
← Cyber Security Happy Hour Podcast13. Apr. · 1 Std. 04 Min.
Episode 46 Real-World Insights into PCI DSS with PCI DSS Analyst Todd Ballard
Episode 46: Beyond Compliance Real‑World Insights into PCI DSS
In this episode of Cyber Security Happy Hour, host Christie is joined by PCI DSS Analyst and certified PCI Professional (PCIP) Todd Ballard for a practical, experience‑led conversation on what PCI DSS compliance really looks like beyond the checklist.
Todd shares his journey into cybersecurity and explains why PCI DSS should be treated as a continuous business‑as‑usual process rather than a once‑a‑year audit exercise. Together, they explore the most common misconceptions around PCI compliance, the real‑world impact of PCI DSS v4.0, and why risk‑based validation, enhanced evidence requirements, and multi‑factor authentication are fundamentally changing how organisations must approach payment security.
The discussion dives into practical challenges such as scoping complex cloud and hybrid environments, managing third‑party and supply‑chain risk, handling shared responsibility models, and avoiding common remediation mistakes.
Todd also highlights often‑underrated controls like security awareness training and explains how automation, continuous monitoring, and AI‑driven tooling are shaping the future of PCI DSS compliance.
Whether you’re responsible for PCI DSS compliance, preparing for v4.0, or looking to move from checkbox compliance to meaningful security outcomes, this episode delivers real‑world insight you can apply immediately.
Key topics covered:
PCI DSS v4.0 and the shift to risk‑based validation
Defined vs customised approaches – benefits and risks
Scoping PCI in cloud, containerised, and hybrid environments
Third‑party and supply‑chain compliance management
Automation, continuous monitoring, and the future of PCI DSS