ERMProtect

ERMProtect

Speciality: Network Penetration Testing

Coral Gables, United States 17 employees
[01] About

Cybersecurity company specializing in penetration testing, PCI compliance, and digital forensics; 12 employees, founded in 1998, headquartered in Coral Gables, Florida, with 26+ years of experience and a 4.7/5 employer rating. Offers services including penetration tests, compliance audits, incident response, and security assessments.

ERMProtect protects businesses from cyber threats. Services include Penetration Tests, PCI & Regulatory Compliance Audits, Digital Forensics, Incident Response, Comprehensive IT Security & Risk Assessments, SOC Audits, and Security Awareness Training. Founded in 1998, we have served 400+ clients in 39 industry verticals globally. In addition to performing PCI QSA audits, we are one of only 20 firms in the world designated as a PCI PFI company certified to investigate credit-card breaches for the major brands.
[02] Services
Penetration Testing
PCI And Regulatory Compliance Audits
Digital Forensics
Incident Response
IT Security And Risk Assessment
Security Awareness Training
AI Risk Management And Governance.
[03] Certifications
GDPR

GDPR Certification Overview


Origin


The General Data Protection Regulation (GDPR) was created by the European Union and came into effect on May 25, 2018. It was developed by the European Parliament and Council to modernize and unify data protection laws across all EU member states. The regulation was created in response to the rapid growth of digital technology and data processing, aiming to give individuals greater control over their personal data while establishing clear obligations for organizations that collect, store, and process such information.


Industry Value


GDPR compliance is highly valued in the industry because it demonstrates an organization's commitment to data privacy and security, which has become a critical business concern globally. Organizations with GDPR expertise can avoid substantial fines (up to €20 million or 4% of annual global turnover), maintain customer trust, and gain competitive advantages when doing business with European entities or handling EU citizens' data. Professionals with GDPR certification are in high demand as companies worldwide seek to ensure compliance, implement proper data protection frameworks, and avoid the legal, financial, and reputational risks associated with data breaches and non-compliance.

GLBA
HIPAA

HIPAA Compliance and Cybersecurity


HIPAA (Health Insurance Portability and Accountability Act) was enacted by the U.S. Congress and signed into law in 1996. The legislation was created to protect sensitive patient health information from being disclosed without patient consent or knowledge. The Security Rule, added in 2003, established national standards for protecting electronic personal health information (ePHI), requiring covered entities and their business associates to implement administrative, physical, and technical safeguards. While HIPAA itself is legislation rather than a certification, various organizations offer HIPAA compliance training and certification programs to help IT professionals understand and implement these requirements.


HIPAA compliance is critically important in healthcare IT because violations can result in severe penalties, ranging from $100 to $50,000 per violation, with annual maximums reaching $1.5 million. Beyond avoiding fines, HIPAA knowledge is valued because healthcare data breaches can expose sensitive patient information, damage organizational reputation, and erode patient trust. IT professionals with HIPAA expertise are highly sought after as healthcare organizations increasingly rely on digital systems for medical records, billing, and patient communication. Understanding HIPAA requirements helps ensure that healthcare systems are designed, implemented, and maintained with appropriate security controls to protect patient privacy in an era of growing cyber threats.

CCPA

CCPA Certification Overview


Origin and Background


The Certified Cloud Protection Administrator (CCPA) certification was created by the Cloud Security Alliance (CSA), a nonprofit organization dedicated to defining standards and best practices for secure cloud computing. The certification was developed to address the growing need for professionals skilled in protecting cloud-based systems and data as organizations increasingly migrated their operations to cloud environments. The CSA launched this credential as part of their broader educational initiative to establish industry-recognized standards for cloud security competency.


Industry Value and Importance


The CCPA certification is valued in the IT industry because it validates a professional's knowledge of cloud security fundamentals, including data protection, compliance, and risk management in cloud environments. It demonstrates that holders understand practical security controls and can implement protective measures across various cloud service models (IaaS, PaaS, SaaS). Employers recognize this certification as evidence of specialized cloud security expertise, making it particularly relevant for IT administrators, security analysts, and professionals responsible for managing or securing cloud infrastructure. The credential helps distinguish qualified candidates in a job market where cloud security skills are in high demand.

