Recent Breaches
Breaches
View All →
Retail

POS Network Segmentation and Payment Path Control

Retail networks span thousands of locations, each processing payment card data through point-of-sale systems connected to corporate infrastructure. A single compromised store can provide a path to every other location in the estate.

Back to Control
Control

Retail

When a guest Wi-Fi access point and a payment terminal share the same network, every customer browsing the internet is a potential path to payment card data.

100%

Payment network isolation from store IT

Zero

Persistent vendor paths to POS systems

4

Store network zones with independent governance

Full

PCI DSS 4.0 network segmentation evidence

The Challenge

Retail networks are distributed and high-value targets.

POS Compromise

Point-of-sale systems across thousands of locations create a massive attack surface for payment card data theft.

Flat Store Networks

Many retail locations share a single network for POS, back-office, CCTV, and guest Wi-Fi, enabling lateral movement from any entry point.

Supply Chain Risks

POS software vendors, payment processors, and maintenance contractors each create persistent pathways into the payment environment.

The Scenario

Scenario: Estate-Wide POS Compromise

Attackers compromise a POS software update server and distribute a modified update containing memory-scraping malware. The update propagates to 1,200 stores over a routine maintenance cycle. The malware captures payment card data from POS memory and exfiltrates it through the store internet connection, which shares the same network as the POS systems. Over eight weeks, 4.3 million payment card numbers are stolen. With Firevault Control, POS networks are physically separated from store internet connectivity. The malicious update cannot exfiltrate data because the POS network has no path to the internet. Software updates are delivered through controlled, authorised transfer windows with integrity verification.

"Our PCI assessor told us our segmentation was compliant. But it was VLAN-based. When the attackers compromised the switch management interface, every VLAN boundary in the estate became meaningless."

Module deployment · retail network

Where each Control module is deployed across stores, e-commerce, payments and vendors.

Retail estates carry an internet edge, a corporate office, store and POS systems, an e-commerce platform and the cardholder data environment that handles payments. Control puts a real boundary at every change of trust.

Grounded in PCI DSS v4 network segmentation guidance and NCSC retail sector guidance.

R0

Internet / Customers

External

Web
Mobile app
FirebreakValidate

External traffic stops at the perimeter.

R1

Perimeter / DMZ

DMZ · trust boundary

WAF
Reverse proxy
Isolate

Corporate sits behind its own boundary.

R2

Corporate IT

IT

Office
SOC / SIEM
HQ identity
IsolateValidate

Corporate cannot reach e-commerce on its own terms.

R3

E-commerce

IT

Order mgmt
Web apps
Fulfilment
RelayLock

Store networks are reachable on a defined route.

R4

Stores and POS

Field

Tills
Back-of-house
Store network

Hundreds of physical sites.

Hundreds of physical sites.

IsolateLockExecute

Payments segmented to PCI scope.

R5

Payments (CDE)

Data

Payment switch
Tokenisation

Cardholder data environment, PCI in scope.

Cardholder data environment, PCI in scope.

RelayFirebreakUnlink

Vendor and partner access opens on a schedule.

VND

Vendor zone

DMZ · trust boundary

MSP
Payment partners
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Transaction archives, customer records, evidence and any data you need to keep recoverable.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
RelayTime-bound path
LockNamed access
ExecuteApproved action
UnlinkRemove trust
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Firebreak

    On the R0 to R1 link and the vendor link

    Real hardware off switches on the public and vendor boundaries, ready to sever the live path during a live incident.

  2. Validate

    On the R0 to R1 link and the R2 to R3 link

    Inbound traffic and cross-tier requests are checked for origin and integrity before they progress.

  3. Isolate

    On the R1 to R2, R2 to R3 and R4 to R5 links

    Corporate, e-commerce, stores and payments sit on their own physical fabrics, in line with PCI segmentation expectations.

  4. Lock

    On the R3 to R4 link and the R4 to R5 link

    Store and payments access ties to named users with the right entitlement.

  5. Execute

    On the R4 to R5 link

    Cross-system actions require approval. Execute holds the action until that approval is in place.

  6. Relay

    On the R3 to R4 link and the vendor link

    Store and vendor paths open for the window of work and not a minute more.

  7. Unlink

    On the vendor link

    When a vendor relationship ends, Unlink removes the persistent connection and the inherited trust.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Sovereign Payment Data

All payment system configurations and cardholder data paths remain within the agreed jurisdiction in secured Firevault Bunkers.

Multi-Party Update Control

POS software updates and configuration changes require sign-off from both IT operations and security teams before deployment.

PCI DSS 4.0 Evidence

Automated compliance logging generates continuous evidence for PCI DSS 4.0 network segmentation requirements across the entire estate.

Cellular Failover

Out-of-band management via cellular connectivity ensures control over store networks independent of primary WAN connections.

Estate-Wide Audit Trail

Every access, update, and authorisation across all locations is recorded in centralised, tamper-proof logs.

Rapid Store Recovery

Verified baselines of POS configuration enable rapid restoration of compromised stores without relying on production systems.

Demo to Live

Adoption Guide

Step 1

Estate Network Assessment

Audit network architecture across representative store locations to identify payment path exposure and segmentation gaps.

Step 2

Store Zone Architecture

Design standardised store network zones for POS, back-office, CCTV, and guest access with Control modules at each boundary.

Step 3

Pilot Store Deployment

Deploy in a representative group of stores with full payment path isolation, controlled updates, and compliance logging.

Step 4

Estate-Wide Rollout

Phased deployment across all locations with centralised management, verified configuration baselines, and continuous PCI DSS evidence generation.

Step 1

Estate Network Assessment

Audit network architecture across representative store locations to identify payment path exposure and segmentation gaps.

Step 2

Store Zone Architecture

Design standardised store network zones for POS, back-office, CCTV, and guest access with Control modules at each boundary.

Step 3

Pilot Store Deployment

Deploy in a representative group of stores with full payment path isolation, controlled updates, and compliance logging.

Step 4

Estate-Wide Rollout

Phased deployment across all locations with centralised management, verified configuration baselines, and continuous PCI DSS evidence generation.

Questions

Frequently Asked

Retail blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Retail

    Physically isolate retail POS and payment paths from store IT to drastically reduce PCI DSS scope and contain breaches across the estate.

    © 2026 Firevault Limited. Disconnect to Protect®