POS breaches: lost sales can exceed GDPR fines
A POS breach often hurts a retailer through stopped card payments rather than a regulatory penalty. A point of sale (POS) system includes the till, card terminal and payment software. When it is unsafe or unavailable, customers may leave rather than wait.
Start with your average daily card takings. Then subtract sales you could recover through cash, bank transfer, or another working terminal. The amount left is the sales at risk.
For example, a convenience shop may take £4,000 in card payments on a typical Saturday. It may lose 30% of those sales if two terminals fail. That creates £1,200 in sales at risk before staff time, refunds, or lost customers are considered.
Lost card sales can start within minutes of a terminal outage.
Costs that appear after discovery
Forensic investigation means a specialist checks devices, logs, and accounts. They look for the entry route and the data affected. This work can last for days.
The payment acquirer processes card payments for the retailer. It may need forensic findings before deciding what happens next, which can delay a return to normal trading.
Other costs include legal advice, customer letters, call handling, password resets, replacement hardware, and data recovery. Ransomware can also stop stock systems, delivery bookings, and click-and-collect orders.
A GDPR fine is only one possible outcome. The Information Commissioner's Office can investigate a personal-data breach. A retailer may face card-sales losses and acquirer demands before any regulatory decision.
POS exposure includes staff, suppliers and terminals
POS exposure does not require a hacked website or stolen card numbers. It can start with a shared till login or remote-support account. An unpatched terminal, tampered device, or weak supplier can also create risk.
Staff credentials can open the till network
Shared accounts make it hard to identify who changed a setting. They also hide who approved remote support or accessed a till. Give each employee a unique account.
Remove access as soon as someone changes roles or leaves. Require multi-factor authentication for administrator and remote-access accounts. Multi-factor authentication means using a password plus a second proof, such as a phone code.
Limit each till user to the functions they need. A compromised cashier login should not be able to change payment settings or open back-office systems.
The most common mistake is treating a shared till login as harmless.
Suppliers and remote support need boundaries
Remote support can help, but it should cover only the systems and times needed. Think of it like giving a tradesperson one cupboard key. Do not give them a master key for every room.
Ask each supplier who owns the terminal and patches its software. Ask who keeps system logs and reports a security incident. These answers shape your response plan.
They also affect insurance cover. A policy may treat a supplier outage differently from your own system failure. Check this before an incident, not during one.
Practical POS security reduces both breach risk and breach cost. Check terminals daily for tampering. Use unique staff accounts instead of shared logins.
Install software updates quickly and separate networks for tills, guest Wi-Fi, and office devices. Turn remote support on only when needed. Protect it with multi-factor authentication and review supplier logs.
These controls matter because terminal malware can stop card payments. A compromised supplier account can do the same. Sales may be lost before investigators know whether data was taken.
Documented checks can help show that reasonable safeguards were in place.
In retail cyber security, records can help during PCI-related claims. PCI means Payment Card Industry. It is the card industry's set of security rules for firms handling card data.
Calculate loss by shop, terminals and downtime
Build a realistic estimate for each shop. Include card takings at risk, failed payment rates, disruption days, and extra costs. Include payment-card liabilities too.
Gross profit is sales minus the direct cost of goods sold. It is usually a better interruption measure than annual turnover. Turnover can look large while the actual lost profit is smaller.
A sound POS loss estimate starts with daily card takings and gross profit. It then adds recovery costs, payment-card claims, and sales lost during downtime. This gives a more useful insurance figure than turnover alone.
A simple shop-level loss model
Use recent takings rather than a yearly average. Separate weekends, payday periods, school holidays, and seasonal peaks. Those periods can change footfall and cash use.
- Card sales at risk: Average card takings per trading day multiplied by the percentage that cannot be processed.
- Business interruption: Lost sales at risk multiplied by gross profit margin, subject to policy wording.
- Extra working costs: Temporary terminals, staff overtime, manual reconciliation, cash transport, and alternative payment fees.
- Incident costs: Forensic work, legal advice, notification, recovery, and replacement equipment.
A busy Saturday needs its own estimate.
Compare three retail disruption patterns
| Retail setup | Likely sales pressure | Costs often missed | Planning focus |
|---|
| One shop, 1-2 terminals | Queues and lost walk-in sales within hours | Cash handling, overtime, replacement terminal | Daily card takings and fallback payment route |
| Multi-site retailer | Several shops affected by shared support or network | Central investigation, branch calls, lost peak trading | Supplier outage cover and aggregate limit |
| Omnichannel retailer | In-store and click-and-collect failures together | Refunds, customer service, order reconciliation | Website, POS, and stock-system dependencies |
Turn the estimate into an incident plan
The first 24 hours should focus on safe isolation, evidence, and notification. Keep a timed log and preserve terminals and access records. Tell your insurer and acquirer promptly.
Do not wipe or casually reboot equipment. A forensic provider may need to inspect it first. Lost evidence can make the investigation harder.
POS incident timetable for a UK retailer
0-24 hours
Isolate safely, keep evidence, call insurer and acquirer.
