29 security controls for Indian retailers, and what answers each

What the obligations make you do, the breaches each one would have stopped, what a gateway, marketplace or auditor asks to see — and what answers it.

  • 29controls, in four groups
  • 21answered by software we shortlist
  • 8no software answers
  • 9where our catalogue is thin — said plainly
For
Answer

Showing 29 of 29

Every retailer

10

Store-led or online, every retailer needs these.

Detect and report inside six hours

Both

Endpoint detection and response, or a managed service that watches it 24×7.

4 obligations require it3 breach patterns it stops2 guides

What it is

Endpoint detection and response, or a managed service that watches it 24×7.

Why it matters here

CERT-In and ONDC both start a six-hour clock at the moment you notice — and you cannot report in six hours what you find in six days. Verizon’s 2026 retail data: 61% of breaches were system intrusion.

What a client or auditor asks to see

Coverage on every POS back-office PC, server and laptop; 24×7 monitoring (in-house or MDR); dated detection-to-report times from your last incidents or drills.

Keep 180 days of logs — and a year for personal data

Both

Central log collection with retention matched to the law: 180 days for CERT-In, a year under DPDP from May 2027.

3 obligations require it1 breach pattern it stops1 guide

What it is

Central log collection with retention matched to the law: 180 days for CERT-In, a year under DPDP from May 2027.

Why it matters here

CERT-In can ask for 180 days of firewall, web, database and application logs; DPDP Rule 8(3) wants order and processing logs kept a year — even after a customer deletes the account.

What a client or auditor asks to see

A retention policy citing both rules, and proof you can pull a given day’s logs from six months ago.

Phishing-resistant MFA and SSO for staff

Both

Single sign-on with strong multi-factor authentication for head office, warehouse and store-manager accounts.

3 obligations require it2 breach patterns it stops1 guide

What it is

Single sign-on with strong multi-factor authentication for head office, warehouse and store-manager accounts.

Why it matters here

Amazon’s seller-API policy and PCI DSS 8.4.2 both demand MFA; the Snowflake-linked retail breaches of 2024 used stolen passwords on accounts without it.

What a client or auditor asks to see

MFA coverage across admin, back-office and cloud consoles; which factors are phishing-resistant; how shared store logins are handled.

Email security, DMARC and lookalike-site takedown

BothThin coverage

Filter phishing aimed at staff; publish DMARC so no one can mail as you; find and take down fake stores and apps using your brand.

2 obligations require it1 breach pattern it stops1 guide + 2 products

What it is

Filter phishing aimed at staff; publish DMARC so no one can mail as you; find and take down fake stores and apps using your brand.

Why it matters here

Fake DMart, JioMart and Flipkart sites circulate every sale season, and CERT-In’s festive advisory names fake shopping sites. PCI DSS 5.4.1 requires anti-phishing for staff in scope.

What a client or auditor asks to see

DMARC at enforcement; phishing-filter coverage; how lookalike domains and apps are found and taken down.

What answers it

Also in our catalogue:

Email filtering and DMARC are well covered; dedicated brand-takedown services are thin — two products, no Indian takedown specialist yet.

Shortlist this with us →

Backups you can restore — offline, and in India for the books

Both

Immutable and offline backups of ERP, POS and storefront data, tested by restore; daily backups of the books on servers in India.

3 obligations require it3 breach patterns it stops3 guides

What it is

Immutable and offline backups of ERP, POS and storefront data, tested by restore; daily backups of the books on servers in India.

Why it matters here

Ransomware stopped Raymond’s supply chain while its stores stayed open, and emptied Co-op’s shelves. The Companies Act wants the books backed up daily in India.

What a client or auditor asks to see

Restore tests with dates and outcomes — not backup success reports — and where the books’ daily copy sits.

Patch what is exposed first

Both

Continuous scanning of what faces the internet — storefront, APIs, VPNs — with critical fixes on a clock.

3 obligations require it3 breach patterns it stops1 guide

What it is

Continuous scanning of what faces the internet — storefront, APIs, VPNs — with critical fixes on a clock.

Why it matters here

Exploited vulnerabilities opened 42% of retail breaches in Verizon’s 2026 data, the top way in. Amazon wants scans every 30 days and a yearly penetration test.

What a client or auditor asks to see

An external attack-surface inventory, scan cadence, and time-to-fix for critical findings.