ISO 27001

ISO 27001: Information Security Management Certification


Origin


ISO 27001 was developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), and was first published in 2005. It evolved from the British Standard BS 7799-2, which was created in the late 1990s. The standard was developed in response to the growing need for organizations to systematically manage and protect sensitive information in an increasingly digital business environment. ISO 27001 has since been revised, with major updates released in 2013 and 2022 to address evolving cybersecurity threats and best practices.


Industry Value and Importance


ISO 27001 is globally recognized as the leading standard for information security management systems (ISMS) and is valued for providing a systematic, risk-based approach to protecting sensitive data. Organizations that achieve ISO 27001 certification demonstrate to clients, partners, and regulators that they have implemented comprehensive security controls and are committed to maintaining confidentiality, integrity, and availability of information. The certification is particularly important for organizations handling sensitive data, as it helps meet regulatory compliance requirements, reduces security incidents, builds customer trust, and often provides a competitive advantage in procurement processes where information security assurance is required.

PCI DSS

PCI DSS Certification


Origin


The Payment Card Industry Data Security Standard (PCI DSS) was created in 2004 by the major credit card companies: Visa, Mastercard, American Express, Discover, and JCB International. These companies formed the PCI Security Standards Council in 2006 to manage and evolve the standard. PCI DSS was developed in response to increasing credit card fraud and data breaches, establishing a unified set of security requirements for all organizations that store, process, or transmit cardholder data. The goal was to create consistent security measures across the payment card industry to protect sensitive payment information.


Industry Value and Importance


PCI DSS compliance is mandatory for any business that handles credit card transactions, making it one of the most critical security standards in commerce today. The certification demonstrates that an organization has implemented robust security controls, including network protection, access management, encryption, and regular security testing. Non-compliance can result in severe consequences, including substantial fines (up to $100,000 per month), increased transaction fees, loss of payment processing privileges, and reputational damage following a breach. For IT professionals, PCI DSS expertise is highly valued as organizations across all industries need qualified personnel to implement, maintain, and audit these security controls.

NIST

NIST Cybersecurity Framework


Origin and Development


The NIST Cybersecurity Framework was created by the National Institute of Standards and Technology (NIST), a non-regulatory agency of the U.S. Department of Commerce. It was developed in response to Executive Order 13636, signed by President Obama in February 2013, which directed NIST to create a voluntary framework to help organizations manage cybersecurity risks. Released in February 2014 and updated in 2018 (version 1.1), the framework was designed to provide a common language and systematic approach for managing cybersecurity risks across critical infrastructure sectors.


Industry Value and Importance


The NIST Cybersecurity Framework is widely valued because it provides a flexible, cost-effective approach to managing cybersecurity risk that can be adapted by organizations of any size or sector. It has become a de facto standard in both the public and private sectors, often referenced in regulations, contracts, and compliance requirements. Organizations use it to assess their current security posture, communicate security requirements to vendors and partners, and demonstrate due diligence in protecting sensitive data. Its voluntary nature, combined with its comprehensive yet practical approach, has made it one of the most widely adopted cybersecurity frameworks globally.

