WhitepaperThe Kenya Data Protection Act: An Engineering Checklist
What the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Checkout, point of sale and the back office — scoped for PCI DSS, tested against the client-side attacks that target payment pages, and ready for your peak trading periods.

From the point of sale to the back office.
Retail security has two distinct halves that are usually managed by different teams and attacked through the same weakness. The digital half — storefront, checkout, loyalty, mobile app — is attacked through client-side script injection and account takeover. The physical half — terminals, in-store networks, back office, warehouse — is attacked through the estate’s weakest branch and the supplier who maintains it.
What connects them is cardholder data and the PCI DSS scope that follows it. The single most valuable piece of work available to most retailers is scope reduction: segmenting so that the number of systems in scope shrinks, which lowers compliance cost and raises security at the same time. It is also the work most often deferred.
Our retail engagements start by establishing where cardholder and customer data genuinely flows — which is almost always wider than the diagram shows — then test the checkout path, the terminal estate and the integrations that reach both.
Malicious script injected into a checkout page, usually through a compromised third-party dependency or tag manager, captures card details before your server ever sees them. PCI DSS v4.0 addresses this directly through its script-integrity requirements.
Terminals and in-store controllers are often maintained by a supplier, running long-lived credentials, on a network shared with everything else in the branch. One branch becomes the route into the estate.
Loyalty balances are liquid and lightly defended, making them a preferred target for credential stuffing. Rate limiting, credential-reuse detection and step-up on redemption are the controls that hold.
Storefront platforms carry extensive plugin ecosystems, and a plugin update is an unreviewed code deployment into your payment path. Dependency inventory and integrity monitoring are the minimum.
Your highest-revenue hours are the hours an availability attack costs most, and the hours your infrastructure is least able to absorb one. Peak readiness is a tested configuration, not a provider assurance.
Fulfilment, inventory and logistics systems increasingly include industrial equipment on networks that were never segmented from the corporate estate — the same IT/OT boundary problem manufacturing has, with less attention paid to it.
The sequence below is what a retail engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Retail teamWe map actual cardholder data flows, identify what can be moved out of scope through tokenisation, redirection or segmentation, and quantify the compliance effort you stop paying for as a result.
Storefront application testing, third-party script inventory and integrity checks, payment integration review, and the tag-manager configuration that is frequently the weakest link in the chain.
Branch estates are too large to test exhaustively and too uniform to need it. A thorough assessment of a representative branch plus configuration review across the estate finds the systemic issues.
Load and availability testing scheduled well before your trading peak, with the configuration changes made and verified while there is still time to verify them.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Research ReportHow fraud actually enters mobile money and agent-banking platforms — social engineering, SIM swap, agent collusion, API abuse — and the control patterns that stand up to each.
Threat AdvisoryThe mailbox-rule and supplier-impersonation patterns we keep finding in finance departments, with the detection logic and the four controls that stop them.