Security · Retail · 4 months
PCI-Ready Security Overhaul
A retailer six months from a failed PCI reassessment. We scoped the cardholder environment down to three accounts, encrypted everything with customer-managed keys, automated evidence collection, and passed with zero compensating controls.
-
Shrink the blast radius
The cardholder environment dropped from sprawl to three tightly-scoped accounts. What the auditor can't reach, you don't have to explain.
-
Encrypt everything, own the keys
Customer-managed keys, enforced by policy-as-code. No unencrypted volume or bucket can survive a pull request.
-
Automate the evidence
Continuous Config rules and GuardDuty findings feed the evidence pack directly — the audit became a reading exercise, not an excavation.
- AWS Control Tower
- KMS
- GuardDuty
- OPA
Audit date circled in red?
Bring me the scope letter — we'll shrink it before the assessor arrives.
Start a project