Our PCI consulting services support your company from the initial scoping steps through compliance.
PCI 4.0 Consulting: We provide expert guidance on navigating the new requirements and changes introduced in PCI DSS 4.0. Our consultants help you understand and implement these updates to ensure continued compliance and security.
PCI DSS Compliance Assessments: A PCI compliance assessment provides a wider review of your security controls against applicable PCI DSS requirements. Tanner Security evaluates areas such as access control, authentication, vulnerability management, network security, security policies, logging, monitoring, incident response, and security testing. The goal goes beyond simply answering “yes” or “no.” We want your leadership team to understand where risks exist, why the controls matter, and what your company should do next.
PCI Policy Consulting: PCI DSS requires more than technical controls. Your company also needs policies and procedures that support the security of payment card data. Tanner Security can review and develop policies covering information security, acceptable use, access management, vulnerability management, incident response, third-party risk, security awareness, data retention, and other areas relevant to your PCI program. We focus on practical policies your employees can use, not just generic documents that get ignored.
PCI CDE Penetration Testing: Penetration testing goes beyond identifying possible vulnerabilities. It attempts to determine whether an attacker can exploit weaknesses and what access that attacker could obtain. Tanner Security performs PCI CDE penetration testing to evaluate the security of systems and networks that support payment card processing. Our testing can include vulnerability identification, manual validation, exploitation, privilege escalation, lateral movement, and other techniques that fit the approved scope.
Network Vulnerability Assessment: Identify known vulnerabilities across systems, network infrastructure, and other technologies that support your payment environment.
Network Penetration Testing: Evaluate internal and external attack paths to determine whether attackers can exploit weaknesses and move through your environment.
Web Application Penetration Testing: Evaluate web applications and APIs for vulnerabilities involving authentication, authorization, session management, input validation, business logic, and other application-security risks.