29 security controls for Indian retailers, and what answers each
What the obligations make you do, the breaches each one would have stopped, what a gateway, marketplace or auditor asks to see — and what answers it.
- 29controls, in four groups
- 21answered by software we shortlist
- 8no software answers
- 9where our catalogue is thin — said plainly
Which controls are whose
Stores-only on the left, online-only on the right, the ones every retailer shares in the middle. Dashed red: no software answers it. Tap a tile to open its card.
- Detect and report inside six hours
- Keep 180 days of logs — and a year for personal data
- Phishing-resistant MFA and SSO for staff
- Email security, DMARC and lookalike-site takedown
- Backups you can restore — offline, and in India for the books
- Patch what is exposed first
- Encrypt and tokenise customer data
- Consent, notices and erasure under DPDP
- Know which vendors hold your customers
- Limit what store and support staff can take
- Verify the caller before any reset
- Decide your PCI scope on purpose
- The six-hour runbook
- Read the breach clauses you have signed
Showing 29 of 29
Stores
5For chains, franchises and anyone with tills, terminals and a store network.
Lock down POS and back-office machines
StoresApplication allow-listing and hardening on POS terminals and store back-office PCs, so only approved software runs.
1 obligation require it1 breach pattern it stops1 guide + 2 products
Lock down POS and back-office machines
StoresApplication allow-listing and hardening on POS terminals and store back-office PCs, so only approved software runs.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Manage handhelds, kiosks and rugged devices
StoresMobile device management with kiosk lockdown for scanners, mPOS, self-checkout and delivery-partner devices.
1 obligation require it1 guide + 3 products
Manage handhelds, kiosks and rugged devices
StoresMobile device management with kiosk lockdown for scanners, mPOS, self-checkout and delivery-partner devices.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Segment the store network and the card environment
StoresThin coverageBranch firewalls or SD-WAN/SASE that keep POS, guest Wi-Fi, CCTV and back office apart — so the card environment stays small.
1 obligation require it1 breach pattern it stops2 guides
Segment the store network and the card environment
StoresThin coverageBranch firewalls or SD-WAN/SASE that keep POS, guest Wi-Fi, CCTV and back office apart — so the card environment stays small.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
Firewalls and SD-WAN are well covered; store Wi-Fi and network access control (Meraki, Aruba, Forescout) are thin.
Shortlist this with us →Filter web and DNS at every store
StoresDNS and web filtering on store networks and devices, blocking known-bad sites and lookalikes.
0 obligations require it1 breach pattern it stops1 guide
Filter web and DNS at every store
StoresDNS and web filtering on store networks and devices, blocking known-bad sites and lookalikes.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Control vendor and franchise access to stores
StoresPrivileged access management and recorded, time-boxed remote sessions for POS vendors, IT contractors and franchise support.
0 obligations require it1 breach pattern it stops2 guides
Control vendor and franchise access to stores
StoresPrivileged access management and recorded, time-boxed remote sessions for POS vendors, IT contractors and franchise support.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Online
6For marketplaces, D2C brands and anyone with a checkout, an app or a seller API.
Web application and API protection, and DDoS
OnlineThin coverageA WAF or WAAP in front of the storefront and its APIs, with DDoS protection for sale days.
1 obligation require it1 breach pattern it stops6 products in our catalogue
Web application and API protection, and DDoS
OnlineThin coverageA WAF or WAAP in front of the storefront and its APIs, with DDoS protection for sale days.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
In our catalogue:
Strong products from six vendors, but no decision guide yet; Imperva and India’s Indusface are not in our catalogue.
Shortlist this with us →Stop bots and account takeover
OnlineThin coverageBot management against credential stuffing, scalping and fake sign-ups, with account-takeover detection on logins.
0 obligations require it2 breach patterns it stops3 products in our catalogue
Stop bots and account takeover
OnlineThin coverageBot management against credential stuffing, scalping and fake sign-ups, with account-takeover detection on logins.
What it is
Why it matters here
What a client or auditor asks to see
What answers it
In our catalogue:
Thin: three dedicated products. HUMAN, Kasada and DataDome are not in our catalogue.
