Case Study

PCI DSS Compliance for a Renowned Grocery Store Outlet Chain in Illinois

During the pandemic in 2020, a leading grocery store chain in Illinois experienced an unprecedented surge in credit card transactions. A major payment brand mandated PCI DSS Level 2 compliance within a stringent timeline. DCC was engaged as the Program Manager to drive end-to-end compliance without disrupting business operations.

PCI DSSSAQ D17 LocationsZero DowntimeRetail
Grocery store payment
Scroll
Achievements

Compliance delivered. Operations intact.

PCI DSS Level 2 Compliance Achieved
On-Time Delivery with Zero Downtime
Significant Cost Savings Using Open Source Stack
Enhanced Security & Audit Readiness
Business Challenges

Seven obstacles to PCI compliance.

  1. 01

    Risk of losing authorization to process credit card transactions without PCI compliance.

  2. 02

    First-time compliance effort with no prior PCI DSS experience.

  3. 03

    Distributed infrastructure across 17 locations with no segmentation — entire network was in scope.

  4. 04

    Initial SAQ B-IP deemed inapplicable; SAQ D required — 3X more stringent requirements.

  5. 05

    High cost proposals including expensive security tools (SIEM, MFA, NMS, Vulnerability Scanner, Patch Mgmt.).

  6. 06

    Limited IT security resources and high risk of budget overrun.

  7. 07

    Zero tolerance for downtime during peak business growth.

Solution Delivered

Eight workstreams driving compliance.

01

Assessment Management

Coordinated QSA, ASV, and Penetration Testing vendors for assessments, scanning and testing.

02

Remediation Management

Engineering support for remediation across network, servers, endpoints — on-site and remote.

03

Network Segmentation

Implemented PCI-compliant segmentation across 17 locations through multiple rounds of design, implementation, and reviews.

04

Open Source Stack Implementation

Deployed SIEM, RADIUS for MFA, Vulnerability Scanner, and Network Monitoring using open source technologies.

05

Internal VAPT

Scanned several hundred devices across 17 locations multiple times to validate remediations until acceptable results were achieved.

06

Documentation & Policies

Created all required policies, procedures, network diagrams (17 locations) and compliance records.

07

Project Management

Provided tools for task tracking, document management, approvals and reporting.

08

Training & Awareness

Conducted security awareness training for general users and PCI essentials training for IT staff.

Key Outcomes

Compliance, continuity and capability.

PCI DSS Level 2 (SAQ D) Compliance Achieved

Met all PCI DSS requirements within the mandated timeline.

Zero Business Disruption

Ensured uninterrupted store operations during implementation.

Cost Optimization

Eliminated need for expensive proprietary tools by leveraging open source stack.

Improved Security Posture

Implemented proper segmentation, access controls and monitoring across all locations.

Audit & Compliance Ready

Complete documentation and evidence for audit and future compliance initiatives.

Stronger Team Capability

Empowered internal team through targeted training and knowledge transfer.

Our Approach — End to End PCI DSS Compliance Lifecycle

Six phases from assessment to continuous improvement.

  1. 1

    Assess

    Identify assets, data flows, vulnerabilities and gaps.

  2. 2

    Plan

    Define remediation strategy and roadmap.

  3. 3

    Remediate

    Implement security controls, segmentation and hardening.

  4. 4

    Validate

    VAPT, scans and testing to verify effectiveness.

  5. 5

    Comply

    Documentation, policies and audit readiness.

  6. 6

    Continuously Improve

    Monitor, review and enhance security posture.

Business Impact

Continuity, trust and a foundation for growth.

Transaction Continuity

Continued ability to process credit card transactions without interruption.

Customer Trust

Enhanced customer trust and brand reputation.

Scalable Security

Scalable, cost-effective security architecture for future growth.

Ongoing Compliance

Strong foundation for ongoing compliance and risk management.

Testimonial

In the client's words.

Illumia Solutions played a critical role in helping us achieve PCI DSS compliance on time, within budget, and without impacting our business. Their expertise, leadership and use of open source technologies delivered exceptional value.
— IT Director, Grocery Store Chain (Illinois)