Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Use this retail cybersecurity checklist to protect accounts, POS, payments, store networks, ecommerce, devices, backups and incident response.
Independent retailers should protect administrator accounts, separate payment and guest networks, keep every device supported, control website changes, maintain recoverable backups and practise incident response. The checklist must include stores, ecommerce, head office and suppliers because attackers and failures move across those boundaries.
Reviewed: 9 September 2026
| Area | Minimum evidence | Owner |
|---|---|---|
| Accounts | Named users, MFA, separate administrators and current leaver records | Business and IT |
| Payments and POS | Approved devices/software, inspection log and controlled network | Retail operations |
| Devices | Inventory, supported versions, updates and protection status | IT support |
| Ecommerce | Controlled changes, reviewed apps/scripts and monitored checkout | Website owner |
| Recovery | Independent backups, restore evidence and an exercised response plan | Named incident lead |
Maintain an inventory of tills, terminals, laptops, phones, access points, routers, cameras, servers, cloud services, ecommerce components and administrator accounts. Record the business owner, technical supplier, support status, criticality and renewal or end-of-support date.
Unknown technology cannot be patched, monitored or recovered reliably. Include systems installed by landlords, franchise partners and specialist retail suppliers where they touch your environment.
A regular access review is particularly important for seasonal staff and changing agencies. ACA’s joiner, mover and leaver checklist helps make the hand-off consistent.
Use supported, provider-approved payment devices and software. Replace default credentials, restrict management access and inspect terminals for unexpected damage, overlays or substitutions. Train staff to escalate concerns instead of reconnecting unknown equipment.
Separate guest access from staff, POS, payment and management networks according to the assessed design. Secure wireless administration and document changes. The PCI Security Standards Council’s merchant payment-security guidance is a useful starting point. Your acquiring bank or a qualified professional should confirm the requirements for your environment; this checklist is not a PCI assessment.
Remove unsupported operating systems and applications or place them behind a documented, time-bound risk plan. Apply security updates through controlled deployment, monitor failures and keep enough capacity for urgent fixes. Limit local administrator rights and prevent unapproved software where practical.
Portable devices need encryption, screen lock, recovery keys and a remote response route. Avoid storing unnecessary customer or employee data on shop-floor devices.
Require MFA for store administrators, minimise privileges and review extensions, apps and third-party scripts. Test updates away from production where possible, keep recoverable backups and monitor the buying journey after changes. Remove abandoned accounts and integrations.
Payment-page attacks can exploit authorised third-party scripts as well as the core platform. PCI SSC’s payment-page security guidance explains techniques for authorising, checking the integrity of and monitoring scripts. Use the related ecommerce security checklist for a deeper review.
Retail teams receive supplier invoices, delivery messages, password resets and urgent requests—ideal material for impersonation. Protect the company email domain, enable filtering and give staff a simple verification route for payment, bank-detail and credential requests. Never rely on the reply address alone.
Test domain authentication with ACA’s free email readiness checker. Results describe public records, not the security of every message or mailbox.
Protect essential configuration, business records, ecommerce data and locally held documents according to defined recovery objectives. Keep backup access separated from ordinary administration where possible. Monitor jobs and perform representative restores; a successful job notification is not proof that the business service can return.
Document the recovery order across identity, network, POS, payments, stock and customer communications. Note which supplier must act at each stage.
Name decision-makers, technical contacts and an alternative communication channel. Keep accessible copies of the response plan. Practise a realistic scenario, record decisions and improve the plan. NCSC’s small-organisation cyber guidance and its recovery guidance provide current, independent steps.
If an incident may involve personal data, follow the organisation’s data-protection incident process and obtain appropriate advice. Notification decisions depend on the facts and applicable requirements.
Assign each action, due date and evidence. Review access as people change, check critical systems before trading, test recovery periodically and inspect the highest risks after supplier or store changes. ACA’s retail IT service can help bring store systems, suppliers and continuity into one support plan.
No single supplier relationship proves compliance. Responsibilities depend on the payment channels and environment. Confirm the validation route with the acquiring bank or qualified adviser.
Guest traffic should not have trusted access to operational or payment systems. The technical design should reflect the store, equipment and assessed requirements.
No. The provider may operate the platform, while the retailer still owns accounts, devices, configuration, staff practice, local networks and supplier access.
Review it on a defined schedule and after meaningful changes such as a new store, supplier, payment flow, ecommerce app or staff departure.