Encrypt and tokenise customer data

Both

Encryption at rest and in transit, tokens in place of card and identity data, and discovery of where customer data actually sits.

10 obligations require it1 breach pattern it stops2 guides

What it is

Encryption at rest and in transit, tokens in place of card and identity data, and discovery of where customer data actually sits.

Why it matters here

DPDP Rule 6 names encryption, masking and tokens as the minimum; the leaked BigBasket, Domino’s and boAt databases were customer data at rest.

What a client or auditor asks to see

A data map of where customer data lives, what is encrypted, and how keys are managed.

Consent, notices and erasure under DPDP

BothThin coverage

Capture and record consent at every sign-up and checkout, honour withdrawals, and erase on schedule.

9 obligations require it4 products in our catalogue

What it is

Capture and record consent at every sign-up and checkout, honour withdrawals, and erase on schedule.

Why it matters here

DPDP wants notices a customer can understand alone and withdrawal as easy as consent; the E-Commerce Rules forbid pre-ticked boxes; large platforms must erase inactive users after three years.

What a client or auditor asks to see

Consent records tied to purposes, withdrawal handling, and the erasure job with its 48-hour warning.

What answers it

In our catalogue:

Four consent and privacy products, no decision guide yet — and no registered DPDP Consent Manager in our catalogue.

Shortlist this with us →

Know which vendors hold your customers

BothThin coverage

An inventory of every agency, SaaS tool and processor that touches customer data, with security checks proportionate to what they hold.

4 obligations require it2 breach patterns it stops4 products in our catalogue

What it is

An inventory of every agency, SaaS tool and processor that touches customer data, with security checks proportionate to what they hold.

Why it matters here

Third parties were involved in 68% of retail breaches in Verizon’s 2026 data. Dunzo was entered through a third party’s server; Juspay held many merchants’ card metadata.

What a client or auditor asks to see

A vendor register with data held, last assessment date, and the contract’s breach-notice clause.

What answers it

In our catalogue:

GRC suites are covered; dedicated vendor-risk ratings (SecurityScorecard, BitSight) and Indian compliance automation (Sprinto, Scrut) are not in our catalogue yet.

Shortlist this with us →

Limit what store and support staff can take

Both

Data loss prevention and least-privilege access for customer-service, store and warehouse staff who see customer records.

1 obligation require it1 breach pattern it stops1 guide

What it is

Data loss prevention and least-privilege access for customer-service, store and warehouse staff who see customer records.

Why it matters here

Swiggy’s 2023 incident was a former employee reaching test systems; return fraud at Meesho ran through a colluding seller. The Consumer Protection Act treats leaking a customer’s data as an unfair trade practice.

What a client or auditor asks to see

Who can export customer lists, what is monitored, and how access ends when people leave.

Stores

5

For chains, franchises and anyone with tills, terminals and a store network.

Lock down POS and back-office machines

Stores

Application allow-listing and hardening on POS terminals and store back-office PCs, so only approved software runs.

1 obligation require it1 breach pattern it stops1 guide + 2 products

What it is

Application allow-listing and hardening on POS terminals and store back-office PCs, so only approved software runs.

Why it matters here

Store POS malware — Target, Wendy’s, Wawa — ran on machines that would run anything. Allow-listing stops it at the till.

What a client or auditor asks to see

Which store machines run allow-listing or EDR, and how exceptions are approved.

Manage handhelds, kiosks and rugged devices

Stores

Mobile device management with kiosk lockdown for scanners, mPOS, self-checkout and delivery-partner devices.

1 obligation require it1 guide + 3 products

What it is

Mobile device management with kiosk lockdown for scanners, mPOS, self-checkout and delivery-partner devices.

Why it matters here

A store runs dozens of shared Android devices handled by seasonal staff — lost, swapped and rarely updated. They carry customer and payment apps.

What a client or auditor asks to see

An inventory of store devices, lockdown profiles, update status, and remote wipe.

Required by

Segment the store network and the card environment

StoresThin coverage

Branch firewalls or SD-WAN/SASE that keep POS, guest Wi-Fi, CCTV and back office apart — so the card environment stays small.

1 obligation require it1 breach pattern it stops2 guides

What it is

Branch firewalls or SD-WAN/SASE that keep POS, guest Wi-Fi, CCTV and back office apart — so the card environment stays small.

