Protecting Data in POS Environments
POS security, or point-of-sale security, is the prevention of unauthorized access to electronic payment systems by individuals who are typically looking to steal customers’ personal details such as credit card information. POS security aims to create a safe environment for customers to complete their purchases and transactions, and it’s a must-have measure for fostering trust with today’s consumers.
How POS Security Compromises Work
It is important to acknowledge that all POS systems do have some level of risk when it comes to security. Many attackers are just looking for targets using systems that are vulnerable and launching automated attacks on their POS environments. According to the SANS Institute, “the basic POS breach phases include infiltration, propagation, exfiltration and aggregation.” In the first phase, an attacker gains access to the targeted systems, often by exploiting a system vulnerability or through social engineering techniques. Once inside, the attacker installs malware, which spreads until it can access the system’s memory and collect the desired data. From there the data is moved to another location within the target’s environment for aggregation and finally offloaded to an external location accessible to the attacker.
Examples of Data Breaches Involving POS Security Compromises
Many of the most high profile data breaches of customer payment information involved POS security compromises. Here are just a few examples from recent years:
Best Practices for POS Security
Enterprise should take several measures to improve POS security, prevent POS malware infections, and avoid POS data breaches:
The Need for POS Security
POS security is challenging because of the sheer volume of both known and unknown threats that exist, coupled with the value that POS system data holds for cybercriminals. In addition, the number of threats facing POS systems continues to rise because new POS malware is being created or updated all the time. Despite these challenges, enterprises - especially those in retail, hospitality, food service, or others that rely heavily on POS systems - should prioritize POS security, as these systems handle sensitive customer data and a breach of customer payment information can be highly costly both literally and in terms of damage to your company’s reputation. By implementing measures to protect POS systems and transactions and training staff on POS security policies, businesses can drastically reduce their likelihood of experiencing a costly POS security incident.