PCI DSS 4.0 and Data in Motion: The Security Gap Many Retailers Still Miss

August 11, 2026 | Innovation, Resilience, Security, Transformation

Read the Story

PCI DSS 4.0 has pushed payment security up the boardroom agenda. Most retailers have responded by tightening the obvious things: who can reach cardholder data, how it is stored, how systems are monitored. All of that matters. But one gap gets missed again and again, and it hides in the space between systems. The risk is not just the data sitting in a database. It is the data on the move.

What is data in motion security?

Data in motion security is the practice of protecting information while it travels between systems, rather than while it sits in storage. Data at rest lives in a database or on a disk. Data in motion is in transit, moving from one place to another.

In retail, that journey is constant. Card and payment data travels from a POS terminal or checkout to a payment gateway, an acquirer, a data centre or the cloud, across whatever network sits in between. Encrypting stored data is now well understood. Protecting payment data at every step of that journey is where many retailers still fall short.

Why PCI DSS 4.0 sharpens the focus on data in transit

PCI DSS 4.0 raised expectations across encryption, key management, monitoring and validation. Requirement 4 is explicit: cardholder data must be protected with strong cryptography whenever it is transmitted across open or public networks. You can read the standard itself on the PCI Security Standards Council site.

The message is hard to miss. Encryption in transit is no longer optional or assumed. It is expected, and it is tested. Sitehop supports these objectives, though full PCI DSS compliance always remains the retailer’s own responsibility.

The retail blind spot: a sprawling estate, data everywhere

Modern retail runs on a wide, distributed estate. POS terminals, self-checkout, kiosks, ATMs, e-commerce platforms and mobile apps all handle payment data, and all of it has to move: between stores and head office, between sites and data centres, out to payment processors, across MPLS, the public internet, 5G and private networks.

Every one of those links is a place where data in motion could be intercepted. Attackers understand that endpoints are increasingly well defended, so the connections between them become the target. The more places data travels, the more the gaps multiply.

How encryption and network segmentation close the gap

Two mechanisms do most of the heavy lifting here.

The first is strong, end-to-end encryption. When payment data is encrypted for its whole journey, anyone who intercepts it finds nothing usable, only scrambled traffic. The data protects itself, wherever it goes.

The second is network segmentation. By dividing the network into separate zones and keeping payment systems apart from everything else, network segmentation limits how far an attacker can move and shrinks the area that must be secured and audited. It also helps reduce PCI DSS scope, which lowers both cost and complexity.

Encryption protects the data itself. Network segmentation controls where it can travel. Strong data in motion security needs both.

 

Used together, encryption and network segmentation turn a flat, open estate into something far harder to exploit.

Building data in motion security that lasts

The threat does not stand still, so the protection cannot either.  Encrypted traffic captured today could be stored and broken later, once quantum computing matures. That is why crypto-agility matters: the ability to update ciphers and keys without ripping out equipment across hundreds of stores. Managing that centrally, with consistent policy and key control at scale, is what keeps a large retail estate protected as standards evolve.

Closing the gap

Stored data is only half the picture. The retailers who take PCI DSS 4.0 seriously are the ones giving data in motion security the same attention they already give data at rest.

Sitehop protects payment data wherever it moves, with end-to-end encryption across any network, centralised policy and key management, and a crypto-agile, PQC-ready design that supports PCI DSS 4.0 objectives without disrupting stores or slowing payments. To see how it works at the edge, where payment data first meets the network, read how SAFEcore Edge secures data from the field to HQ.

 

Close the data in motion gap across your payment estate. Book a Sitehop demo to see how encryption and segmentation protect payment data end to end.

Book a Sitehop demo to see how end-to-end encryption keeps payment data safe across every store, network and payment system.

Or call us: +44 (0)114 478 2366

Sitehop.

Sitehop. Engineered for speed. Built for the future.

Payment Security: Customers Don’t Buy Compliance. They Buy Trust.

July 27, 2026 | Innovation, Resilience, Security, Transformation

Read the Story

No shopper ever chose a store because it passed its last PCI DSS audit. They choose you because the checkout is quick, the app remembers their details, and nothing about handing over a card makes them pause. That pause, or the absence of it, is where retail is won and lost. Underneath it sits something customers rarely name but always feel: payment security. It is the quiet foundation of customer trust.

