PCI DSS 4.0 and Data in Motion: The Security Gap Many Retailers Still Miss

August 11, 2026

PCI DSS 4.0 has pushed payment security up the boardroom agenda. Most retailers have responded by tightening the obvious things: who can reach cardholder data, how it is stored, how systems are monitored. All of that matters. But one gap gets missed again and again, and it hides in the space between systems. The risk is not just the data sitting in a database. It is the data on the move.

What is data in motion security?

Data in motion security is the practice of protecting information while it travels between systems, rather than while it sits in storage. Data at rest lives in a database or on a disk. Data in motion is in transit, moving from one place to another.

In retail, that journey is constant. Card and payment data travels from a POS terminal or checkout to a payment gateway, an acquirer, a data centre or the cloud, across whatever network sits in between. Encrypting stored data is now well understood. Protecting payment data at every step of that journey is where many retailers still fall short.

Why PCI DSS 4.0 sharpens the focus on data in transit

PCI DSS 4.0 raised expectations across encryption, key management, monitoring and validation. Requirement 4 is explicit: cardholder data must be protected with strong cryptography whenever it is transmitted across open or public networks. You can read the standard itself on the PCI Security Standards Council site.

The message is hard to miss. Encryption in transit is no longer optional or assumed. It is expected, and it is tested. Sitehop supports these objectives, though full PCI DSS compliance always remains the retailer’s own responsibility.

The retail blind spot: a sprawling estate, data everywhere

Modern retail runs on a wide, distributed estate. POS terminals, self-checkout, kiosks, ATMs, e-commerce platforms and mobile apps all handle payment data, and all of it has to move: between stores and head office, between sites and data centres, out to payment processors, across MPLS, the public internet, 5G and private networks.

Every one of those links is a place where data in motion could be intercepted. Attackers understand that endpoints are increasingly well defended, so the connections between them become the target. The more places data travels, the more the gaps multiply.

How encryption and network segmentation close the gap

Two mechanisms do most of the heavy lifting here.

The first is strong, end-to-end encryption. When payment data is encrypted for its whole journey, anyone who intercepts it finds nothing usable, only scrambled traffic. The data protects itself, wherever it goes.

The second is network segmentation. By dividing the network into separate zones and keeping payment systems apart from everything else, network segmentation limits how far an attacker can move and shrinks the area that must be secured and audited. It also helps reduce PCI DSS scope, which lowers both cost and complexity.

Encryption protects the data itself. Network segmentation controls where it can travel. Strong data in motion security needs both.

 

Used together, encryption and network segmentation turn a flat, open estate into something far harder to exploit.

Building data in motion security that lasts

The threat does not stand still, so the protection cannot either.  Encrypted traffic captured today could be stored and broken later, once quantum computing matures. That is why crypto-agility matters: the ability to update ciphers and keys without ripping out equipment across hundreds of stores. Managing that centrally, with consistent policy and key control at scale, is what keeps a large retail estate protected as standards evolve.

Closing the gap

Stored data is only half the picture. The retailers who take PCI DSS 4.0 seriously are the ones giving data in motion security the same attention they already give data at rest.

Sitehop protects payment data wherever it moves, with end-to-end encryption across any network, centralised policy and key management, and a crypto-agile, PQC-ready design that supports PCI DSS 4.0 objectives without disrupting stores or slowing payments. To see how it works at the edge, where payment data first meets the network, read how SAFEcore Edge secures data from the field to HQ.

 

Close the data in motion gap across your payment estate. Book a Sitehop demo to see how encryption and segmentation protect payment data end to end.

Book a Sitehop demo to see how end-to-end encryption keeps payment data safe across every store, network and payment system.

Or call us: +44 (0)114 478 2366

Sitehop.

Sitehop. Engineered for speed. Built for the future.