Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Use this practical retail IT checklist to protect POS systems, card terminals, staff and guest Wi-Fi, backups and trading continuity in UK shops.
A retail IT checklist should protect the ability to take payments and keep trading. That means treating tills, card terminals, connectivity, Wi-Fi, stock systems, back-office devices and suppliers as one operating environment—not a collection of unrelated gadgets.
Reviewed: 18 August 2026
Record failures in one place. Repeated brief dropouts can be more damaging than a clear outage, and a log gives suppliers evidence to diagnose them.

Document the path from product scan to settled payment. It may involve the till application, local network, card terminal, payment processor, stock platform, receipt printer and cloud account. Note which steps can continue offline and which cannot.
For every component, record the supplier, support number, account reference, contract owner and escalation route. A store manager should not have to search an old inbox while a queue grows.
Do not place card terminals and guest devices on one flat Wi-Fi network. Use separate network segments or securely configured networks for payment devices, staff systems, CCTV or building equipment, and visitors. Change default router passwords, restrict administration and keep network equipment supported and updated.
The PCI Security Standards Council’s guide for small merchants recommends isolating payment devices, using a firewall and separating guest Wi-Fi from payment environments. Your payment provider or acquiring bank can confirm the exact PCI DSS responsibilities for your setup.
Keep an inventory of terminal make, model, serial number and location. Train staff to notice unexpected cables, broken seals, swapped devices or unusual prompts. Obtain replacement terminals and software updates only through authorised providers.
Never ask a general IT supplier to alter a payment terminal contrary to the payment provider’s instructions. Good retail support coordinates the right supplier and protects the wider network without blurring responsibility.
Ask the POS and payment providers whether their products support an approved offline mode and what limits apply. Document any secondary connection, such as business-grade mobile failover, and test it during a quiet period. A phone hotspot improvised during an outage may be unreliable and can bypass the store’s security controls.
Write a short downtime procedure: who decides whether trading continues, what can be recorded manually, how customers are informed and how transactions or stock changes are reconciled afterward.
Use supported operating systems, automatic security updates, screen locks and named accounts. Staff should not browse personal email or install arbitrary software on tills. Remove unused applications and local administrator rights where they are not required.
Keep spare, compatible cables and low-cost peripherals for predictable failures. For critical hardware, document whether the supplier provides advance replacement and the expected delivery time.
Give each manager and administrator a named login and require MFA for email, ecommerce, payment dashboards, remote support and domain accounts. Review supplier remote-access tools and remove old accounts. Remote access should be enabled deliberately, logged where possible and limited to approved support personnel.
Shared shop-floor logins may sometimes be necessary for the POS workflow, but privileged changes and refunds should still be attributable to an authorised person.
Confirm what the POS or ecommerce supplier backs up, for how long, and how a restore works. Include product data, stock records, customer data, reports, staff configuration, website orders and local files that are not stored in the main platform.
Test an export and a restore, not just the presence of a backup setting. Keep recovery contacts and essential configuration available outside the failed system.
Guest Wi-Fi should not compete with payment traffic. Place access points based on a survey or measured signal, not simply wherever a socket is available. Check key areas at busy times and monitor recurring disconnections.
For retailers with online ordering or click and collect, monitor the website, checkout and order-notification path too. A healthy till does not help if online orders stop reaching the store.
Define supported sites, devices, operating hours, response targets, remote and onsite coverage, supplier coordination, planned maintenance and exclusions. Priority should reflect operational impact: a complete inability to take payment is different from one failed office printer.
Also agree who owns the POS application, card terminals, cabling, internet circuit, network equipment, ecommerce platform and cyber security. The most valuable support partner may not manufacture every component, but should be able to triage the problem and coordinate the correct vendor.
ACA Tech Solutions supports tills, card machines, staff and guest Wi-Fi, back-office systems, websites and practical security as one retail stack. See retail and hospitality IT support, or use on-demand IT support for a defined one-off problem.
The terminal provider normally controls terminal hardware, firmware and payment configuration. An IT provider can diagnose connectivity, cabling, Wi-Fi and related systems, then coordinate the payment provider without making unauthorised changes.
Not necessarily. It should be securely separated from business and payment systems, rate-limited where appropriate and designed so guest demand cannot disrupt trading. Higher-risk or high-footfall sites may justify separate connectivity.
Test it regularly and after any network, router, SIM or provider change. A monthly check is a sensible starting point for sites where connectivity is essential to payment.