 

Compliance is the floor, not the finish line

Retailers put enormous effort into standards like PCI DSS 4.0, and they should. The bar is higher than ever, with tougher expectations for encryption, key management and monitoring. But compliance is the minimum you must meet to be allowed to take payments. It does not capture how safe your customers actually are, or how safe they feel.

Food hygiene works the same way. A passing inspection means a kitchen meets the rules. It does not, by itself, make anyone love the restaurant. Trust is built on everything a customer experiences, and it can be lost in a single bad moment.

 

Compliance is the minimum you must do to take payments. Trust is the reason customers come back.

What customers are really handing you

Every transaction is a small act of faith. Tap a card, open your app, check out online, and a person is giving you data that could be used against them, on the understanding that you will keep it safe. That understanding now stretches across a far wider surface than it once did:

  • POS terminals and self-checkout on the shop floor
  • Kiosks and ATMs
  • E-commerce sites and mobile apps
  • The third-party links and networks tying them all together

Every one of these is a place where payment data moves. And every point where data moves is a point where it could be exposed. Customers never see this complexity. They simply expect it to work, safely, every single time. That expectation is customer trust in its purest form.

Why a breach costs far more than a fine

When payment security fails, the fine is rarely the worst of it. Penalties hurt, but they are finite. The damage that lingers is to reputation. News of a breach travels further than any campaign you could buy, and the customers who leave are often the loyal, high-value ones who felt personally let down.

The pattern is familiar to anyone in retail. Trust is earned slowly and lost quickly.

Winning a customer’s trust takes years. Losing it can take a single breach.

A breach flips your most valuable asset, customer confidence, into your heaviest liability.

Payment security is how trust is kept

If trust is the goal, payment security is how you protect it every day. The most overlooked part is data in motion: the payment information travelling between tills, stores, data centres and processors. Firewalls guard the edges, but the data itself needs protecting while it moves, right out to the edge where payments actually happen.

This is where strong, always-on encryption earns its keep. When payment data is encrypted from end to end, anyone who intercepts it finds nothing they can use. Done well, that protection runs silently in the background, without slowing the checkout or adding hassle for store teams. Customers get the two things they came for at once: speed and safety.

Building trust that outlasts the checklist

The retailers who will still be trusted in five years are already looking past today’s requirements. Threats change, and so does cryptography. Post-quantum computing is coming, and the encrypted data captured today could be the target tomorrow. Building on encryption that can adapt, without tearing out every terminal, is how a brand keeps its promise to customers for the long haul, not just the current audit cycle.

That is the real prize. Not a certificate on the wall, but a customer who never thinks twice about paying you.

 

Secure payments, protected trust

Compliance will always matter. It is where the conversation starts, though, not where it ends. The retailers who pull ahead treat payment security as the foundation of customer trust and brand reputation, rather than a box to tick once a year.

Sitehop helps retailers protect payment data wherever it moves, supporting PCI DSS 4.0 objectives today and a post-quantum future tomorrow, all without slowing payments or disrupting stores.

 

 

Protect your customers’ trust, from the checkout to the core.

Book a Sitehop demo to see how end-to-end encryption keeps payment data safe across every store, network and payment system.

Or call us: +44 (0)114 478 2366

Sitehop.

Sitehop. Engineered for speed. Built for the future.

Network Segmentation: Preventing a Single Breach from Becoming a Business-Wide Incident

June 22, 2026 | Innovation

Read the Story

Understanding Network Segmentation as a Cyber Security Architecture
The Core Concept of Network Segmentation

Network segmentation is the practice of dividing a network into smaller, separated zones and controlling what is allowed to pass between them. Instead of one large, open environment where any device can talk to any other, you create boundaries that reflect how the business actually works, separating payment systems from office laptops, or industrial controllers from email servers. Each zone communicates only with what it genuinely needs to reach, and nothing more.

The opposite of this is the flat network, a single connected space that links users, applications, servers and devices with few internal controls. Flat networks are simple to run, and for a long time they were just as simple to attack. Segmentation replaces that openness with structure. It extends the principle of least privilege beyond individual user accounts to the network itself, so that access is earned rather than assumed. Done well, the role of network segmentation in cyber security becomes foundational, because it shapes how far any problem can travel before it is stopped.

