Retail
Global
WovenCart
D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.
Systems
- Shopify Plus
- AWS (ECS, RDS)
- Marketing CDP
- Warehouse management system
Regulatory exposure
- PCI DSS
- CCPA / state privacy laws
- GDPR for EU customers
Relevant frameworks
- PCI DSS
- NIST CSF
Top risks
- Peak-season DDoS
- Cardholder data leakage via marketing tooling
- Phishing of finance team during peak
- Open-source dependency compromise
Control priorities
- WAF and DDoS posture
- Marketing-tooling segmentation
- Payment flow scoping
- SAQ A evidence
Audit concerns
- PCI scope clarity (Shopify handling vs in-scope systems)
- Marketing CDP data flow documentation
Your task
Quantify the PCI scope question for the next QSA and write the internal page that walks finance through what is and is not in PCI scope at WovenCart.
Vendor risk
High dependency on Shopify Plus; long tail of marketing and analytics vendors.
BCP/DR
Peak-season contingency declared; off-season failover cadence unknown.