Retail and e-commerce businesses simultaneously handle payment data, large volumes of customer personal data, and expose an attack surface directly accessible from the internet — the online storefront itself. This continuous application-layer exposure, combined with PCI DSS requirements that apply as soon as card payment data is processed, makes the sector a preferred target for both automated, opportunistic attacks and targeted campaigns.
Last updated — August 22, 2026
Verizon, Data Breach Investigations Report (DBIR)
Yes, a PCI DSS validation requirement still applies even when payment is delegated to a third-party provider (PSP), notably regarding site security and the absence of unauthorized card-data storage.
The scope and testing window are defined to limit any impact on availability; a representative staging environment is recommended when one exists.
Yes — even on a SaaS e-commerce platform, configuration (access rights, third-party integrations, API) remains the merchant's responsibility and is a frequent source of incidents.
PCI DSS specifically governs payment card data; GDPR (for European customers) and law 09-08 (Morocco) more broadly govern all personal data collected — the two frameworks are generally addressed in parallel.