Finding

The Segmentation Gap Nobody Budgets For: A Recurring Pattern in Retail SD-WAN RFPs

Across large multi-site retail transformations, the same segmentation gap keeps showing up between the network design and how PCI/PoS traffic actually gets isolated. Here's the pattern and what closes it.

network segmentationretailSD-WANPCI

Sample post included to show the format and tone of this section. Replace it with your own writing whenever you’re ready — see the README for how new posts get added.

Across several large-scale retail SD-WAN and network modernization engagements, one gap keeps reappearing in almost identical form, regardless of the incumbent vendor or the size of the retailer. It’s rarely called out explicitly in the RFP, and it’s rarely priced correctly the first time a design goes to the client. This is that pattern, and the fix that’s worked.

The pattern

A retailer with hundreds of locations is modernizing its WAN — usually moving from MPLS-heavy or legacy hub-and-spoke architectures to SD-WAN, often bundled with a security transformation (NGFW at the edge, sometimes SASE). The RFP correctly specifies segmentation requirements: PoS/payment traffic, guest Wi-Fi, corporate/back-office traffic, and IoT (digital signage, refrigeration monitoring, RTLS) all need to be isolated from each other, in line with PCI DSS scope-reduction goals.

Where it breaks down is between network-layer segmentation and security-policy segmentation, which get designed by two different workstreams that don’t always talk to each other on a compressed RFP timeline:

  • The network team defines VLANs and SD-WAN segments per traffic class per store — this part is usually done well and shows up cleanly in the architecture diagrams.
  • The security team defines firewall policy and (if applicable) SASE/SSE policy for those segments — but this is frequently designed against a reference store, not validated against the actual variability across the store footprint.

The gap: retailers rarely have architecturally identical stores. Store formats accumulated over a decade of acquisitions, renovations, and regional buildouts mean the “reference store” segmentation design doesn’t map cleanly onto 15–20% of the footprint — smaller-format stores with collapsed switch stacks, older stores with PoS systems on flat VLANs that were never separated, or stores where a franchise or leased-space tenant’s network was never fully isolated from corporate.

Why it survives to the RFP response stage

This gap is invisible in most RFP responses because both sides are working from the same simplifying assumption: that “typical store” segmentation policy generalizes. It generalizes for 80-85% of locations. The remaining stores get discovered — expensively — during phased rollout, when a site survey shows PCI-scope traffic sharing a VLAN with something it shouldn’t, and the SD-WAN policy has to be reworked store-by-store instead of templated.

The cost isn’t just engineering time. It’s schedule risk on a rollout that was priced and sold as a templated, repeatable deployment, and it’s the kind of finding that erodes trust mid-project if it isn’t flagged during solutioning.

What closes it

The fix isn’t more detailed reference-store diagrams — it’s a cheap, early step that’s easy to skip under RFP time pressure:

  1. Segment a statistically meaningful sample of non-reference stores early, not just the flagship/reference site. A sample across store formats (smallest, oldest, most recently acquired, most recently renovated) surfaces the variance before it’s a rollout-phase surprise.
  2. Price a segmentation remediation contingency explicitly, rather than assuming zero exceptions. Even a rough percentage-of-footprint contingency, agreed with the client up front, changes the conversation from “unplanned change order” to “known and budgeted variance.”
  3. Separate “network segment exists” from “security policy correctly scopes it” as two distinct sign-offs in the design validation process, so a VLAN being present isn’t mistaken for the PCI boundary being enforced.

None of this is exotic. It’s closer to a project-management fix than a technical one. But it’s the single most common gap I’ve seen between a segmentation design that looks complete on paper and one that survives contact with several hundred real stores.


← Back to all writing