Sarbanes Oxley
SEC Cybersecurity
State Cybersecurity Regulations
[05] Notable Clients
  • The Adrienne Arsht Center for the Performing Arts
  • The Norton Museum of Art
  • Airfox
  • Amerant Bank
  • Apollo Bank
  • Arion Bank
  • Banco Davivienda
  • Banco de Crédito e Inversiones (BCI)
  • Banco de Crédito del Perú
  • Banco de Bogotá
  • Banco do Brasil
  • Banco Internacional de Costa Rica
  • Banco Itaú Europa International
  • Banco Pichincha
  • Banco Popular Dominicano
  • Banco Sabadell
  • Banco Santander
  • Bancredito
  • Banesco
  • Banco de la Producción
  • SA
  • Bank United
  • Bayview
  • BCI Securities
  • Bladex
  • Brickell Bank
  • Capital Collections Management
  • ChargeBack Help
  • Circle Back Lending
  • Continental National Bank of Miami
  • Consultiva Wealth Management
  • Credit Agricole/CA Indosuez Wealth Miami
  • Eastern National Bank
  • Euro Bank
  • First Bank of Highland Park
  • First State Bank
  • FMSbonds
  • Inc.
  • GenTrust
  • Girosol Corp
  • Helm Bank
  • Heritage Bank
  • Interamerican Bank
  • Intercredit Bank
  • Itau Bank & Trust Cayman Ltd
  • Jallcard
  • JMMN Group Jamaica
  • LASCA Financials
  • Latin America Agribusiness Corporation (LAAD)
  • LNR Property Corporation
  • Luxury Mortgage Corporation
  • Mercantil Commerce Bank
  • Mission Capital
  • National Bank of Canada
  • National Bank of Egypt
  • North American Securities Admin. Association
  • Ocean Bank
  • Pacific National Bank
  • Professional Bank
  • Safra Bank
  • SnapCheck
  • Smart Money Finance
  • Starwood Property Trust
  • St. Kitts-Nevis-Anguilla National Bank
  • Terrabank
  • N.A.
  • The Belize Bank
  • Ltd.
  • TotalBank
  • Tropical Financial Credit Union
  • U.S. Century Bank
  • Vantage Point Title
  • Axiomatic LLC
  • B Riley Financial
  • Berkowitz Pollack Brant
  • CEO Coaching International
  • Cliff Berry
  • Inc.
  • Consulting Containment
  • Gerson Preston Klein
  • Ironside Group
  • OutPLEX
  • Premier Consulting International
  • Regis HR Group
  • Sigma Marketing
  • Softek Puerto Rico
  • Studio Twenty-Seven
  • Yip Associates
  • Titan List & Mailing Services
  • Inc.
  • Total Marketing Concepts
  • Inc.
  • Trident Crisis Management Group
  • Aeropost
  • Boost Payment Solutions
  • Inc.
  • Charge Back Help
  • e-Data Financial System
  • Inc.
  • GeoCom
  • Girosol Corporation
  • Itelbpo Smart Solutions
  • LASCO Financials
  • Merchant Services Network
  • Paybox
  • Safra Pay
  • Segpay
  • Slim CD
  • Inc.
  • TecniData
  • TouchSuite
  • United Nearshore Operations (UNO)
  • United Transactions
  • Valitor
  • Barry University
  • Cooperative Educational Service Agency 10
  • Florida International University
  • Gulliver Schools
  • Laureate Education
  • Inc.
  • Miami Dade County Public Schools
  • National Children Center
  • National Network of Digital Schools
  • Nearpod
  • Nova Southeastern University
  • Read-A-Thon Fundraising
  • Reading Area Community College
  • Rhode Island Society of Technology Educators
  • Syracuse University
  • The Children Trust
  • Thought Industries
  • University of Texas
  • University of Miami
  • Washburn University
  • Xavier University
  • NEXTera Energy
  • Rosetta Resources
  • Uepa Tickets
  • Sixthman
  • Studio 1 System
  • Boca Raton Airport Authority
  • Broward County
  • Brown County
  • Wisconsin
  • Citrus County Board of Commissioners
