Blog / Practical controls
Practical controls
Restaurants and Hotels: The Point-of-Sale Network, the Guest Wi-Fi and the PCI Question Your Bank Will Eventually Ask
Restaurant and hotel PCI compliance starts with one cable: how the point-of-sale network, guest Wi-Fi and the SAQ your bank asks for actually fit together.
The fish tank, the fifty-two dollar router and the second Wi-Fi name
The owner of a four-location taco group also runs a fourteen-room boutique hotel his father built. He is careful with money in the way people who survived 2020 are careful with money. When the hotel needed Wi-Fi for guests in 2019, his nephew put in a router he bought online, gave it a name with the hotel's logo in it, and set the password to the hotel's phone number so the front desk could tell people at check-in.
That router is still there. Behind the front desk, under a stack of laminated breakfast menus.
Plugged into the same little switch: the property management system, the card terminal at reception, the office computer where payroll runs, and the tablet that controls the outdoor speakers. Also, since last spring, the smart controller for the lobby fish tank.
On a Thursday in February the acquiring bank sends an email with the subject "Annual PCI validation required" and a link to a questionnaire. He forwards it to his bookkeeper, who forwards it to the nephew, who is now an orthodontist in another state.
Nothing has gone wrong yet. That is the only good news in this story, and it will hold only as long as nobody notices that the guest network and the card terminal share a switch, a router and a password that half the town knows.
What the heck does this mean
PCI DSS is the card industry's security standard. It is not a government law, it is a contract you agreed to when you accepted cards, and your acquiring bank is the one who asks about it. Version 4.0.1 has been fully mandatory since 31 March 2025, which means the phase-in period is over and the future-dated requirements are now simply requirements.
An SAQ, a self-assessment questionnaire, is the short-form validation most small merchants complete instead of a full audit. There is more than one, and which one you get depends on how you take cards. That is the whole trick: a terminal that encrypts the card inside the reader keeps your network out of scope and drops you onto a much shorter questionnaire. A point-of-sale system that handles card numbers on your own computers pulls the entire building into scope, fish tank included.
Segmentation means the guest network cannot reach the payment network, physically or logically. Scope means the list of systems the standard applies to, and it grows every time something new gets plugged into the wrong switch. Hospitality is where scope grows quietly, because the people plugging things in are trying to fix a broken tablet during a dinner rush.
The numbers that matter
Retail recorded 806 breaches in the Verizon 2026 Data Breach Investigations Report, with third parties involved in 68% of them. The vendor who installed and remotely supports your point-of-sale is the most likely route in, not a stranger in the car park.
The human element featured in 58% of those retail breaches (Verizon 2026 Data Breach Investigations Report). Somebody clicked, somebody reused a password, somebody plugged the wrong cable into the wrong port.
Ransomware appeared in 88% of breaches at small and mid-sized businesses in the Verizon 2026 report, with a median ransom of USD 139,875. A hotel that cannot check anyone in on a Friday night does not have a week to negotiate.
What to do this week
- Walk the cable, physically, at every site. Open the cupboard behind the front desk and follow each wire to what it serves. Write the list on paper. In hospitality that walk almost always turns up a device nobody remembers installing. (CIS 12 Network Infrastructure Management)
- Put guest Wi-Fi on its own segment that cannot reach the payment or back-office network, and confirm it by testing rather than by trusting the label. A second network name on the same flat network is decoration. (CIS 12 Network Infrastructure Management)
- Change every default password on the routers, switches, cameras, door controllers and booking tablets, and take the router's remote administration off the internet. The fish tank controller counts. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Call your acquiring bank and ask, in writing, which SAQ they expect from you and why. Then ask your terminal provider whether card data is encrypted inside the reader. Those two answers can cut the annual paperwork by four fifths. (CIS 15 Service Provider Management)
- List every provider that touches payments or guest data: the point-of-sale vendor, the booking engine, the channel manager, the payroll service, the marketing platform holding guest emails. For each one, note what they hold and what their contract says about telling you when something goes wrong. (CIS 15 Service Provider Management)
- Decide today what the front desk does at 9pm on a Friday when the property management system will not open. Paper folios, a manual imprint process, a phone number for the vendor, and who is allowed to authorise it. Rehearse it once with the evening shift. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment starts where the cables are, not where the policy binder is: what sits on your payment network today, which providers touch card and guest data, and which SAQ your bank should be asking for. You get a ranked list with the four fixes that shrink both the risk and the paperwork. The Cyber Hygiene Test takes three minutes and works for a single restaurant or a fourteen-property group, and 15 minutes with your Risk Assessor usually settles the scope question that has been sitting in your inbox since last year. Start with the hospitality page or the wider retail and hospitality overview.