How Attackers Exploit Unsegmented Networks Through Lateral Movement

Lateral movement is the stage of an attack where an intruder, having gained an initial foothold, works their way toward more valuable systems. It rarely makes the news, yet it is often where a minor incident becomes a major one. The first machine an attacker compromises is seldom the one they want. The credentials on a marketing laptop, or the access tied to a third-party maintenance account, are simply a way in.

From there, attackers exploit the trust that flat networks extend so freely. They reuse harvested credentials, abuse legitimate administrative tools, and follow open pathways between systems that were never meant to be reachable from one another. A compromised endpoint becomes a launchpad. A single supplier connection becomes a route into core infrastructure.

This is why ransomware operators treat lateral movement as the main event rather than an afterthought. Before they encrypt anything or make a single demand, they spend time mapping the network, escalating privileges and reaching backups and critical servers, precisely so that the eventual damage is as wide and as painful as possible. The further they travel unseen, the stronger their position. Limiting that movement is therefore central to breach containment, and to cyber resilience as a whole.

Network Segmentation and Breach Containment
Reducing the Blast Radius of a Cyberattack

Security teams increasingly talk about the blast radius of an incident: how much of the organisation a single compromise can affect. Segmentation is one of the most direct ways to shrink it. When a network is divided into well-defined zones, a breach in one area does not hand over access to the rest. The intruder is held within a much smaller space, and defenders gain the time and room to respond.

The consequences of getting this wrong are measured in more than technical terms. Uncontrolled lateral movement turns a contained problem into operational paralysis, regulatory exposure and lasting reputational harm, and recovery grows slower and more expensive when every system is potentially in scope. A segmented network changes the question from how do we recover the whole business to how do we isolate and restore one zone, which is a far more survivable place to start

Security Zones and the Compartmentalisation Principle

The practical building block of segmentation is the security zone, a grouping of systems that share a function, a risk level or a degree of sensitivity. Payment environments, operational systems, guest networks and third-party access areas are common examples, each separated according to what it does and what it would cost the business if it were lost.

This is compartmentalisation, the same principle that puts watertight bulkheads in a ship’s hull. If one compartment floods, the vessel stays afloat because the water cannot spread. Applied to a network, it means a breach in a guest Wi-Fi zone has no path into a payment system, and a compromised supplier link cannot reach the systems that run the business. When these boundaries are drawn to match compliance requirements and data classifications as well as business processes, they cut disruption and recovery costs at the same time as satisfying auditors.

Network Segmentation and Zero Trust

Segmentation also underpins one of the most significant shifts in modern security thinking. Zero Trust moves away from the old perimeter-based model, where anything inside the network was broadly trusted, toward continuous verification, where no user, device or application is trusted by default.

For that model to mean anything, trust has to be removed from the network itself, and segmentation is what removes it. By controlling which systems can communicate, and forcing every interaction to be justified, segmentation becomes the mechanism that enforces Zero Trust policy rather than leaving it as an aspiration. The two ideas reinforce each other. Zero Trust sets the rule that nothing is trusted implicitly; segmentation is how that rule is made real on the wire.

Network Segmentation Examples Across Critical Industries

Some of the clearest network segmentation examples come from industries where a single breach can halt operations or expose highly sensitive data. The principle stays constant, but the way it is applied shifts with the environment.

 

Retail and Payment Environments

In retail, the priority is keeping payment systems away from everything else. Point-of-sale infrastructure, self-service kiosks and third-party retail technology are isolated from corporate networks, store operations and guest Wi-Fi, so that a compromise at the store level cannot reach cardholder data or ripple out into wider operations. The same separation supports compliance: by tightly defining the cardholder data environment, segmentation reduces the scope of PCI DSS assessments while making the whole estate more resilient.

 

Financial Services

Financial institutions run some of the most interconnected environments in existence, which is exactly why they segment so carefully. Customer-facing applications, trading platforms and core banking systems are kept apart, so that an attacker who reaches one cannot move freely into the others. Protecting transaction flows, customer records and critical financial infrastructure in this way limits the spread of any single attack and supports the operational resilience that regulators and customers now expect.

 

Telecommunications

Telecommunications providers face the added pressures of scale and availability. Operational networks carrying live services are separated from business systems and management platforms, so that a compromise in one cannot disrupt the other. Across highly distributed communications infrastructure, where uptime is non-negotiable, segmentation protects critical systems while keeping services running.

