Case Study

E-Commerce Retailer: Segmentation Testing Ahead of a PCI DSS Audit

An e-commerce retailer engaged Derivee for PCI DSS-scoped penetration testing ahead of their annual QSA audit, specifically to validate the network segmentation reducing their cardholder data environment scope.

Testing found that a legacy reporting server, believed to be outside the CDE, in fact had an open path into the segment handling payment data — a gap that would have failed segmentation validation during the formal audit.

The finding was remediated and retested three weeks before the scheduled QSA review, and the report was accepted directly as supporting evidence.

← all case studies