24-72 hours
Scope affected systems, assess ICO reporting, set safe payment fallback.
Days 4-30
Recover, reconcile costs, fix access, and document lessons.
A hardware firewall can separate till equipment from guest Wi-Fi and office devices. It cannot replace patching or insurer-approved incident help, but it can reduce needless routes into a POS network.
- It can place card terminals on a separate network from customer Wi-Fi.
- It can control remote-support links to approved suppliers.
- It can keep traffic records that aid a forensic investigation.
Ver opciones en Amazon →
Policy wording decides what a cyber claim pays
Cyber insurance can pay incident response and business interruption costs, but it does not automatically pay every POS-related cost. Policy wording determines what the insurer will pay.
PCI DSS assessments, card reissue costs, chargebacks, fraud, contractual claims, and fines may have separate limits. They may also have conditions or exclusions. Read these sections with care.
Check payment-card and acquirer liabilities
Ask whether the wording covers a PCI forensic assessment. Ask about card replacement costs, fraud claims, and acquirer demands. Do not assume data-breach cover includes these items.
A common real case is an acquirer demanding an assessment after suspected card compromise. The shop may have incident cover but no payment-card liability cover. The resulting bill may then fall outside the main limit.
Check interruption, fines and exclusions
Business interruption cover may have a waiting period before payment starts. This period is often between six and 24 hours. Check whether the trigger covers a supplier outage or system failure.
Check whether it covers ransomware or only a confirmed security breach. A simple terminal fault may not meet the trigger. The policy must link the outage to a covered event.
| Loss type | Typical POS example | How cover is commonly treated |
|---|
| First-party incident cost | Forensic investigation and recovery | Often covered, subject to panel-provider rules |
| Operational loss | Lost gross profit during terminal outage | Covered only if the trigger and waiting period apply |
| Payment-card liability | PCI assessment or acquirer demand | Often sub-limited or excluded unless stated |
| Regulatory cost | ICO investigation and legal defence | Defence may be covered; fines need a direct check |
| Reputational loss | Customers who do not return | Usually hard to insure as a standalone amount |
This guidance is less relevant if your business takes no card payments or does not use POS systems or payment processing. It is not a substitute for instructions from your acquirer, insurer, solicitor, or forensic provider.
If you are renewing cover, use the shop-level estimate when speaking to a broker. Ask for written confirmation of PCI, acquirer, supplier-outage, and social-engineering cover. This is more useful than comparing premium alone.
Insurance price does not depend on turnover alone. Insurers often consider shop and terminal numbers, card-payment volume, and cardholder data access. They also consider past incidents and reliance on one payment provider.
They may assess multi-factor authentication, offline backups, and managed patching. Higher limits can raise the premium. Lower excesses and wider supplier-outage cover can also cost more.
A cheaper policy may fail during a busy trading period.
Compare the premium with each sub-limit and waiting period. A low-priced policy may offer little value during a card-payment outage. This is especially true if interruption cover does not respond.
What people ask
How much can a POS breach cost a small retailer?
There is no fixed figure. Start with card takings lost during the outage. Then apply gross profit margin and add overtime, temporary equipment, investigation, recovery, support, and payment-card liabilities.
If £1,200 of Saturday sales cannot be processed, a 30% margin means about £360 lost gross profit. That figure excludes extra costs and repeat-customer loss.
Does cyber insurance cover chargebacks after a POS breach?
It may cover some payment-card liabilities, but chargebacks are often limited or excluded. Check the wording for fraud, merchant-services liability, PCI costs, and acquirer contractual claims.
Do I need to tell the ICO about a POS breach?
Not every POS incident needs an ICO report. Under UK GDPR, report a personal-data breach within 72 hours where feasible. Report it if it is likely to risk people's rights and freedoms.
Record your assessment even when you make no report. If the risk is high, tell affected people without undue delay.
What is PCI DSS in simple terms?
PCI DSS is a card-industry security standard for firms handling card data. It covers access control, system updates, and monitoring. Compliance does not guarantee that a breach cannot happen.
Does a broken card terminal count as business interruption?
It can, but the cause must match the policy trigger. Any waiting period must also have passed. A hardware fault may differ from malware, ransomware, or provider outage.
Can an IT supplier cause a POS data breach?
Yes, a supplier with remote access can create a route into a till network. Weak login controls or unpatched software can also create risk. Your contract and policy should state reporting, evidence, and recovery duties.
Are GDPR fines covered by cyber insurance in the UK?
Some policies cover legal defence and regulatory investigation costs. Fines may be restricted or uninsurable. Check the exact regulatory wording, not just the main policy limit.
What should I do first if I suspect POS malware?
Call your insurer and payment acquirer promptly. Preserve evidence and isolate affected systems safely. Do not wipe, reimage, or casually reboot terminals before forensic advice.
Protect card sales before the next incident
Test payment fallback before disruption occurs.
Cyber insurance is worth considering when sub-limits match losses that could stop trading. Cover should sit beside basic controls, not replace them. Use unique accounts, multi-factor authentication, patching, separated networks, and terminal checks.
Related sources
These articles can help you explore the topic in more depth: