Cybersecurity for
Retail and E-Commerce

Checkout, point of sale and the back office — scoped for PCI DSS, tested against the client-side attacks that target payment pages, and ready for your peak trading periods.

A customer being served at a retail storefront

What Security Means
In Retail

From the point of sale to the back office.

Retail security has two distinct halves that are usually managed by different teams and attacked through the same weakness. The digital half — storefront, checkout, loyalty, mobile app — is attacked through client-side script injection and account takeover. The physical half — terminals, in-store networks, back office, warehouse — is attacked through the estate’s weakest branch and the supplier who maintains it.

What connects them is cardholder data and the PCI DSS scope that follows it. The single most valuable piece of work available to most retailers is scope reduction: segmenting so that the number of systems in scope shrinks, which lowers compliance cost and raises security at the same time. It is also the work most often deferred.

Our retail engagements start by establishing where cardholder and customer data genuinely flows — which is almost always wider than the diagram shows — then test the checkout path, the terminal estate and the integrations that reach both.

Where Retail
Actually Gets Hit

Client-side payment page skimming

Malicious script injected into a checkout page, usually through a compromised third-party dependency or tag manager, captures card details before your server ever sees them. PCI DSS v4.0 addresses this directly through its script-integrity requirements.

Point-of-sale estate compromise

Terminals and in-store controllers are often maintained by a supplier, running long-lived credentials, on a network shared with everything else in the branch. One branch becomes the route into the estate.

Loyalty and account takeover

Loyalty balances are liquid and lightly defended, making them a preferred target for credential stuffing. Rate limiting, credential-reuse detection and step-up on redemption are the controls that hold.

E-commerce platform and plugin supply chain

Storefront platforms carry extensive plugin ecosystems, and a plugin update is an unreviewed code deployment into your payment path. Dependency inventory and integrity monitoring are the minimum.

Peak-period availability

Your highest-revenue hours are the hours an availability attack costs most, and the hours your infrastructure is least able to absorb one. Peak readiness is a tested configuration, not a provider assurance.

Warehouse and logistics systems

Fulfilment, inventory and logistics systems increasingly include industrial equipment on networks that were never segmented from the corporate estate — the same IT/OT boundary problem manufacturing has, with less attention paid to it.

Built Around
Your Constraints

The sequence below is what a retail engagement looks like in practice — shaped by what your environment can and cannot tolerate.

Talk to our Retail team
01

Reduce PCI scope before anything else

We map actual cardholder data flows, identify what can be moved out of scope through tokenisation, redirection or segmentation, and quantify the compliance effort you stop paying for as a result.

02

Test the checkout path end to end

Storefront application testing, third-party script inventory and integrity checks, payment integration review, and the tag-manager configuration that is frequently the weakest link in the chain.

03

Assess one branch properly, then the estate

Branch estates are too large to test exhaustively and too uniform to need it. A thorough assessment of a representative branch plus configuration review across the estate finds the systemic issues.

04

Rehearse for peak

Load and availability testing scheduled well before your trading peak, with the configuration changes made and verified while there is still time to verify them.

What You Are
Held To

Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.

PCI DSS v4.0
The central obligation wherever cards are accepted. Requirements 6.4.3 and 11.6.1, covering management and integrity monitoring of payment-page scripts, became effective in March 2025 and apply to most e-commerce checkouts.
Data Protection Act, 2019
Covers customer, loyalty and marketing data. Consent for marketing, retention limits on transaction history and honouring deletion requests across analytics systems are the usual gaps.
Consumer protection and e-commerce rules
Kenya’s consumer protection framework bears on how transaction disputes, refunds and the security of customer accounts are handled, alongside the sector-specific rules for your category.
OWASP Top 10
The practical baseline for storefront application testing, and a reasonable minimum to require contractually of the agency or platform building your checkout.

Reading For
Retail Teams

All publications

What Retail Clients
Ask First

Almost certainly, though in a much lighter form. If your page loads the provider’s iframe or script, the page itself is in scope for the script-integrity requirements — which is precisely the gap the v4.0 changes address.
No. A thorough on-site assessment of one or two representative branches, combined with remote configuration review across the estate, surfaces the systemic issues at a fraction of the cost of visiting all of them.
With enough lead time to fix what it finds — typically a full quarter before your peak. Testing two weeks out tells you what is wrong without leaving time to change it.