Row midpoint Shape Decorative svg added to bottom
Gaming

Epic Games

RSI Security helped the video game giant Epic Games navigate regulatory and security challenges.

Epic Games Case Study | RSI Security’s Penetration Testing Success

I’m looking forward to partnering with RSI Security now and into the future.

– Kevin Carpenter, Director of Information Security, Epic Games

The Challenge

Epic Games Icon

Epic Games (epicgames.com), founded in 1991, is one of the worldwide leaders in video games and 3D engine technology. One of its flagship franchises, Fortnite, features over 250 million accounts. And its Unreal Engine is one of the global gold standards for game and 3D experience development.

To bring entertainment and connection to millions of players across the globe—and support its comprehensive digital ecosystem for creators and consumers alike—Epic Games leverages over 40 international offices. In any organization of this size and complexity, security and regulatory concerns carry increased significance due to the sheer number of people they impact. And for Epic Games, time zone differences add a layer of difficulty to communicating responsibilities.

Ultimately, Epic Games needed to secure Payment Card Industry (PCI) compliance, including both preparing for an upcoming assessment and laying the groundwork for long-term maintenance.

Building a Winning Compliance Strategy

RSI Security worked alongside Epic Games to turn complex PCI requirements into a practical path forward. From strengthening architecture and coordinating security assessments across global teams to establishing a sustainable approach to ongoing compliance, each step was designed to solve the immediate challenge while preparing Epic Games for what came next.

Step #1

RSI Security

Architectural Changes

Senior Security Assessor Peter Phaneuf worked closely with Epic Games Director of Information Security, Kevin Carpenter, to analyze which changes were needed to comply with the PCI Data Security Standards (DSS). RSI Security advised on which changes to make and how. Prior to implementing new architecture or making other critical changes to their systems, Epic Games would consult with Phaneuf and his team to ensure that the new controls were effective and efficient.

Step #2

RSI Security

Security Assessments

PCI compliance requires in-depth testing across all systems, which is challenging in a global context. Phaneuf and RSI Security’s Project Manager, Arman Bashir, coordinated assessments with international development teams to ensure smooth communication and collaboration across diverse IT and security contexts. This groundwork set Epic Games up for a seamless Report on Compliance (ROC) and Attestation of Compliance (AOC) documentation process.

Step #3

RSI Security

Compliance Management

Phaneuf and Bashir developed a comprehensive system Epic Games can rely on for long-term PCI compliance. It included building on what made this fragmented engagement work, such as reliable schedules for ongoing regular meetings and realistic timelines for future assessment and remediation exercises. Another major pillar of this system is the streamlined total compliance tracking (TCT) portal—established to facilitate cross-team communication.

Compliance Built
for the Long Game

Epic Games needed more than short-term PCI readiness. Working with RSI Security, the team strengthened its controls and architecture, coordinated assessments across a complex global environment, and established a clear path to ongoing compliance. With repeatable processes and an actionable plan in place, Epic Games can maintain its PCI program while keeping its focus on the millions of players, creators, and stakeholders who rely on its platforms.

THE CLIENT PERSPECTIVE

Prior to our partnership, we were ready for PCI compliance to be a daunting challenge. However, after working with RSI Security, everything about the process has been as efficient and painless as possible. We’ve turned a potential weakness into a strength overnight.

Kevin Carpenter
Director of Information Security, Epic Games

Explore Our Case Studies

USA for IOM feature

USA for IOM

Non-Profit

Accepting digital donations independently meant taking on PCI requirements without a dedicated IT team. USA for IOM turned a complex compliance challenge into a secure fundraising foundation, gaining the knowledge, policies, and processes needed to support future growth.

Macomb Community College Case Study | RSI Security's Compliance Expertise

Macomb Community College

Education

A complex higher education environment called for a more unified approach to cybersecurity. Macomb Community College built stronger governance, implemented CIS Controls, and established a roadmap its teams could sustain long term.

Lumistry Case Study | Scalable vCISO Services by RSI Security

Lumistry

Healthcare

Preparing for HITRUST meant turning hundreds of requirements into a manageable security program. Lumistry streamlined the process while building a stronger foundation for ongoing compliance and security.

Turn Your Security Challenges Into Success

Every organization’s security and compliance journey looks different. RSI Security brings the expertise, guidance, and practical support needed to navigate complex requirements, reduce risk, and build a stronger security program around your organization’s goals.