A PCI assessment finding
Usually on shared accounts, MFA into the cardholder environment, or segmentation.
Retail identity is a numbers problem. Hundreds of locations, thousands of seasonal staff who arrive in October and leave in January, a point-of-sale estate that has to work at 6pm on a Saturday, and a cardholder data environment that PCI-DSS expects you to keep separate from all of it. The retailers breached in recent years have one thing in common with Target a decade earlier: the attackers did not break in. They logged in.
The accounts that outlive the employment are the ones that get used later.
That is standing privilege in hundreds of locations.
PCI-DSS applies to anyone storing, processing or transmitting card data, and Requirements 7 and 8 are where identity lives: restrict access to cardholder data by business need to know, and identify and authenticate every user individually. No shared accounts in the cardholder data environment. MFA for all access into it. Access reviews at least every six months. And the segmentation that keeps the cardholder environment separate has to be tested, not assumed — which is PCI penetration testing.
The CISO or CIO owns the program; the finance function usually signs the attestation of compliance, because a lapse is a merchant-agreement problem before it is a security one. Where an attestation is the trigger, that starts with a compliance readiness assessment. Point-of-sale security specifically — the accounts and access paths around the POS estate — is where the retail-specific work sits.
The systems we secure. Point-of-sale and payment systems. E-commerce platforms and the customer identity behind them. Store networks and the shared devices on them. Supply chain and inventory systems. Loyalty and customer data platforms. Headquarters directories and cloud. Platform names are trademarks of their respective owners.
The single control that matters most in retail is the one that removes access on the last day of employment, automatically, for thousands of people at once. That is lifecycle automation driven from the HR or workforce management system, and it is IGA implementation work. The role model for retail is simpler than most sectors — store associate, shift lead, store manager, regional — which is why phase one tends to be faster here than in finance or healthcare. What takes the time is the number of locations, not the number of roles.
Standing privilege in stores is the other half: store-manager local admin removed and elevation granted for approved tasks, which is endpoint privilege management under PAM implementation. For smaller and franchise estates, KeeperPAM fits the store footprint better than an enterprise platform.
Usually on shared accounts, MFA into the cardholder environment, or segmentation.
A credential that should have been dead and was not.
The realization that the seasonal hiring wave is six weeks away and last year's accounts are still active.
Because the first step into a store network is so often a phishing email to a manager, email security and security awareness training sit close to this sector, and the POS estate is a standing candidate for a managed SOC.
By automating the whole lifecycle from the workforce system. Hire creates the account with the right store-level access, termination removes it the same day, and nobody has to file a ticket in either direction. The volume is exactly why it cannot be manual.
Yes. Individual authentication into a shared device — badge or PIN — takes a second and attributes every action to a person. Shared logins persist because individual ones are slow; make them fast and the problem goes.
Brokered, recorded, scoped to the system they maintain, and expired at grant. The vendor never holds a credential to your network, which is the difference between the Target breach and a non-event.
Requirement 8 does, for anyone with access to the cardholder data environment. Shared or generic accounts there are a finding, and a QSA will look for them.

PAM secures the accounts with the most system power. Here's what privileged access management does and why attackers go after these credentials first.
Jul 28, 2026
Most CyberArk PAM comparisons are written by vendors selling against it. Here is what actually differs, from a team that deploys these platforms.
Aug 25, 2026
A password vault encrypts and centralizes credentials so only authorized users can access them — a major step up from spreadsheets or sticky notes.
Aug 14, 2026A free audit is a 30-minute review of your privileged, shared and vendor accounts by a certified engineer, with the findings in writing. The Retail blind spot brief covers what recent retail breaches have in common and how to check your own estate.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.