It is 7:15 on a Friday. Every table is turned, twelve names are on the wait list, and the expo window is stacked. Then a server tells you the card reader is spinning. Not down, just spinning. Nobody knows if the last four tickets went through. The line does not stop, the guests do not stop, and now you are troubleshooting a network problem in the busiest ninety minutes of your week.

Restaurants run on thin margins and tight timing, and technology fails differently here than in an office. An office loses productivity. You lose covers, in the exact window that pays for the week. The encouraging part is that most restaurant technology problems come from a short list of causes, and most are fixable on a slow Tuesday afternoon. Here is what we see most often.

The Point of Sale Is the Beating Heart

Everything else in the building can wobble. The point of sale cannot. When it stops, service stops, and every minute is measurable in dollars. Treat it as the system that gets protected first.

  • Know what your system needs to run. Some point of sale systems keep working locally when the internet drops. Others stop entirely. Ask your vendor which yours is, and reconfirm as they push updates, because this behavior changes between versions.
  • Put it on its own network. The PCI Security Standards Council advises small merchants not to use the device or system you take payments with for anything else. Separating payment traffic is the most valuable thing you can do here.
  • Put the terminals and router on battery backup. A brownout on a Texas summer evening should not force a reboot mid rush. An uninterruptible power supply costs less than one lost hour.
  • Wire the stations if you can. Cabled terminals do not drop when the microwave runs or the dining room fills with two hundred phones. Wireless is a convenience, not a foundation.
  • Post the vendor support number. Not in someone’s phone. Taped inside the office door, where a closing manager finds it at 10 p.m.

Guest Wi-Fi That Never Touches the Register

Guests expect Wi-Fi. That is fine. What is not fine is guest devices sitting on the same network as your terminals, office computer, and cameras. Anyone in the parking lot with the password is then one step from the systems that run your business.

  • Separate the networks properly. The PCI Security Standards Council’s guidance for small merchants is explicit: if you offer customer Wi-Fi, use another network for your payment system, which it calls network segmentation.
  • A different password is not a different network. This is the most common mistake we find. Two names broadcasting from one router with no isolation between them is one network wearing two hats.
  • Change every default password. Router, access points, cameras, all of it. The Federal Trade Commission, in its cybersecurity basics for small business, advises changing default router credentials, turning off remote management, and confirming WPA2 or WPA3 encryption is on.
  • Keep the guest network boring. Rotate the password on a schedule. Cap the bandwidth so a table streaming video does not slow your terminals.

The Back Office PC Under the Shelf

Every restaurant has one. It runs scheduling, payroll, inventory, and ordering. It sits on a metal shelf near the walk in, collecting grease and flour, and it is eight years old. It is also where your labor data, recipe costs, and often employee records live.

  • Grease is a hardware killer. Fans pull in vaporized oil and it coats everything inside. Get the machine off the floor, out of the path of the line, and blown out periodically.
  • Back it up somewhere else. The FTC recommends backing up files offline, on an external drive, or in the cloud. Schedules and payroll history are painful to reconstruct from memory.
  • Keep it patched. CISA notes in its Cyber Guidance for Small Businesses that many attacks succeed because victims were running vulnerable software when a safer version was available. Turn on automatic updates.
  • It should not be the karaoke machine. Personal browsing and staff logins on the same box that holds payroll is a bad combination. Give it one job, and lock the screen and the office door.

Card Payments and Why Your Processor’s Terminal Choice Matters

The honest disclaimer first: this is general information, not compliance or legal advice. What applies to your restaurant depends on your processor agreement, your card volume, and how you accept payments, and a qualified advisor or your acquiring bank should confirm your obligations. That said, a few practical points hold up well.

  • The terminal is a real decision, not a giveaway. The PCI Security Standards Council advises small merchants to make sure their payment terminal is on the List of PCI Approved PTS Devices and supports chip technology, and to consider devices offering encryption and tokenization. Ask your processor which of those your terminal does.
  • Inspect your terminals on a schedule. The Council recommends keeping photographic records of terminals including the back and cords, and looking for obvious signs of tampering such as broken seals over access cover plates or screws. Skimmers are physical, and a manager who knows what the back should look like will notice.
  • Only let approved people touch them. The Council advises authorizing repairs only from approved personnel and reporting suspected tampering to your merchant bank immediately. If a technician shows up unannounced to swap a reader, call your processor first.
  • Close down vendor remote access. Support vendors often keep a remote connection open permanently. The Council recommends vendors disable remote access when not needed and enable it only when requested, with multi factor authentication if it stays on.

Turnover, Shared Logins, and the Dinner Rush Outage

Restaurant staffing moves fast. A shared manager code that half a dozen former employees still remember is not small, because that code voids checks, opens the drawer, and adjusts comps.

  • Give every person their own login. The PCI Security Standards Council advises making user IDs unique for each person with access to your payment system wherever possible, so you can see who logged in and what changed. That visibility is also how you find the source of a shortage.
  • Kill access on the last shift, not next month. Build it into offboarding alongside collecting the key and the uniform. Any code more than one person knows should also change on a schedule.
  • Have a written plan for the internet going down. Do your terminals work offline, and for how long? Can you take cash only? Decide on a Tuesday, not at 7:15 Friday.
  • Consider a cellular backup connection. A router that fails over to cellular when the main line drops pays for itself the first time. Cloud services and internet providers both have outages, which we covered in this piece on cloud downtime.

The Bottom Line

Restaurant technology should be simple and separate. Payment systems on their own network with nothing else on it. Guest Wi-Fi genuinely isolated, not just differently named. The back office machine cleaned, patched, and backed up. Individual logins so you know who did what. A written answer for what happens when the internet fails during a rush.

None of that requires a big budget or technical staff. It requires deciding these things once, during daylight, instead of improvising during service. For the broader case, we made it in this piece on why security is no longer optional.

We work with restaurants around Denton County, and we know a service window is not the time for a support ticket. If you want someone to separate your networks properly, get the back office machine backed up, and give you a straight answer about what happens when the line goes down, we are glad to look. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).