PCI DSS Compliance Starts With Segregating Your Payments
If you take card payments, PCI DSS applies. The single biggest factor in how painful - and how expensive - compliance becomes is whether your payment devices are properly isolated from the rest of your network. We get that architecture right.
This is the part most businesses get wrong. PCI DSS scope follows the network. If your card terminals (PDQs), tills and EPOS sit on the same flat network as your office PCs, guest WiFi, CCTV and printers, then ALL of those devices are in scope for PCI DSS - every one of them has to meet the standard. Put the payment devices on their own isolated VLAN and the scope collapses down to just those devices.
- Flat network: PDQs, tills, office PCs, WiFi, CCTV - all in PCI scope
- Segmented network: only the payment VLAN (PDQs / tills) in scope
- Smaller scope means a shorter SAQ, fewer controls and far less cost
- It also dramatically shrinks your breach risk and your liability
Flat Network vs Properly Segregated

A Dedicated Payment VLAN, Properly Isolated
We design your network so card payment devices live on their own VLAN with firewall rules that stop anything else from reaching them - and stop them reaching anything else. That isolation is what takes the rest of your business out of PCI scope, and it's documented so your acquirer and your assessor can see exactly how it's enforced.
- Dedicated VLAN for PDQs, tills and EPOS
- Firewall rules enforcing strict segmentation both ways
- Guest and staff WiFi kept entirely separate
- Documented topology and rules ready for your SAQ or audit
A small Surrey cafe (see our Networking page) ran guest WiFi on the same router as their card terminal and an unsecured PC. An attacker pivoted from the public network to the payment data and the business ended up over £25,000 out of pocket between PCI fines, an ICO penalty and forensics. Proper VLAN segregation - a few hundred pounds of managed networking - would have made the attack impossible and kept the rest of the network out of scope entirely.
- PCI non-compliance fines from acquiring banks start around £5,000/month
- A breach involving card data brings ICO penalties on top
- Cyber-insurance often won't pay out where basic segregation was missing
- Segmentation is cheap insurance against a very expensive day
PCI DSS FAQs
Does PCI DSS really apply to my small business?
Yes - if you accept card payments in any form, you have PCI DSS obligations. The level of assessment scales with your transaction volume, but even the smallest merchant has to complete a Self-Assessment Questionnaire (SAQ). Good network design keeps that questionnaire short.
What is network segmentation and why does it matter?
Segmentation means putting your payment devices on their own isolated network segment (VLAN) so nothing else can reach them. It matters because PCI scope follows connectivity - isolate the payment devices and everything else drops out of scope, which slashes the cost and effort of compliance.
Can you work with our existing card terminals?
In most cases yes. We design the network around your existing PDQs, tills and EPOS - the isolation is done at the network and firewall layer, so you usually don't need to replace payment hardware.
How long does it take to get segregated?
For a typical small site it's a short project - survey, VLAN design, firewall configuration and documentation. We'll scope it precisely after a segmentation review.
Shrink Your PCI Scope the Right Way
Let us review your network and show you exactly what's in scope today - and how much smaller it could be.