
Practical Cybersecurity with Jen Stone · 2026-07-21 · 21 min
How much of your business actually needs to be PCI compliant? Almost always less than you think. Every system inside your PCI scope is something you have to secure, document, and prove - year after year. So the fastest way to cut the cost and effort of compliance isn't working harder on controls. It's making your scope smaller. In this episode, Principal Security Analysts Jen Stone and Michael Simpson break down how PCI scope actually works - the three buckets every system falls into, the connected systems most people forget, and four practical ways to shrink your Cardholder Data Environment (and the bill that comes with proving it).