How should a venue handle card payments securely?
By keeping the payment environment on its own network segment, keeping terminals current and supported, and keeping card numbers out of your own systems wherever possible. Most venues are better protected than they assume on the terminal side and worse protected in the places nobody thinks about.
Start with the reassuring part. Modern payment terminals are designed so card data does not traverse your network in a usable form, which means a venue using current terminals has considerably less exposure than the anxiety around this topic suggests. The card data risk in hospitality is mostly not the terminal; it is everything around it.
Where the exposure actually lives is worth naming specifically. Card numbers written on a booking sheet for a function deposit. Details taken over the phone and noted on a pad or in a booking system's free-text field. A spreadsheet of regular customers with stored details for convenience. Emails from customers containing card numbers, sitting in a mailbox indefinitely. None of that goes near a payment terminal and all of it is card data you are now responsible for.
So the first practical step is finding and eliminating it. Ask where card numbers are written, typed or stored outside the terminal, and expect to find at least one place. Then replace the practice: a payment link sent to the customer, a deposit taken through the terminal, or a booking system feature designed for it. Removing card data from your systems entirely is far easier than protecting it well, and it is the single most useful thing most venues can do here.
Network separation is the second element and it follows the same logic as guest Wi-Fi. Payment terminals and point of sale should sit on their own segment, separate from guest traffic and from general staff use, so that a compromise elsewhere does not reach them. Card industry requirements expect this segregation, and beyond compliance it is simply sound design: the systems handling money should be the ones with the fewest neighbours.
Terminal lifecycle is the third and is easy to neglect because terminals keep working long past the point where they are supported. Ask your payment provider when your current terminals reach end of support and put replacement on a plan rather than waiting for a failure. An unsupported device processing card payments is a poor position to be in if anything goes wrong, and the replacement conversation is much easier when it is scheduled.
PCI DSS is the framework in the background and it is worth understanding at the right level. Merchants accepting cards are generally subject to it through their acquiring bank, with obligations scaled to transaction volume and how payments are processed. For most venues using modern terminals and not storing card data, the requirements are lighter than feared, and the way to know rather than guess is to ask your acquirer what specifically applies to you.
The related risk is the one that has cost Australian venues real money and gets less attention: invoice and payment redirection. A compromised mailbox lets an attacker watch supplier correspondence and then send amended bank details at a plausible moment. Multi-factor authentication on email and a rule that any change to payment details is verified by phone to a known number address it, and neither costs anything beyond insisting.
Physical security matters more in hospitality than in most sectors because of the public environment. Terminals, tablets and back-office computers are accessible to people who are not staff, and a device left unlocked behind a bar is a genuine risk rather than a theoretical one. Screen locks, secured mounting and putting back-office equipment somewhere that is not reachable from the public side are unglamorous and effective.
The honest caveats. This is not advice about your specific PCI DSS obligations, which come from your acquirer and depend on how you process payments. Keeping card data out of your systems reduces rather than removes the compliance surface. And the venue-side controls only matter alongside the ordinary ones, since a venue with a perfectly segregated payment network and no multi-factor authentication on email has protected the wrong thing. If you want your payment environment reviewed, call 1800 456 567.
The most useful first step is the least technical one: walk the venue and ask where card numbers get written down or typed outside the terminal. Whatever you find is the exposure worth removing before anything else.
Get the payment environment right
We separate and secure the payment side of a venue's network, so card processing is isolated from guest Wi-Fi and general use.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business