A third party IT company with little security skills configured POS systems across multiple locations.
Quick Answer: Why Is Sharing One Server Across Multiple Franchise Locations Risky
Connecting all franchise locations to a single shared file server creates a single point of failure, meaning one breach can compromise every store's cardholder data at once.
- Identical, easily-guessable default POS passwords across all restaurant locations made the entire network easy to compromise.
- If an attacker accesses the corporate file server, every connected restaurant becomes vulnerable to card compromise.
- Consistent configuration across locations simplifies management but can create widespread security exposure if not done securely.
- Ask your POS installer about unique credentials and segmentation before consolidating locations onto shared infrastructure.
Linking 100 restaurants through one insecure server connection is a bad idea.
The following post is a segment in the Auditing Archives series. Hopefully the security failures I’ve seen while auditing businesses will help inspire better practices to ensure your own business security.
I have a sad story to tell. An unfortunate franchisee with hundreds of restaurant locations hired a third party IT company with little security skills to configure their restaurant point-of-sale (POS) systems across multiple locations. By allowing every restaurant access to the same programs and files back at corporate headquarters, it promoted process consistency across each restaurant management system, making information exchange easy, but also opening security holes.
Want to read more Auditing Archives stories?
The sad part of the story is, the IT company configured every in-store POS system identically … with the same easily-guessable password. (Read more about vendor default passwords.) And each of those stores were connected to a common file server back at corporate. Now, if a bad guy can get into the corporate network and on to the file share server, every single restaurant owned by that franchisee is at risk for card compromise.
See also: 7 Questions To Ask Your POS Installer
Check out the case study below.
Auditing Archives: The Case of the File Sharing Franchisee from SecurityMetrics




