PCI_DSS_v4Requirement 4voice-validated

PCI_DSS_v4 R4: Requirement 4

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Sensitive information must be encrypted during transmission over networks that are easily accessed by malicious individuals. Misconfigured wireless networks and vulnerabilities in legacy encryption and authentication protocols continue to be targets of malicious individuals who exploit these vulnerabilities to gain privileged access.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T11331. Attackers target external remote services, especially when encryption is weak or absent during transmission, as specified in Requirement 4. This allows unauthorized access to sensitive data.
90%
T11901. Exploiting public-facing applications is a primary method when vulnerabilities exist in legacy encryption or authentication protocols, as highlighted in Requirement 4. This leads to initial access.
90%
T10781. Weak authentication protocols, as mentioned in Requirement 4, enable attackers to compromise valid accounts. 2. This provides initial access and facilitates further malicious activities.
80%
T10681. Exploiting vulnerabilities in network services or protocols, particularly legacy ones, can lead to privilege escalation. 2. Requirement 4 directly addresses the risk of gaining privileged access through such exploits.
80%
T10561. Input capture, such as sniffing unencrypted network traffic on misconfigured wireless networks, directly exposes sensitive information. 2. Requirement 4 mandates encryption to prevent this.
90%
T10461. Attackers perform network service discovery to identify systems with weak encryption or legacy protocols. 2. This reconnaissance precedes exploitation, as described in Requirement 4.
70%
T10211. Remote services can be accessed using compromised credentials or by exploiting weak protocols. 2. This facilitates lateral movement within a network, a risk amplified by non-compliance with Requirement 4.
80%
T10051. Once privileged access is gained through network vulnerabilities, attackers collect sensitive data from local systems. 2. This is a direct consequence of failing to protect data in transit.
70%
T10711. Attackers use application layer protocols for command and control, especially if network traffic is not adequately encrypted. 2. Requirement 4's focus on encryption mitigates this C2 channel risk.
80%
T10411. Exfiltration over C2 channels is a common method for stealing sensitive data. 2. Lack of strong encryption during transmission, as addressed by Requirement 4, makes this technique highly effective.
90%
T10201. Automated exfiltration of data is facilitated when network security, including encryption during transmission, is weak. 2. Requirement 4 aims to prevent such data loss.
80%
T10031. If privileged access is gained via network vulnerabilities, attackers often dump OS credentials. 2. This technique is a follow-on to initial access enabled by weaknesses in encryption or authentication protocols.
70%
T15521. Unsecured credentials can be discovered when transmitted over unencrypted or weakly encrypted networks. 2. Requirement 4 directly addresses this by mandating encryption for sensitive information in transit.
90%
T15721. Protocol tunneling can bypass network controls, especially if encryption is not universally enforced or monitored. 2. This technique allows attackers to evade detection and exfiltrate data.
70%
T15661. Phishing can be an initial access vector, leading to compromised systems where sensitive data is then transmitted. 2. While not directly about transmission, it's a common precursor to exploiting network weaknesses.
70%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10411. Encrypting sensitive information is the core defensive measure mandated by Requirement 4. 2. This directly protects data during transmission over networks.
100%
M10371. Filtering network traffic blocks malicious activity and enforces the use of secure protocols. 2. This prevents exploitation of legacy encryption and authentication protocols, as per Requirement 4.
90%
M10421. Multi-factor authentication strengthens access controls, mitigating risks from weak authentication protocols. 2. This directly addresses a vulnerability cited in Requirement 4.
90%
M10381. Network segmentation isolates sensitive systems, limiting the impact of a breach even if initial access occurs. 2. This reduces the attack surface for exploiting network vulnerabilities.
80%
M10401. Network intrusion prevention systems detect and block network-based attacks. 2. This includes attempts to exploit misconfigured wireless networks or legacy protocols, as specified in Requirement 4.
80%
M10351. Limiting access to resources over the network restricts unauthorized connections. 2. This reduces the exposure of sensitive information and the potential for exploitation of network weaknesses.
80%
M10321. Using standard user accounts limits the impact of compromised credentials obtained through weak authentication protocols. 2. This reduces the scope of privileged access an attacker can gain.
70%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-3191. Cleartext transmission of sensitive information directly violates Requirement 4's mandate for encryption during network transmission. 2. This is a fundamental security flaw.
100%
CWE-3261. Inadequate encryption strength, often due to legacy protocols, is explicitly identified in Requirement 4 as a target for malicious individuals. 2. This weakness compromises data confidentiality.
100%
CWE-2871. Improper authentication, particularly with legacy protocols, is a direct vulnerability highlighted in Requirement 4. 2. This allows attackers to gain unauthorized access.
90%
CWE-2001. Exposure of sensitive information to an unauthorized actor is the direct consequence of failing to encrypt data in transit. 2. Requirement 4 aims to prevent this exposure.
90%
CWE-2951. Improper certificate validation can render encryption ineffective, even if present. 2. This weakness allows attackers to intercept and decrypt sensitive information, undermining Requirement 4.
80%
CWE-7321. Incorrect permission assignments for critical network resources can lead to unauthorized access. 2. This contributes to the risk of gaining privileged access mentioned in Requirement 4.
70%
CWE-2841. Improper access control on network resources allows unauthorized individuals to bypass security measures. 2. This weakness facilitates the exploitation of network vulnerabilities.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0186 compute · voice-rubric self-validated