Why Payment Card Security Is Now a Cross-Border Business Problem

Digital payments have lowered the practical barriers for a small business to sell into foreign markets, but they have also made payment card data a cross-border liability. The Payment Card Industry Data Security Standard, or PCI DSS, was built to standardize how businesses protect cardholder account data, and it remains the baseline most regulators use even as newer privacy laws appear. The problem for small firms is not the standard's intent; it is that compliance can consume resources they do not have.

The cost of ignoring that exposure is well documented. Wawa's 2019 point-of-sale breach, which began with a phishing attack, affected 34 million cards and produced $48.8 million in settlements. M&S closed online orders for weeks after its own breach, losing millions in sales. British Airways was fined £20 million in 2020 partly because it held card and CVV data it did not need.

Those cases matter for small exporters because PCI DSS enforcement is not uniform. In some countries, acquirers do not actively monitor compliance or require annual validation. Where regulatory pressure is weak, customer and partner trust becomes the main commercial reason to maintain the standard.

Where Small Exporters Get PCI DSS Wrong — and Where the Costs Actually Bite

Why Weak Enforcement Makes Reputation the Real Penalty

PCI DSS is not policed equally across markets. In regions where acquirers do not require annual validation, the absence of fines can make compliance appear optional. The evidence in this guide points the other way: the reputational damage from a public breach — lost customers, disrupted trading partnerships, weeks of offline sales in the M&S case — can exceed the direct settlement cost. For an SME entering a market where compliance is expected but not formally checked, a breach can close doors before the business has established itself.

Scoping, Not Shortcuts, Is the Cost Lever

The biggest avoidable expense is over-compliance: protecting card data flows that do not need to exist. The British Airways fine is the clearest illustration. Temporary storage, CVV retention and unnecessary data transmission expand the assessment scope and increase both breach exposure and remediation effort. The operational insight is to map where cardholder data actually enters, moves and leaves the business before choosing between a self-assessment questionnaire and a PCI Qualified Security Assessor. That upfront scoping can reveal where the company can simply stop handling data.

Third-Party Tools Do Not Transfer the Obligation

Payment plugins and analytics scripts are a recurring weak point because they extend the attack surface without reducing the merchant's responsibility. The Picreel skimming incident and the Funnel Builder WordPress plugin hack show how a small business can be compromised through code it did not write. Under PCI DSS, using a third-party processor, store or script provider does not eliminate the business's duty to protect its customers' card data — it only changes where the controls must be verified.

A Scoped PCI DSS Checklist for Small Businesses Selling Abroad

  • Map every flow that touches cardholder data before choosing an assessment path. That determines whether a self-assessment questionnaire is enough or a PCI Qualified Security Assessor is required, and it can remove unnecessary scope.
  • Stop retaining card numbers and CVV codes unless there is a specific operational reason. British Airways' £20 million fine was tied to holding data it did not need.
  • Check the scripts running on payment pages and confirm that any plugin is on a patched version; the Funnel Builder WordPress plugin attack left users exposed even after a fix because many stayed on the old version.
  • Include part-time staff, contractors and consultants in phishing and security-awareness training, with clear escalation steps for anything unusual — human error was the entry point in the Wawa breach.
  • Assign a named individual to own PCI DSS compliance and set an annual reassessment rhythm with approved scanning vendors; compliance is continuous, not a one-off project.

Risk & Opportunity Assessment

Commercial RiskHighBreach costs can be severe for small firms: Wawa's phishing-related point-of-sale breach produced $48.8 million in settlements, and M&S lost millions in sales while online orders were shut for weeks.
Competitive RiskMediumIn markets where PCI DSS compliance is expected but not formally policed, a weak security record can make international customers and partners choose a competitor that can demonstrate serious data protection.
Regulatory RiskMediumEnforcement is uneven across jurisdictions, but fragmented regional laws and penalties remain; British Airways was fined £20 million in 2020 for a breach involving card and CVV data.
Reputation RiskHighThe article argues that reputational damage from a publicized breach can be almost as costly as the breach itself, particularly for SMEs trying to build trust in new markets.
Technology DisruptionMediumOutdated payment infrastructure and third-party scripts create recurring exposure; the Funnel Builder WordPress plugin and Picreel card-skimming examples show how quickly external tools can become attack vectors.
Commercial OpportunityMediumContinuous PCI DSS compliance can be used as a market-access advantage, reassuring overseas customers and partners and supporting expansion into territories where compliance is expected.