LAN (Local Area Network)
LAN (Local Area Network) is a computer network covering a limited geographic area, such as an office or building. In payments, LANs may support point-of-sale systems and internal processing infrastructure.

A LAN, or local area network, is a network that connects devices within a single physical site, such as a shop, warehouse or office, rather than spanning multiple locations the way a wide area network (WAN) does. In a retail setting, that usually means the till, the card reader, the back-office computer and maybe a stock-management terminal all sitting on the same local network, talking to each other and to the internet through a shared connection.
It sounds like a fairly mundane piece of infrastructure, and most of the time it is. But a LAN carrying payment traffic isn't quite the same as a LAN carrying ordinary office traffic, because cardholder data moving across it becomes a target the moment it's on the network. How that LAN is designed, and specifically how well it's segmented from everything else a business runs, ends up shaping a good deal of its exposure to fraud and its obligations under card industry security rules.
Why Retailers Rarely Run One Single Flat Network
A flat network, where every device sits on the same segment with no separation, is simple to set up but risky to run. If a till and, say, a guest Wi-Fi router share the same network with no controls between them, a weakness in one can potentially expose the other. That's not a hypothetical concern: publicly reported retail breaches have shown attackers pivoting from a poorly segmented, less sensitive part of a network into the systems that actually process card data. Segmentation exists specifically to prevent that kind of lateral movement.
How Segmentation Actually Reduces PCI Scope
Under PCI DSS, any system that touches, stores or could affect the security of cardholder data generally falls within scope for compliance purposes. Properly segmenting a LAN, so that payment systems sit isolated from everything else, can meaningfully shrink how much of the network actually falls under that scope.
Firewalls, VLANs and access control lists are the usual tools for enforcing that separation, explicitly allowing only the traffic that needs to pass between segments and denying everything else by default.
Wireless LANs Bring Their Own Complications
Wireless LANs add a layer of risk that wired networks don't really have, since a Wi-Fi signal doesn't stop neatly at a shop's front door. A poorly secured wireless network can potentially be accessed from outside the building entirely, which is why guidance on wireless LAN security generally calls for strong encryption, regularly rotated credentials, and keeping any wireless access used for payment devices on its own isolated segment rather than sharing it with general guest or staff Wi-Fi.
What Happens When Segmentation Isn't Done Properly
Segmentation only reduces risk if it's actually verified to work, rather than assumed to work. A firewall rule that looks correct on paper can still leave an unintended path open between segments, and it's generally the job of a qualified assessor to confirm during a PCI audit that an out-of-scope system genuinely couldn't affect the security of the cardholder data environment even if it were compromised. Without that verification, a business can end up believing it has a smaller compliance footprint than it actually does.
Where Kiosks And Point-Of-Sale Devices Fit In
Unattended devices like a kiosk payment terminal raise the stakes a little further, since there's no member of staff nearby to notice unusual activity on the local network segment that device sits on. Businesses running unattended payment hardware generally isolate it on its own tightly controlled segment, separate even from staffed point-of-sale terminals, precisely because the lack of supervision makes that segment a more attractive target.
Practical Steps For Getting LAN Segmentation Right
Businesses generally start by mapping exactly where card data flows across the network, since it's hard to segment effectively without first knowing what needs separating from what.
From there, using dedicated firewalls between zones, restricting wireless access for payment devices, and having a qualified assessor verify the segmentation actually holds under testing all tend to matter more than any single piece of hardware.
As SecurityMetrics notes in its guidance on network segmentation, even segmentation that looks adequate on a network diagram can fail in practice if it hasn't been properly tested against real-world attack paths.
How LAN Design Fits Into The Wider Payment Stack
A LAN is only one layer in a much larger stack of controls that protects a business's payment flows, sitting alongside encryption, tokenisation, and monitoring at the application level. finera.'s own overview of security layers in modern payment stacks makes a similar point: no single control, LAN segmentation included, is meant to carry the full weight of protecting cardholder data on its own.
Treating network design as one piece of a layered defence, rather than a standalone fix, tends to produce a more resilient setup than leaning heavily on any one control in isolation.
Frequently Asked Questions
A LAN carrying payment traffic is a more attractive target than an ordinary office network, since cardholder data moving across it can be exposed if the network isn't properly segmented from less secure systems.
Network segmentation isolates payment systems from other parts of a business's network. Properly done, it can reduce how much of the network falls under PCI DSS compliance requirements.
Generally yes. A Wi-Fi signal can potentially be accessed from outside a building, so wireless LANs used for payment devices typically need strong encryption and isolation from general staff or guest Wi-Fi.
Segmentation is generally verified by a qualified assessor during a PCI audit, who tests whether an out-of-scope system could still affect the security of the cardholder data environment if compromised.
Usually not. Unattended devices like payment kiosks are typically isolated on their own tightly controlled network segment, separate from staffed point-of-sale terminals, due to the lack of on-site supervision.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


