PCI DSS 4.0 and Data in Motion: The Security Gap Many Retailers Still Miss
August 11, 2026 | Innovation, Resilience, Security, Transformation
PCI DSS 4.0 has pushed payment security up the boardroom agenda. Most retailers have responded by tightening the obvious things: who can reach cardholder data, how it is stored, how systems are monitored. All of that matters. But one gap gets missed again and again, and it hides in the space between systems. The risk is not just the data sitting in a database. It is the data on the move.
What is data in motion security?
Data in motion security is the practice of protecting information while it travels between systems, rather than while it sits in storage. Data at rest lives in a database or on a disk. Data in motion is in transit, moving from one place to another.
In retail, that journey is constant. Card and payment data travels from a POS terminal or checkout to a payment gateway, an acquirer, a data centre or the cloud, across whatever network sits in between. Encrypting stored data is now well understood. Protecting payment data at every step of that journey is where many retailers still fall short.
Why PCI DSS 4.0 sharpens the focus on data in transit
PCI DSS 4.0 raised expectations across encryption, key management, monitoring and validation. Requirement 4 is explicit: cardholder data must be protected with strong cryptography whenever it is transmitted across open or public networks. You can read the standard itself on the PCI Security Standards Council site.
The message is hard to miss. Encryption in transit is no longer optional or assumed. It is expected, and it is tested. Sitehop supports these objectives, though full PCI DSS compliance always remains the retailer’s own responsibility.
The retail blind spot: a sprawling estate, data everywhere
Modern retail runs on a wide, distributed estate. POS terminals, self-checkout, kiosks, ATMs, e-commerce platforms and mobile apps all handle payment data, and all of it has to move: between stores and head office, between sites and data centres, out to payment processors, across MPLS, the public internet, 5G and private networks.
Every one of those links is a place where data in motion could be intercepted. Attackers understand that endpoints are increasingly well defended, so the connections between them become the target. The more places data travels, the more the gaps multiply.
How encryption and network segmentation close the gap
Two mechanisms do most of the heavy lifting here.
The first is strong, end-to-end encryption. When payment data is encrypted for its whole journey, anyone who intercepts it finds nothing usable, only scrambled traffic. The data protects itself, wherever it goes.
The second is network segmentation. By dividing the network into separate zones and keeping payment systems apart from everything else, network segmentation limits how far an attacker can move and shrinks the area that must be secured and audited. It also helps reduce PCI DSS scope, which lowers both cost and complexity.
Encryption protects the data itself. Network segmentation controls where it can travel. Strong data in motion security needs both.
Used together, encryption and network segmentation turn a flat, open estate into something far harder to exploit.
Building data in motion security that lasts
The threat does not stand still, so the protection cannot either. Encrypted traffic captured today could be stored and broken later, once quantum computing matures. That is why crypto-agility matters: the ability to update ciphers and keys without ripping out equipment across hundreds of stores. Managing that centrally, with consistent policy and key control at scale, is what keeps a large retail estate protected as standards evolve.
Closing the gap
Stored data is only half the picture. The retailers who take PCI DSS 4.0 seriously are the ones giving data in motion security the same attention they already give data at rest.
Sitehop protects payment data wherever it moves, with end-to-end encryption across any network, centralised policy and key management, and a crypto-agile, PQC-ready design that supports PCI DSS 4.0 objectives without disrupting stores or slowing payments. To see how it works at the edge, where payment data first meets the network, read how SAFEcore Edge secures data from the field to HQ.
Close the data in motion gap across your payment estate. Book a Sitehop demo to see how encryption and segmentation protect payment data end to end.
Book a Sitehop demo to see how end-to-end encryption keeps payment data safe across every store, network and payment system.
Or call us: +44 (0)114 478 2366
Sitehop.
Sitehop. Engineered for speed. Built for the future.
Payment Security: Customers Don’t Buy Compliance. They Buy Trust.
