Retail & e-commerce

Protect every till, every checkout page, every peak

Retail security is a scale problem wearing a deadline. Thousands of physically exposed terminals, a checkout page assembled from a dozen third-party scripts, a supplier network nobody fully mapped, and a four-week window in which most of the year's revenue arrives. Guardian Sentinel covers all of it from one console, with capacity provisioned for your worst hour rather than your average one.

  • PCI DSS 4.0
  • Req. 6.4.3
  • Req. 11.6.1
  • GDPR & CCPA
  • SOC 2 Type II
9× Peak-to-baseline transaction ratio in a typical retail year Concentrated in eleven trading days
62% Of retail breaches begin at a third party or supplier Guardian Labs incident data, 2024–2026
47 days Median time a payment skimmer stays live undetected Industry average; Guardian median is 1.4 seconds
$3.9M Average cost of a retail data breach Excluding card-brand fines and forensic assessment

PCI DSS 4.0

The requirements that changed, and what now has to run continuously

PCI DSS 4.0 moved several controls from annual verification to ongoing operation, and added two that did not exist before: payment-page script inventory and integrity, and change-and-tamper detection on payment pages. Both are now assessed, and both are impossible to satisfy with a quarterly scan.

PCI DSS 4.0 requirement, what it demands in practice, the Guardian control that satisfies it, and the evidence produced for your assessor.
Requirement What it demands Guardian control Assessor evidence
1.3 & 1.4 Cardholder data environment isolated from untrusted networks, verified regularly Continuous segmentation verification: Guardian actively tests reachability into the CDE from every other zone Dated segmentation validation with the specific paths tested and their result
5.2 & 5.3 Anti-malware active, current, and generating audit logs on all applicable systems Behavioural prevention on POS, back-office and e-commerce hosts, with tamper protection that survives local administrator access Per-system coverage report including offline terminals and their last check-in
6.4.3 New. Inventory every script on the payment page, justify each one, and assure its integrity Automatic script inventory with cryptographic baselines, business justification capture and change approval workflow Live script register with owner, justification, hash and last-verified timestamp
10.2 & 10.7 Audit logs for all access to cardholder data; critical control failures detected and responded to promptly Immutable telemetry across CDE systems with control-failure detection on the security controls themselves Control-failure log with detection time, notification time and remediation time
11.5.2 Change-detection on critical files, evaluated at least weekly Real-time file integrity monitoring with change attribution to a process and a user, not just a diff Change record with the responsible process lineage and approval state
11.6.1 New. Detect and alert on unauthorised modification of payment page HTTP headers and content Client-side integrity monitoring from real browser sessions, comparing delivered content against the approved baseline Tamper alert with the offending payload, the affected sessions and the block action taken
12.10 Incident response plan tested at least annually and executed on detection Automated containment playbooks with a written narrative per incident, plus annual tabletop facilitation Exercise record and per-incident response timeline against the documented plan

Scroll the table sideways to see every column.

Guardian's compliance team works with your QSA directly, and supplies the control implementation narrative in the format used by the Report on Compliance. See compliance advisory.

POS & endpoint fleet at scale

Thousands of terminals, no local IT, and a store manager with the keys

A retail endpoint estate is unlike any other: physically accessible to the public, staffed by people whose job is not technology, connected over links that were sized for card authorisation and nothing else, and expected to keep trading when the connection drops entirely.

IN-STORE ESTATE POS terminals Self-checkout units Back-office servers Store network gear 22,400 across 1,480 stores 6,200 units, public-facing 1,480 servers, one per site Switches, APs, payment routers IN-STORE ENFORCEMENT Local detection engine Kernel USB & device policy Peer-to-peer content sharing Offline enforcement, 30 days Bandwidth ceiling: 4 MB/day DIGITAL & SUPPORTING ESTATE E-commerce tierCheckout & CDN FulfilmentWarehouse & logistics CorporateMerchandising & finance Guardian Sentinel One console for the whole estate Fleet-wide policy in one place Rollout rings and canary stores Store-level posture scorecards PCI evidence generated nightly A store that loses connectivity keeps trading, keeps detecting and keeps enforcing.
Enforcement happens in the store; correlation and reporting happen centrally.
4 MB Daily bandwidth per endpoint at the retail default profile
30 days Full detection and enforcement while disconnected
1.1% Median sensor CPU on a POS terminal image
0 Reboots required for sensor or content updates

The terminal is a public device

Guardian enforces peripheral policy in the kernel, so a USB device plugged into a self-checkout at 02:00 cannot present itself as a keyboard and run a script. Hardware skimmer insertion is detected as a device-tree change, with the store, lane and timestamp attached.

