Retail & Store Networks · PCI DSS & GDPR

Your store has more entrances
than the front door

Checkouts, back office, stockroom, online shop: a retailer with a store network repeats the same weaknesses at every location, staffed by people who may have started last week for the holiday season. Retail was the second most attacked industry in Germany in 2024. We walk through one store with you, digitally and on foot, and afterwards you know what the others look like.

PCI DSS evidence for Requirement 11 IT, checkout and access in one visit Free initial consultation
The picture

Roughly one in eight attacks in Germany hits retail

According to an analysis by the security provider Yarix, 12.2% of recorded cyberattacks in Germany in 2024 targeted retail and e-commerce, second only to manufacturing. Unlike hospitals or utilities, retail has no KRITIS sector of its own and no statutory testing duty. The pressure comes from contracts: anyone accepting card payments falls under PCI DSS, and Requirement 11 demands a penetration test every year and after every significant change. Add GDPR for customer accounts and loyalty programmes, plus the NIS2 pressure that large groups pass down to franchise partners and service providers through supplier audits.

Sources: Yarix analysis 2024, cited via security-insider.de; PCI DSS v4, Requirement 11.

  1. Station 01 · Shop floor & checkout

    The checkout sits in public, and so does the network behind it

    What stands out

    Network sockets under the counter, card terminals nobody checks for tampering, a guest Wi-Fi on the same segment as the merchandise system. Someone in a hi-vis vest with a clipboard saying they are swapping the card reader rarely gets stopped.

    What we test

    POS infrastructure and card terminals for tampering, network segmentation between checkout, Wi-Fi and store IT, and the fake service technician scenario as an agreed social engineering test.

  2. Station 02 · Back office & staff room

    The door to the back office is usually just a door

    What stands out

    The transition from shop floor to back office is often a curtain or an unlocked door. Behind it: the store PC with someone logged in, shift plans, sometimes the safe. Temporary staff do not know all their colleagues after two weeks.

    What we test

    Tailgating and pretext scenarios during off-peak hours, screen locks and accounts on the store PC, and a phishing simulation built for seasonal and store staff rather than head office.

  3. Station 03 · Stockroom & network cabinet

    In the stockroom the switch sits next to the pallets

    What stands out

    Unlocked network cabinet, access points within reach, suppliers coming and going through the loading bay without anyone signing them in. The cabinet is rarely the target, but often the route.

    What we test

    Physical access to network and server components, open ports and default passwords on store devices, the connection to merchandise management and head office.

  4. Station 04 · Online shop & head office

    The shop is the store that never closes

    What stands out

    Customer accounts, loyalty programmes, vouchers and returns logic form their own attack space: account takeovers, points fraud, interfaces to payment and logistics, franchise partners with remote access to central systems.

    What we test

    Web application pentest of shop and loyalty programme, permissions at the interfaces to payment providers and stores, third-party access from partners and service providers.

Two orders of magnitude

A group and a single store, the same pattern

Two publicly documented cases from recent years, deliberately far apart in size.

A group

Marks & Spencer

United Kingdom · 2025 · according to company statements and media reports

After a cyberattack, the retailer had to suspend online orders for weeks; product availability and logistics were affected. The company later put the impact on operating profit at around 300 million pounds.

A single store

EDEKA store in Lower Saxony

according to media reports

An employee opened an email containing a supposed job application. Malware installed itself in the background and the store's operations came to a halt. It took neither a corporate group nor a head office, one email was enough.

The attack scales. The defence has to as well.

Based on public reporting. accessgranted was not involved in these incidents.

PCI DSS · Requirement 11

What the auditor wants to see

Requirement 11 of PCI DSS calls for regular testing of the security of systems and networks. For the pentest, that means:

RequirementWhat it meansHow we cover it
At least annuallyOne penetration test per year, plus another after every significant change to infrastructure or applications.Fixed test cadence, re-test after changes
External and internalAttacks from outside against reachable systems and from inside the cardholder data environment.Infrastructure pentest, store network included
Application layerWeb applications and interfaces carrying card or customer data, tested against the common vulnerability classes.Web application pentest of shop and portals
SegmentationProof that the cardholder data environment is genuinely separated from the rest of the network, for example from the guest Wi-Fi in a store.Segmentation test on site and from head office

The report maps every finding to the matching requirement, so you can hand it to your PCI assessor as it is. That retail needs more political attention was recently raised by the CDU Economic Council, as reported by Handelsblatt: many stores, networked checkouts, sensitive payment data.

Ownership

Who at your company owns the back door

In many retail businesses, physical security and IT security sit in two departments that rarely meet. The break-in happens exactly in the gap between them.

Loss prevention / store security

Knows shrinkage, cameras, locking schedules and behaviour at the gate. Sees the network cabinet in the stockroom as an IT topic.

Head of IT / CISO

Knows firewalls, POS software and the shop. Sees the back office door as the store manager's problem.

A combined assessment gives both the same report. Who fixes which item then sits as a line in the action list instead of getting stuck as a question of principle between two departments.

Modules

What belongs in a store assessment

One location, one visit, four angles. Spot checks at further stores on request.

  • Physical Pentest

    Access to back office, stockroom and network cabinet, tampering with card terminals, how staff respond to supposed technicians and suppliers.

  • Social Engineering

    Phishing and pretext scenarios for store and seasonal staff, evaluated per location rather than per company.

  • Web App Pentest

    Online shop, customer accounts, loyalty programme and the interfaces to payment and logistics, following OWASP and mapped to PCI DSS.

  • Infrastructure Pentest

    Store network, segmentation towards the cardholder data environment, remote access by franchise partners and service providers.

Standalone

If staff are the only thing in focus

For chains with high staff turnover, we also run the phishing simulation on its own, evaluated per store, with a report within 48 hours.

Pentesting in retail: your questions

Legally, in most cases no; contractually, almost always yes. Anyone accepting card payments falls under PCI DSS, and Requirement 11 demands an annual penetration test plus one after every significant change. Violations carry contractual penalties and, in the worst case, the loss of card acceptance. On top of that, GDPR covers all customer data in your shop and loyalty programme.
Yes. Active tests on tills and terminals are scheduled for off-peak hours or run on test devices; physical checks happen during normal trading without customers noticing. The store manager or someone you nominate is informed, the rest of the staff deliberately is not, otherwise we would only be testing the announcement.
We build scenarios that fit daily store life: a supposed job application, a delivery notice, a message from head office about shift planning. Results are evaluated per location, so you see where awareness is missing without singling anyone out. The EDEKA case shows that one email is enough.
No. We fully test one or two representative stores and carry the findings across the network, because layout, technology and processes are usually standardised. Spot checks at further locations make sense afterwards, especially at franchise partners running their own equipment.
Yes, as its own station. The shop with customer accounts and loyalty programme is tested as a web application pentest, including the interfaces to payment providers and merchandise management. Account takeovers and voucher or points fraud are common patterns in retail that often go unnoticed for a long time.
It depends on whether one or several stores are in scope, whether shop and head office are added, and whether you need the report mapped to PCI DSS. After the free initial consultation the scope is clear and you get a fixed price that fits retail budget cycles, so it stays plannable after the holiday season too.
The EDEKA store brought down by a job application email was one. Attackers look for the open door, and with standardised tills and store networks it is the same door in many businesses, whatever the size of the chain. A test at one location shows you whether you have it.