July 27, 2026 | Innovation, Resilience, Security, Transformation
No shopper ever chose a store because it passed its last PCI DSS audit. They choose you because the checkout is quick, the app remembers their details, and nothing about handing over a card makes them pause. That pause, or the absence of it, is where retail is won and lost. Underneath it sits something customers rarely name but always feel: payment security. It is the quiet foundation of customer trust.
Compliance is the floor, not the finish line
Retailers put enormous effort into standards like PCI DSS 4.0, and they should. The bar is higher than ever, with tougher expectations for encryption, key management and monitoring. But compliance is the minimum you must meet to be allowed to take payments. It does not capture how safe your customers actually are, or how safe they feel.
Food hygiene works the same way. A passing inspection means a kitchen meets the rules. It does not, by itself, make anyone love the restaurant. Trust is built on everything a customer experiences, and it can be lost in a single bad moment.
Compliance is the minimum you must do to take payments. Trust is the reason customers come back.
What customers are really handing you
Every transaction is a small act of faith. Tap a card, open your app, check out online, and a person is giving you data that could be used against them, on the understanding that you will keep it safe. That understanding now stretches across a far wider surface than it once did:
- POS terminals and self-checkout on the shop floor
- Kiosks and ATMs
- E-commerce sites and mobile apps
- The third-party links and networks tying them all together
Every one of these is a place where payment data moves. And every point where data moves is a point where it could be exposed. Customers never see this complexity. They simply expect it to work, safely, every single time. That expectation is customer trust in its purest form.
Why a breach costs far more than a fine
When payment security fails, the fine is rarely the worst of it. Penalties hurt, but they are finite. The damage that lingers is to reputation. News of a breach travels further than any campaign you could buy, and the customers who leave are often the loyal, high-value ones who felt personally let down.
The pattern is familiar to anyone in retail. Trust is earned slowly and lost quickly.
Winning a customer’s trust takes years. Losing it can take a single breach.
A breach flips your most valuable asset, customer confidence, into your heaviest liability.
Payment security is how trust is kept
If trust is the goal, payment security is how you protect it every day. The most overlooked part is data in motion: the payment information travelling between tills, stores, data centres and processors. Firewalls guard the edges, but the data itself needs protecting while it moves, right out to the edge where payments actually happen.
This is where strong, always-on encryption earns its keep. When payment data is encrypted from end to end, anyone who intercepts it finds nothing they can use. Done well, that protection runs silently in the background, without slowing the checkout or adding hassle for store teams. Customers get the two things they came for at once: speed and safety.
Building trust that outlasts the checklist
The retailers who will still be trusted in five years are already looking past today’s requirements. Threats change, and so does cryptography. Post-quantum computing is coming, and the encrypted data captured today could be the target tomorrow. Building on encryption that can adapt, without tearing out every terminal, is how a brand keeps its promise to customers for the long haul, not just the current audit cycle.
That is the real prize. Not a certificate on the wall, but a customer who never thinks twice about paying you.
Secure payments, protected trust
Compliance will always matter. It is where the conversation starts, though, not where it ends. The retailers who pull ahead treat payment security as the foundation of customer trust and brand reputation, rather than a box to tick once a year.
Sitehop helps retailers protect payment data wherever it moves, supporting PCI DSS 4.0 objectives today and a post-quantum future tomorrow, all without slowing payments or disrupting stores.
Protect your customers’ trust, from the checkout to the core.
Book a Sitehop demo to see how end-to-end encryption keeps payment data safe across every store, network and payment system.
Or call us: +44 (0)114 478 2366
Sitehop.
Sitehop. Engineered for speed. Built for the future.
How Shrinking the Attack Surface Powers a Faster, Safer Digital World
November 7, 2025 | Attack Surface, Resilience, Transformation
The story of cybersecurity doesn’t have to be one of fear. It can be one of confidence, of businesses, governments, and individuals moving faster because they trust the systems they use. In an era when everything from financial transactions to energy depends on connected infrastructure, the attack surface, every point where systems can be compromised, has become one of the defining measures of digital resilience.
