Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



This is a common misconception PGI hears from security and compliance teams, and it's a dangerous assumption in the world of e-commerce. Hosted payment pages, iframes and redirects do genuinely reduce your PCI DSS scope, but "reduced" often gets quietly misread as "removed." When a breach happens, assessors and regulators will hold you accountable, not your provider.
Many retailers outsource their website hosting and payment solution, believing that using third-party service providers and a Payment Service Provider (PSP) through an iframe or redirect means the provider manages all aspects of PCI DSS security and compliance.
As the merchant, you remain responsible and accountable for ensuring the security of your payment environment. Although your hosting provider or PSP may implement security controls on your behalf, it is your responsibility to ensure those controls are in place, operating effectively and meet the applicable PCI DSS requirements.
The retail sector continues to experience an increase in targeted cyber attacks, making the security of e-commerce platforms more important than ever. PCI DSS compliance helps reduce exposure by ensuring baseline security controls are in place across the payment environment and wider supply chain.
This is particularly relevant as more retailers adopt outsourced payment models to reduce their PCI DSS scope. Technologies such as hosted payment pages, iframes and redirects are widely used to shift payment processing to third-party service providers, reducing the systems that fall within the merchant’s PCI DSS environment.
However, while outsourcing your payment page can reduce scope, it also does not remove the need for merchants to understand how their payment journey is delivered and secured.
A common assumption among merchants is: “we use a third-party payment provider, so payment-page security isn’t our responsibility.” And this is partly true - outsourcing the payment page genuinely does reduce your PCI DSS scope. But 'reduce' is not the same as 'remove', and the distinction is where retailers often get caught out.
SAQ A defines the minimum PCI DSS requirements a merchant must meet when using outsourced payment methods (e.g., hosted payment pages, iframes or redirects). Under this model, the payment processing itself is handled by a PCI DSS compliant third party, while the merchant remains responsible for ensuring their implementation meets the eligibility criteria for SAQ A.
This distinction is where many organisations misunderstand their obligations. Outsourcing payment processing reduces PCI DSS scope, but it does not remove the need for the merchant to ensure their chosen integration model is correctly implemented and remains eligible for SAQ A validation.
Once a merchant has confirmed that their payment processing model falls within SAQ A, attention must turn to how third-party service providers are managed. PCI DSS does not allow merchants to rely on outsourcing alone; it requires organisations to actively govern and understand the security responsibilities that have been delegated.
This is the purpose of PCI DSS Requirement 12.8, which focuses on the management of third-party service providers (TPSPs). It requires merchants to take a structured approach to supplier assurance both before and during the engagement.
Before onboarding a service provider, merchants should perform appropriate due diligence to understand the provider’s security posture and confirm that they are capable of meeting the relevant PCI DSS requirements. This should be supported by a formal written agreement that clearly defines the division of responsibilities between the merchant and the provider.
Crucially, this is not a one-time activity. Merchants are also expected to maintain ongoing oversight of their service providers. This includes understanding which PCI DSS requirements are being fulfilled by the TPSP and verifying, at least annually, that the provider continues to maintain its PCI DSS compliance.
In practice, this assurance is typically obtained through a valid Attestation of Compliance (AOC) from the provider, or through inclusion of the service provider within the merchant’s own PCI DSS assessment, where applicable. The objective is not to assume compliance, but to maintain evidence that the outsourced controls remain in place and effective over time.
Requirement 12.8 therefore acts as the bridge between outsourcing and accountability. While service providers may deliver the technical security controls, merchants remain responsible for governing that relationship and ensuring those controls continue to meet PCI DSS expectations.
We help clients understand their requirements under the PCI DSS framework, ensure your environment is correctly scoped and interpret controls as they are intended—rather than how they may be interpreted. We also provide practical guidance on where changes can be made to improve compliance maturity and give you greater confidence in your overall PCI DSS position.
Our PCI DSS specialists work with retailers to ensure their environments are correctly scoped, advise on opportunities for appropriate descoping where applicable and validate whether controls are truly being met in practice, not just documented.
We can also support with Approved Scanning Vendor (ASV) scanning and provide penetration testing services, helping to further validate your security posture and strengthen the overall maturity of your PCI DSS assessment.

You have clients approaching you with a brief of what they want. What's the pattern you keep seeing?"Recently I’ve noticed that clients often come in with a clear idea of what they think they need: A specific framework, certification or service they've heard about.

Retail businesses are good at implementing things like new technology and payment channels. What often goes unnoticed is the compliance and operational overhead that accumulates around them, building quietly in the background, year after year, and lingering long after the technology itself has been replaced.

Many organisations invest heavily in ISO 27001 and PCI DSS year after year — but few realise they may be paying for a scope that is larger, more complex, and more expensive than necessary.