A busy restaurant might serve 200 covers a day, take card payments from every one of them, run an online booking platform, employ fifteen staff on variable hours, and manage supplier invoices through an email inbox. That’s a meaningful amount of sensitive data being handled by a business that typically has no IT support at all.

Cyber criminals know this. Hospitality businesses are attractive targets precisely because they process high volumes of payment transactions and often have weak security controls. Here’s what actually matters for UK restaurants, cafés, pubs, and food businesses.

Your Highest-Risk Systems

Your point of sale (POS) system is where payment data lives, and it’s the most critical system to protect. Modern POS systems — EPOS Now, Square, Lightspeed, Tevalis, and others — generally handle card data securely if you use them correctly. Where things go wrong:

  • POS terminals connected to the same network as your public Wi-Fi (they should be completely separate)
  • Staff using the POS admin account for general internet browsing
  • POS software that hasn’t been updated in months
  • Card readers that have been tampered with (skimming devices are physically attached to legitimate readers)

Check your card reader regularly for anything that looks out of place — loose fittings, unusual overlays on the keypad, or extra hardware attached anywhere on the device. It takes seconds and can prevent a serious data breach.

Online booking platforms (OpenTable, ResDiary, SevenRooms, or a custom website booking form) collect customer names, email addresses, phone numbers, and sometimes dietary requirements and allergy information. Allergy information is health data under UK GDPR — special category data requiring extra protection and explicit consent to collect.

Email is where most attacks on hospitality businesses start. Your bookings@ or manager@ address is public-facing and gets targeted with phishing emails impersonating suppliers, HMRC, or payment processors. A member of staff clicking a malicious link during a busy service is how most breaches begin.

Payment Security: What You Actually Need to Do

The good news for small hospitality businesses: if you’re using a modern card terminal (Worldpay, Barclaycard, Sumup, Square) and not storing card numbers yourself, your PCI DSS obligations are relatively limited. The key rules:

Never write down card numbers, take card details over the phone and store them in a spreadsheet, or photograph card details on your phone. If you take phone bookings that require payment, use a virtual terminal provided by your payment processor — it takes the card details directly into a compliant system without them passing through your own devices.

Network separation is non-negotiable. Your card terminals must be on a separate network from your customer Wi-Fi and from any device your staff use for general browsing. Most business routers support a guest Wi-Fi network that’s isolated from the main network — your customer Wi-Fi should be on this, and your POS should be on the main network (or better, its own VLAN). If you’re not sure how your network is set up, your ISP or a local IT company can check this in an hour.

Contactless limit awareness: the £100 contactless limit means individual fraudulent transactions are bounded, but repeated small fraudulent charges on a compromised terminal can add up quickly. Review your card transaction reports weekly.

The Booking Platform Problem

GDPR applies to every restaurant collecting customer booking data, and most don’t have this properly sorted. The basics:

Your booking confirmation emails should include a privacy notice or link to one — explaining what data you hold, why, and how long you keep it. A customer who booked a birthday dinner two years ago and never returned shouldn’t still be in your system with their full details indefinitely.

Allergy information is particularly sensitive. If you’re recording dietary requirements and medical allergies in your booking platform, make sure that data is only accessible to staff who need it, isn’t shared with anyone it doesn’t need to be shared with, and is deleted when it’s no longer needed.

If you suffer a breach involving customer data — including bookings data — you may need to report it to the ICO within 72 hours. Booking data plus payment data would almost certainly require reporting.

Common Attack Scenarios

Fake supplier emails: you receive an email from what looks like your card machine provider or food delivery platform saying your account needs urgent attention, with a link to log in. The email address is slightly wrong (wordpay.com instead of worldpay.com, for instance). The link goes to a fake login page that captures your credentials.

What to do: train yourself and your staff to check the sender’s email domain carefully. If an email asks you to click a link and log in, go directly to the platform’s website by typing the URL — don’t follow the link.

Ransomware locking your booking system: an infected email attachment encrypts your booking database, customer records, and possibly your supplier contacts. You’re locked out and someone demands payment in cryptocurrency to restore access.

What to do: regular backups that are kept separately from the main system. Cloud-based booking platforms (where the data lives with the provider, not on your local hardware) are significantly lower risk for this kind of attack.

Fraudulent refund requests: attackers who gain access to your payment processor account may try to issue refunds to themselves. Review your transaction reports for unexpected refund activity weekly.

Practical Steps for Your Business

These are the highest-impact actions that don’t require technical expertise:

Enable multi-factor authentication (MFA) on your business email, your booking platform, your payment processor account, and any cloud services you use. This single step prevents the majority of account takeover attacks even when passwords are compromised.

Create individual login accounts for each member of staff on systems that support it, rather than sharing a single login. When someone leaves, you can close their access immediately without changing a password that everyone else uses.

Make sure your POS and booking system software is set to update automatically. Outdated software is one of the main routes attackers use to compromise business systems.

Back up your booking data and any locally stored business records — weekly at minimum, to a cloud service or an external drive kept off-site.

When Something Goes Wrong

If you suspect a breach — customer card details may have been compromised, your booking system has been accessed without authorisation, or you’ve received ransomware — call Action Fraud on 0300 123 2040 to report it. Check whether you need to notify the ICO (ico.org.uk) within 72 hours if personal data has been affected. If you have cyber insurance, call your insurer before taking recovery steps, as they’ll have an incident response process.

The NCSC offers free guidance specifically for small businesses at ncsc.gov.uk/cyberaware. It’s practical, jargon-free, and takes less than an hour to work through. For a sector where margins are tight and reputation is everything, the cost of a customer data breach — financial, regulatory, and reputational — is far higher than the cost of preventing it.