DPDP deadline: May 2027 · 220 days left Get your business ready in 15 days, done for you Learn more →
Home / Security / Security for E-commerce INDUSTRY FILE · SEC-03
SEC-03 / INDUSTRY: D2C, MARKETPLACES & ONLINE RETAIL

Cyber security for online commerce that survives sale day

Peak-sale DDoS defence rehearsed before the sale, not during. Bot rules that separate scalpers from customers. PCI-DSS scope reduction through tokenisation so your audit boundary shrinks by an order of magnitude. Checkout abuse detection that catches card testing and coupon fraud. DPDP-aligned customer data workflows. Built for D2C brands, marketplaces and online retail.

70+VAPT engagements shipped
< 15minMTTR at sale peak
99.99%Uptime under bot flood
4Compliance regimes supported
FILE 01 / THREAT SURFACE FOR E-COMMERCE

Attack shapes every retail engineering lead has to plan against

THREAT-01

Sale-day DDoS on the checkout

Attackers time volumetric floods to the moment marketing has spent lakhs driving traffic. Some are competitors, some are extortion attempts, most are opportunistic. The default cloud WAF setup does not stop this on its own. You need real scrubbing capacity, WAF rules tuned for the specific request shape of your checkout, and a runbook the on-call team has actually rehearsed.

THREAT-02

Bot traffic that eats inventory and skews caching

Scalper bots buying limited drops in the first 8 seconds. Price-scraper bots hitting product detail pages until your CDN cache hit rate collapses. Inventory-watch bots hammering search endpoints for stock signals. All of these degrade the customer experience for legitimate buyers, and only endpoint-specific bot rules catch them.

THREAT-03

Card testing on the payment gateway

A botnet with a fresh dump runs thousands of auth attempts against your checkout to identify live cards. The payment gateway catches some, but often not before the attempts show up on your acquirer statement as chargebacks and gateway fees. Detection rules that correlate account creation, coupon use and payment failure rate turn this from a monthly fire into a solved problem.

THREAT-04

Account takeover and refund abuse

Credential stuffing against customer logins, followed by refund abuse loops or wallet drain. Loyalty point theft. COD address enumeration. These are the fraud patterns that show up on the CFO's dashboard as "cost of promotions" but are really the cost of missing fraud rules on the checkout and account layer.

WHY RETAIL TEAMS PICK US

Sale-day uptime is not a checklist, it is a rehearsal

Every retail vendor promises DDoS defence. We rehearse the runbook with your on-call team the week before the sale, run a synthetic load test on the actual production edge, and sit on the war-room call from sale start to +2 hours. The difference between a Diwali outage and a Diwali record is who is on the call when the first weird spike hits.

See full security service
FILE 02 / WHAT WE DO

Six security engagements for online retail

ENG-01 · Bot-abuse coverage

Storefront + Checkout VAPT

Named-tester penetration testing on the store, checkout, admin panel and public API. Includes bot-abuse testing on inventory, login, coupon and search endpoints. CVSS 3.1 scoring, PoC screenshots, remediation retest.

ENG-02 · Rehearsed, not promised

Sale-Event DDoS Defence

Cloudflare Magic Transit or AWS Shield Advanced at the edge for volumetric absorption. WAF rules tuned for checkout, cart and product endpoints. Synthetic load test against production edge. War-room support from sale-start to +2 hours.

ENG-03 · Per-endpoint rules

Bot Management & Scraper Defence

Cloudflare Bot Management, DataDome or PerimeterX rules per endpoint. Session-level rate limits, fingerprint velocity checks, business-logic rules for inventory hoarding. Weekly rule review with your fraud ops team.

ENG-04 · SAQ A qualification

PCI-DSS Scope Reduction + Tokenisation

Tokenisation with your acquirer or PA (Razorpay, Cashfree, Juspay, Stripe). CHD flow reduction. Segmentation of the reduced environment. Most brands qualify for SAQ A after this work. Annual pen test and ASV scans handled.

ENG-05 · Card-testing blocked

Checkout Abuse & Fraud Rules

Card testing detection correlated across account age, coupon use and payment failure. Refund abuse loop detection. COD address velocity rules. Alerts routed to fraud ops with raw session for review and rule tuning.

ENG-06 · Rules kept fresh

Managed WAF + SOC (Retail)

Monthly WAF rule tuning that tracks your catalogue and promo changes. 24x7 alerting on Wazuh or Sentinel. On-call incident support. Post-sale review with metrics and rule updates for the next event.

Sale event coming up? Card testing spiking? Bot traffic eating CDN?

15-min call. Tell us the platform, the sale date, the current pain. Fixed-price plan and edge rehearsal timeline back in 48 hours.

FILE 03 / TECH STACK WE USE

Vendors we operate at production scale

Boring, proven pieces. If your team already runs a specific WAF or bot vendor, we work inside it. No forced replacement.

STACK-01

Edge & WAF

Cloudflare (Enterprise) · AWS Shield Advanced · AWS WAF · Imperva

STACK-02

Bot Management

Cloudflare Bot Management · DataDome · PerimeterX / HUMAN

STACK-03

VAPT Toolchain

Burp Suite Pro · Nessus Pro · Nuclei · MobSF

STACK-04

SIEM & Detection

Wazuh · Microsoft Sentinel · Splunk (where run) · Falco (runtime)

STACK-05

Endpoint & EDR

CrowdStrike Falcon · SentinelOne · Sysdig (container)

STACK-06

Secrets & Identity

HashiCorp Vault · AWS Secrets Manager · 1Password Business

FILE 04 / COMPLIANCE WE PREP YOU FOR

Regimes online retail has to answer to

REG-01

PCI-DSS 4.0

Tokenisation-first scope reduction, SAQ A qualification, ASV scans, annual pen test.