Shortlist this with us →Watch every script on the checkout page
OnlineThin coverageAn inventory, authorisation and integrity check for each payment-page script, with alerts when one changes — PCI DSS 6.4.3 and 11.6.1.
3 obligations require it1 breach pattern it stops2 products in our catalogue
Watch every script on the checkout page
OnlineThin coverageAn inventory, authorisation and integrity check for each payment-page script, with alerts when one changes — PCI DSS 6.4.3 and 11.6.1.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
In our catalogue:
Thin: one dedicated product, plus Cloudflare’s module. Jscrambler, Feroot and c/side are not in our catalogue.
Shortlist this with us →Secure customer logins
OnlineThin coverageCustomer identity (CIAM) with passwordless or risk-based multi-factor login for shoppers and loyalty members.
2 obligations require it2 breach patterns it stops1 guide + 2 products
Secure customer logins
OnlineThin coverageCustomer identity (CIAM) with passwordless or risk-based multi-factor login for shoppers and loyalty members.
What it is
Why it matters here
What a client or auditor asks to see
Required by
What answers it
Also in our catalogue:
Two dedicated customer-identity products; Ping Identity and LoginRadius are not in our catalogue.
Shortlist this with us →Verify sellers, riders and partners
OnlineThin coverageIdentity verification and KYC for marketplace sellers, delivery partners and new merchants.
2 obligations require it1 breach pattern it stops3 products in our catalogue
Verify sellers, riders and partners
OnlineThin coverageIdentity verification and KYC for marketplace sellers, delivery partners and new merchants.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
What answers it
In our catalogue:
KYC is covered; e-commerce order-fraud scoring (Riskified, Forter, SEON) for refund, coupon and cash-on-delivery abuse is not in our catalogue.
Shortlist this with us →Stay up on sale day
OnlineReal-user monitoring, synthetic checks and a CDN that see a checkout slowdown before customers do.
1 obligation require it1 guide + 2 products
Stay up on sale day
OnlineReal-user monitoring, synthetic checks and a CDN that see a checkout slowdown before customers do.
What it is
Why it matters here
What a client or auditor asks to see
Required by
What no software answers
8Procedure, design, contracts and policy — where the 2024–26 retail attacks got in.
Verify the caller before any reset
BothNot a productA help-desk procedure that proves who is calling before a password or MFA reset — especially for admin accounts.
0 obligations require it1 breach pattern it stopsNo software answers it
Verify the caller before any reset
BothNot a productA help-desk procedure that proves who is calling before a password or MFA reset — especially for admin accounts.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Why software does not answer this
This is a procedure, not a tool. Self-service resets with strong verification help, but the control is who the help desk will and won’t believe.
Decide your PCI scope on purpose
BothNot a productChoose how card data flows — redirect, iframe, or your own form; P2PE terminals or not — knowing what each puts in scope.
3 obligations require it1 breach pattern it stopsNo software answers it
Decide your PCI scope on purpose
BothNot a productChoose how card data flows — redirect, iframe, or your own form; P2PE terminals or not — knowing what each puts in scope.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Why software does not answer this
A design decision with your gateway and acquirer. Products then protect whatever you left in scope.
The six-hour runbook
BothNot a productWho tells CERT-In, the gateway, Amazon, ONDC and customers — in what order, inside which clock.
7 obligations require itNo software answers it
The six-hour runbook
BothNot a productWho tells CERT-In, the gateway, Amazon, ONDC and customers — in what order, inside which clock.
What it is
Why it matters here
What a client or auditor asks to see
Why software does not answer this
A plan and a rehearsal. Detection tools start the clock; people meet it.
Read the breach clauses you have signed
BothNot a productKnow the notice windows, audit rights and data rules in your gateway, marketplace, logistics and agency contracts — and write your own into vendors’.
3 obligations require it1 breach pattern it stopsNo software answers it
Read the breach clauses you have signed
BothNot a productKnow the notice windows, audit rights and data rules in your gateway, marketplace, logistics and agency contracts — and write your own into vendors’.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Why software does not answer this
A legal and procurement exercise. No software signs a contract.