  • City of Apopka
  • City of Boca Raton
  • City of Boynton Beach
  • City of Cape Coral
  • City of Coral Gables
  • City of Deerfield Beach
  • City of Doral
  • City of Hollywood
  • City of Lake Worth Beach
  • City of Miramar
  • City of Port St. Lucie
  • City of San Francisco
  • City of Sanibel
  • City of St. Petersburg
  • City of West Palm Beach
  • Cooper City
  • Criminal Justice Coordinating Council - District of Columbia Government
  • Department of Defense – DeCA
  • Department of Defense – SECDEF
  • Department of Defense – US Army
  • Department of Defense – WHS
  • Department of Homeland Security – FLETC
  • Department of Homeland Security – USCIS
  • Department of State – USAID
  • Department of the Navy – NAVAIR
  • Department of the Navy – ONR
  • Department of Treasury – Bureau of Public Debt
  • Department of Treasury – OCC
  • Greenville Utility Commission
  • Harris County
  • Texas
  • John F. Kennedy CV67 Memorial Foundation
  • Linden Rosell Sewage Authority
  • Madison County
  • Illinois
  • Manatee County Port Authority
  • Maryland Judiciary
  • Miami Dade County
  • Miami Dade School Board
  • National Institute of Allergy and Infectious Diseases
  • Navy Mutual
  • New York City Employees Retirement System
  • Office of Naval Research
  • Orange County
  • Owensboro Municipal Utilities
  • Palm Beach County Attorney's Office
  • Port of Oakland
  • Rhode Island Student Loan Authority
  • School Employee Retirement System of Ohio
  • South Carolina Dept. of Health and Human Services
  • State of Kansas
  • State of Kansas – Office of the State Bank Commissioner
  • State of Mississippi
  • State of New Hampshire
  • State of Oregon
  • Steuben County
  • NY
  • The Children's Trust
  • U.S. International Boundary & Water Commission
  • United States Postal Service
  • West Virginia State Treasurer’s Office
  • AlphaNet
  • Automated Healthcare Solution
  • AvMed Health Plans
  • Bankers Healthcare Group
  • Best Option Health Care PR
  • Inc.
  • Broward Health
  • Health Coalition
  • Inc.
  • Hematology-Oncology Associates of the Treasure Coast
  • HGS Corporation
  • HGS Healthcare
  • Jackson Health System
  • Jackson Memorial Hospital
  • Larkin Hospital
  • Manati Medical Center
  • PR
  • Mayagüez Medical Center
  • PR
  • MCS Healthcare Holdings
  • LLC / Medical Card Systems
  • MMR Healthcare
  • Monarch Well Works
  • Mount Sinai Medical Center
  • MSP Recovery
  • Native Tremedies
  • LLC
  • Nipro Medical Corporation
  • Olympus Managed Health Care
  • Phillips Medical Systems PR
  • Inc.
  • Smith & Nephew
  • Solis Healthcare
  • Southern Diagnostic Association
  • Streamline Healthcare
  • University of Miami School of Medicine
  • ABTS Convention Services
  • Biltmore Hotel
  • Carnival Cruise Lines
  • Duty Free Partners
  • CMI Leisure Management
  • Entertainment Benefits Group
  • Grupo Agrisal
  • Holland America Cruise Lines
  • LifeMiles
  • JW Marriott Hotel
  • Norwegian Cruise Lines
  • Peterson & Smith Equine Hospital
  • Pharmalogic
  • Reyes Holdings
  • Seabourn Cruise Line
  • Slatebridge Restaurant Group
  • Trump International Beach Resort
  • Virgin Hotels
  • Wild East Asian Bistro
  • ABCO Insurance
  • AvMed Health Plans
  • Cost Containment Group
  • CUNA Mutual
  • FedNat
  • Gold Kidney Health Plan
  • Oscar Insurance Company of Florida
  • Simply Healthcare Plans
  • States Title Family Company
