Back to all resources
guide

IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe

October 8, 2026
10 min read
IT Rapid Support Team
IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe

A restaurant needs IT that keeps service running and keeps card data safe: a point of sale (POS) network that is separated from guest Wi-Fi and office computers, an internet connection with a backup so an outage does not mean cash only, battery backup on the POS, kitchen and network equipment, multi-factor authentication on email and every online ordering, delivery and payroll account, individual logins for staff that are removed the day someone leaves, and support that answers during evening and weekend service. The difference from an office business is timing. Most restaurant IT problems happen when the room is full, and a down POS or a dead router costs sales by the minute.

This guide is a practical checklist for owners, operators and general managers of restaurants, cafes, bars and small restaurant groups in Ontario. It covers what to protect, how to set up the network behind the POS, how to handle payment security, staff turnover and online ordering accounts, and what to ask when you choose an IT provider. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT.

What a Restaurant Actually Depends On

Before changing anything, write down every system the business needs to take an order, cook it, get paid and pay staff. For most restaurants the list looks like this:

  • POS terminals, card readers and the POS back office, whether hosted by the vendor in the cloud or on a local server.
  • Kitchen display screens and kitchen printers that receive orders from the POS.
  • Online ordering, delivery platform tablets and the reservation system.
  • The internet connection, router, firewall, network switch and Wi-Fi access points that connect all of the above.
  • Email (often Microsoft 365 or Google Workspace), accounting, payroll and scheduling apps used from the office or the manager's phone.
  • Security cameras and their recorder, music, and any digital menu boards.

For each item, note who supplies it, who supports it and the number to call. When something fails at 7 PM on a Saturday, the first ten minutes are usually lost working out whose problem it is.

Keep the POS Running During Service

  • Internet failover: a second connection, usually a cellular backup, that takes over automatically when the main line drops. Test it by unplugging the main connection during a quiet period.
  • Battery backup (a UPS) on the POS server if there is one, the router, the firewall and the main network switch, so a brief power flicker does not reboot the network mid-order.
  • Offline mode: ask your POS vendor exactly what keeps working without internet, for how long, and how offline card transactions are handled, then make sure managers know the procedure.
  • A spare: a spare card reader or tablet, or a documented way to move a terminal to another station, so one failed device does not shut down a section.
  • Supported hardware and software: POS terminals, card readers and the PCs or tablets around them on firmware and operating systems that still receive security updates.
  • Cabling and power that are labelled and tidy, so whoever is on site can tell the POS switch from the music system.

Separate Guest Wi-Fi From Payment Systems

Network segmentation is the most important technical control for a restaurant. A guest on free Wi-Fi, a staff member's personal phone or an infected office laptop should not be able to reach the POS or card readers.

  • Guest Wi-Fi runs on its own network with client isolation, a bandwidth limit and no access to anything inside the business.
  • POS terminals, card readers and kitchen displays sit on their own segment with firewall rules that allow only the traffic the POS vendor requires.
  • The office PC, cameras and staff devices are on separate segments again.
  • The Wi-Fi and router admin passwords are changed from the installer's defaults and kept somewhere other than a sticky note behind the bar.
  • Staff phones use the guest network, not the network the POS is on.

Payment Card Security and PCI DSS

Any business that accepts cards is expected to follow the Payment Card Industry Data Security Standard (PCI DSS), and your payment processor or acquiring bank is the party that tells you which validation applies to you, usually a self-assessment questionnaire each year. Most of what the standard asks of a small restaurant overlaps with this checklist:

  • Card data is entered only on the approved card reader and is never written down, emailed or stored in a spreadsheet, including for phone orders and catering deposits.
  • Card readers are checked regularly for tampering and skimming devices, and staff know what a tampered reader looks like.
  • The payment network is segmented from guest and office networks, behind a managed firewall.
  • Every person who logs in to the POS back office or payment portal has their own account, not a shared one.
  • You keep the evidence: network diagram, the questionnaire you submitted and records of the checks you do.

Confirm with your processor which requirements apply to your setup before buying anything; many hosted POS systems handle a large part of the card environment for you.

Staff Turnover, Shared Logins and Accounts

Restaurants hire and lose staff faster than almost any other business, which makes account hygiene a real security issue rather than paperwork.

  • Each staff member gets their own POS login or PIN, with manager-level functions such as voids, refunds and discounts limited to managers.
  • When someone leaves, their POS PIN, email, scheduling and any vendor portal access are removed the same day, and shared passwords they knew are changed.
  • Multi-factor authentication is on for email, the POS back office, online ordering and delivery platform accounts, payroll, banking and the domain and website login.
  • The accounts that control money, such as the delivery platform payout settings and the payroll system, are owned by the business, not by one manager's personal email.

Online Ordering, Delivery Platforms and Payment Fraud

Delivery platform tablets and online ordering dashboards hold payout details and customer information, and they are a common target. A phishing email that looks like it comes from a delivery platform, a supplier or your POS vendor can capture a password and redirect payouts or deposits.

  • Payout and banking changes on any platform are confirmed by phone with a known contact before they take effect.
  • Supplier requests to change banking details are verified by calling the number you already have, not the one in the email.
  • Gift card requests by email or text that appear to come from the owner are treated as fraud until confirmed in person.
  • Your domain has SPF, DKIM and DMARC email authentication set up, so others cannot easily send email that appears to come from your restaurant. Our free email spoofing check shows where you stand.

