What the organization was facing.
The organization accepted payment cards across retail locations, an e-commerce platform and a call centre, and each channel had grown independently. Nobody could produce a definitive map of where cardholder data was stored, processed or transmitted, which meant PCI scope was assumed rather than evidenced. With the v4.0 future-dated requirements becoming mandatory, leadership needed to know what was genuinely in scope before committing to a remediation budget.
The approach.
- 01
Traced cardholder data flows across every payment channel, including third-party processors, call recording systems and support tooling that had never been formally assessed.
- 02
Confirmed merchant level, applicable SAQ and the boundary of the cardholder data environment, then identified systems that were in scope only because of flat network connectivity.
- 03
Ran a gap assessment against PCI DSS v4.0, giving specific attention to the newer requirements: targeted risk analyses, authenticated internal scanning, and client-side script management on payment pages.
- 04
Modelled segmentation and scope-reduction options, quantifying which changes removed the most systems from assessment scope for the least operational disruption.
- 05
Built a remediation roadmap sequenced against the compliance deadline, with owners, dependencies and evidence requirements attached to each item.
What changed.
- 01
A documented, evidence-backed PCI scope replacing the previous assumed boundary.
- 02
A reduced cardholder data environment through targeted segmentation, lowering ongoing assessment effort.
- 03
A remediation plan mapped to the v4.0 deadline, with clear ownership and evidence expectations per control.
Capabilities behind this engagement.
PCI DSS Readiness & Assessment
Scope discovery, gap assessment and remediation planning for cardholder data environments.
Explore service →Vulnerability Management
Ongoing vulnerability assessment, prioritization and remediation to reduce exploitable weaknesses.
Explore service →Compliance & Cyber Insurance Readiness
Translate requirements into practical controls, evidence and improvements.
Explore service →