New · Retail & Finance PCI DSS v4.0.1 and DORA support now live

Cybersecurity for Retail & Finance in Sweden

Payment pages, POS networks and core banking systems all carry obligations general office IT does not. eBuilder Security runs 24/7 MDR built around transaction integrity, PCI DSS scope and DORA’s incident-reporting clock, for retailers and financial institutions that cannot staff that watch internally.

See the DORA and PCI DSS Regulatory Mapping

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Organisations Since 2002

Two Regulatory Spines

PCI DSS for Retail. DORA for Finance.

Finance is governed primarily by DORA, in force since 17 January 2025, which takes precedence over NIS2 as the sector-specific law and is supervised in Sweden by Finansinspektionen. Retail is largely outside NIS2 scope unless it runs an online marketplace, so PCI DSS v4.0.1 and GDPR are the binding baseline instead.

Do not treat these as one blended commerce requirement. A retailer’s checkout page and a bank’s core systems answer to different regulators, different deadlines and different penalty structures.

4 Hours Financial entities must send initial notification within 4 hours of classifying an incident as major, no later than 24 hours from detection, then an intermediate report within 72 hours. DORA, in force since January 2025 · EBA Joint Technical Standards, 2024
PCI DSS · Payment Pages Lock Down the Checkout

Inventory and authorise every script on payment pages, detect tampering, and require MFA across the entire cardholder data environment, not just admin accounts.

NIS2 · Retail Scope Know If You Are Actually In Scope

Most retailers sit outside NIS2 unless they run an online marketplace. PCI DSS and GDPR remain the binding baseline for anyone handling card data.

DORA · Five Pillars Build Board-Approved ICT Resilience

ICT risk management, incident classification and reporting, resilience testing including threat-led penetration testing, third-party oversight and information sharing.

DORA · Art. 1(2) DORA Comes First for Finance

For financial entities, DORA takes precedence over NIS2 as lex specialis. Finansinspektionen supervises reporting through its FIDAC portal in Sweden.

The Threat Picture

Payment Data. Transaction Rails. Two Different Targets.

Retail’s exposure sits at the point of sale and the checkout page: card data, customer credentials and third-party POS vendors. Finance’s exposure is direct fraud, account takeover and operational resilience under regulatory watch. Both are being actively targeted right now, not hypothetically.

DORA & PCI DSS · Control Mapping

Every DORA Pillar. Every PCI DSS Control. One Partner.

DORA’s five pillars govern finance. PCI DSS v4.0.1 governs anyone handling card data. Here is how each requirement maps to what we do, so your board and auditors have a clear answer either way.

DORA · Pillar 1 ICT Risk Management

A board-approved ICT risk framework covering production, payment and core systems, kept current for audits.

DORA · Pillar 2 Incident Classification & Reporting

Detection tight enough to hit DORA’s 4-hour initial, 24-hour, 72-hour and one-month reporting chain.

DORA · Pillar 3 Resilience Testing & TLPT

Annual resilience testing plus threat-led penetration testing under TIBER-EU for entities designated by Finansinspektionen.

DORA · Pillar 4 ICT Third-Party Risk

Register of Information covering every ICT vendor and critical provider contract, kept current and audit-ready.

DORA · Pillar 5 Information Sharing

Voluntary threat-intelligence sharing folded into ongoing SOC reporting rather than a separate process.

PCI DSS · 6.4.3 / 11.6.1 Payment-Page Integrity

Every script on the payment page authorised, inventoried and checked for tampering, the direct answer to Magecart-style skimming.

PCI DSS · 8.4.2 Access Control & MFA

MFA required across the entire cardholder data environment, not just administrator accounts.

PCI DSS · 12.8.4 Vendor & Service Provider Management

Third-party service provider responsibilities documented and reviewed on an ongoing basis.

DORA Art. 1(2) & PCI DSS Governance Board & Management Accountability

Leadership gets a clear, personal answer on DORA and PCI DSS accountability through governance support and audit-ready documentation.

Mapping provided for orientation. Confirm final scoping against current Finansinspektionen and PCI SSC guidance for your entity type.