Rollouts that cannot take down trading

Sensor and policy changes deploy in rings — canary stores, then a region, then the estate — with automatic rollback if any health metric moves. Change freezes for peak trading periods are enforced by the platform, not by a calendar reminder.

Store-level accountability

Every site gets a posture score covering patch state, policy compliance, peripheral exceptions and incident history. Regional managers see their own stores ranked, which moves remediation faster than any security memo.

E-skimming & Magecart defence

Your checkout page runs code you did not write

A modern payment page loads analytics, tag management, personalisation, chat, fraud scoring and A/B testing — most of it from third parties, several of them loading fourth parties of their own. Any one of them can be modified upstream to read the card field. Server-side scanning will never see it, because the malicious code only ever exists in the customer's browser.

shop.example.com / checkout / payment Payment details Card number Expiry Security code Name on card Pay now Modified script attempts to read the card field SCRIPT INTEGRITY MONITOR — LIVE SESSIONS checkout-core.js tag-manager.js payments-sdk.js cdn-analytics.min.js chat-widget.js ab-testing.js sha384-9f2c…d41a sha384-13ba…7e08 sha384-c07e…5b92 sha384-4a11…ff3d sha384-8de6…1c47 sha384-2b95…a6f0 Hash mismatch — script blocked, sessions unaffected Script modified upstream Mismatch detected Script blocked Evidence recorded T + 0 T + 1.4 s T + 1.9 s T + 2.1 s At the third-party CDN In real customer sessions CSP directive updated PCI DSS 11.6.1 artefact written Industry median time to detect a live skimmer: 47 days.
Detection happens in the browser, where the attack happens. Timings are Guardian medians across monitored checkout flows.

How the monitor works

  1. Inventory, automatically

    Guardian enumerates every script executing on the payment page from real sessions — including scripts injected by other scripts, which a crawler will never see. Each entry captures origin, owner and load context.

  2. Justify and baseline

    Each script is assigned a business justification and an approver, satisfying PCI DSS 6.4.3. Approval sets a cryptographic baseline; the register becomes the evidence artefact.

  3. Verify continuously

    Delivered content is verified against the baseline in live sessions across browsers, devices and geographies — because a skimmer commonly serves clean code to everyone except real shoppers on mobile.

  4. Block, then explain

    An unapproved change is blocked through Content Security Policy and the client agent within two seconds, and the incident record captures the payload, the exfiltration destination and the affected session count.

Why server-side scanning misses this entirely. The skimmer is never in your codebase, your repository or your build. It arrives from a third-party CDN at page load, often only for a fraction of sessions, and frequently disables itself when it detects developer tools. Only observation from the real client can catch it.

Evasion techniques Guardian accounts for

  • Selective serving. Malicious variant delivered to 3% of sessions, filtered by geography, device and referrer.
  • Fourth-party injection. An approved vendor's script loading a compromised dependency of its own.
  • Form-field shadowing. An overlay input that harvests the card number before the legitimate field ever sees it.
  • WebSocket exfiltration. Card data streamed out through a channel that never appears in a request log.
  • Delayed activation. Benign for six weeks after approval, then switched on remotely during peak trading.

Seasonal surge

Capacity is a security control in the fourth quarter

If a security platform degrades, queues or samples under load, it will do so precisely when the fraud is heaviest, the change freeze is on and the seasonal workforce is at its largest. Guardian is provisioned against your peak, tested against it before the season, and contractually committed to it.

0 12k 24k 36k 48k TRANSACTIONS PER SECOND — PEAK TRADING SEASON Guardian provisioned & load-tested capacity — 45,000 TPS 28,400 Black Friday 24,900 Cyber Monday 58% headroom at peak 1 Nov 15 Nov 29 Nov 13 Dec 27 Dec Composite profile from a 1,480-store omnichannel retailer. Guardian's inline decision latency stayed flat at 3.6 ms p50 throughout.
Guardian runs a joint load test against your projected peak in September, and holds the resulting capacity as a contractual commitment for the season.