 

Operational Technology (OT)

In industrial settings, segmentation draws a firm line between operational technology and corporate IT. Industrial control systems are isolated from office networks, and supplier, contractor and remote access into operational environments is tightly managed. The aim is to ensure that an IT compromise, a phished email or an infected laptop, cannot reach the systems that run production or critical infrastructure. Good IT/OT separation achieves this without interfering with the operational processes themselves.

 

Building an Effective Network Segmentation Strategy
Choosing the Right Segmentation Approach

There is no single correct way to segment a network. Traditional segmentation divides it into broad zones. Microsegmentation applies far more granular controls, down to individual workloads. Hardware-enforced segregation provides the strongest physical separation between environments. Choosing between them is a matter of matching the model to the business: its risk profile, its operational constraints and the sensitivity of what is being protected.

For many environments, software-defined controls are sufficient and bring welcome flexibility. In the highest-security settings, where the consequences of a breach are severe, stronger isolation is warranted. The skill lies in balancing security against manageability and performance, and in being honest about the limits of each approach. The right network security solutions are the ones that deliver the separation a given environment actually needs, without creating more complexity than the team can sustain.

 

Managing Complexity Across Distributed Environments

Segmentation is easy to describe and hard to maintain. Modern infrastructure spans cloud platforms, data centres, branch offices and the network edge, and policy has to stay consistent across all of them. Third-party access has to be granted without quietly opening new pathways between systems. Visibility has to keep pace as the estate grows.

The recurring danger is segmentation decay, the slow erosion of boundaries as networks expand, exceptions accumulate and temporary rules quietly become permanent. A segmentation strategy is not a one-off project but an ongoing discipline, and the architectures that hold up best are those designed to stay coherent as everything around them changes.

 

Compliance, Governance and Risk Reduction

Segmentation carries real weight in compliance and governance too. By isolating critical systems, it can reduce the scope of regulatory assessments, with PCI DSS the clearest example: a well-defined cardholder data environment is smaller, cheaper and easier to prove secure. Frameworks such as DORA and NIS2 place growing emphasis on resilience and the protection of critical systems, and segmentation gives organisations a tangible way to demonstrate stronger governance over sensitive assets, data flows and access.

 

Beyond Segmentation: Securing Data Between Security Zones
Why Segmentation Alone Is Not Enough

For all its value, segmentation has a clear limit. It governs where traffic can go, not whether that traffic is protected in its own right. It controls the routes, but it does not secure the cargo. Data moving between sites, systems and applications still needs protection in transit, so that an attacker who does manage to intercept an internal connection finds nothing usable. This is why segmentation works best as one layer within a defence-in-depth strategy, paired with strong encryption so that the boundaries and the data crossing them are both defended.

 

Building Long-Term Security Resilience

Resilience is not only about today’s threats. Security architectures need to evolve as cryptography, regulation and attacker capability change, which is why crypto-agility matters: the ability to adopt new algorithms without tearing out and replacing infrastructure. The growing focus on post-quantum readiness makes this more pressing still, since data intercepted today could be exposed by future advances in computing. The goal is to protect critical communications without adding operational complexity or performance bottlenecks, and to build architectures that stay effective as the landscape shifts rather than needing wholesale replacement each time it does.

 

From Breach Prevention to Breach Containment
Designing Networks That Limit the Impact of Compromise

The most resilient organisations have stopped assuming they can keep every attacker out. They plan instead for the moment one gets in, and they design their networks so that the moment is survivable. That means limiting lateral movement, shrinking the blast radius, and combining segmentation with encryption and resilient architecture so that the inevitable incident stays small.

The objective is simple to state and demanding to achieve: a single compromised user, device, application or location should never be able to bring down the whole business. Segmentation is what holds that line. It is the difference between an incident contained to one zone and a crisis that spreads across the organisation.

 

Strengthen breach containment across your network.

Book a Sitehop demo to see how hardware-enforced segregation and crypto-agile encryption keep a single breach from becoming a business-wide incident.

 

Request a demo if you’d like to see our platform in action.

Stay in touch with Sitehop’s latest thinking, subscribe to our PQC Bulletin.

Or call us: +44 (0)114 478 2366

Sitehop.

Sitehop. Engineered for resilience. Built for the life.