A. Strategic principles (how to think about the problem)
Assume compromise at scale. Treat card-testing as inevitable; design to detect and contain fast.
Layered defenses win. No single control (e.g., WAF) is sufficient; combine tokenization, behavioral ML, rate limits, device signals, and...