SEptember 2025: Getting you PCI DSS Scope Right

Defining PCI DSS scope correctly is one of the most critical — and often misunderstood — parts of compliance. In this concise guide, Fiona Howard, PCI DSS Qualified Security Assessor (QSA) and cybersecurity specialist at Locked Stack, shares practical insights to help organisations document and maintain their PCI environment effectively. Drawing from real-world assessments, Fiona explains how to identify what’s in scope, manage boundaries, and simplify ongoing reviews. Whether you’re preparing for your first PCI DSS v4.0.1 assessment or refining existing documentation, this guide provides clear, actionable steps to streamline compliance and strengthen your organisation’s security posture.

October 2025: The HUMAN ELEMENT IN CYBERSECURITY

Fiona is a former educator turned cybersecurity specialist and PCI DSS Qualified Security Assessor (QSA) at Locked Stack. She focuses on aligning human-centric security strategies with regulatory frameworks like PCI DSS. During assessments, security awareness training is often a recurring topic—and one of the most challenging areas for organisations to get right.