DORA & PCI DSS · Free Checklist

Everything Your Board Needs to Know About DORA & PCI DSS

Two regulatory spines, one checklist. See where your organisation stands against DORA’s pillars and PCI DSS v4.0.1, written for Swedish retailers and financial institutions.

  • Incident reporting: DORA requires initial notification within 4 hours of classifying a major incident, no later than 24 hours from detection, then a 72-hour intermediate report and a final report within one month.
  • Third-party & vendor risk: DORA’s Register of Information covers every ICT third-party contract, and PCI DSS 12.8.4 requires documented third-party service provider responsibilities.
  • Board accountability: DORA and PCI DSS both make governance and compliance ownership a board-level issue, with critical ICT provider penalties reaching 1% of daily worldwide turnover.

Plain language, built for Swedish retail and finance teams, takes around 20 minutes to complete.

DORA & PCI DSS Readiness Checklist

Board-ready output reflecting current Finansinspektionen and PCI SSC guidance. Delivered to your inbox instantly.

No spam. EU data residency. Unsubscribe any time.

Transactions Covered, Both Sides

Built Around Payment Data and Fraud Risk.

Retail and finance each get monitoring shaped for how they actually get attacked, not one generic package stretched across both.

NEW

AI Detection & Response

Separate Signal from Seasonal Noise

Retail gets anomaly detection tuned to spot credential-stuffing and bot fraud inside legitimate seasonal traffic spikes. Finance gets fraud-adjacent account-takeover detection and DDoS mitigation, built to distinguish a real attack from a busy trading day.

Learn About AIDR

24/7 MDR & SOC

Watch the Checkout, Watch the Ledger

For retail, our Sweden-based SOC watches POS networks and payment pages, with extra coverage through understaffed holiday periods. For finance, it runs continuous transaction monitoring built to detect fast enough to feed DORA’s 4-hour major-incident reporting clock.

Learn About MDR

Penetration Testing

Test Where the Money Moves

Retail testing is scoped around PCI DSS boundaries and e-commerce payment-page integrity. Finance testing covers core banking systems and API security, plus threat-led penetration testing under TIBER-EU for entities designated under DORA.

Learn About Penetration Testing

Security Awareness

Close the Helpdesk Gap

Helpdesk social engineering was the entry point for the Scattered Spider retail attacks, and phishing plus pretexting lead finance social-engineering incidents. Training targets both, with realistic simulations for store, branch and support staff.

Learn About Security Awareness

CISO as a Service

Own Governance Without a Full-Time Hire

Finance clients get DORA governance support, board accountability and Register of Information upkeep. Retail clients get PCI DSS compliance ownership, GDPR alignment and NIS2 scope assessment where an online marketplace is operated.

Learn About CISO as a Service

Not Sure
Where to Start?

FREE 30-MIN SECURITY REVIEW

Book a 30-minute review. We’ll review your current posture and tell you exactly what matters most.

Talk to a Security Analyst
Built in Sweden. Proven in Practice.

Evidence, Not Assurances.

We lead with operational discipline: how fast we detect, how consistently we report, and where the data physically sits. None of this is a marketing claim, it is what we walk through with your board or auditors on request.

See the Full DORA & PCI DSS Mapping

2m 50s
Average Response Time

Detection measured in minutes, fast enough to feed DORA’s 4-hour reporting clock rather than lag behind it.

24/7
Sweden-Based SOC

Every signal watched around the clock, with logs held entirely within Sweden-based infrastructure.

<72h
Live Coverage, Not Quarters Away

MDR coverage can go live within 72 hours once access and approvals are confirmed, POS and core systems included.

20+
Years in Cybersecurity

A dedicated practice within eBuilder, a Swedish technology company operating since 2002.

ISO 27001
Independently Certified

Our SOC is independently audited and certified to the ISO 27001 information security standard.

ISO 27001 certification mark

DORA
Operational Resilience Support

Services support ICT risk management, incident reporting and third-party oversight required under DORA.

GDPR
& Schrems II Aligned

Human-led monitoring and infrastructure aligned with GDPR and Schrems II requirements.

Common Questions

The Questions We Hear from Retail & Finance Teams

Browse by topic to find the answer you need.