  • United Automobile Insurance Co. (UAIC)
  • Adsuar Muñiz Goyco Seda & Pérez-Ochoa
  • Allen Norton & Blue
  • P.A.
  • Avila Rodriguez Hernandez Mena & Ferri
  • Baxter Smith & Shapiro
  • Bilzin Sumberg
  • Brumbaugh & Quandahl
  • P.C. L.L.O.
  • Buckner & Miles
  • Carey
  • O'Malley
  • Whitaker
  • Mueller
  • Roberts & Smith P.A.
  • Carlton Fields
  • Clark Silverglate PA Law Offices
  • DLD Lawyers
  • Hunton & Williams
  • Holland & Knight
  • LLP
  • Infante Zumpano
  • Keller & Bolz
  • Kirwan Spellaci & Danner
  • Kozyak Tropin & Throckmorton
  • Law Offices of David Pollack
  • Leesne Law
  • Leon Cosgrove
  • Marlow
  • Adler
  • Abrams
  • Newman & Lewis Attorneys at Law
  • Matthew Wallace
  • McDermott Will & Emery LLP
  • My Motion Calendar
  • Nardello & Co. LLC
  • Panza Maurer & Maynard
  • P.A.
  • R. Figueroa P.A.
  • Reid & Wise New York Law Firm
  • Salazar Law
  • Shutts & Bowen
  • LLP
  • Susy Ribero-Ayala
  • P.A.
  • Rudy
  • Exelrod & Zieff
  • LLP
  • Sonia Colon Law Offices
  • P.A.
  • Tripp Scott
  • Truststorm
  • Ver Ploeg and Lumpkin
  • ION Media
  • Sony Latin América
  • Inc.
  • Allied Building Products
  • Daabon Organic USA
  • DSS Condo LLA
  • EAM Worldwide
  • Heico Aerospace
  • Hyperice
  • Jodee
  • Inc.
  • Mastec
  • Point Blank Solutions
  • Inc.
  • Rinker Materials
  • Roskam Baking Company
  • Sony Electronics Latin America
  • Sylvania Lighting International
  • Larch Capital Partners
  • WE Family Offices
  • Trivest
  • Comras Company
  • Rohrer Realty Partners
  • Terranova Corporation
  • GGPLP Reit Services
  • LLC
  • ADT Inc.
  • ASAL Inc.
  • Bacardi-Martini
  • Inc.
  • Baer's Furniture Store
  • Bijoux Terner
  • Boxy Charm
  • Brightstar Corporation
  • Brothers & Farmers
  • Compressionsale.com
  • El Aguila Supermarket
  • Enjuku Racing Parts
  • Grupo Unicomer
  • Home Defender
  • News Café
  • Nexcom - Navy
  • Patio Furniture Supplies
  • Perry Ellis International
  • Samuel Hubbard Shoe Company LLC
  • Stealth Monitoring
  • The GAP
  • Inc.
  • T-ROC
  • YMCA
  • AeroStar Inc.
  • Blue Grass Airport – Kentucky
  • Dallas Area Rapid Transit
  • JM Family
  • Kenton County Airport Board
  • Metropolitan Atlanta Rapid Transit Authority (MARTA)
  • Metropolitan Washington Airports Authority
  • North Palm Motors & Custom Fleet Services
  • Ryder Systems
  • Inc.
  • Sunrise Airways
  • Swift Transportation
  • Acumen Data
  • Afriex
  • Agency 720
  • AtPoint
  • AuthIT
  • Big Data Exchange
  • Bridgevine
  • Central Reach
  • Check21.com
  • LLC
  • Coras
  • Cosecal
  • Credence Corp
  • CSID
  • Data Escrow Security
  • Dataline Systems
  • Inc.
  • Denmark Technologies
  • Dulles Technology Partners
  • EMerchantPay Corporation
  • EnCircle
  • Exaptive
  • Inc.
  • Fineline Technologies
  • First Class Flyer
  • First Payment Systems
  • GB Group
  • GCS International
  • Global Outsource Services
  • Go Canvas
  • GradSave
  • HOPS International
  • Host.net
  • Infocentro Popular
  • Intelcia Jamaica Limited
  • International Data Depository
  • Nicey
  • Ocean Systems
  • Payventures
  • LLC
  • Periscope Holdings
  • Plex Systems
  • Provider Network Solutions
  • Servicios Digitales Popular
  • Stealth Monitoring
  • Support Services Group
  • Taylor Technology
  • The Select Group
  • Velocitude
  • Vertex
  • Welligent
  • WEY Technologies
  • Inc.
  • XTec