Skip to main content
Retail, FMCG & Quick Commerce

Retail, FMCG & Quick Commerce Cybersecurity

CERT-In empanelled cybersecurity services for Retail, FMCG & Quick Commerce organisations. 6,700+ assessments delivered since 2006.

6,700+
Assessments Delivered
1,000+
Enterprise Clients
150+
Security Professionals
Since 2006
Founded · CERT-In 2008

Challenges

Security challenges in Retail, FMCG & Quick Commerce

1

PCI DSS compliance for omnichannel payments — in-store POS, e-commerce, mobile app, and delivery

2

Customer PII at scale — loyalty programs, purchase histories, and personalization data

3

Supply chain and logistics API security — inventory, fulfillment, last-mile delivery integrations

4

Seasonal peak security — Black Friday, Diwali, and end-of-season sale testing windows

5

Franchise and multi-brand infrastructure with inconsistent security postures across locations

Trusted by

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The estate

The same compromise, seen from two very different places

Retail runs a digital business and a physical one on partly shared systems, and an incident does not respect the boundary.

The same event

A third-party script on the checkout starts copying card entries

What the e-commerce team sees
Nothing. The site is up, conversion is normal, the script is one the marketing team legitimately added months ago, and it is served from the vendor's domain rather than yours.
What the store estate sees
Nothing either — and that is the point. Stores run their own payment path, so a card-present environment can be entirely healthy while the online one is not, which delays the conclusion that anything is wrong at all.
What the assessment has to establish
What executes in the checkout page, who can change each of those things, and whether anything would detect a change. That is answerable in an afternoon and almost never asked before an incident.

The estate

The stores you do not run are still your surface

Franchise locations

Operating under your brand, on networks procured locally, with staff who are not your employees and a point-of-sale estate you may not administer. A customer harmed there was harmed by your brand.

The in-store network

Payment terminals, back-office machines, digital signage, guest Wi-Fi and increasingly a lot of connected equipment, frequently on flatter networks than anyone intends after years of ad-hoc additions.

Loyalty and customer data

The most valuable non-payment asset in retail, joined across online and in-store, and usually reachable from more places than the card data is.

Supplier and logistics interfaces

Ordering, stock and delivery integrations with hundreds of counterparties, built for throughput and authenticated accordingly.

Seasonal and campaign infrastructure

Microsites, competition pages and promotional apps stood up for a season by an agency and left running afterwards, still branded as you.

How it runs

The calendar is a security consideration, not a scheduling one

Retail concentrates a large share of its year into a small number of days, and everything about the security posture changes across them. Change freezes mean a vulnerability disclosed in November may not be patched until January. Temporary staff are onboarded in volume and offboarded unevenly, so account lifecycle failures cluster after every peak. Capacity work introduces new caching, new content delivery configuration and new third-party tooling in the weeks before the freeze, which is precisely when it receives least scrutiny. And the traffic that would make an attack visible in a quiet month disappears into legitimate volume. The practical consequence is that assessment timing matters more in retail than in most sectors: testing after the freeze is set is testing something you have already decided not to change, and testing during peak is asking for an outage. The useful window is early enough that findings can still be fixed before the freeze, which in practice means starting a quarter earlier than most organisations do.

What we test

Where retail assessments actually find things

Ordered by yield rather than by where a scope template would start.

AreaWhat tends to be there
The checkout page Third-party scripts nobody has inventoried, loading further scripts, with no integrity checking and no alerting on change. The control is knowing what runs; the finding is that nobody does.
Promotions and loyalty Business-logic flaws that produce value rather than access — stacking discounts, redeeming a balance twice, or converting points through a path that was never meant to be reversible.
Store network segmentation A flat enough network that a back-office machine, a signage controller or the guest network can reach the payment segment. Usually the result of a legitimate fix applied under time pressure and never revisited.
Left-over campaign estate Microsites and promotional apps from previous seasons, unpatched, still branded, sometimes still collecting customer data into a database nobody monitors.

The checkout page

What tends to be there
Third-party scripts nobody has inventoried, loading further scripts, with no integrity checking and no alerting on change. The control is knowing what runs; the finding is that nobody does.

Promotions and loyalty

What tends to be there
Business-logic flaws that produce value rather than access — stacking discounts, redeeming a balance twice, or converting points through a path that was never meant to be reversible.

Store network segmentation

What tends to be there
A flat enough network that a back-office machine, a signage controller or the guest network can reach the payment segment. Usually the result of a legitimate fix applied under time pressure and never revisited.

Left-over campaign estate

What tends to be there
Microsites and promotional apps from previous seasons, unpatched, still branded, sometimes still collecting customer data into a database nobody monitors.

Frequently Asked Questions

We have hundreds of stores. Does every one need testing?

No — the estate is tested by representative sample plus architecture review, not store by store. Stores are built from a small number of standard configurations, so testing one of each pattern establishes what all of them do, and the review covers how a store connects to the centre and what it can reach when it gets there. Franchise locations need separate treatment because the configuration is genuinely not uniform, and that is worth establishing rather than assuming.

When in the year should this happen?

Early enough that findings can be remediated before the change freeze — for most Indian retailers that means starting well before the festive quarter, not during it. Testing after the freeze is set produces a report about things you have already decided not to change for two months, and testing at peak risks an outage at the worst possible moment. A quarter of lead time before the freeze is the pattern that works.

Secure Your Retail, FMCG & Quick Commerce Organisation

One scoping call to align on scope, methodology, and timing.

Request a Scoping Call →