Why it matters here

Target’s attackers moved from an HVAC vendor’s access to the POS. Segmentation is also what keeps PCI DSS scope — and its cost — contained.

What a client or auditor asks to see

A network diagram showing the card environment’s boundary, and the rules between store zones.

What answers it

Firewalls and SD-WAN are well covered; store Wi-Fi and network access control (Meraki, Aruba, Forescout) are thin.

Shortlist this with us →

Filter web and DNS at every store

Stores

DNS and web filtering on store networks and devices, blocking known-bad sites and lookalikes.

0 obligations require it1 breach pattern it stops1 guide

What it is

DNS and web filtering on store networks and devices, blocking known-bad sites and lookalikes.

Why it matters here

Store staff browse, click and download on shared machines; one infected back-office PC can reach the POS. Protective DNS is the cheapest layer across hundreds of sites.

What a client or auditor asks to see

Filtering coverage across stores and roaming devices, and the block reports.

Control vendor and franchise access to stores

Stores

Privileged access management and recorded, time-boxed remote sessions for POS vendors, IT contractors and franchise support.

0 obligations require it1 breach pattern it stops2 guides

What it is

Privileged access management and recorded, time-boxed remote sessions for POS vendors, IT contractors and franchise support.

Why it matters here

Wendy’s franchise POS malware came through “certain service providers’ remote access credentials”; Target’s came through an HVAC contractor’s.

What a client or auditor asks to see

Who can reach store systems remotely, how sessions are approved and recorded, and when access expires.

Online

6

For marketplaces, D2C brands and anyone with a checkout, an app or a seller API.

Web application and API protection, and DDoS

OnlineThin coverage

A WAF or WAAP in front of the storefront and its APIs, with DDoS protection for sale days.

1 obligation require it1 breach pattern it stops6 products in our catalogue

What it is

A WAF or WAAP in front of the storefront and its APIs, with DDoS protection for sale days.

Why it matters here

Basic web-application attacks are one of the three patterns behind 95% of retail breaches (Verizon 2026), and PCI DSS 6.4.2 wants an automated control in front of public web apps.

What a client or auditor asks to see

What sits in front of the storefront and the APIs, which rules are in blocking mode, and the sale-day DDoS plan.

What answers it

In our catalogue:

Strong products from six vendors, but no decision guide yet; Imperva and India’s Indusface are not in our catalogue.

Shortlist this with us →

Stop bots and account takeover

OnlineThin coverage

Bot management against credential stuffing, scalping and fake sign-ups, with account-takeover detection on logins.

0 obligations require it2 breach patterns it stops3 products in our catalogue

What it is

Bot management against credential stuffing, scalping and fake sign-ups, with account-takeover detection on logins.

Why it matters here

Meesho blocked 13 lakh bot orders in a year and pursued account-takeover cases; The North Face reported a credential-stuffing attack in 2025.

What a client or auditor asks to see

Login-abuse rates, how bots are told from shoppers, and what happens on a suspicious login.

What answers it

In our catalogue:

Thin: three dedicated products. HUMAN, Kasada and DataDome are not in our catalogue.

Shortlist this with us →

Watch every script on the checkout page

OnlineThin coverage

An inventory, authorisation and integrity check for each payment-page script, with alerts when one changes — PCI DSS 6.4.3 and 11.6.1.

3 obligations require it1 breach pattern it stops2 products in our catalogue

What it is

An inventory, authorisation and integrity check for each payment-page script, with alerts when one changes — PCI DSS 6.4.3 and 11.6.1.

Why it matters here

Web skimmers read what a shopper types before the card is ever tokenised; the ICO fined British Airways £20 million for one. Since March 2025 PCI DSS requires this control.

What a client or auditor asks to see

The script inventory with a reason for each, the integrity mechanism, and change alerts at least weekly.

What answers it

In our catalogue:

Thin: one dedicated product, plus Cloudflare’s module. Jscrambler, Feroot and c/side are not in our catalogue.

Shortlist this with us →

Secure customer logins

OnlineThin coverage

Customer identity (CIAM) with passwordless or risk-based multi-factor login for shoppers and loyalty members.

