Case Study · E-commerce retail

Online Retailer: Cutting PCI Scope and Closing 14 Critical Findings

An acquirer flagged the retailer for a longer PCI questionnaire than the business could realistically satisfy. Restructuring how payments were taken was cheaper than securing what they had.

Client
E-commerce retail
Sector
E-commerce retail
Size
11 staff, online plus one shop
Location
East Midlands, UK
In short

How do you reduce PCI DSS scope for a small online shop?

By making sure card data never touches your own systems. Moving checkout to a hosted payment page from the payment provider, and putting the in-store terminal on its own segregated connection, moved this retailer onto the shortest Self-Assessment Questionnaire.

The challenge

The retailer took card details on their own checkout page and had an in-store

terminal sharing the office network with the till system, the back-office PC and the guest Wi-Fi.

Their acquiring bank had indicated a Self-Assessment Questionnaire far longer than an eleven-person

business could realistically evidence.

An initial vulnerability assessment found the technical position was worse than the compliance

position suggested.

  • 14 critical and high findings, mostly in unmaintained e-commerce platform extensions
  • Two administrator accounts belonging to a developer who had finished 18 months earlier
  • Eleven third-party scripts loading on the checkout page, four of which nobody could account for
  • Card terminal on the same network segment as guest Wi-Fi
  • No content security policy, and no monitoring of payment page changes

What we did

Reduce the scope first

Securing a large card data environment is expensive. Removing it is not. We restructured payments

before doing anything else:

  1. Checkout moved to a hosted payment page supplied by the payment provider, so card data never

reaches the retailer's systems

  1. The in-store terminal moved onto its own segregated connection, away from the till and office

network

  1. Confirmed with the acquirer which Self-Assessment Questionnaire this position qualified for

before committing to the work

Then fix the technical findings

  1. Platform, theme and extensions brought current; three abandoned extensions removed entirely
  2. Dormant administrator accounts removed and MFA enforced on those remaining
  3. Checkout scripts inventoried — four removed, the rest justified and documented
  4. Content Security Policy implemented restricting where scripts may load from
  5. Integrity monitoring configured on the payment page, as PCI DSS v4.0 expects
  6. Guest Wi-Fi separated onto its own VLAN with client isolation

Retest

All findings were retested at no charge five weeks after the initial report.

The outcome

The retailer moved onto a substantially shorter Self-Assessment Questionnaire and

cleared every critical and high finding.

  • Card data no longer touches the retailer's systems
  • Shortest applicable SAQ confirmed by the acquirer
  • All 14 critical and high findings closed and verified at retest
  • Checkout script count reduced from eleven to seven, each with a documented justification
  • Payment page integrity monitoring in place ahead of the PCI DSS v4.0 requirement
  • Guest Wi-Fi fully isolated from payment and back-office systems

Total elapsed time was five weeks, including the retest. The largest single saving was not technical:

restructuring the payment flow removed most of the compliance burden before any security work was

purchased at all.

This case study is published anonymously and the retailer is not identified.

The point worth repeating

The cheapest PCI DSS project is the one where card data never enters your environment. Businesses

routinely pay to secure and evidence a card data environment they did not need to have.

Ask your acquirer which questionnaire applies to your current setup, then ask which one would apply

if you moved to a hosted payment page. The difference is often the whole project.

Published anonymously. Identifying details have been removed or generalised, and no client is named without written consent. Outcomes described relate to this engagement and are not a guarantee of results elsewhere.