Why Retail + E-commerce is distinct
Retail handles dual identity surfaces — workforce (employee + contractor) and customer (loyalty + e-commerce + in-store). PCI DSS Requirements 7 + 8 layer prescriptive IAM controls on cardholder data handling. ATO via loyalty programs is the fastest-growing fraud category.
Regulators
- PCI Security Standards Council (PCI DSS 4.0)
- FTC (Section 5)
- State Attorneys General
- EU GDPR + UK GDPR
- state privacy laws (CCPA, CPA, VCDPA, CTDPA, UCPA, etc.)
Industry-specific challenges
The IAM challenges that recur in Retail + E-commerce.
- Guest checkout vs account conversion — every CIAM decision affects conversion
- Loyalty-points fraud is liquid + redeemable + barely controlled
- Returns fraud via stolen identity / synthetic identity
- PCI DSS 4.0 IAM controls on cardholder data systems
- POS terminal + shared device identity
- Seasonal scaling — Black Friday spikes
The canonical Retail + E-commerce resources
Everything we’ve published, organized by topic.
Compliance + audit
Architecture + reference
Incident + risk tracking
Sector-relevant insights
Retail + E-commerce IAM engagement