Midwest Home Goods operates 23 locations across five states. In 2022, they implemented point-to-point encryption for all payment terminals after a competitor suffered a breach that cost $2.3 million in settlements. Purchasing manager Astrid Källberg oversaw the transition from their previous system, which stored card data in partially masked format.
Measurable Advantages
The company reduced PCI DSS compliance scope by 70%, cutting annual audit costs from $28,000 to $8,400. Insurance premiums for cyber liability dropped 22% because encrypted payment data lowered their risk profile. Customer complaints about unauthorized charges decreased, though Källberg noted this might correlate with broader industry improvements in fraud detection. The encryption system blocked three attempted breaches in 14 months, incidents they only discovered through security logs.
Ongoing Costs and Complications
Hardware upgrades for 180 payment terminals cost $94,000 upfront. Monthly encryption service fees added $1,200 to operating expenses. Staff training took longer than projected because 15 employees at various locations struggled with the new transaction flow, which added two extra steps to each sale. During the first six months, transaction processing times increased by 4 seconds on average, creating longer checkout lines during peak hours. The system requires quarterly security updates that temporarily disable terminals, forcing stores to use backup manual processing that employees find confusing.
The Calculation Behind the Decision
Källberg compared the $94,000 implementation cost against potential breach expenses. The competitor's breach affected 50,000 customers and cost $46 per affected record in legal fees, notification costs, and credit monitoring. With 200,000 customers in their database, a similar breach could exceed $9 million. The math supported encryption despite the operational friction it introduced.