Loxada makes it straightforward to maintain PCI DSS network segmentation outside a controlled office, for remote and hybrid staff and across retail estates, without complex setups.
PCI DSS requires strong network controls and separation between systems that handle cardholder data and those that do not, so that an organization’s entire IT estate does not fall into scope. In a controlled office that is relatively straightforward. Two situations make it hard: staff working remotely, and payment systems sitting on shared store networks.
Remote and hybrid staff. Customer service agents, finance teams and fraud investigators increasingly reach payment data from home offices, temporary setups and serviced locations. Those environments typically rely on off-the-shelf routers that are unmanaged and potentially unpatched. Even where an encrypted-connectivity client or remote desktop is in use, the local network still presents risk: a compromised or poorly configured home router can allow lateral movement, traffic interception or DNS spoofing before the secure session is established.
Retail stores and franchises. A typical outlet runs a single internet connection shared across everything: POS terminals, tills, admin devices, customer Wi-Fi, even security cameras. If the Cardholder Data Environment is not segmented, all of it falls in scope, including devices with nothing to do with payments. That means more testing, higher audit costs, and greater exposure in a breach, multiplied across every location in the estate.
In both cases, without segmentation the surrounding network becomes part of the CDE, sharply increasing both audit scope and exposure.
Loxada provides device-enforced network separation that supports PCI DSS segmentation, whether the device is in a home office or on a shop floor.
Each Loxada secure router creates a hardened work network regardless of the local infrastructure it connects to, and routes that traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet. Devices on the Loxada network are isolated from the surrounding environment, keeping them separate from unknown and potentially vulnerable systems.
Hardware-level segmentation. Devices and payment systems accessing cardholder data are separated from other devices on the local network.
Encrypted connectivity with no user configuration. Traffic is routed through Loxada’s secure connectivity layer, with no reliance on the local network being sound.
Central control and secure-state behavior. Devices cannot be modified locally and return to a secure default if reset. Access is controlled centrally through subscription and cannot be bypassed by the user.
Blocks known malicious domains. Requests to domains on Loxada’s aggregated blocklist are dropped before they resolve.
Consistent policy. Whether staff are at home, traveling, at a secondary site or behind a till, network access stays predictable and auditable.
This supports the intent of PCI DSS segmentation without the cost or complexity of managing firewalls, VLANs or agent-based software across networks you do not control.
Customer service agentsn handling card data remotely, keeping CDE boundaries intact on unmanaged networks.
Back-office finance teams in hybrid setups, with consistent protection in the office or at home.
Retail operations staff and stores, isolating payment systems on shared or outsourced infrastructure.
Call centers using BYOD or temporary staff, providing a consistent access layer without reconfiguring personal networks
By creating a consistent, isolated environment for handling payment data, Loxada helps organizations avoid unnecessarily expanding their CDE, saving time, cost and audit scope.
The current standard places greater emphasis on flexibility and customized approaches, alongside clear expectations around secure access and segmentation. Assessors may ask for network diagrams, documentation showing traffic is isolated, and evidence of reduced scope based on segmentation controls.
Loxada gives you a repeatable control you can document and demonstrate: a physical, centrally managed system that reduces reliance on variable per-location router configurations and software agents, keeps non-CDE systems out of scope, and behaves consistently regardless of where the user or the till is. Deployment is fully auditable, with monthly security reports and device-status visibility.
Whether a given segmentation approach reduces your assessed scope is ultimately your QSA’s determination. What Loxada provides is a consistent, documentable control to bring to that conversation.