How Currys plc achieved PCI DSS discovery and cloud migration with Enterprise Recon

Industry
Retail
Challenge
As one of the largest technology retailers in Europe, Currys plc needed a data management solution that provided comprehensive discovery and remediation across on-premises and cloud environments to ensure data security and compliance with PCI DSS and data protection and privacy regulations.
Results
Enterprise Recon has enabled Currys plc to establish and maintain high-level data security practices covering their entire data footprint – on-premises and in the cloud – utilizing its scheduled discovery scanning and advanced remediation features.
Key Product
Enterprise Recon PII
“Using Ground Labs Enterprise Recon has been a game changer for our data security processes. Setting up scans, reviewing results and managing our security risks has been straightforward, and with the fact that we can automate these effortlessly has helped save a lot of time.”
Currys plc

About Currys plc
Currys plc is a leading omnichannel retailer of technology products and services, operating through online and 727 stores in 6 countries through its Currys and Elkjøp brands.
As a leading retailer across its operating regions, Currys plc is responsible for security of sensitive and personal information of its 24,000 employees and millions of customers – including payment card data and PII – held in its systems.
The challenge
The search for a comprehensive discovery solution
As one of the leading technology retailers in Europe, Currys plc processes significant volumes of customer data daily, from purchases made across its store network to orders placed online.
In addition to sales and payment-related information, Currys plc employs more than 24,000 people across its operations. As a result, it holds significant stores of personal data and sensitive personal information related to both its customers and employees.
The initial driver for data discovery was PCI DSS compliance; a mandatory security standard for retailers aimed at securing payments information from theft and subsequent fraud. However, the company soon realized that Ground Labs solutions could provide benefits beyond cardholder data discovery.
The solution
Ground Labs’ Enterprise Recon PII delivered comprehensive, flexible discovery for a range of data security initiatives
The Currys group had previous experience with Ground Labs’ solutions through Dixons Carphone Warehouse before the companies were consolidated in 2021, where Enterprise Recon was instrumental in enabling the company to achieve PCI DSS compliance.
Currys plc had since invested in other scanning technologies, however these were unable to provide the ease of use and comprehensive coverage of both data types and platforms offered by Ground Labs’ Enterprise Recon.
As a result, in 2024 Currys plc selected Ground Labs Enterprise Recon as a comprehensive data discovery and data management solution that offered them the coverage and flexibility they were looking for.
Using the PCI DSS data types pre-packaged with Enterprise Recon PII, Currys plc can identify and remediate payments information entering their network. It also enables them to provide QSA-ready reports demonstrating that their environments do not store credit card information for their annual compliance assessment.
In addition, Currys plc has utilized the solution’s comprehensive PII scanning capabilities to enhance sensitive data management across their application databases and unstructured data stores throughout their server estate, on-premises and in the cloud. The solution has been instrumental in their cloud migration strategy, enabling them to identify and protect sensitive data throughout the migration process. Its cloud scanning capabilities ensure that Currys plc can continue to verify the security of this data across their cloud-based infrastructure.
Enterprise Recon PII provides fast, accurate discovery with minimal impact to operational systems, which has allowed Currys plc to scan their entire data footprint with no operational impact. Enterprise Recon’s extensive customization, user-friendly interface and scan scheduling features have empowered Currys plc to automate their scanning process, achieving fast, accurate results.
Once Enterprise Recon PII was deployed, the company was able to get immediate results and flag any data security risks.
As a result, Currys plc is able to maintain high-level data security practices across their organization, efficiently and without disrupting daily business operations. The solution has delivered complete control of Curry’s data security, made compliance effortless and provided peace of mind – all backed up with outstanding technical support.