Put POS Security in the Spotlight

The Cybersecurity Awareness Month POS Security Checklist

Put POS Security in the Spotlight

October is Cybersecurity Awareness Month, and for ISVs, VARs, and other solutions providers, it’s an opportunity to stress to your team and your merchants why point of sale (POS) security is a critical priority. For you, Payment Card Industry Security Standards Council (PCI SSC) compliance is where you live. You make sure systems, networks, and POS environments are PCI Data Security Standard -compliant. You’re looking at PCI PIN Transaction Security Point of Interaction Modular Security Requirements v7 devices with stronger cryptography options, app sandboxing, and biometric ID security. And you’re doing your due diligence to ensure software vendors follow the PCI Secure Software Standard. It doesn’t take Cybersecurity Awareness Month to remind you that the systems you provide must be secure and protect customer and payment data.

On the other hand, Cybersecurity Awareness Month can be an annual event when you take stock and make sure that your team isn’t overlooking the basics that contribute to a secure POS environment. This 10-point checklist can help you tighten POS security to keep payment data, your merchants, and your own business more secure.

October POS Security Checklist

  1. Device Inventory
    The first step is knowing every device that you manage that runs a payment app. Maintaining an accurate inventory of devices, including models and where merchants use them, should be an ongoing project. And as IT environments grow, this list may be longer than it was last October. Once you have the inventory and review it, note hardware that’s no longer supported and make a plan to replace it. Also, make sure all firmware is updated.

  2. Physical Security
    Physically inspect all devices to ensure there are no signs of tampering. Evaluate setups to determine if they need new or upgraded locks, mounts, or enclosures to protect them, and deactivate any unused ports. Cybersecurity Awareness Month is also a good occasion to set up a regular schedule for device inspections.

  3. Network Segmentation
    Network segmentation is a best practice, but as merchants expand the number of ways they accept payments, it may not be as controlled as in the past. Make sure payment data communications are handled separately from other network traffic to help control PCI scope, but more importantly, limit an attacker’s ability to access payment data. Make sure the network, whether wired or wireless, that handles payment data has strong network security.

  4. Application Management
    Ensure that all payment apps are up to date and patched, and double-check that only authorized apps, i.e., those that are cryptographically signed, are running on payment terminals. Disable or delete all unused services or solutions.

  5. Encryption
    Review the cryptography methods your merchants use with their payment solutions. Keep in mind that PCI PTS v7 enables stronger encryption that can help protect against future threats as computing and AI become more powerful.

  6. Avoiding Unprotected Card Data
    Even merchants who know better can sometimes get a little careless. Remind merchants that they should never keep a readable copy of card data, such as a card number written on paper or a digital form with a readable card number entered on it. Stress that card data should be used only in the payment system, controlled by following PCI compliance requirements, encrypted end to end, and tokenized for recurring billing or future purchases.

  7. Controlled Access Privileges
    Ensure that only people in your organization and your merchants’ teams who need access to POS systems, admin privileges, and remote management have it. Following the principle of least privilege minimizes the number of targets that a hacker can attack to get information that gives them access to sensitive data and systems.

  8. Continuous Monitoring
    Merchants need a 24/7 monitoring system that can spot unusual traffic, failed login attempts, and other indicators of suspicious activity. If merchants don’t have IT resources in house to address monitoring and alerts, consider offering this service or arranging it through a partner.

  9. Employee Training
    Make sure merchants’ employees can recognize phishing attempts, protect their login credentials, utilize MFA, and recognize when a device has been tampered with. Trained employees are an important POS security layer.

  10. Preparing for the Unexpected
    Discuss the importance of an incident response plan with merchants so that they know how to respond if they find a payment device that’s been tampered with or see signs of unusual activity in their POS system. Merchants should create and practice their response so they understand who has the responsibility for specific actions if a security breach occurs.

Best Practices for Securing Cardholder Data

Our checklist can help you make sure you aren’t overlooking any interventions that can make payment solutions vulnerable. However, it’s only an additional security layer. There are three highly effective ways to protect cardholder data by ensuring it’s never accessible or visible to hackers.

  1. Semi-Integrated Payments
    Semi-integrated payments connects payment technology to the POS system to receive the amount of the sale and then to provide approval or declines. However, cardholder data is never shared with the POS system. If hackers were to gain access to the POS system, they would not find any cardholder data to steal or monetize.

  2. Point-to-Point Encryption or End-to-End Encryption
    Point-to-point encryption (P2PE) or end-to-end encryption (E2EE) replace human-readable cardholder data with cryptographs that require a key to decipher. Strong cryptography protects payment data and also decreases the merchant’s PCI scope because no plain text cardholder data is used in any part of the merchant’s system.

  3. Tokenization
    Tokenization replaces cardholder data with random alphanumeric characters, which can only be associated with the actual data with information stored securely in a token vault. Tokens allow merchants to remember customers for recurring billing or future purchases without putting human-readable cardholder data at risk.

How Do Your POS Security Policies Measure Up?

With cybersecurity in the news this October, it’s a good time to start a conversation about protecting payment data and business systems with your merchants and spread the word on social media and in marketing campaigns. But remember, although POS security basics may seem simple, they are too important to overlook.

Take some time to review your practices, evaluate your merchants’ security status, and make sure all the bases are covered, from the basics up.

Datacap is available to help partners strengthen POS security and to implement semi-integrated payments, P2PE or E2EE, and tokens to keep cardholder data secure. Contact us to learn more.

FAQs

What’s the merchant’s responsibility for POS security?

Although an ISV or VAR usually handles configuration and updates that help keep POS systems secure, merchants are responsible for following security policies, controlling access, protecting their networks, training employees, regularly inspecting payment devices, and following all PCI requirements. ISVs and VARs need to make sure merchants understand their role in keeping POS systems, customer information, and payment data secure.

Absolutely. If payment data is communicated over an unsecured wireless network, it’s possible for a hacker to capture it. ISVs and VARs should make sure their merchants understand the risks of not using a secure, monitored, segmented network for payment data.

POS solution providers should instruct merchants to look for broken seals, loose components, odd attachments, changes to the card slot, and unfamiliar cables. ISVs and VARs should train merchants to learn what a device should look like and to regularly inspect their payment hardware for signs that someone has tampered with it.

POS systems should be set up so that employees never see card data. The customer can tap or insert their payment card; the payment device should initiate the transaction; and the merchant’s system should receive the approval. Merchants should train employees not to request to see cards and to never write card numbers or take an image of cards that could compromise customer accounts.

ISVs and VARs achieve a stronger market position by making security a part of their value proposition. They can expand the services they offer with, for example, employee security training, compliance guidance, and keeping systems updated. They can also partner to connect merchants with the security solutions and services they need. Taking the role of a POS solution provider that prioritizes security can help merchants reduce risk and build their trust in the ISV or VAR business.