Rethinking the Modern Attack Surface
Today’s digital ecosystems are a vast web of distributed applications, cloud services, connected devices, and global networks all exchanging data across borders and time zones. It is the data in motion between endpoints that has become the most exposed. While data at rest often resides behind firewalls or within encrypted storage, data in motion travels through routers, gateways, and public infrastructure. Each transfer creates a point of vulnerability, an opportunity for interception, manipulation, or exploitation.
The real challenge lies in how data is handled as it moves. Most VPNs and network security systems still process customer data in software before handing it off to an ASIC to accelerate certain cryptographic functions. This approach exposes the data within the software stack, where most vulnerabilities exist. By contrast, processing customer data directly within hardware, such as an FPGA or ASIC, removes that exposure entirely. It allows encryption and protection to begin at the very first point of contact, before the data ever touches an operating system or software layer, closing one of the most significant gaps in today’s digital security model.
Common weak points include:
- Unsecured or misconfigured tunnels, where encryption isn’t applied end-to-end.
- Software-defined networks, where shared resources expose encryption keys to potential side-channel attacks.
- Edge and IoT devices, which transmit sensitive data without hardware protection.
Each of these represents not just a technical risk, but a business risk. When data in motion can be intercepted or altered, confidence in the entire digital supply chain erodes. The challenge isn’t simply to encrypt more, but to encrypt smarter, to build protection into the fabric of communication itself, without slowing the flow of data or business.
The Hidden Cost of Software Encryption
Software encryption has long been the default. It’s adaptable, deployable anywhere, and easily updated. But it also shares the same resources, the same memory, CPU, and operating environment, that attackers can exploit. Every software patch, every new algorithm, adds friction. The system slows down, the complexity grows, and the attack surface widens.
In the end, the protection becomes its own bottleneck. What began as a safeguard starts holding back performance, scalability, and trust.
Hardware Encryption: Security at the Speed of Life
Encryption must be part of the very fabric of technology, built into silicon, operating at line speed, invisible to users yet impenetrable to attackers. This is hardware encryption, and it represents a profound shift in how we think about both security and performance. By isolating cryptography within dedicated hardware, organisations can:
- Eliminate software vulnerabilities from the encryption path.
- Scale securely, maintaining performance as data volumes and key sizes grow.
- Protect keys absolutely, safeguarding against both cyber and physical compromise.
And the impact reaches beyond data centres or enterprise networks. When encryption happens seamlessly and instantly, it touches everyone. Reducing the attack surface doesn’t just protect systems, it protects experiences. It builds a world where trust is engineered, not assumed.
Beyond Today: Quantum Threats and Crypto Agility
The next wave of change is already on the horizon. Quantum computing promises unprecedented computational power, and with it, the potential to break today’s strongest encryption. The solution is crypto agility. Hardware-based designs make this agility possible. Algorithms can be upgraded without rewriting software or redesigning infrastructure. Security evolves in step with innovation, not in reaction to it.
The Strategic Payoff: Security as a Business Accelerator
For CIOs, CISOs, and network architects, encryption done right isn’t just a technical necessity, it’s a strategic advantage.
- Performance and protection align: systems stay secure without slowing down.
- Compliance becomes proactive: hardware simplifies certification and governance.
- Cost and complexity fall: fewer patches, fewer breaches, more uptime.
- Trust becomes measurable: secure-by-design enhances brand credibility.
How Sitehop Is Leading the Change
At Sitehop, that reality is here. Our hardware-accelerated, crypto-agile solutions deliver security at the speed of life, protecting data without compromise. Because when the attack surface shrinks, possibility expands.
To find out more, email info@sitehop.com
Or call us: +44 (0)114 478 2366
Sitehop.
Engineered for speed. Built for the future.

