Epic Games
RSI Security helped the video game giant Epic Games navigate regulatory and security challenges.
I’m looking forward to partnering with RSI Security now and into the future.
– Kevin Carpenter, Director of Information Security, Epic Games
The Challenge
Epic Games (epicgames.com), founded in 1991, is one of the worldwide leaders in video games and 3D engine technology. One of its flagship franchises, Fortnite, features over 250 million accounts. And its Unreal Engine is one of the global gold standards for game and 3D experience development.
To bring entertainment and connection to millions of players across the globe—and support its comprehensive digital ecosystem for creators and consumers alike—Epic Games leverages over 40 international offices. In any organization of this size and complexity, security and regulatory concerns carry increased significance due to the sheer number of people they impact. And for Epic Games, time zone differences add a layer of difficulty to communicating responsibilities.
Ultimately, Epic Games needed to secure Payment Card Industry (PCI) compliance, including both preparing for an upcoming assessment and laying the groundwork for long-term maintenance.
Building a Winning Compliance Strategy
RSI Security worked alongside Epic Games to turn complex PCI requirements into a practical path forward. From strengthening architecture and coordinating security assessments across global teams to establishing a sustainable approach to ongoing compliance, each step was designed to solve the immediate challenge while preparing Epic Games for what came next.
RSI Security
Architectural Changes
Senior Security Assessor Peter Phaneuf worked closely with Epic Games Director of Information Security, Kevin Carpenter, to analyze which changes were needed to comply with the PCI Data Security Standards (DSS). RSI Security advised on which changes to make and how. Prior to implementing new architecture or making other critical changes to their systems, Epic Games would consult with Phaneuf and his team to ensure that the new controls were effective and efficient.
RSI Security
Security Assessments
PCI compliance requires in-depth testing across all systems, which is challenging in a global context. Phaneuf and RSI Security’s Project Manager, Arman Bashir, coordinated assessments with international development teams to ensure smooth communication and collaboration across diverse IT and security contexts. This groundwork set Epic Games up for a seamless Report on Compliance (ROC) and Attestation of Compliance (AOC) documentation process.
RSI Security
Compliance Management
Phaneuf and Bashir developed a comprehensive system Epic Games can rely on for long-term PCI compliance. It included building on what made this fragmented engagement work, such as reliable schedules for ongoing regular meetings and realistic timelines for future assessment and remediation exercises. Another major pillar of this system is the streamlined total compliance tracking (TCT) portal—established to facilitate cross-team communication.
Compliance Built
for the Long Game
Epic Games needed more than short-term PCI readiness. Working with RSI Security, the team strengthened its controls and architecture, coordinated assessments across a complex global environment, and established a clear path to ongoing compliance. With repeatable processes and an actionable plan in place, Epic Games can maintain its PCI program while keeping its focus on the millions of players, creators, and stakeholders who rely on its platforms.
THE CLIENT PERSPECTIVE
Prior to our partnership, we were ready for PCI compliance to be a daunting challenge. However, after working with RSI Security, everything about the process has been as efficient and painless as possible. We’ve turned a potential weakness into a strength overnight.
Kevin CarpenterDirector of Information Security, Epic Games
Explore Our Case Studies
USA for IOM
Non-ProfitAccepting digital donations independently meant taking on PCI requirements without a dedicated IT team. USA for IOM turned a complex compliance challenge into a secure fundraising foundation, gaining the knowledge, policies, and processes needed to support future growth.
Macomb Community College
EducationA complex higher education environment called for a more unified approach to cybersecurity. Macomb Community College built stronger governance, implemented CIS Controls, and established a roadmap its teams could sustain long term.
Lumistry
HealthcarePreparing for HITRUST meant turning hundreds of requirements into a manageable security program. Lumistry streamlined the process while building a stronger foundation for ongoing compliance and security.
Turn Your Security Challenges Into Success
Every organization’s security and compliance journey looks different. RSI Security brings the expertise, guidance, and practical support needed to navigate complex requirements, reduce risk, and build a stronger security program around your organization’s goals.