Does our retail business need to comply with NIS2, PCI DSS, or both?

Most retailers are not directly in NIS2 scope unless they operate an online marketplace, an important entity under Annex II, or are pulled in via size thresholds or supply-chain requirements. The binding baseline for a retailer handling card payments is PCI DSS v4.0.1, mandatory since 31 March 2025, alongside GDPR.

Does our finance company need to comply with DORA, NIS2, or both, and which takes precedence?

Financial entities must comply with DORA, which takes precedence over NIS2 as the sector-specific act, or lex specialis, under Article 1(2) of DORA and Article 4(1) of NIS2. Cybersäkerhetslagen applies to non-financial sectors instead.

What PCI DSS controls actually changed with v4.0.1?

51 future-dated requirements became mandatory on 31 March 2025 with no grace period. The two built specifically to counter Magecart-style skimming are 6.4.3, which requires every payment-page script to be authorised, integrity-assured and inventoried, and 11.6.1, which requires tamper and change detection on payment pages. Requirement 8.4.2 now requires MFA for all access to the cardholder data environment, not just administrators.

What are the five pillars of DORA?

ICT risk management; ICT-related incident management, classification and reporting; digital operational resilience testing, including threat-led penetration testing based on TIBER-EU; managing ICT third-party risk, including oversight of critical providers; and information sharing.

What is different about securing payment or transaction systems versus general office IT?

Payment systems sit inside a PCI DSS cardholder data environment requiring tokenisation, encryption, MFA for all access, real-time transaction monitoring and payment-page script integrity checks. General office IT carries none of these obligations, which is why generic monitoring falls short.

What happens if our POS systems or core banking systems are breached?

Operationally, payment processing can stop entirely. A 2021 supply-chain ransomware attack on a Swedish supermarket chain’s point-of-sale provider forced nearly 800 stores to close. Financially, card reissuance runs 5 to 15 euros per card, and finance firms also face steep regulatory fines and account attrition.

How does MDR work for a payment-heavy or transaction-heavy environment?

Our SOC monitors POS networks and payment pages, runs fraud-adjacent anomaly detection, and is built to detect fast enough to feed DORA’s 4-hour major-incident notification clock. This matters most during holiday periods, when a large majority of attacked organisations are hit on a weekend or holiday.

What are the incident-reporting obligations and penalties under NIS2, DORA and PCI DSS?

Cybersäkerhetslagen requires reporting within 24 and 72 hours, with fines up to €10 million or 2% of turnover. DORA requires initial notification within 4 hours of classifying an incident as major, no later than 24 hours from detection, an intermediate report within 72 hours and a final report within one month. Critical ICT third-party providers can face penalties of up to 1% of daily worldwide turnover for up to six months. PCI DSS non-compliance risks card-network fines and loss of card-processing ability.

Who supervises DORA compliance in Sweden?

Finansinspektionen is the competent authority for DORA supervision, receiving incident reports through its FIDAC portal, while Riksbanken is responsible for threat-led penetration testing. Digital operational resilience is an FI supervisory priority for both 2025 and 2026.

How is eBuilder Security priced for retail and finance clients?

Pricing mirrors our endpoint-based MDR model, with one predictable monthly fee covering incident response, analyst escalation and alert handling. Penetration testing, CISO as a Service and security awareness training sit outside MDR and are scoped separately based on what you need.

Why choose eBuilder Security over a larger global cybersecurity platform?

Larger platforms are built for generic global coverage, not Nordic regulatory fluency. eBuilder Security understands DORA, Finansinspektionen and Cybersäkerhetslagen from the inside, keeps data within Sweden-based infrastructure, and responds the same business day, framed around protecting payment data, transaction integrity and regulatory-audit readiness rather than generic platform coverage.

Book a Briefing

Every Transaction Watched.
Every Report Ready.

Talk to a Sweden-based analyst for 30 minutes, no cost, no obligation. We’ll walk through your current PCI DSS or DORA position, flag what actually needs attention first, and show you the SOC in action.

Get the DORA & PCI DSS Readiness Checklist
No commitment required Sweden-based advisor responds same business day