Blog · K.10 · Industry

Penetration testing for retail & POS

Retail spreads card data and customer records across the widest attack surface in business — POS terminals in dozens of stores, an e-commerce checkout, loyalty databases, in-store Wi-Fi, back-office systems, all stitched together by APIs. Every one is an entry point, and payment data makes them all worth attacking. Here's why retailers keep getting hit, what PCI and PDPL demand, and exactly what a test should cover.

RetailPOSPCI DSSE-commercePDPL
Retail: POS + Payment Flows · E-commerce Checkout · Loyalty & Customer Data · In-store Networks · PCI DSS + PDPL · Distributed Estate · Segmentation Testing Retail: POS + Payment Flows · E-commerce Checkout · Loyalty & Customer Data · In-store Networks · PCI DSS + PDPL · Distributed Estate · Segmentation Testing
// TL;DR

Retailers are prime targets because they combine card data, large customer/loyalty databases and a sprawling distributed surface — POS across many stores, e-commerce, in-store Wi-Fi, back-office and the APIs linking them. The regulatory drivers are PCI DSS (internal + external + segmentation testing) and the PDPL over customer data, plus franchise/enterprise contracts. A retail test should cover POS & payment flows, the e-commerce checkout, loyalty/customer systems, in-store networks, and cross-channel APIs — with heavy focus on segmentation and business logic (pricing, discounts, returns, loyalty points) where manipulation means direct financial loss. Details below; the online-only angle is in pentesting for e-commerce.

// 01 Why retail is a prime target

Retail has a threat profile few sectors match: directly monetisable data (card details), large customer databases (loyalty, marketing, delivery), and the widest, most distributed attack surface in business. A single chain runs POS terminals across many locations, an e-commerce platform, a loyalty programme, in-store Wi-Fi and back-office systems — each a potential entry point, each patched to a different standard. Attackers exploit exactly this: POS malware scraping card data at the till, e-commerce skimming (Magecart-style scripts on the checkout), card skimming hardware, and credential stuffing against loyalty accounts to drain points and harvest personal data. The distributed estate multiplies the ways in, which is why regulators expect real testing, not a scan.

// 02 The regulatory drivers

Two forces make retail testing non-optional. First, PCI DSS: any retailer that stores, processes or transmits cardholder data must run internal and external penetration tests at least annually and after significant change, plus segmentation testing to prove the cardholder data environment is isolated — the full requirement is in PCI DSS penetration testing requirements. Second, the PDPL (in the UAE, Saudi Arabia and across the region) governs the large customer and loyalty datasets retailers accumulate, driving security testing of those systems. On top sit franchise and enterprise contracts that frequently demand a recent test. For a medium-to-large GCC retailer, the result is a recurring obligation across payments and personal data.

// 03 What to test

01

POS & payments

Terminals, POS software, and the flow from till to payment processor — the card-data core.

02

E-commerce

The online store and checkout — skimming, payment logic and account takeover.

03

Loyalty & customer

Loyalty platforms and customer accounts — credential stuffing and points fraud.

04

In-store network

Store networks, Wi-Fi and segmentation isolating the cardholder data environment.

Beneath these sit the web, API and network layers, and the wireless testing that in-store Wi-Fi demands.

// 04 Business logic: where retailers lose money

Beyond stolen cards, retail has a category of flaw that hits the P&L directly: business-logic abuse. Pricing that can be manipulated in the cart, discount and coupon codes that stack or replay, returns and refunds that can be triggered without a matching purchase, loyalty points that can be minted or transferred, gift cards that can be enumerated or brute-forced — none of these are “classic” vulnerabilities, and a scanner won't find any of them. Yet each is a straight line to financial loss, and at retail transaction volumes a small logic gap becomes a large number quickly. A strong retail test therefore weights business-logic testing heavily across the checkout, loyalty and returns workflows — the kind of logic flaws only human testers reliably surface.

// 05 The distributed-estate challenge

Retail's defining testing problem is scale across locations. You rarely have one environment — you have dozens of stores, possibly across countries, each with POS, network and Wi-Fi, plus central e-commerce and back-office. Testing every till in every branch is neither practical nor necessary; the art is representative scoping: test a representative sample of store configurations, validate the segmentation that keeps stores and the cardholder data environment isolated, and concentrate depth on the central platforms that all stores depend on. Get segmentation wrong and a breach at one poorly-secured branch reaches the whole estate. Engagements follow our standard shape — scoped rules of engagement, manual-led testing, a report mapped to PCI and PDPL — per our methodology.

// 06 Frequently asked questions

Why is retail a target?

It combines high transaction volumes, card data, large customer databases and a sprawling distributed surface — POS across many locations, e-commerce, loyalty, in-store Wi-Fi and back-office. Payment data makes it monetisable and the distributed estate means many entry points. Retailers are repeatedly hit by POS malware, card and e-commerce skimming, and credential stuffing.

What regulations require testing for retailers?

Primarily PCI DSS, which requires internal and external testing at least annually and after significant change plus segmentation testing for anyone handling card data. The regional PDPLs govern the large customer and loyalty databases, and franchise or enterprise contracts often add testing requirements. Most medium and large retailers have a recurring obligation.

What should a retail pentest cover?

POS and payment flows, the e-commerce platform and checkout, loyalty and customer-account systems, in-store networks and Wi-Fi, and cross-channel APIs — across web, API, network and configuration layers. It should weight business-logic testing of pricing, discounts, returns and loyalty points, where manipulation causes direct financial loss.

How is POS testing different from a web pentest?

POS testing extends into the payment ecosystem and physical estate: terminals and their software, the segmentation isolating the cardholder data environment, connections to processors, and POS malware or skimming risk. It combines application, network and configuration testing with a strong PCI focus, and must account for many distributed store locations, so scoping and segmentation validation are central.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Tests retail estates across the GCC — POS, e-commerce, loyalty and in-store networks — with representative scoping, hard segmentation validation, and a focus on the business-logic flaws that hit the P&L.

Retail or omnichannel brand?

We'll test your POS, e-commerce, loyalty and store networks with representative scoping and hard segmentation validation — mapped to PCI DSS and PDPL, focused on the flaws that cost you money.

Scope a retail test → E-commerce testing →