


Table of Contents
Share with network
Related Insights
Management asked Elliott Davis to help answer, "How can we ensure that we have a secure environment and are meeting PCI compliance?"
Context
Our Approach
•Completed gap analysis on cardholder data environment annually
Report formal findings
Determine steps to remediation
Assist team in remediation efforts
•Performed quarterly external ASV scanning for compliance Requirement 11.2
•Completed internal and external vulnerability scans quarterly
Customer Impact
For more information on this and other topics, contact a member of our team.
The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.


Credential overlap, often mistaken for credential stuffing, is a major cybersecurity risk caused by password reuse across multiple accounts. This article explores how attackers exploit this weakness, insights from Elliott Davis penetration tests, and practical strategies to strengthen security and prevent unauthorized access.


The SEC’s new cybersecurity disclosure rules now require public companies to report material cybersecurity incidents within four business days and provide detailed risk management disclosures in annual reports. Organizations must assess the materiality of cyber threats, outline board oversight, and describe management’s role in mitigating risks to ensure transparency for investors.


Cyber threats are constantly evolving, and one often-overlooked vulnerability is clear text password storage. This article explores the risks of storing passwords in plain text, how attackers exploit this weakness, and practical solutions—including password managers, user awareness, and professional cybersecurity assistance—to strengthen your security posture.