We map the assessment to the regulators that apply to your entity, and the read-only compliance agent gives you continuous insight into your cloud and infrastructure so you can prioritise the right fixes and keep an eye on them. We have no access and we do not remediate. You or your IT partner fix it, and we show you where.
Questions people ask
Does taking cards through a modern terminal make us PCI compliant automatically? No, but a good terminal shrinks the work enormously. If the card data is encrypted inside the reader and your systems never see it, most of the standard stops applying to your network and you qualify for a much shorter self-assessment questionnaire. What remains is real: the terminals themselves, who can touch them, your service providers, and the paper records at the front desk. Ask your acquiring bank in writing which SAQ they expect from you, because that answer defines the whole job.
Can guests and the point-of-sale system share one internet connection? They can share the internet line. They must not share the network. Guest devices, the booking tablets and the card terminals belong on separate segments that cannot see each other, which usually means separate VLANs or separate hardware, not just a second Wi-Fi name on the same box. A second SSID on the same flat network is a label, not a wall.
Who is responsible if our point-of-sale vendor gets breached? Contractually it depends on what you signed. Practically, the guest whose card was used calls you, not them. Third parties were involved in 68% of retail breaches in the Verizon 2026 Data Breach Investigations Report, so this is not a rare scenario. Ask every provider that touches payments for a written statement of which PCI requirements they cover and which stay with you, and keep it with the contract.
In a restaurant the danger is never the thing you bought last month; it is the thing your nephew plugged in seven years ago and nobody has looked at since.
Questions people ask
Does taking cards through a modern terminal make us PCI compliant automatically?
No, but a good terminal shrinks the work enormously. If the card data is encrypted inside the reader and your systems never see it, most of the standard stops applying to your network and you qualify for a much shorter self-assessment questionnaire. What remains is real: the terminals themselves, who can touch them, your service providers, and the paper records at the front desk. Ask your acquiring bank in writing which SAQ they expect from you, because that answer defines the whole job.
Can guests and the point-of-sale system share one internet connection?
They can share the internet line. They must not share the network. Guest devices, the booking tablets and the card terminals belong on separate segments that cannot see each other, which usually means separate VLANs or separate hardware, not just a second Wi-Fi name on the same box. A second SSID on the same flat network is a label, not a wall.
Who is responsible if our point-of-sale vendor gets breached?
Contractually it depends on what you signed. Practically, the guest whose card was used calls you, not them. Third parties were involved in 68% of retail breaches in the Verizon 2026 Data Breach Investigations Report, so this is not a rare scenario. Ask every provider that touches payments for a written statement of which PCI requirements they cover and which stay with you, and keep it with the contract.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Cybersecurity Awareness Month for a 30-Person Business: Four Controls, in Order
Cybersecurity Awareness Month, done properly by a 30-person business: four controls in the order that removes the most risk per hour of work, not a poster.
Practical controlsA Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs
A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.
Practical controlsEDR vs Antivirus for a Small Business, and the Question That Matters More: Who Is Watching It at 2 a.m.?
EDR vs antivirus explained for a business owner: what each one catches, why insurers ask for EDR, and why a red alert nobody reads is the same as no alert.