Backups, Cameras and the Back Office

  • Back up what lives on-site: the POS server if you have one, the office PC, recipes and costing spreadsheets, and accounting files. Test that a restore actually works.
  • For cloud POS and accounting, export the reports you would need if the account were locked, such as sales history and tax summaries.
  • The camera recorder has its default password changed, is not exposed directly to the internet, and keeps footage long enough for your insurer and any incident review.
  • Office and manager devices are on a supported operating system, patched, and protected by managed endpoint security.

Restaurant Groups and Multiple Locations

Once there are two or more locations, standardise: the same router and firewall model, the same network layout, the same POS configuration and the same naming at every site, so a problem at one location can be diagnosed from a known template. Monitor each location's internet connection and network centrally so outages are seen before the manager calls, keep a documented checklist for opening a new location, and give every site the same support number.

What to Ask an IT Provider for a Restaurant

  • Is support available during our service hours, including evenings, weekends and holidays, and how fast does a person answer?
  • Will they work directly with our POS vendor, internet provider and payment processor when the problem belongs to them?
  • How would they separate guest Wi-Fi, the POS and the office, and will they set up and test internet failover?
  • Can they come on-site when a remote fix is not enough, and how is that scheduled?
  • How do they handle staff joiners and leavers across email, POS back office and other accounts?
  • Is the agreement clear about what is included, and is project work such as a new location fit-out scoped and quoted in writing before it starts? Our guide on what a managed IT contract should include lists the clauses to check.

How IT Rapid Support Works With Restaurants

IT Rapid Support provides managed IT, network support and cybersecurity for restaurants, cafes, bars and hospitality businesses across the Greater Toronto Area from our office at 7810 Keele St in Vaughan. Our helpdesk is available 24/7, we coordinate with your POS vendor and internet provider rather than leaving you in the middle, and on-site work is dispatched across the GTA. Support is billed by the hour or covered under an agreement scoped to your locations and devices, and projects are scoped and quoted in writing. The service details are on our page for IT support for restaurants and hospitality, and main-street businesses in Mississauga can also read our guide to small business IT in Streetsville and Port Credit. If something is down right now, our IT emergency checklist covers the first hour. To review your restaurant against this checklist, call (289) 582-9930 or contact us.

Frequently Asked Questions

What IT support does a restaurant need?

At minimum: a POS network separated from guest Wi-Fi and office devices, internet failover and battery backup so service survives an outage, supported and patched POS and office hardware, individual staff logins removed promptly when people leave, multi-factor authentication on email, ordering, delivery and payroll accounts, tested backups of anything stored on-site, and a support line that answers during evening and weekend service.

Is there 24/7 IT support for restaurants?

Yes, some providers run a 24/7 helpdesk, which matters for restaurants because most problems happen during service, not office hours. Ask any provider who actually answers at 8 PM on a Saturday, whether they can work remotely on your network and POS environment, and how quickly they can send someone on-site.

Should guest Wi-Fi be on the same network as the POS?

No. Guest Wi-Fi should run on its own isolated network with no access to the POS, card readers, kitchen displays, cameras or office computers. Segmenting the payment network is one of the most effective security controls a restaurant can put in place and is part of what PCI DSS expects.

What happens to card payments when the internet goes down?

It depends on your POS and payment processor. Some systems can store transactions offline for a limited time and send them later, with limits and risks the processor sets; others stop taking cards entirely. Ask your vendor exactly how it works, and add a cellular internet backup so the question rarely arises.

Does a small restaurant need to comply with PCI DSS?

Yes. Any business that accepts payment cards is expected to follow PCI DSS, and your payment processor or acquiring bank decides how you validate it, which for most small restaurants is an annual self-assessment questionnaire. Using an approved card reader, never storing card numbers and segmenting the payment network cover much of what a small restaurant is asked.

What cybersecurity threats do restaurants face most?

The common ones are phishing emails that capture email, POS or delivery platform passwords, fraudulent requests to change supplier or payout banking details, gift card scams that impersonate the owner, card skimmers on readers, and former staff whose logins were never removed. Multi-factor authentication, call-back verification of banking changes and same-day offboarding stop most of them.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants
guide
•
October 8, 2026

IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants

The IT and security controls a manufacturer needs: separating office IT from the plant floor, containing legacy machine PCs, ERP and EDI uptime, backups of machine programs, vendor remote access, payment fraud, customer security questionnaires, shift coverage and what to ask an IT provider.

Read more: IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants
What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses
guide
•
October 8, 2026

What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses

How to tell an IT emergency from an urgent ticket, first-15-minute checklists for network outages, server failures, email down, ransomware and payment fraud, what to have ready before you call, and a one-page emergency plan.

Read more: What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses
What Are IT Professional Services? A Guide for GTA Businesses
guide
•
October 7, 2026

What Are IT Professional Services? A Guide for GTA Businesses

IT professional services are project work with an end date: migrations, network builds, server replacements, office moves. How they differ from managed IT and consulting, and what a statement of work should include.

Read more: What Are IT Professional Services? A Guide for GTA Businesses

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch