All articles

Hardware & POS

Keeping your payment network separate from your store wifi

Network separation means the device that takes cards does not sit on the same network as everything else in your building. Not the camera recorder, not the office computer, not the tablet a vendor rep brings in, and certainly not the guest wifi. In most small stores all of those share one router and one flat network, because that is what happens when things get added one at a time over five years.

The reason to care is not paperwork. It is that a flat network makes every device a route to every other device.

What is the actual risk?

Compromise spreads sideways. A camera recorder running firmware from 2019, a smart thermostat, a staff phone that picked something up, a laptop a relative used — any of those on the same network as the payment path gives an attacker a place to stand.

Card breaches at small merchants have historically come through exactly this door: not an attack on the terminal, but an attack on something else that happened to be able to reach it. Separation does not make the other devices safer. It makes them irrelevant to the payment path.

What does separation look like in practice?

Three levels, cheapest first. A payment terminal with its own cellular connection, which is not on your network at all. A separate physical router or a second line for payment devices only. Or a single router configured with a guest network and a main network, with payments on one and everything else on the other.

The first is the simplest and often the cheapest for a single counter, because it sidesteps the configuration question entirely. A cellular terminal has no relationship with your store wifi to get wrong.

Where does guest wifi fit?

Guest wifi should be isolated from everything, and on most consumer routers that is a checkbox rather than a project. It should not reach your point-of-sale system, your recorder, your office computer or your printer.

Two details get missed. Guest isolation sometimes only prevents guests reaching each other, not guests reaching your main network — check which your router does. And the password on the wall is known to everyone who has ever sat in your store, which makes "it has a password" a weak claim.

What about the default passwords?

Change them. Every router, recorder, printer and network device arrives with credentials that are published on the internet, and leaving them is the single most common security failure in small business networks. It is the first item on nearly every small-business guide to the subject, for good reason.

Write the new ones down somewhere physical and secure. The reason people leave defaults is fear of being locked out of their own equipment, which is a reasonable fear with an easy answer.

How do you find out what is actually on your network?

Log into your router and look at the connected-devices list. Most owners doing this for the first time find two or three things they cannot identify — an old phone, a device a former employee added, a piece of equipment a vendor installed and never mentioned.

That list is the real inventory, and it is usually longer than the one in your head. Anything on it you cannot name is either something to identify or something to remove, and both of those are better than leaving it there because it has been working.

What is the cheapest version of all this?

A cellular payment terminal, a router whose firmware is current and whose admin password is not the one printed on its underside, and guest wifi that reaches nothing. That combination costs very little, takes an afternoon, and removes most of the paths that have historically been used against small merchants.

Everything beyond it is refinement. Stores that get hurt are almost never the ones that did those three things and stopped; they are the ones that did none of them.

Frequently asked questions

Does a cellular terminal make all of this unnecessary?

For the payment path, largely yes, and that is a strong argument for one at a single-counter store. It does not help the rest of your network, and a compromised office computer is still a problem — just no longer a card data problem.

Is a guest network enough separation for payments?

It is better than nothing and worse than a dedicated path. A guest network is designed to keep guests away from your systems, not to protect a payment device from the rest of your store. If it is what you have, put the guest devices on the guest side and keep payments on the main side with everything else removed.

Do I need a firewall?

Your router almost certainly includes one, and for a small store the configuration matters more than the product. The valuable settings are the ones already there: change the admin password, turn off remote administration, keep the firmware updated, and isolate the guest network.

What about a vendor who wants network access to install something?

Ask what it needs to reach and why, and give it the narrowest path that works. A vendor asking for access to your whole network to run one device is asking for convenience, and it is reasonable to decline.

Does any of this affect my compliance questionnaire?

Yes, directly. Several questions turn on whether the payment environment is segmented from other systems, and a store that can answer clearly has a much shorter and more honest attestation than one that cannot.

How often should this be reviewed?

Once a year, and whenever a device is added. The practical trigger is any sentence that starts "we just put in a new…" — new equipment is exactly when a carefully separated network quietly becomes a flat one again.