Secure customer payment data and protect your brand reputation with BOSSS retail-focused security platform.
PCI DSS
v4.0 Ready
CCPA
Privacy Controls
GDPR
EU Compliance
Multi-Site
Governance
We understand the unique security challenges facing retail organizations.
Meet payment card industry data security standards across all locations.
Safeguard customer PII, payment data, and loyalty information.
Maintain consistent security across all stores and locations.
Manage access for temporary and seasonal employees securely.
Purpose-built solutions for retail security and compliance.
Complete PCI compliance with automated evidence collection
CCPA, GDPR, and state privacy law compliance
Centralized security management for all locations
Automated provisioning and deprovisioning for seasonal staff
POS system monitoring and protection
Web application security and fraud detection
Five situations a retailer actually faces, from the store shelf to the shopper account.
Havenridge Retail Group — a composite organization in the BOSSS demo environment
The situation
Memory-scraping malware reaches terminals through a flat store network
A district manager is phished, and the attacker pivots from a corporate workstation onto the store network over the SD-WAN. Memory-scraping malware lands on point-of-sale terminals at several stores and begins harvesting card data in the window between swipe and encryption. The store network turns out to be flat — no segmentation between corporate and card environments.
Who is involved
Scenario timing
How BOSSS handles it
Memory-scraping behaviour is detected on point-of-sale terminals
Memory-scraping malware on Tillstone POS terminal fleet
Lateral movement from corporate into the store network is correlated
Lateral movement from corporate workstation onto store network
Escalated to a card-compromise investigation
POS Compromise Investigation — Multi-Store Card Exposure
Formal incident record scoping the exposure across affected stores
Cardholder Data Exposure via POS Terminal Compromise
The flat store network is recorded as its own requirement gap
PCI DSS Req 1.2.1 — No Segmentation Between Corporate and Store Card Networks
Card-brand notification is produced from the incident record
Card Brand Notification — POS Compromise
What this makes possible
What it touches
Entities
Havenridge Stores
Retail operationsMarbury Falls, TN
Havenridge Retail Group
Corporate ITMarbury Falls, TN
Locations
Havenridge Flagship Store
Retail store · terminals affectedMarbury Falls, TN
Brightwater Commons Store
Retail store · terminals affectedBrightwater, GA
Cedarhurst Mall Store
Retail store · terminals affectedCedarhurst, OH
Havenridge Support Center
Headquarters · initial compromiseMarbury Falls, TN
Applications
Tillstone POS terminal fleet
Malware deployed120 stores
Store SD-WAN
Flat — no segmentation120 stores
Beckworth payment gateway
Marbury Falls, TN
Vendors
Tillstone Commerce
Point-of-sale platformMinneapolis, MN
Beckworth Payment Processing
Card acquiring and gatewayWilmington, DE
Ravenwood Network Services
Store SD-WANDallas, TX
Tarnfield Endpoint Security
Endpoint detectionAustin, TX
Data
Card Primary Account Number (PAN)
~4.2M card transactions/year120 stores
Card CVV / Expiration
~4.2M card transactions/year120 stores
Store Sales Transaction
~38M transactions/year120 stores
Why BOSSS
Protect customer payment data and achieve PCI DSS compliance across all your locations.
Key Benefits:
See how BOSSS can help your organization achieve security and compliance goals.
We use strictly necessary cookies to run this site. With your permission we would also use analytics and marketing cookies, including session recording. Cookie Policy