
5 Steps to Securing Web Applications from Third-Party Script Risks
by Source Defense Modern websites depend on JavaScript to deliver analytics, chat, payments, and personalization. But every external script running in a customer’s browser introduces
In March 2022, the Payment Card Industry Security Standards Council released a revised version of its Data Security Standard, commonly known as PCI DSS v4.0. In this revised version are two new sections, 6.4.3 and 11.6.1 which offer guidance regarding 3rd, 4th, and nth party JavaScript running on your websites.
The articles, video and downloadable guide below are for anybody in the PCI DSS industry who focus on PCI DSS security and compliance and can be used as a resource for Qualified Security Assessors (QSA) who want to learn more about staying PCI compliant.

by Source Defense Modern websites depend on JavaScript to deliver analytics, chat, payments, and personalization. But every external script running in a customer’s browser introduces

by Source Defense Why the Browser Has Become the Weakest Link and How to Reinforce It The VikingCloud 2025 Cyber Threat Landscape Report paints a

by Stephen Ward I am incredibly proud that Source Defense has officially joined the PCI Security Standards Council’s Board of Advisors for the 2025 to

by Source Defense The landscape of payment security is at a critical turning point. As we approach the March 31, 2025 PCI compliance deadline for


Discuss New Trends in eSkimming: Recent reports show a 103% surge in attacks; card associations are saying 80+% of fraud is eSkimming related; Source Defense and Verizon have partnered to shed light on the growing threat surface – learn why the time to act is NOW.

With the March 2025 deadline for PCI DSS v4.0 compliance looming, businesses face the challenge of adapting to over 50 new security requirements. Among these, eSkimming protections are crucial for safeguarding online transactions. Time is running out—begin your compliance efforts today to stay ahead of the curve and secure your payment systems.

With the March 2025 PCI DSS 4.0 deadline looming, organizations face new challenges, particularly in securing against eSkimming threats. At a recent Source Defense roundtable, industry experts shared crucial insights on navigating these changes. Learn how to prepare for compliance and protect your organization from emerging client-side security risks.

New research from Source Defense included in the 2024 Verizon Payment Security Report sheds light on the ever-growing use of 3 rd party digital supply chain partners in modern website design.
Produced in collaboration with Verizon as part of the prestigious Verizon Payment Security Report (2024), this research provides crucial insights into the rise and risk of third-party scripts on modern websites. It covers essential topics such as: