Sporting Goods Retailer · Build

Standing up security for a $6.5B retailer from zero

First enterprise information security leader the company had. 40,000 employees across stores, e-commerce, payment, and corporate. Millions of card transactions a year, a PCI DSS obligation with a date attached, and no existing function to build on.

Organization
Major sporting goods and outdoor retailer — $6.5B revenue, 40,000 employees, national footprint
Role
Head of Information Security (CISO) — first in the role
Scope
Enterprise security across stores, e-commerce, payment, and corporate; team of 10 engineers
Outcome
PCI DSS compliance achieved; security function established and funded

The situation

Retail at this scale has a specific risk shape. Card-present transactions across a large physical store estate, an e-commerce channel with a different threat profile entirely, seasonal workforce turnover measured in thousands, point-of-sale environments that are operationally sensitive and hard to change during trading periods, and a corporate environment holding customer and employee data.

There was no enterprise security function. That is not the same as no security — there were controls and competent people — but there was no one accountable for the whole picture, no strategy, no roadmap, and no seat at the table where decisions with security consequences were being made. And there was a PCI DSS obligation, which unlike most security goals comes with an external assessor and a date.

The temptation in this position is to lead with the audit, because the audit is the thing with the deadline. That produces a compliance function rather than a security function, and it is very hard to convert one into the other afterwards.

What I did

Used PCI as the forcing function, not the destination

PCI DSS was the mandate that made the function fundable, so I used it — but scoped the work so that satisfying it built capabilities worth having regardless. Network segmentation done for cardholder-data scope reduction is good architecture anyway. Access control done properly for PCI is the foundation of enterprise IAM. Logging and monitoring built to PCI standards is the start of a real detection capability.

We achieved PCI DSS compliance and I managed the internal and external audits supporting millions of transactions annually. Just as importantly, the estate was left in better shape than a narrowly-scoped compliance push would have produced.

Modernized identity and moved toward Zero Trust

In a retailer with high seasonal turnover, identity is the control that does the most work. Thousands of people join and leave every year across a large store estate, and the gap between someone leaving and their access being removed is a standing exposure that grows with headcount.

Modernizing IAM addressed that directly, and set the direction toward Zero Trust across card-present, online, and corporate environments — moving away from an implicit trust model where being on the network conferred access. In a distributed store estate, network-location-based trust is not a defensible assumption.

Reduced attack surface, then watched what was left

Deployed EDR across the estate for detection and response capability that did not previously exist. Ran testing and assessments to find and reduce attack surface rather than assuming the picture from documentation. Delivered security awareness training to the full workforce — which in a retail environment, where store staff handle payment devices and customer interactions daily, is a control with real operational leverage rather than a checkbox.

Built the function to be funded, not tolerated

The part that determined whether any of this lasted was partnership. I worked with Sales, IT, Engineering, and Customer Support to keep the roadmap funded, pragmatic, and aligned with growth and customer trust. A first-generation security function that positions itself as the department of no gets routed around within a year and defunded in two.

Practically that meant being useful to those teams — understanding trading calendars, not proposing changes during peak season, and making the case for security work in terms of customer trust and revenue protection rather than in terms of threat.

Outcome

  • PCI DSS compliance achieved, with internal and external audits managed across an environment processing millions of transactions annually.
  • An enterprise security function established from nothing, with 10 engineers and a funded roadmap.
  • IAM modernized and the company moved toward Zero Trust across card-present, online, and corporate environments.
  • EDR deployed and attack surface reduced through structured testing and assessment.
  • Security awareness delivered to the full 40,000-person workforce.

What transfers

When you are the first security leader somewhere, the compliance mandate is your funding, not your strategy. Scope the compliance work so it builds the capability you would have wanted anyway, and spend your political capital on being useful to the operating business. Function-building is mostly a credibility exercise; the technical work is the easy half.

Related