2 obligations require it2 breach patterns it stops1 guide + 2 products

What it is

Customer identity (CIAM) with passwordless or risk-based multi-factor login for shoppers and loyalty members.

Why it matters here

Swiggy customers were taken over through fake IVR calls and charged on linked BNPL; RBI wants a dynamic factor for online card payments from April 2026.

What a client or auditor asks to see

How customers authenticate, what triggers step-up, and how a takeover is reversed.

What answers it

Also in our catalogue:

Two dedicated customer-identity products; Ping Identity and LoginRadius are not in our catalogue.

Shortlist this with us →

Verify sellers, riders and partners

OnlineThin coverage

Identity verification and KYC for marketplace sellers, delivery partners and new merchants.

2 obligations require it1 breach pattern it stops3 products in our catalogue

What it is

Identity verification and KYC for marketplace sellers, delivery partners and new merchants.

Why it matters here

Meesho lost ₹5.5 crore to a seller who faked buyers and returns. The RBI’s aggregator rules and the EU DSA both require knowing who the trader is.

What a client or auditor asks to see

Seller onboarding checks, re-verification triggers, and how fake accounts are found.

What answers it

In our catalogue:

KYC is covered; e-commerce order-fraud scoring (Riskified, Forter, SEON) for refund, coupon and cash-on-delivery abuse is not in our catalogue.

Shortlist this with us →

Stay up on sale day

Online

Real-user monitoring, synthetic checks and a CDN that see a checkout slowdown before customers do.

1 obligation require it1 guide + 2 products

What it is

Real-user monitoring, synthetic checks and a CDN that see a checkout slowdown before customers do.

Why it matters here

Victoria’s Secret took its site down for three days and put the online-sales hit at about $20 million; Krispy Kreme’s online ordering was disrupted for weeks.

What a client or auditor asks to see

Checkout availability and latency at the last sale peak, and the alerting that fired.

Required by

What no software answers

8

Procedure, design, contracts and policy — where the 2024–26 retail attacks got in.

Verify the caller before any reset

BothNot a product

A help-desk procedure that proves who is calling before a password or MFA reset — especially for admin accounts.

0 obligations require it1 breach pattern it stopsNo software answers it

What it is

A help-desk procedure that proves who is calling before a password or MFA reset — especially for admin accounts.

Why it matters here

M&S said attackers impersonated someone and tricked a third party into a reset; the UK NCSC told every firm to review how its help desk authenticates staff.

What a client or auditor asks to see

The written verification procedure, who is allowed to override it, and a test of it.

Why software does not answer this

This is a procedure, not a tool. Self-service resets with strong verification help, but the control is who the help desk will and won’t believe.

Decide your PCI scope on purpose

BothNot a product

Choose how card data flows — redirect, iframe, or your own form; P2PE terminals or not — knowing what each puts in scope.

3 obligations require it1 breach pattern it stopsNo software answers it

What it is

Choose how card data flows — redirect, iframe, or your own form; P2PE terminals or not — knowing what each puts in scope.

Why it matters here

A redirect to the gateway removes the SAQ A script test; an iframe keeps it; your own form puts your whole site in scope. Segmented stores keep the card environment small.

What a client or auditor asks to see

The data-flow diagram for every payment channel, and the SAQ or report it supports.

Why software does not answer this

A design decision with your gateway and acquirer. Products then protect whatever you left in scope.

The six-hour runbook

BothNot a product

Who tells CERT-In, the gateway, Amazon, ONDC and customers — in what order, inside which clock.

7 obligations require itNo software answers it

What it is

Who tells CERT-In, the gateway, Amazon, ONDC and customers — in what order, inside which clock.

Why it matters here

One incident can start several clocks at once — law, network, gateway and platform — and filing one does not discharge another. Without a runbook the shortest is missed while the team investigates.

What a client or auditor asks to see

The runbook, its contact list, and the timestamps from the last drill.

Why software does not answer this

A plan and a rehearsal. Detection tools start the clock; people meet it.

Read the breach clauses you have signed

BothNot a product

Know the notice windows, audit rights and data rules in your gateway, marketplace, logistics and agency contracts — and write your own into vendors’.

3 obligations require it1 breach pattern it stopsNo software answers it

What it is

Know the notice windows, audit rights and data rules in your gateway, marketplace, logistics and agency contracts — and write your own into vendors’.

