Restaurants are a top target for cybercrime. Your point-of-sale (POS) system touches credit cards, staff logins, and customer data every single day — and most restaurant breaches start with something small: a default password, an unpatched terminal, or a phishing email to a busy manager.
The good news: you don't need an IT department to dramatically reduce your risk. Here is an eight-step POS security checklist built for owners and operators of small and mid-sized restaurants.
1. Segment your POS network
Your POS should live on its own network, separate from guest Wi-Fi and office computers. If a customer's laptop on the guest network gets infected, it should never be able to reach the terminal that processes cards. Most modern routers support a "guest network" — put POS traffic on a separate VLAN or a dedicated connection.
This single change stops a huge share of lateral attacks. See our full restaurant POS security guide for router settings.
2. Change every default password
POS terminals, routers, and back-office software ship with default logins (often printed on a sticker). Attackers know these by heart. Change admin credentials on:
- POS terminals and the POS server
- Your router/modem (especially the ISP-supplied one)
- Any cloud dashboard or vendor portal
- Staff-facing admin accounts
3. Require multi-factor authentication (MFA)
For any account that can change settings or see reports — your processor portal, email, and POS admin — turn on MFA. A one-time code blocks 99% of account takeover attempts even if a password leaks.
4. Keep terminals and software patched
Vendors release security fixes constantly. Enable automatic updates where possible, and schedule a monthly check for terminals, the back-office PC, and the payment app. An unpatched system is an open door.
5. Lock down physical access
POS breaches aren't always digital. Terminals should be where staff can see them, and unused USB ports should be disabled. Log off terminals at the end of a shift, and never leave admin passwords on a sticky note under the drawer.
6. Train your team on phishing
The most common entry point is a fake email — "your payroll needs updating," "click to view this invoice." Teach staff to pause and verify, and run a quick security quiz with new hires. A 2-minute habit prevents most incidents.
7. Choose PCI-compliant, tokenizing processors
Use a processor that tokenizes card data (replaces it with a useless placeholder) so your systems never store full card numbers. This shrinks your PCI scope and your breach blast radius. Our website security tools guide covers providers that do this well.
8. Have an incident response plan
If something looks wrong — duplicated charges, a locked terminal, a weird login alert — know who to call: your processor's fraud line, your POS vendor, and (for larger events) the relevant authorities. Write it down and post it near the office phone.
Make it a habit
Security isn't a one-time setup. A quarterly review — change passwords, check for updates, re-run the quiz with staff — keeps you protected as you grow. Start with our 10-employee security checklist and adapt it to the kitchen.
Frequently Asked Questions
What are the PCI requirements for restaurant POS systems?
PCI DSS requires: (1) Install and maintain firewall configuration, (2) Change vendor-supplied defaults for system passwords, (3) Protect stored cardholder data, (4) Encrypt transmission of cardholder data across open networks, (5) Use and regularly update anti-virus software, (6) Develop and maintain secure systems and applications, (7) Restrict access to cardholder data by business need-to-know.
How do I secure my restaurant's Wi-Fi for customers?
Create two separate networks: (1) Internal network for POS and business operations, (2) Guest network for customers. The guest network should be isolated from your internal systems. Use a business-grade router that supports VLANs or multiple SSIDs. Set up content filtering and monitoring on both networks.