Decipher
Book a Call Get Started
Home / Security / Security for E-commerce
Industry: D2C, Marketplaces & Online Retail

Cyber security for online commerce that survives sale day

Peak-sale DDoS defence rehearsed before the sale, not during. Bot rules that separate scalpers from customers. PCI-DSS scope reduction through tokenisation so your audit boundary shrinks by an order of magnitude. Checkout abuse detection that catches card testing and coupon fraud. DPDP-aligned customer data workflows. Built for D2C brands, marketplaces and online retail.

70+
VAPT engagements shipped
< 15 min
MTTR at sale peak
99.99%
Uptime under bot flood
4
Compliance regimes supported
Threat Surface for E-commerce

Attack shapes every retail engineering lead has to plan against

Sale-day DDoS on the checkout. Attackers time volumetric floods to the moment marketing has spent lakhs driving traffic. Some are competitors, some are extortion attempts, most are opportunistic. The default cloud WAF setup does not stop this on its own. You need real scrubbing capacity, WAF rules tuned for the specific request shape of your checkout, and a runbook the on-call team has actually rehearsed.

Bot traffic that eats inventory and skews caching. Scalper bots buying limited drops in the first 8 seconds. Price-scraper bots hitting product detail pages until your CDN cache hit rate collapses. Inventory-watch bots hammering search endpoints for stock signals. All of these degrade the customer experience for legitimate buyers, and only endpoint-specific bot rules catch them.

Card testing on the payment gateway. A botnet with a fresh dump runs thousands of auth attempts against your checkout to identify live cards. The payment gateway catches some, but often not before the attempts show up on your acquirer statement as chargebacks and gateway fees. Detection rules that correlate account creation, coupon use and payment failure rate turn this from a monthly fire into a solved problem.

Account takeover and refund abuse. Credential stuffing against customer logins, followed by refund abuse loops or wallet drain. Loyalty point theft. COD address enumeration. These are the fraud patterns that show up on the CFO's dashboard as "cost of promotions" but are really the cost of missing fraud rules on the checkout and account layer.

Why retail teams pick us

Sale-day uptime is not a checklist, it is a rehearsal

Every retail vendor promises DDoS defence. We rehearse the runbook with your on-call team the week before the sale, run a synthetic load test on the actual production edge, and sit on the war-room call from sale start to +2 hours. The difference between a Diwali outage and a Diwali record is who is on the call when the first weird spike hits.

See full security service
What We Do

Six security engagements for online retail

Storefront + Checkout VAPT

Named-tester penetration testing on the store, checkout, admin panel and public API. Includes bot-abuse testing on inventory, login, coupon and search endpoints. CVSS 3.1 scoring, PoC screenshots, remediation retest.

Bot-abuse coverage

Sale-Event DDoS Defence

Cloudflare Magic Transit or AWS Shield Advanced at the edge for volumetric absorption. WAF rules tuned for checkout, cart and product endpoints. Synthetic load test against production edge. War-room support from sale-start to +2 hours.

Rehearsed, not promised

Bot Management & Scraper Defence

Cloudflare Bot Management, DataDome or PerimeterX rules per endpoint. Session-level rate limits, fingerprint velocity checks, business-logic rules for inventory hoarding. Weekly rule review with your fraud ops team.

Per-endpoint rules

PCI-DSS Scope Reduction + Tokenisation

Tokenisation with your acquirer or PA (Razorpay, Cashfree, Juspay, Stripe). CHD flow reduction. Segmentation of the reduced environment. Most brands qualify for SAQ A after this work. Annual pen test and ASV scans handled.

SAQ A qualification

Checkout Abuse & Fraud Rules

Card testing detection correlated across account age, coupon use and payment failure. Refund abuse loop detection. COD address velocity rules. Alerts routed to fraud ops with raw session for review and rule tuning.

Card-testing blocked

Managed WAF + SOC (Retail)

Monthly WAF rule tuning that tracks your catalogue and promo changes. 24x7 alerting on Wazuh or Sentinel. On-call incident support. Post-sale review with metrics and rule updates for the next event.

Rules kept fresh

Sale event coming up? Card testing spiking? Bot traffic eating CDN?

15-min call. Tell us the platform, the sale date, the current pain. Fixed-price plan and edge rehearsal timeline back in 48 hours.

Book Free 15-min Call
Tech Stack We Use

Vendors we operate at production scale

Boring, proven pieces. If your team already runs a specific WAF or bot vendor, we work inside it. No forced replacement.

Edge & WAF

Cloudflare (Enterprise) AWS Shield Advanced AWS WAF Imperva

Bot Management

Cloudflare Bot Management DataDome PerimeterX / HUMAN

VAPT Toolchain

Burp Suite Pro Nessus Pro Nuclei MobSF

SIEM & Detection

Wazuh Microsoft Sentinel Splunk (where run) Falco (runtime)

Endpoint & EDR

CrowdStrike Falcon SentinelOne Sysdig (container)

Secrets & Identity

HashiCorp Vault AWS Secrets Manager 1Password Business
Compliance We Prep You For

Regimes online retail has to answer to

PCI-DSS 4.0

Tokenisation-first scope reduction, SAQ A qualification, ASV scans, annual pen test.

