Physical stores, distribution centers, marketplaces, and e-commerce rely on systems that cannot stop and store card and customer data. We help retail chains protect their operations, meet PCI DSS and LGPD requirements, and get through peak dates without incidents.
In retail, every hour of downtime is a lost sale. Attackers know this and choose the moment and the point of entry:
Anyone who stores, processes or transmits card data follows PCI DSS v4.0.1, required by the card brands and enforced by acquirers. Since March 31, 2025, the requirements that were future-dated in version 4.0 have been in effect, including control of payment page scripts (6.4.3) and detection of changes to that page (11.6.1). The standard also calls for an automated solution against attacks on public-facing web applications (6.4.2), multi-factor authentication for access to the cardholder data environment (8.4.2), and periodic penetration testing (11.4).
A LGPD (Law No. 13.709/2018) requires adopting security measures to protect personal data (art. 46) and reporting to the ANPD and data subjects any incidents that may cause relevant risk or harm (art. 48). Resolution CD/ANPD No. 15/2024 sets a deadline of three business days for this notification. In e-commerce, Decree No. 7.962/2013, which regulates the Consumer Protection Code, requires suppliers to use effective security mechanisms for payments and for processing consumer data.
Continuous monitoring of stores, distribution centers, cloud, and e-commerce, with ransomware detection and containment before encryption.
WAF and API protection for e-commerce and the app, data loss prevention (DLP) and DevSecOps in the development cycle.
Penetration testing of checkout, APIs, apps and the store network, aligned with what PCI DSS requires.
NDR to see lateral movement between stores, POS terminals, distribution centers and headquarters.
MFA, privileged access management, and control of third-party, franchisee, and service provider accounts.
Mapping of PCI DSS and LGPD requirements to internal controls and organization of evidence for audits and acquirers.
Black Friday, Christmas, and holidays concentrate traffic, promotions, and overloaded teams. That is when coupon scams and fake sites multiply, bots test credentials en masse, and a DDoS or ransomware attack causes the greatest damage.
Preparation starts weeks ahead: a pentest and remediation of flaws before the change freeze, a review of WAF and bot protection rules, tested backups kept out of the attacker's reach, a incident response rehearsed with the team and reinforced monitoring during the campaign. For customers, it is worth pointing them to the store's official channels. Read about AI-driven phishing and social engineering.
Both provided the support we needed and stayed with us throughout the whole process.
Yes, with a reduced scope. Outsourcing checkout shrinks the cardholder data environment, but the merchant remains responsible for the page that loads the payment, the scripts it runs and the annual compliance validation with the acquirer.
6.4.3 requires an inventory, authorization and integrity assurance for every script executed on the payment page, with a justification for each one. 11.6.1 requires a mechanism that detects unauthorized changes to that page and alerts the team. Both have been mandatory since March 31, 2025.
If the incident may cause relevant risk or harm to data subjects, yes. The LGPD requires notification to the ANPD and to data subjects, and Resolution CD/ANPD No. 15/2024 sets a deadline of three business days from learning that the incident affected personal data.
PCI DSS requires penetration testing at least once every 12 months and after significant changes. In retail, it pays to schedule the test before the change freeze that precedes peak dates, with time to fix whatever is found.
Talk to a specialist and see where the gaps are between PCI DSS, the LGPD, and your controls.