TL;DR:
- PoS malware and physical skimming are the two main threats to card payment systems in small businesses
- PCI DSS compliance is required if you handle card payments — it’s not optional, and non-compliance can cost you your ability to accept cards
- Network segmentation (keeping your PoS system on a separate network from your general business Wi-Fi) eliminates a large chunk of your card data risk
Card payments are the lifeblood of most UK small businesses. They’re also a direct path to your customers’ financial data — and criminals know it. PoS (point-of-sale) attacks are less headline-grabbing than ransomware, but they’re common, often invisible for months, and the consequences (PCI DSS fines, card network penalties, lost customer trust) can be severe.
Here’s what you actually need to worry about and what to do.
The Two Main Threats
Physical skimming is the older attack: a criminal fits a device over your card reader that copies the card’s magnetic stripe and sometimes a tiny camera captures PIN entries. Modern contactless and chip-and-PIN systems significantly reduce this risk, but overlay skimmers still appear on unattended terminals in retail and hospitality.
How to spot it: check your card reader every day before opening. A genuine terminal will feel solid — skimmers are often slightly loose or don’t fit perfectly. Look for anything covering the keypad or card slot that wasn’t there yesterday. If in doubt, pull it — skimmers are usually attached with adhesive and come off easily.
PoS malware is the modern threat. If your PoS system connects to the internet (and almost all of them do for software updates and payment processing), it’s reachable from the outside world. PoS malware — with names like TinyPOS, FIN6-linked POS scrapers, and various commodity RAM-scrapers — installs on the PoS computer and captures card data from memory as it’s being processed, before encryption. This is how large retail breaches happen, but the same malware targets small businesses.
The entry points are usually weak: an unpatched Windows operating system, a remote desktop port (RDP) left open for your PoS vendor to do remote support, or your PoS system sitting on the same network as everything else and getting infected via a phishing email someone clicked on a different computer.
PCI DSS: What It Actually Means for You
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements you agree to follow when your bank account is set up to accept card payments. You don’t get a certificate or badge — you either comply or you don’t, and the card networks audit through your payment processor.
For most UK small businesses using a modern cloud-based PoS provider (Square, SumUp, Zettle, Worldpay, PaymentSense), you’re in what’s called a SAQ P2PE or SAQ A environment — the PoS hardware encrypts card data before it ever touches your network, so your compliance scope is dramatically reduced. Your main obligations:
- Don’t store card numbers, CVVs, or PIN data anywhere (paper, spreadsheet, email)
- Use a card terminal provided by your payment processor, not something you’ve found independently
- Keep your PoS software updated
- Have a basic firewall between your PoS system and the internet
- Train staff not to click suspicious links on PoS computers
If you take manual card imprints, store card numbers in your own system, or run your own payment software connected directly to a payment gateway, your PCI DSS scope is much larger and you should talk to a Qualified Security Assessor.
Non-compliance doesn’t generate an immediate fine, but if you suffer a breach and investigators find you weren’t compliant, the fines from your payment processor and the card networks can easily exceed £10,000, plus you may lose your ability to accept cards for a period.
The Most Important Step: Network Segmentation
If your PoS system, your office computers, your staff Wi-Fi, and your customer Wi-Fi are all on the same network, one infected laptop can reach your card terminals. Separation is the single most effective technical control.
What to do:
- Put your PoS terminals on their own network segment, either a separate VLAN or a separate router/switch entirely
- Give PoS terminals internet access only to the domains they need (your payment processor’s servers) — your IT provider or a capable router can do this with allowlisting
- Put customer Wi-Fi on a completely separate guest network that has no path to your internal systems
This doesn’t require expensive equipment. A modern business router (Unifi, TP-Link Omada, Draytek) supports multiple VLANs and guest networks in the £150–£300 range. Your PoS vendor may also do this as part of installation — ask them explicitly.
Practical Checklist
Daily:
- Physically check card readers before opening — look for anything that doesn’t belong
Weekly:
- Reconcile card payment totals against your PoS reports — unexplained discrepancies can indicate card data theft
When setting up or reviewing:
- Confirm your PoS system is on a separate network from your general business computers
- Check whether your payment processor provides a hardware security module (HSM) encrypted terminal — prefer this over software-based readers
- Ask your PoS provider: what RDP or remote access do you use for support? Make sure remote access requires multi-factor authentication and isn’t always-on
When offboarding staff:
- Remove their access to the PoS system immediately — it’s common for PoS fraud to involve former employees who retained access
If You Think You’ve Been Compromised
If you suspect card fraud linked to your terminal:
- Call your payment processor immediately — they have a dedicated fraud team and can suspend the terminal while investigating
- Don’t turn off or reset the PoS system without guidance — forensic evidence may be needed
- Notify Action Fraud (actionfraud.police.uk) and your bank
- Under UK GDPR, if customer card data was involved, you may need to notify the ICO within 72 hours