Solutions

Cyber Security for Retail and E-commerce Businesses

Card data, website uptime and customer trust. We reduce how much card data you touch in the first place, secure the platform your revenue depends on, and keep the shop floor network separate from everything else.

FRAMEWORK
PCI DSS v4.0 (SAQ Level)
FOCUS
Scope Reduction & Platform Security
COVERS
E-commerce, EPOS, Guest Wi-Fi
THREAT
Card Skimming & Account Takeover
In short

Does a small shop or online store need PCI DSS compliance?

Any business that accepts card payments has PCI DSS obligations, passed down through its acquiring bank. Most small merchants qualify for a Self-Assessment Questionnaire rather than a full audit, and the scope shrinks dramatically if card data never touches your own systems.

Reduce the scope before you secure it

PCI DSS compliance gets dramatically cheaper when card data never enters your environment. Using a hosted payment page or an iframe from your payment provider, rather than capturing card details on your own page, moves most of the burden to them and typically qualifies you for a much shorter Self-Assessment Questionnaire.

The same applies in store. A card terminal that connects directly to the acquirer over its own path, on a segmented network, keeps your till system and office network out of scope. Getting this architecture right first is the single largest cost saving available in retail compliance.

  • Hosted or iframe payment pages rather than capturing card data yourself
  • Never store card numbers, and confirm no supplier or log is storing them for you
  • Segment card terminals and EPOS onto a dedicated network
  • Confirm your SAQ type with your acquirer before doing the work

Protecting the payment page itself

Digital skimming — where an attacker injects a script into a checkout page to harvest card details as customers type them — remains a live threat for online retailers. It usually arrives not through the shop itself but through a third-party script: an analytics tag, a chat widget, an abandoned plugin, or a compromised supplier.

Defences are practical: know exactly which scripts load on your checkout, remove the ones nobody can justify, apply a Content Security Policy, monitor the payment page for unauthorised change, and keep the platform and its extensions patched. PCI DSS v4.0 now requires script inventory and integrity monitoring on payment pages for exactly this reason.

  • Full inventory of scripts loading on checkout, with a business justification each
  • Content Security Policy restricting where scripts may load from
  • Integrity monitoring and change alerting on the payment page
  • Prompt patching of the platform, theme and every extension
  • Removal of unused plugins and dormant administrator accounts

Customer accounts and fraud

Retailers hold customer accounts containing addresses, order history and stored payment tokens, and those accounts are attacked at volume using credentials stolen from unrelated breaches. Customers reuse passwords, so a list from another site works against yours.

Rate limiting, bot detection, breached-password checking at registration and optional multi-factor authentication for customers all reduce this materially, and none of them requires a large project.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Retail & E-commerce Security — your questions answered

What is PCI DSS and does it apply to us?
PCI DSS is the card industry security standard, applied to merchants through their acquiring bank. It applies to any business accepting card payments. Most small merchants complete a Self-Assessment Questionnaire annually rather than undergoing a full audit.
What happens if we are not PCI DSS compliant?
Acquirers can levy non-compliance fees and, after a breach, fines and forensic investigation costs are passed to the merchant. In serious cases the ability to take card payments can be withdrawn.
Our website is on Shopify or WooCommerce. Is it secure by default?
The platform handles a good deal, but you remain responsible for your themes, plugins, third-party scripts, administrator accounts and configuration. Most e-commerce compromises we see come through an extension or a stale admin account, not the platform core.
Can customers use our guest Wi-Fi safely?
Yes, provided it is properly isolated. Guest Wi-Fi must be on its own network with no route to tills, card terminals or back-office systems, and with client isolation enabled.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about retail & e-commerce security?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.