Payment security sounds like a technology subject and is mostly an administrative one. The card networks moved the difficult parts to the equipment years ago. What is left for you is a questionnaire, a handful of habits, and knowing which risks are genuinely yours to carry.
📋 What PCI actually asks of you
PCI is the card industry's own rulebook, enforced through your processor rather than by a government. In practice it means:
- A self-assessment questionnaire, once a year. Which one applies depends on how you take cards — a restaurant using standalone terminals with encryption answers a much shorter version than one that stores data. Ask your processor which applies to you; they know, and they will usually walk you through it.
- Possibly a network scan, if you take payments online. Your processor arranges it.
- A monthly non-compliance fee if you never do it. This is the reason most restaurants eventually complete the form: they were already paying for it. Check your statement for that line.
- Nothing exotic. The questions are about the things in the previous course: separate networks, unique logins, changed default passwords, applied updates, restricted access. If you did topic 4 there, you have already done most of this.
Complete it, keep the certificate, and diary it for next year. It is an afternoon, and the alternative is a monthly fee plus a much worse position if anything ever happens.
⚖️ The liability shift nobody explained
Since 2015 in the United States, the rule for counterfeit card fraud is roughly this: whoever is the weaker link pays. If a customer's chip card is cloned and used at a business that only swiped it, the loss tends to land on the business rather than the bank. If you accepted the chip properly, it does not.
That is the practical reason to insist on dips and taps rather than swipes, beyond the small saving in topic 3. The rules are more detailed than one sentence, but the direction is consistent: the party who avoided the safer technology carries the fraud.
🔍 The frauds that actually hit restaurants
| What it looks like | What stops it |
| A skimmer added to a terminal, or a terminal swapped for a lookalike | Serial numbers written down; a quick look and a tug at open and close; terminals not left alone with strangers |
| Card numbers collected on paper for phone orders | Keying straight into the terminal while the customer is on the line. No paper stage to steal |
| A caller claiming to be your processor, asking to "verify" or change your deposit account | Hang up. Call back on the number from your own statement. This one takes real money and it works often |
| A large first-time delivery order, keyed card, delivery elsewhere, in a hurry | A phone call to the number on the order before it is cooked |
| Refunds to a card that never bought anything | Refund permissions limited to managers, and the exception report from the previous course |
| An email asking you to update banking details for a supplier or a payroll account | Verify by phone on a number you already had. Never on a number in the email |
Notice how few of these are technical. The expensive ones are conversations, and the defense is a rule that staff are allowed to follow: nobody is ever in trouble for saying "let me call you back on our own number".
🧯 If something goes wrong
- Call your processor first. They have a procedure, deadlines and a fraud team. Delay is the thing that makes it worse.
- Do not clean up. Leave the terminal, the machine and the logs alone; an investigation needs them.
- Write down what you know — when, which terminal, who noticed, what changed recently.
- Tell your POS vendor if their equipment is involved, and your bank if deposits are.
- Have the numbers on paper, next to the outage plan from the previous course. Nobody looks up a support number well under pressure.