REG-02

DPDP Act 2023

Consent capture, purpose limitation, erasure workflow, 72-hour breach notification.

REG-03

ISO 27001

SoA scoped for online retail, risk register, internal audit, cert body handover.

REG-04

GDPR (EU customers)

If you ship to EU, DPA templates, DSR workflow, region-locked storage options.

REG-05

CERT-In Directions

6-hour incident reporting workflow, 180-day log retention.

REG-06

SOC 2 (marketplaces)

Where you sell into US or EU enterprise brand partners with security questionnaires.

REG-07

RBI PA / PG (where in scope)

If you hold a PA licence, the RBI framework maps in alongside PCI-DSS.

REG-08

CCPA (California)

For US-facing D2C brands with California customers. DSR workflow overlap with DPDP.

FILE 05 / PRICING

Fixed-scope engagements, fixed prices

ENGAGEMENT

Storefront + Checkout VAPT

Store, checkout, admin, API. Bot-abuse tests on inventory / coupon / search. Named tester, CVSS, retest.

Rs. 1.5-4 L
SETUP

Sale-Event DDoS + Bot

Edge scrubbing, per-endpoint WAF, bot rules, synthetic load test, war-room cover. Vendor licence separate.

Rs. 2-5 L
SPRINT

PCI Scope + Tokenisation

Tokenisation architecture, CHD flow reduction, segmentation, SAQ A qualification, ASV scans, annual pen test.

Rs. 4-8 L
ONGOING

Managed WAF + SOC

Rule tuning that tracks catalogue changes, 24x7 alerting, fraud pattern review, on-call IR support.

Rs. 80k-2 L/mo

This page covers e-commerce specifics. For the full service catalogue — access control, backup and recovery, monitoring, continuity planning and how engagements run — see Security & Continuity →

FILE 06 / FIELD MANUAL — FAQ

Questions retail engineering leads ask on every call

How do you keep a storefront up during a Diwali or BFCM sale?
Two things kill sale-day uptime. Volumetric DDoS aimed at the checkout, and bot traffic that eats inventory and skews cache hit rates. We put Cloudflare Magic Transit or AWS Shield Advanced at the edge for volumetric absorption. We tune WAF rules so legitimate promo landing traffic gets through while scripted requests get challenged. Bot management (Cloudflare Bot Management, DataDome or PerimeterX) separates scalpers from real customers. Then we rehearse the runbook with the ops team the week before the sale so the on-call knows exactly which lever to pull at 11:59pm.
How do you reduce PCI-DSS scope for a marketplace or D2C brand?
Tokenisation with an approved provider (Razorpay, Cashfree, Juspay, Stripe or your acquiring bank) means the actual PAN never touches your servers. We map every place card data currently flows, replace direct capture with iframe or hosted-fields, and segment the reduced CHD environment behind its own network boundary. Post-work, most brands qualify for SAQ A instead of SAQ D. That is where the audit cost and control burden drop by an order of magnitude. Annual pen test and ASV scans still apply, we handle both.
How is your bot protection different from what Cloudflare gives out of the box?
Cloudflare Bot Management is the tooling. What matters is the rules. A generic setup blocks obvious bad bots but lets checkout scrapers and inventory watchers through because their traffic shape looks like a mobile browser. We instrument your specific endpoints (search, product detail, add-to-cart, checkout) and build rules per endpoint. Rate limits per session, not just per IP. Fingerprint velocity checks. Business logic rules for inventory hoarding. All logged so fraud ops can review and tighten weekly.
What is checkout abuse and why do we need rules for it?
Card testing at scale (thousands of failed auths against your gateway from a botnet), coupon stacking with generated accounts, refund abuse loops, address enumeration to game COD workflows. Payment gateways catch some of it but not all, because the abuse pattern often looks like normal traffic in isolation. We build detection rules that correlate signals across account creation, coupon use, address velocity and payment failure rate. Alerts land in the fraud ops queue with the raw session for review.
Do we need DPDP compliance if we already have a privacy policy?
Yes. DPDP Act 2023 requires more than a privacy policy. It requires consent capture at the point of collection (with a clear notice), purpose limitation (you cannot use address data for marketing if consent was for delivery), the ability to serve access and erasure requests inside timelines, and a 72-hour breach notification playbook to the Data Protection Board. We do a data-flow map, gap review, and build the consent + erasure + notification workflows your ops team can actually run.
Do you work with Shopify Plus, Magento, WooCommerce and custom stacks?
Yes to all. Shopify Plus and custom stacks on AWS / GCP get similar treatment at the edge (WAF, bot management, CDN rules). For self-hosted platforms like Magento and WooCommerce we also handle server hardening, secrets rotation, admin-panel access controls, and dependency vulnerability management. For headless commerce (Next.js storefront + commerce API) we tune the WAF and rate limits per API surface, since the attack shape is different from a monolithic store.
How much does an e-commerce security engagement cost?
Storefront + checkout VAPT: Rs. 1.5 to 4 lakh depending on the surface (public store + admin + API). Sale-event DDoS + bot defence setup: Rs. 2 to 5 lakh plus vendor licence cost. PCI-DSS scope reduction sprint: Rs. 4 to 8 lakh depending on how much of the flow currently touches raw card data. Managed WAF + SOC retainer: Rs. 80,000 to 2 lakh per month. Fixed-price scoping in 48 hours.

Turn sale day from firefight into record

15-min call. Tell us the platform, the sale date, the current pain. Fixed-price plan and edge rehearsal timeline back in 48 hours.