Selling online.
WHAT YOU HOLD
Customer names, addresses, contact details, order history.
WHAT YOU SHOULD NOT HOLD
Card numbers.
Those stay with your payment gateway.
If your site stores them, that is a serious problem requiring immediate attention.
WHAT TO SECURE
Administrative access, with a second step The checkout process Customer data Everything the shop runs on, kept updated
WHAT TO MONITOR
Unusual order patterns Repeated small failed payments, which may indicate card testing Administrative logins Changes to payment settings
THAT LAST ONE
A compromised shop redirecting payments is a known attack.
Check your gateway settings periodically.
WHAT TO ENABLE
Your gateway's fraud controls Transaction alerts
WHAT TO LIMIT
Who can export customer data Who can change payment configuration
WHAT TO TEST
A complete purchase, monthly.
WHAT TO DELETE
Order data past its retention period.