The Cheapest PCI Control Is a Smaller Scope
Before you buy anything for PCI DSS v4.0, shrink the cardholder data environment. Scoping and segmentation decisions that hold up to a QSA, mapped and documented. A regional e commerce retailer came to us convinced they needed to spend six figures to get through their PCI assessment. Their QSA had scoped nearly their entire corporate network as the cardholder data environment, because card data — or systems that could reach card data — seemed to be everywhere. Two hundred and some workstations, a dozen servers, the whole office VLAN. Every one of those systems would need to meet all the applicable PCI DSS requirements, get scanned, get patched on a schedule, get logged and monitored. The bill wasn't the assessment fee. It was the operational weight of securing all of it forever. We told them what we tell everyone in this position: before you spend a dollar on a control, spend two weeks shrinking your scope. In PCI, scope is the single biggest cost driver, and it's the one lever most organizations never seriously pull. Nearly every requirement in the standard applies to systems in the CDE and systems connected to it. Fewer systems in scope means fewer things to secure, scan, patch, and prove. The retailer eventually went from roughly 220 in scope systems to about 15. That was worth more than any firewall we could have sold them. You can't sco