Free Consultation
Case Study: Retail

Payment Card Data Was Sharing
a Network with Guest WiFi

A multi-location retail operation had never completed a PCI DSS assessment. Point-of-sale terminals were on the same flat network as employee workstations and customer WiFi. We fixed it.

Industry: Retail Location: NJ / CT Service: Cybersecurity • Network Infrastructure

The Situation

A multi-location retail operation was running point-of-sale terminals on the same flat network as employee workstations, back-office systems, and customer-facing WiFi. Payment card data was traversing shared infrastructure with no isolation, no segmentation, and no firewall rules restricting access between systems that handle payments and systems that do not.

The business had never completed a formal PCI DSS assessment and was not aware of the exposure. They had a working system, a processing relationship with their bank, and no obvious symptoms, but the liability was real. A breach of cardholder data from a flat network carries significant fines, chargeback exposure, and the potential loss of card processing privileges.

What We Did

01

Conducted a PCI Scoping Assessment

We identified every system that touches, transmits, or could affect cardholder data, POS terminals, back-office reconciliation workstations, payment processor connections, and any system on a network path that intersects with them.

02

Isolated Payment Systems on a Dedicated VLAN

All POS terminals were moved to a dedicated VLAN with no lateral access to employee workstations, back-office systems, or any general-purpose network segment. Payment traffic flows only to the payment processor, nothing else.

03

Enforced Strict Firewall Rules on the Payment Segment

Firewall rules were written to permit only the specific outbound connections required for payment processing. All other traffic from the payment segment is denied by default, not blocked as an afterthought, but designed out of the architecture.

04

Separated Guest WiFi Onto an Isolated Segment

Customer-facing WiFi was moved onto its own isolated SSID and VLAN with no routing path to any internal network segment. Guests have internet access. They have no access to anything else.

05

Documented the Network and Implemented Quarterly Access Reviews

Network topology was fully documented. Quarterly reviews are now part of the managed services agreement, firewall rules, VLAN configurations, and access controls are reviewed every 90 days so compliance posture does not degrade over time.

The Outcome

  • Cardholder data now isolated to a dedicated, firewall-restricted network segment
  • Guest WiFi has zero network path to payment infrastructure
  • PCI DSS compliance assessment passed following remediation
  • Firewall rules designed to deny by default, payment systems talk only to the payment processor
  • Quarterly network access reviews standard, compliance posture is maintained, not assumed
Cybersecurity Network Infrastructure PCI Compliance Managed IT

Work With Us

If You Take Card Payments, Your Network Is in Scope for PCI

We will scope your cardholder data environment, identify what is exposed, and give you a fixed-price plan to bring you into compliance, before an incident forces the conversation.

Request a PCI Scoping Assessment All Case Studies

Free Consultation

Talk to a Local IT Expert

Tell us about your business and we will follow up within one business day with a straight answer on how we can help.

Protected by a proof-of-work security check. No third-party tracking. Sent securely over an encrypted connection.

Frequently Asked Questions

Answers to Common Questions

What areas does Cobham Tech serve?

We are headquartered in Pottersville, New Jersey and support businesses across New Jersey, New York, Connecticut, Pennsylvania, Massachusetts, and North Carolina. Most issues are handled remotely, and we provide on-site visits throughout our New Jersey service area.

How is managed IT priced?

Managed IT is usually billed as a flat monthly fee, priced per user or per device, so your cost is predictable. The right tier depends on your size, systems, and the level of support you need. We recommend a free assessment first so any quote reflects your actual environment.

Do you require a long-term contract?

We work with businesses on both ongoing managed IT and one-time projects. We will recommend the arrangement that fits your goals rather than lock you into something you do not need. The details are always agreed on before any work begins.

Do you work with small businesses?

Yes. Much of our work is with small and mid-sized businesses that do not have a full internal IT department. We scale our support to the size of your team and the systems you rely on.

What if we already have an IT person on staff?

We can work alongside your internal staff in a co-managed model, handling monitoring, security, and after-hours coverage while your person focuses on day-to-day needs. We can also take over fully if that is a better fit.

Can you help with HIPAA or other compliance requirements?

Yes. We support medical, dental, and other regulated businesses with the technology side of compliance, including access controls, encryption, backups, and documentation. Compliance is about how your systems are configured and maintained, and that is work we do every day.

Do you provide emergency or after-hours support?

Managed IT clients have around-the-clock system monitoring and access to after-hours emergency support. If something critical happens outside business hours, you have a way to reach us rather than waiting until morning.

What kinds of businesses do you work with?

We support professional services firms, medical and dental practices, legal and financial offices, retailers, logistics companies, and nonprofits, among others. The common thread is a business that depends on its technology working and cannot afford to manage it alone.

Can you handle both our technology and our physical security?

Yes. Alongside managed IT and cybersecurity, we install and support physical security systems including cameras and access control. Bringing both under one provider keeps your digital and physical protection working together.

How do we get started?

Start with a free assessment. We review your current setup, identify what needs attention, and give you a straight answer on how we can help, with no obligation and no sales pressure. Call us at +1 315 436 1036 or request an assessment through the contact form.

See all frequently asked questions