Applied IAM

Identity Security for Retail

Retail identity is a numbers problem. Hundreds of locations, thousands of seasonal staff who arrive in October and leave in January, a point-of-sale estate that has to work at 6pm on a Saturday, and a cardholder data environment that PCI-DSS expects you to keep separate from all of it. The retailers breached in recent years have one thing in common with Target a decade earlier: the attackers did not break in. They logged in.

PCI-DSS Requirements 7 and 8Point of saleSeasonal turnoverVendor access
The seasonSeasonal turnover
Staff employedAccounts still active

The accounts that outlive the employment are the ones that get used later.

The four problems

Why retail access is hard to govern

  • Seasonal turnover. Staff hired for the peak season and gone three months later, in numbers that swamp any manual offboarding process. The accounts that outlive the employment are the ones that get used later.
  • Shared store logins. A till, a back-office PC and a handheld that everyone on shift uses, under a login nobody owns. Convenient at the till, unattributable in an investigation, and non-compliant under PCI-DSS Requirement 8.
  • Store managers as administrators. In a franchise or multi-brand estate, the store manager often holds local admin on everything in the building, because there is nobody else to hold it. That is standing privilege in hundreds of locations.
  • Vendors in the estate. The HVAC contractor, the POS maintenance company, the e-commerce agency — each with remote access into the store network, granted once and rarely reviewed. The Target breach began with an HVAC vendor's credential, and the pattern has not changed.
Shared store loginStore manager as administratorVendor in the estate
One store, opened upSeasonal staff: gone three months later
A login nobody owns
TillBack-office PCHandheld
Store managerLocal admin on everything in the building
Remote access, granted once
HVAC contractorPOS maintenance companyE-commerce agency
Hundreds of locations
Headquarters
Directories and cloudPoint-of-sale and payment systemsE-commerce platformsSupply chain and inventory systemsLoyalty and customer data platforms

That is standing privilege in hundreds of locations.

The framework

What PCI-DSS requires of access control

PCI-DSS applies to anyone storing, processing or transmitting card data, and Requirements 7 and 8 are where identity lives: restrict access to cardholder data by business need to know, and identify and authenticate every user individually. No shared accounts in the cardholder data environment. MFA for all access into it. Access reviews at least every six months. And the segmentation that keeps the cardholder environment separate has to be tested, not assumed — which is PCI penetration testing.

The CISO or CIO owns the program; the finance function usually signs the attestation of compliance, because a lapse is a merchant-agreement problem before it is a security one. Where an attestation is the trigger, that starts with a compliance readiness assessment. Point-of-sale security specifically — the accounts and access paths around the POS estate — is where the retail-specific work sits.

The systems we secure. Point-of-sale and payment systems. E-commerce platforms and the customer identity behind them. Store networks and the shared devices on them. Supply chain and inventory systems. Loyalty and customer data platforms. Headquarters directories and cloud. Platform names are trademarks of their respective owners.

The control that matters

Offboarding that keeps up with the calendar

The single control that matters most in retail is the one that removes access on the last day of employment, automatically, for thousands of people at once. That is lifecycle automation driven from the HR or workforce management system, and it is IGA implementation work. The role model for retail is simpler than most sectors — store associate, shift lead, store manager, regional — which is why phase one tends to be faster here than in finance or healthcare. What takes the time is the number of locations, not the number of roles.

Standing privilege in stores is the other half: store-manager local admin removed and elevation granted for approved tasks, which is endpoint privilege management under PAM implementation. For smaller and franchise estates, KeeperPAM fits the store footprint better than an enterprise platform.

Triggers

Where a program usually starts

A PCI assessment finding

Usually on shared accounts, MFA into the cardholder environment, or segmentation.

An incident involving a vendor or a former employee

A credential that should have been dead and was not.

Peak season approaching

The realization that the seasonal hiring wave is six weeks away and last year's accounts are still active.

Because the first step into a store network is so often a phishing email to a manager, email security and security awareness training sit close to this sector, and the POS estate is a standing candidate for a managed SOC.

FAQs

What retail teams ask first

By automating the whole lifecycle from the workforce system. Hire creates the account with the right store-level access, termination removes it the same day, and nobody has to file a ticket in either direction. The volume is exactly why it cannot be manual.

Yes. Individual authentication into a shared device — badge or PIN — takes a second and attributes every action to a person. Shared logins persist because individual ones are slow; make them fast and the problem goes.

Brokered, recorded, scoped to the system they maintain, and expired at grant. The vendor never holds a credential to your network, which is the difference between the Target breach and a non-event.

Requirement 8 does, for anyone with access to the cardholder data environment. Shared or generic accounts there are a finding, and a QSA will look for them.

See which accounts outlived the season

A free audit is a 30-minute review of your privileged, shared and vendor accounts by a certified engineer, with the findings in writing. The Retail blind spot brief covers what recent retail breaches have in common and how to check your own estate.