Change freeze, enforced

From your nominated freeze date, sensor updates, policy changes and content deployments are held automatically. Only emergency detections for active campaigns are released, and each one requires your approval.

The seasonal workforce problem

Tens of thousands of temporary accounts created in six weeks and deprovisioned in two. Guardian baselines seasonal roles separately, so a temporary till operator accessing a merchandising system is an anomaly on day one rather than day forty.

Peak-season standby

Named Guardian analysts are assigned to your account for the trading period, with a pre-agreed escalation path, a standing bridge and a fifteen-minute response commitment on critical detections.

Supply chain & third-party risk

Most retail breaches arrive through someone else's credentials

Refrigeration contractors, cleaning schedulers, digital marketing agencies, logistics providers, tag managers and payment orchestrators all hold access to something that touches the estate. Guardian scopes every one of them to a behavioural envelope and contains deviation automatically.

Vendor remote access to store systems

Building management, refrigeration, HVAC and digital signage vendors connect to store networks on maintenance schedules. Guardian learns each vendor's normal pattern — which stores, which hours, which systems, which protocols — and treats anything outside it as containable.

A refrigeration contractor's account touching a point-of-sale VLAN is stopped in under a second and reported to the store operations owner, not just to the SOC.

Software and dependency supply chain

Guardian monitors the build pipeline for your e-commerce and store applications: unexpected dependency changes, unsigned artefacts, modified build agents and credentials appearing in source. Runtime behaviour is compared against the SBOM, so a component doing something its manifest does not justify is surfaced.

See cloud security for pipeline and container coverage.

Payment orchestration and PSP integrations

Retailers routinely integrate three or more payment providers, plus buy-now-pay-later, gift card and loyalty platforms. Each integration is an API relationship with its own credentials and its own blast radius. Guardian monitors API behaviour for enumeration, credential replay and volume anomalies, and can throttle or block a specific integration without affecting the others.

Logistics, fulfilment and warehouse robotics

Warehouse management systems, handheld scanners, conveyor controllers and autonomous mobile robots increasingly share a network with corporate IT. Guardian applies its industrial profile here: passive monitoring, no agent on controllers, and containment actions restricted to network path changes that cannot stop a running process.

Franchise and concession estates

Franchisees and concession partners operate systems you are accountable for but do not control. Guardian's multi-tenant hierarchy gives each operator its own console and its own administration, while the brand owner retains a consolidated posture view and can enforce a minimum policy baseline as a condition of connection.

Loyalty programmes and account takeover

Loyalty balances are cash equivalents with none of the fraud controls that protect cards. Guardian detects credential stuffing, points-draining patterns and mule account clusters at the identity layer and returns a decision inline to the storefront. See identity protection.

Customer proof

Halcyon Retail Group

1,480 stores across nine markets, 22,400 POS terminals, an e-commerce platform doing 38% of revenue, and a Level 1 PCI obligation in three card-brand regions.

We deployed to 1,480 stores in eleven weeks, in the middle of the year, without a single trading interruption. Then in November the script monitor caught a modified tag-manager payload nine minutes after our agency pushed it. Nine minutes. Our previous answer to that question was "the card brands would tell us".

James Whitfield
Director of Information Security, Halcyon Retail Group

What the programme covered

  • 22,400 POS terminals and 6,200 self-checkout units across nine markets
  • Client-side integrity monitoring across four storefront platforms
  • Four cloud accounts, 1,900 containers and the fulfilment estate
  • 620 third-party identities scoped to behavioural access envelopes
  • Three legacy tools retired, including a separate FIM product
11 weeks To deploy across 1,480 stores in nine markets Zero trading interruptions
9 min From unauthorised script push to blocked and reported Detected in live customer sessions
-79% Reduction in PCI evidence preparation effort Measured in assessor and internal hours
0 Security-caused outages across two peak seasons
Read the full case study

Find out what is running on your checkout page today

Guardian will inventory every script executing on your live payment flow, from real customer sessions, and hand you the register with owners, origins and integrity state. It takes a week and you keep the findings.