Assessment Management
Coordinated QSA, ASV, and Penetration Testing vendors for assessments, scanning and testing.
During the pandemic in 2020, a leading grocery store chain in Illinois experienced an unprecedented surge in credit card transactions. A major payment brand mandated PCI DSS Level 2 compliance within a stringent timeline. DCC was engaged as the Program Manager to drive end-to-end compliance without disrupting business operations.

Risk of losing authorization to process credit card transactions without PCI compliance.
First-time compliance effort with no prior PCI DSS experience.
Distributed infrastructure across 17 locations with no segmentation — entire network was in scope.
Initial SAQ B-IP deemed inapplicable; SAQ D required — 3X more stringent requirements.
High cost proposals including expensive security tools (SIEM, MFA, NMS, Vulnerability Scanner, Patch Mgmt.).
Limited IT security resources and high risk of budget overrun.
Zero tolerance for downtime during peak business growth.
Coordinated QSA, ASV, and Penetration Testing vendors for assessments, scanning and testing.
Engineering support for remediation across network, servers, endpoints — on-site and remote.
Implemented PCI-compliant segmentation across 17 locations through multiple rounds of design, implementation, and reviews.
Deployed SIEM, RADIUS for MFA, Vulnerability Scanner, and Network Monitoring using open source technologies.
Scanned several hundred devices across 17 locations multiple times to validate remediations until acceptable results were achieved.
Created all required policies, procedures, network diagrams (17 locations) and compliance records.
Provided tools for task tracking, document management, approvals and reporting.
Conducted security awareness training for general users and PCI essentials training for IT staff.
Met all PCI DSS requirements within the mandated timeline.
Ensured uninterrupted store operations during implementation.
Eliminated need for expensive proprietary tools by leveraging open source stack.
Implemented proper segmentation, access controls and monitoring across all locations.
Complete documentation and evidence for audit and future compliance initiatives.
Empowered internal team through targeted training and knowledge transfer.
Identify assets, data flows, vulnerabilities and gaps.
Define remediation strategy and roadmap.
Implement security controls, segmentation and hardening.
VAPT, scans and testing to verify effectiveness.
Documentation, policies and audit readiness.
Monitor, review and enhance security posture.
Continued ability to process credit card transactions without interruption.
Enhanced customer trust and brand reputation.
Scalable, cost-effective security architecture for future growth.
Strong foundation for ongoing compliance and risk management.
Illumia Solutions played a critical role in helping us achieve PCI DSS compliance on time, within budget, and without impacting our business. Their expertise, leadership and use of open source technologies delivered exceptional value.