The Challenge
DDoS and suspected card-skimming jeopardised PCI renewal 90 days before Black Friday.
Key Issues
- Legacy payment stack, weak network segmentation
- Rising charge-backs and fraud
- Only 12 weeks to audit and peak season
The Solution
We hardened the payment environment and stabilised revenue streams.
Key Actions
- Isolated payment flow in a dedicated AWS account with WAF Bot Control ->blocked malicious traffic, reduced PCI DSS scope.
- Implemented real-time log aggregation and automated playbooks -> incident resolution 45 % faster.
- Ran a scoped private bug-bounty -> surfaced critical issues well before audit.
- Optimised CDN and caching rules -> checkout pages 23 % faster, boosting conversion.