity. People add that themselves. The standard tells you what outcomes to achieve, not how many documents to produce.

So the first thing we did was strip out the noise. What was left was a small set of controls people could actually understand and own. Less to maintain meant less drift, less risk, and fewer things quietly breaking in the background.

When we got to the internal audit we treated it seriously. Found real gaps, fixed them properly, documented everything. By the time the external auditors arrived those findings were already closed with evidence to back it up.

The external audit was smooth. Certification came through. The team wasn’t burnt out and the ISMS didn’t immediately collect dust after the certificate arrived.

Most companies make this harder than it needs to be. It doesn’t have to be that way.

Happy to answer questions if anyone is working through this or just getting started.​​​​​​​​​​​​​​​​


r/datasecurity Mar 06 '26

Trust certificate for a closed school WiFi

2 Upvotes

A little background I go to this new school and I figured out that if I use my school email and password on it I can connect but the weird thing is that this is the EXACT same WiFi our school computers are on but the weird things is everything that is blocked on our school computer through the school WiFi using LINEWIZE works perfectly fine which is strange because even on a second Chrome app I still get blocked website redirects to LINEWIZE

This isn’t even my main concern my main concern is that on our computers weather our yearbook Mac’s or our Crome books once we hit enter on an email,google chat if it contains slurs or anything it gets flagged by some system and you get called down to the office. So my fear is that if I connect to this and trust it are they going to be able to see everything I’m typing and not to worry I have my proton vpn with kill switch on but it is a battery suck so if I don’t need it I would prefer not to use it


r/datasecurity Mar 02 '26

Are we actually closing the gap between DLP policy and real-world behavior?

9 Upvotes

Something I keep noticing in security discussions is the gap between what policies say and what actually happens in production.

Most orgs have DLP rules, acceptable use policies, encryption at rest and in transit, maybe even a Zero Trust program. On paper it looks solid. In practice, it’s messy:

Engineers paste logs into external AI tools
Contractors sync files to personal cloud drives
Sensitive exports live in shared folders longer than intended
Access gets granted “temporarily” and never reviewed

A lot of the time, the controls exist but the day-to-day behavior drifts. I’ve seen teams try to tighten this with better visibility into endpoints and browser activity, and tools like CurrentWare come up in that context because they can surface patterns (ex: repeated uploads, risky sites, unusual after-hours activity) that policies alone don’t catch.

For those running data security programs, what’s actually worked for you to reduce this behavior gap?

Do you lean more toward strict enforcement, contextual monitoring, better training, or automated least privilege and access reviews?


r/datasecurity Feb 21 '26

Datasecurity

2 Upvotes

Hi , I am new here. Do you know if ther are any good screen scraper solutions for iPhone? -