The short answer
A retail chain in Kuwait should run one network across all branches, not one network per branch. In practice that means a FortiGate firewall at every site joined by encrypted VPN tunnels to head office, separate VLANs for POS, back office, CCTV and guest Wi-Fi, a PoE switch and access points per branch, and CCTV retained for 120 days as Kuwait's Law 61/2015 requires. Built this way, opening branch six is a repeat of branch one instead of a new project.
Why most multi-branch retail networks in Kuwait are built wrong
Chains rarely plan a network. They open a shop, the ISP installs a router, someone plugs in the POS, and cameras are added later by a different contractor. Repeat that five times and you have five unrelated networks. The symptoms are always the same:
- Card payments are slow or drop at busy times, because the POS terminal shares one flat network with staff phones, guest Wi-Fi and a wall of cameras uploading footage.
- Nobody can see the other branches. Head office phones the branch manager to ask what the stock system says, and reviewing camera footage means driving there.
- Every branch is configured differently, so every fault is a fresh investigation and no one knows which password belongs to which site.
- Guest Wi-Fi sits on the same network as the tills. A customer's infected laptop is one hop from the payment terminals.
- There is no failover. When the line to one branch goes down, that branch stops trading.
The design that fixes it
1. A FortiGate at every branch, tunnelled to head office
Each site gets its own FortiGate firewall, and each one builds an encrypted IPsec tunnel back to a FortiGate hub at head office. Head office becomes the centre of a private network: stock systems, reporting and camera access all travel inside the tunnels instead of across the open internet.
With SD-WAN on the same devices, each branch can hold two internet connections — a fixed line plus a 5G backup — and switch over automatically when one fails. A branch that keeps trading through an outage pays for that firewall quickly. We covered the economics of 5G links in our 5G business internet case study.
2. Segmentation: one connection, several separate networks
This is the part that matters most and the part most often skipped.
| VLAN | Carries | Rule |
|---|---|---|
| 10 | POS terminals | Payment traffic only; no browsing, no guest access |
| 20 | Back office | Staff PCs, printers, ERP and stock |
| 30 | CCTV | Cameras and NVR; heavy and constant, kept off the POS path |
| 40 | Guest Wi-Fi | Internet only, speed limited, fully isolated |
| 50 | Management | Switches, access points, firewall administration |
The firewall decides what may pass between these networks and, by default, nothing does. Guest Wi-Fi cannot reach a till. A compromised camera cannot reach the back office. Camera uploads cannot slow down a payment.
This is also the honest answer to a question we are asked often: putting POS terminals on their own segmented network is a basic requirement of card-payment security, not an optional extra.
3. Wi-Fi that is designed, not accumulated
Each branch gets a PoE switch and the right number of Ruijie Reyee access points, powered over their network cables so there are no adapters behind the counter. Two wireless networks are published: a staff one joined to the back-office VLAN, and a guest one that only reaches the internet. Because the access points are cloud managed, head office sees every branch's Wi-Fi in one dashboard and we can support it without a site visit.
4. CCTV that satisfies Law 61/2015
Kuwait's Law No. 61 of 2015 requires named categories of premises — including shopping malls, co-operative societies, gold and jewellery shops, and storage facilities — to run approved surveillance systems, keep recordings for 120 days, maintain the equipment, and display signs stating cameras are in use. Penalties for installation and maintenance breaches reach KD 1,000 to 5,000.
For a chain this drives three decisions: an NVR at each branch sized for 120 days of storage rather than 30, cameras on their own VLAN so retention never competes with trading traffic, and a central Hikvision view at head office so footage can be pulled without travelling. Our CCTV installation guide covers camera placement, and the CCTV storage calculator works out how much disk 120 days actually needs.
5. One standard build, repeated
The commercial argument for doing all of this is repeatability. When every branch uses the same firewall model, the same switch, the same access points and the same VLAN numbering, a new branch is a configuration copy rather than a design exercise. Openings get faster, spares cover every site, and any technician can work on any branch.
What to ask before you sign anything
- Will each branch have its own firewall, or is head office the only protected site?
- Are POS terminals on a separate network from guest Wi-Fi and cameras? Ask to see it, not just to be told.
- Is there a second internet connection at branches that cannot afford to stop trading?
- Is camera storage sized for 120 days at the resolution actually being recorded?
- Can head office see all branches — network and cameras — without a site visit?
- Is the build documented and identical across branches, and do you hold the admin passwords?
How UltraTech delivers it
We survey each branch, agree one standard build, and roll it out branch by branch so trading is not interrupted — typically outside opening hours. You get the documentation, the credentials and a single point of contact for the firewalls, the switches, the Wi-Fi and the cameras, rather than four contractors blaming each other.
If you run a chain of shops, restaurants, pharmacies or showrooms in Kuwait, talk to UltraTech Kuwait about a branch network survey. See also our firewall and cybersecurity services and our network solutions.
Expert Insight
The fault we see most often in Kuwait retail is a flat network: tills, cameras, staff devices and customer Wi-Fi all sharing one router. It works until the chain grows, then every branch becomes its own unsupportable design. Standardising on one firewall, one switch and one VLAN scheme across all branches costs less per site than repeatedly troubleshooting five different ones.
References & Sources
