You know your margins to the penny. You know which twelve items pay the rent and which forty just take up shelf space. You know the Saturday before a holiday does more business than the three weeks before it, and you have staffed around that for years. What you have not had a spare hour for is the technology holding it together: the registers, the inventory counts, the website, and the quiet question of what happens to a customer’s card number after they tap.

That last one is where most retailers feel least sure of themselves, and understandably so. The card industry has its own vocabulary and rulebook. Before we go further: this article is general information, not legal or compliance advice. Card payment obligations depend on how you accept payments and which processor you use, so your acquiring bank, processor, or a qualified assessor has to confirm what applies to your business. Here is the practical version of what a small retailer or online seller should be thinking about.

The Card Data You Never Want to Touch

Start with the simplest idea in this whole subject. In its guide “Data Security Essentials for Small Merchants: Guide to Safe Payments,” version 2.0 published in August 2018, the PCI Security Standards Council states it plainly: “The best way to protect against data breaches is not to store card data at all.” The Federal Trade Commission makes the same point in its August 2023 business guidance “Start with Security,” where the opening lesson is “No one can steal what you don’t have.”

So the goal is not to secure a pile of card numbers. The goal is not to have one.

  • Let the processor hold it. The PCI Security Standards Council guide advises merchants to “consider outsourcing your card processing to a PCI DSS compliant service provider.”
  • Check that your equipment is on the approved lists. The same guide tells merchants to confirm their terminal appears on the list of PCI approved devices and their payment software on the list of validated payment applications.
  • Ask about encryption or tokenization. The guide recommends asking vendors about technologies that “make card data useless even if stolen.” Tokenization replaces the number with a meaningless stand-in.
  • Kill the paper habits. Numbers written on order forms, taped near the phone, or sitting in an email folder are the version nobody budgets for.

Registers, Inventory, and Shared Staff Logins

Retail turnover is a fact of life, not a failure. But most point of sale and inventory systems get set up once with a couple of logins, then run for years while dozens of people cycle through. When everyone uses the same register login, you lose the ability to answer basic questions: who processed that void, who applied that discount, who was at the terminal when the drawer came up short.

The PCI Security Standards Council guide tells merchants to limit employee access based on job requirements and to use unique user IDs. It also warns that default passwords such as “password” or “admin” are “commonly known by hackers and are a frequent source of small merchant breaches.”

  • One login per person, even part timers. A few minutes at hire, and removal on the day they leave, same shift as collecting the key.
  • Manager functions need manager credentials. Voids, refunds, price overrides, and drawer opens should require someone with authority, not a code the whole store knows.
  • Inspect the terminals. The guide advises checking payment devices for signs of tampering and keeping a record of who goes behind the counter. Card skimmers get attached to real terminals in real stores.

The Season Your Website Cannot Go Down

Every retailer has one. For some it is the six weeks before Christmas. For others it is back to school, a spring event, or the day a product drops. Whatever it is, a stretch of hours in that window outearns entire ordinary months, and that is exactly when systems get pushed hardest and nobody has slack to troubleshoot. Preparation starts about ninety days out, not the week before.

  1. Do the boring updates early. Website platform, plugins, and register software get patched in the slow season.
  2. Freeze changes before the rush. Pick a date after which nothing new gets installed. Most peak season outages are self inflicted.
  3. Know who you call at 2am. Host, payment processor, and platform support numbers with account IDs, written on paper.
  4. Have a manual sale plan. If the network drops, how do you take payment and record the sale? Decide in September, not December.
  5. Test your backups now. Restore something, while there is still time to fix it if it fails.

Remember too that outages are not always yours. Big cloud and hosting providers have bad days and take a lot of businesses with them, which we covered in the cloud can go down and what that means for your business.

Gift Cards and Returns: Where the Fraud Actually Lives

Retail fraud rarely looks like hacking. It looks like someone patiently exploiting a normal business process, and gift cards and returns are the two most exploited processes in retail. Gift cards are attractive because they are close to cash and hard to trace. Common patterns include buying cards with stolen card numbers before the charge is disputed, draining balances from numbers harvested off a rack, and testing batches of numbers against your balance check page. Returns get exploited through receipt manipulation, repeated no receipt returns for store credit, and returning something other than what was bought.

  • Protect the balance lookup. A page that lets anyone check any balance with unlimited tries is a gift to someone with a list of numbers.
  • Keep unsold cards secured. Open racks let numbers be photographed and monitored until they activate.
  • Review a weekly exception report. Large gift card purchases and repeat no receipt returns from the same person are worth a look. Confirm your system records who did what, because many owners discover during an incident that it never did.
  • Back your staff up with policy. A clear written rule protects the employee who has to say no, which makes saying no far more likely.

Remote Access to the Systems That Run the Store

Your point of sale vendor almost certainly has a way to log in remotely, and that is useful when something breaks on a Saturday. The trouble is how it gets left. The PCI Security Standards Council guide warns that “many remote access programs are always on, or always available by default,” advises turning remote access off when it is not needed, and says that when used it should involve multi-factor authentication and strong cryptography, with vendors using credentials unique to your business rather than the same login they use everywhere.

That last point is worth pressing your vendor on. Ask directly whether your remote support login is unique to your store. The answer tells you a lot. For the broader picture, see why cybersecurity is no longer optional for mid-sized businesses.

The Bottom Line

Retail technology gets simpler once you accept one idea: touch as little card data as possible, and know who did what everywhere else. Push card handling to the processor. Give every person their own login. Patch and test before your busy season instead of during it. Treat gift cards and returns as processes worth monitoring. None of that requires a large budget, and all of it is easier in a quiet month. As we said at the start, this is general information rather than legal or compliance advice, so have your processor, acquiring bank, or a qualified assessor confirm the obligations that apply to your business.

We support retailers and online sellers across Denton County, from single storefronts to multi-location operations. If you want a plain English review of your registers, network, and website before your next busy season, we would be glad to take a look. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).