DPDP Act 2023

Consent capture, purpose limitation, erasure workflow, 72-hour breach notification.

ISO 27001

SoA scoped for online retail, risk register, internal audit, cert body handover.

GDPR (EU customers)

If you ship to EU, DPA templates, DSR workflow, region-locked storage options.

CERT-In Directions

6-hour incident reporting workflow, 180-day log retention.

SOC 2 (marketplaces)

Where you sell into US or EU enterprise brand partners with security questionnaires.

RBI PA / PG (where in scope)

If you hold a PA licence, the RBI framework maps in alongside PCI-DSS.

CCPA (California)

For US-facing D2C brands with California customers. DSR workflow overlap with DPDP.

Pricing

Fixed-scope engagements, fixed prices

Engagement
Storefront + Checkout VAPT

Store, checkout, admin, API. Bot-abuse tests on inventory / coupon / search. Named tester, CVSS, retest.

Rs. 1.5-4 L
Setup
Sale-Event DDoS + Bot

Edge scrubbing, per-endpoint WAF, bot rules, synthetic load test, war-room cover. Vendor licence separate.

Rs. 2-5 L
Sprint
PCI Scope + Tokenisation

Tokenisation architecture, CHD flow reduction, segmentation, SAQ A qualification, ASV scans, annual pen test.

Rs. 4-8 L
Ongoing
Managed WAF + SOC

Rule tuning that tracks catalogue changes, 24x7 alerting, fraud pattern review, on-call IR support.

Rs. 80k-2 L/mo
FAQ

Questions retail engineering leads ask on every call

Two things kill sale-day uptime. Volumetric DDoS aimed at the checkout, and bot traffic that eats inventory and skews cache hit rates. We put Cloudflare Magic Transit or AWS Shield Advanced at the edge for volumetric absorption. We tune WAF rules so legitimate promo landing traffic gets through while scripted requests get challenged. Bot management (Cloudflare Bot Management, DataDome or PerimeterX) separates scalpers from real customers. Then we rehearse the runbook with the ops team the week before the sale so the on-call knows exactly which lever to pull at 11:59pm.

Tokenisation with an approved provider (Razorpay, Cashfree, Juspay, Stripe or your acquiring bank) means the actual PAN never touches your servers. We map every place card data currently flows, replace direct capture with iframe or hosted-fields, and segment the reduced CHD environment behind its own network boundary. Post-work, most brands qualify for SAQ A instead of SAQ D. That is where the audit cost and control burden drop by an order of magnitude. Annual pen test and ASV scans still apply, we handle both.

Cloudflare Bot Management is the tooling. What matters is the rules. A generic setup blocks obvious bad bots but lets checkout scrapers and inventory watchers through because their traffic shape looks like a mobile browser. We instrument your specific endpoints (search, product detail, add-to-cart, checkout) and build rules per endpoint. Rate limits per session, not just per IP. Fingerprint velocity checks. Business logic rules for inventory hoarding. All logged so fraud ops can review and tighten weekly.

Card testing at scale (thousands of failed auths against your gateway from a botnet), coupon stacking with generated accounts, refund abuse loops, address enumeration to game COD workflows. Payment gateways catch some of it but not all, because the abuse pattern often looks like normal traffic in isolation. We build detection rules that correlate signals across account creation, coupon use, address velocity and payment failure rate. Alerts land in the fraud ops queue with the raw session for review.

Yes. DPDP Act 2023 requires more than a privacy policy. It requires consent capture at the point of collection (with a clear notice), purpose limitation (you cannot use address data for marketing if consent was for delivery), the ability to serve access and erasure requests inside timelines, and a 72-hour breach notification playbook to the Data Protection Board. We do a data-flow map, gap review, and build the consent + erasure + notification workflows your ops team can actually run.

Yes to all. Shopify Plus and custom stacks on AWS / GCP get similar treatment at the edge (WAF, bot management, CDN rules). For self-hosted platforms like Magento and WooCommerce we also handle server hardening, secrets rotation, admin-panel access controls, and dependency vulnerability management. For headless commerce (Next.js storefront + commerce API) we tune the WAF and rate limits per API surface, since the attack shape is different from a monolithic store.

Storefront + checkout VAPT: Rs. 1.5 to 4 lakh depending on the surface (public store + admin + API). Sale-event DDoS + bot defence setup: Rs. 2 to 5 lakh plus vendor licence cost. PCI-DSS scope reduction sprint: Rs. 4 to 8 lakh depending on how much of the flow currently touches raw card data. Managed WAF + SOC retainer: Rs. 80,000 to 2 lakh per month. Fixed-price scoping in 48 hours.
Explore More

Related services

Turn sale day from firefight into record

15-min call. Tell us the platform, the sale date, the current pain. Fixed-price plan and edge rehearsal timeline back in 48 hours.

Decipher Assistant
Typically replies instantly