Design refunds and returns against abuse
OnlineNot a productReturn, refund and cash-on-delivery rules that make organised abuse expensive — limits, holds, evidence and pattern checks.
0 obligations require it1 breach pattern it stopsNo software answers it
Design refunds and returns against abuse
OnlineNot a productReturn, refund and cash-on-delivery rules that make organised abuse expensive — limits, holds, evidence and pattern checks.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Why software does not answer this
Policy design. Fraud tools score the orders, but the rules decide what a fraudster can extract.
Audit checkout and consent for dark patterns
OnlineNot a productA yearly review of sign-up, checkout and consent screens against the 13 dark patterns — required for e-commerce entities from 2027.
4 obligations require itNo software answers it
Audit checkout and consent for dark patterns
OnlineNot a productA yearly review of sign-up, checkout and consent screens against the 13 dark patterns — required for e-commerce entities from 2027.
What it is
Why it matters here
What a client or auditor asks to see
Why software does not answer this
A review of your own screens. Consent tools record choices; they do not decide whether your design is fair.
Hold franchisees to a minimum
StoresNot a productA security baseline in the franchise agreement — terminals, POS access, patching, who their IT vendor is — and a way to check it.
0 obligations require it1 breach pattern it stopsNo software answers it
Hold franchisees to a minimum
StoresNot a productA security baseline in the franchise agreement — terminals, POS access, patching, who their IT vendor is — and a way to check it.
What it is
Why it matters here
What a client or auditor asks to see
Would have stopped
Why software does not answer this
A contract and an attestation programme. Tools can be mandated in it, but the agreement is the control.
Use validated card terminals
StoresNot a productCard terminals validated under PCI P2PE, and PIN pads approved under PCI PTS — supplied through your payment provider.
1 obligation require it1 breach pattern it stopsNo software answers it
Use validated card terminals
StoresNot a productCard terminals validated under PCI P2PE, and PIN pads approved under PCI PTS — supplied through your payment provider.
What it is
Why it matters here
What a client or auditor asks to see
Required by
Would have stopped
Why software does not answer this
Hardware from your payment operator, not software we sell. Ask your PSO for the validated models.
Guides do the vendor-neutral shortlisting with India pricing. Where no guide exists we name the products in our catalogue that answer the control, and say where that list is thin. General information, not legal advice.
Retail controls, answered
Short answers, each backed by the sources on this page.
Which security controls should a retail chain start with?
The ones every retailer needs (Detect and report inside six hours; Keep 180 days of logs — and a year for personal data; Phishing-resistant MFA and SSO for staff; Email security, DMARC and lookalike-site takedown; Backups you can restore — offline, and in India for the books; Patch what is exposed first; Encrypt and tokenise customer data; Consent, notices and erasure under DPDP; Know which vendors hold your customers; Limit what store and support staff can take), then the store ones: Lock down POS and back-office machines; Manage handhelds, kiosks and rugged devices; Segment the store network and the card environment; Filter web and DNS at every store; Control vendor and franchise access to stores.
What does an online seller need beyond a payment gateway?
A gateway handles the card, not your site. Online sellers also need: Web application and API protection, and DDoS; Stop bots and account takeover; Watch every script on the checkout page; Secure customer logins; Verify sellers, riders and partners; Stay up on sale day.
How do we meet PCI DSS 6.4.3 and 11.6.1 on our checkout?
Keep an inventory of every script on the payment page with a reason for each, authorise and integrity-check them, and alert on unauthorised changes to the page and its security headers at least weekly. Redirecting shoppers to the gateway's own page takes the SAQ A script test off you; an embedded iframe does not.
Which retail security controls can't be bought as software?
Verify the caller before any reset; Decide your PCI scope on purpose; The six-hour runbook; Read the breach clauses you have signed; Design refunds and returns against abuse; Audit checkout and consent for dark patterns; Hold franchisees to a minimum; Use validated card terminals. Procedures, design decisions, policies and contracts: where many 2024 to 2026 retail attacks got in.