Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert
Retail and e-commerce

Cybersecurity for retail, from store to checkout.

Physical stores, distribution centers, marketplaces, and e-commerce rely on systems that cannot stop and store card and customer data. We help retail chains protect their operations, meet PCI DSS and LGPD requirements, and get through peak dates without incidents.

Why retail is a target

Continuous operation, tight margins and data worth money

In retail, every hour of downtime is a lost sale. Attackers know this and choose the moment and the point of entry:

Ransomware in operationsEncrypted stores, POS systems, and distribution centers halt sales, inventory, and shipping all at once.
Checkout attacksMalicious scripts injected into the payment page capture card data without interrupting the sale.
Bots, APIs, and DDoSBots test stolen credentials, scrape prices and drain inventory; denial-of-service attacks take the site down at peak times.
Brand scamsFake sites, coupons and nonexistent promotions use the store's name to steal customers' data and money.
What regulation requires

PCI DSS, LGPD and e-commerce rules

Anyone who stores, processes or transmits card data follows PCI DSS v4.0.1, required by the card brands and enforced by acquirers. Since March 31, 2025, the requirements that were future-dated in version 4.0 have been in effect, including control of payment page scripts (6.4.3) and detection of changes to that page (11.6.1). The standard also calls for an automated solution against attacks on public-facing web applications (6.4.2), multi-factor authentication for access to the cardholder data environment (8.4.2), and periodic penetration testing (11.4).

A LGPD (Law No. 13.709/2018) requires adopting security measures to protect personal data (art. 46) and reporting to the ANPD and data subjects any incidents that may cause relevant risk or harm (art. 48). Resolution CD/ANPD No. 15/2024 sets a deadline of three business days for this notification. In e-commerce, Decree No. 7.962/2013, which regulates the Consumer Protection Code, requires suppliers to use effective security mechanisms for payments and for processing consumer data.

Where we help

Each retail risk and the service that responds to it

24×7 SOC and MDR

Continuous monitoring of stores, distribution centers, cloud, and e-commerce, with ransomware detection and containment before encryption.

Cloud security

WAF and API protection for e-commerce and the app, data loss prevention (DLP) and DevSecOps in the development cycle.

Pentest

Penetration testing of checkout, APIs, apps and the store network, aligned with what PCI DSS requires.

Network detection

NDR to see lateral movement between stores, POS terminals, distribution centers and headquarters.

Identities and access

MFA, privileged access management, and control of third-party, franchisee, and service provider accounts.

GRC

Mapping of PCI DSS and LGPD requirements to internal controls and organization of evidence for audits and acquirers.

Black Friday and peak dates

Peak sales season is also peak attack season

Black Friday, Christmas, and holidays concentrate traffic, promotions, and overloaded teams. That is when coupon scams and fake sites multiply, bots test credentials en masse, and a DDoS or ransomware attack causes the greatest damage.

Preparation starts weeks ahead: a pentest and remediation of flaws before the change freeze, a review of WAF and bot protection rules, tested backups kept out of the attacker's reach, a incident response rehearsed with the team and reinforced monitoring during the campaign. For customers, it is worth pointing them to the store's official channels. Read about AI-driven phishing and social engineering.

“
Both provided the support we needed and stayed with us throughout the whole process.
Afro Vasconcelos Technology Director, Pague Menos, on Fortinet and Network Secure
Read the Pague Menos case study →
Frequently asked questions

Common questions about retail security

Yes, with a reduced scope. Outsourcing checkout shrinks the cardholder data environment, but the merchant remains responsible for the page that loads the payment, the scripts it runs and the annual compliance validation with the acquirer.

6.4.3 requires an inventory, authorization and integrity assurance for every script executed on the payment page, with a justification for each one. 11.6.1 requires a mechanism that detects unauthorized changes to that page and alerts the team. Both have been mandatory since March 31, 2025.

If the incident may cause relevant risk or harm to data subjects, yes. The LGPD requires notification to the ANPD and to data subjects, and Resolution CD/ANPD No. 15/2024 sets a deadline of three business days from learning that the incident affected personal data.

PCI DSS requires penetration testing at least once every 12 months and after significant changes. In retail, it pays to schedule the test before the change freeze that precedes peak dates, with time to fix whatever is found.

Is your operation ready for the next peak?

Talk to a specialist and see where the gaps are between PCI DSS, the LGPD, and your controls.

Talk to an expert →