Why it matters here

Cashfree asks for 12 hours, Razorpay and Amazon 24, ONDC 6 — and your agency’s contract decides whether you hear in time.

What a client or auditor asks to see

A table of every partner’s notice clock and audit right, and the matching clause in your vendor contracts.

Why software does not answer this

A legal and procurement exercise. No software signs a contract.

Design refunds and returns against abuse

OnlineNot a product

Return, refund and cash-on-delivery rules that make organised abuse expensive — limits, holds, evidence and pattern checks.

0 obligations require it1 breach pattern it stopsNo software answers it

What it is

Return, refund and cash-on-delivery rules that make organised abuse expensive — limits, holds, evidence and pattern checks.

Why it matters here

Myntra filed a ₹1.1 crore refund-fraud complaint; Meesho lost ₹5.5 crore to faked returns. Both were business logic working as designed.

What a client or auditor asks to see

Refund rules, limits per account and address, and the alerts that caught the last abuse.

Why software does not answer this

Policy design. Fraud tools score the orders, but the rules decide what a fraudster can extract.

Hold franchisees to a minimum

StoresNot a product

A security baseline in the franchise agreement — terminals, POS access, patching, who their IT vendor is — and a way to check it.

0 obligations require it1 breach pattern it stopsNo software answers it

What it is

A security baseline in the franchise agreement — terminals, POS access, patching, who their IT vendor is — and a way to check it.

Why it matters here

Wendy’s POS malware hit franchised restaurants through franchisees’ service providers, not company stores. Visa counts franchisee volume separately when it isn’t processed by the corporate entity.

What a client or auditor asks to see

The franchise security schedule, attestations from franchisees, and the vendors they use.

Why software does not answer this

A contract and an attestation programme. Tools can be mandated in it, but the agreement is the control.

Use validated card terminals

StoresNot a product

Card terminals validated under PCI P2PE, and PIN pads approved under PCI PTS — supplied through your payment provider.

1 obligation require it1 breach pattern it stopsNo software answers it

What it is

Card terminals validated under PCI P2PE, and PIN pads approved under PCI PTS — supplied through your payment provider.

Why it matters here

The RBI requires payment operators to install exactly these at merchants; point-to-point encryption takes card data off your store network entirely.

What a client or auditor asks to see

The terminal models in each store and their P2PE and PTS listings.

Why software does not answer this

Hardware from your payment operator, not software we sell. Ask your PSO for the validated models.

Guides do the vendor-neutral shortlisting with India pricing. Where no guide exists we name the products in our catalogue that answer the control, and say where that list is thin. General information, not legal advice.

Questions people ask

Retail controls, answered

Short answers, each backed by the sources on this page.

Which security controls should a retail chain start with?

The ones every retailer needs (Detect and report inside six hours; Keep 180 days of logs — and a year for personal data; Phishing-resistant MFA and SSO for staff; Email security, DMARC and lookalike-site takedown; Backups you can restore — offline, and in India for the books; Patch what is exposed first; Encrypt and tokenise customer data; Consent, notices and erasure under DPDP; Know which vendors hold your customers; Limit what store and support staff can take), then the store ones: Lock down POS and back-office machines; Manage handhelds, kiosks and rugged devices; Segment the store network and the card environment; Filter web and DNS at every store; Control vendor and franchise access to stores.

What does an online seller need beyond a payment gateway?

A gateway handles the card, not your site. Online sellers also need: Web application and API protection, and DDoS; Stop bots and account takeover; Watch every script on the checkout page; Secure customer logins; Verify sellers, riders and partners; Stay up on sale day.

How do we meet PCI DSS 6.4.3 and 11.6.1 on our checkout?

Keep an inventory of every script on the payment page with a reason for each, authorise and integrity-check them, and alert on unauthorised changes to the page and its security headers at least weekly. Redirecting shoppers to the gateway's own page takes the SAQ A script test off you; an embedded iframe does not.

Which retail security controls can't be bought as software?

Verify the caller before any reset; Decide your PCI scope on purpose; The six-hour runbook; Read the breach clauses you have signed; Design refunds and returns against abuse; Audit checkout and consent for dark patterns; Hold franchisees to a minimum; Use validated card terminals. Procedures, design decisions, policies and contracts: where many 2024 to 2026 retail attacks got in.