Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT and Cyber Security for Retail Shops: A UK Owner's Guide

In short

Retail shops handle card payments, footfall and busy tills, which makes them a soft target. This guide covers taking payments safely, splitting your till and guest Wi-Fi, locking down the machines behind the counter, giving staff proper logins, and backing up the things you can't afford to lose. Practical steps, no jargon.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why retail shops are an easy target

Retail is a busy, high-turnover environment. You have card payments flowing all day, a public front door, seasonal or part-time staff, and often a single machine in the back office doing everything from stock to payroll. Attackers know this. They are not singling out your shop personally, they are running automated attacks that look for the weakest, most predictable setup, and a small shop that has never had proper IT support is exactly that.

The good news is that the fixes are mostly straightforward and inexpensive. You do not need an in-house IT department. You need a handful of sensible habits and a couple of things set up correctly once. This guide walks through the areas that matter most for a UK retail business, in plain English.

Taking card payments safely

The moment you accept card payments you take on a responsibility for that data. The framework that governs it is called PCI DSS (the Payment Card Industry Data Security Standard). For a big retailer this is a serious undertaking. For most small shops, it is far lighter, provided you do one thing: let a compliant provider handle the card data, and never handle it yourself.

In practice that means:

  • Use a reputable card terminal or payment provider. When the customer taps or inserts their card, the card number is captured and encrypted by the device, not by your till software or your staff.
  • Never write card numbers on paper, type them into a spreadsheet, or take them over email. If a customer offers to “just email the card details”, say no.
  • Complete the annual self-assessment questionnaire (SAQ) your payment provider gives you. It is a short form, and if you use their approved equipment, most of the technical burden sits with them.
  • Keep the terminal’s firmware up to date and buy or rent equipment only from your provider, never second-hand from an unknown source.

The principle is simple: the less card data ever touches your own systems, the smaller your risk and the smaller your compliance headache.

Split your Wi-Fi: tills on one side, guests on the other

Offering customers free Wi-Fi is fine. Letting their devices share the same network as your tills and card terminal is not. If a customer’s phone is infected, or someone parks outside and joins your open network, you do not want them anywhere near the systems that run your shop.

The fix is to run two separate networks:

  • A private network for your tills, card terminals, back-office PC and stock devices. This one is not advertised publicly and uses a strong, unique password that customers never see.
  • A guest network for customers and their phones. Most business routers offer a guest or second network as a built-in feature. It gives internet access but has no route to your business devices.

This one change removes a whole category of risk for very little effort. If you are not sure whether your current router is set up this way, it is worth having someone check.

The less card data ever touches your own systems, the smaller your risk and the smaller your compliance headache.

Lock down the machines behind the counter

The PC in the back office and the tills on the shop floor are the heart of your business, so treat them with a bit of care.

  • Keep them updated. Turn on automatic updates for Windows and for your till and accounting software. If you are still running a Windows 10 machine, be aware that Microsoft ended support on 14 October 2025, so an unsupported PC on your network is a growing risk that should be planned out.
  • Run proper security software. Every machine should have reputable, up-to-date protection running, not a free trial that expired two years ago.
  • Don’t let the till PC double as a personal computer. The machine that runs your shop should not be used for staff browsing, personal email or downloading games. Every extra use is an extra way in.
  • Restrict who can install things. Day-to-day staff accounts should not be able to install software. That single setting stops a lot of accidental infections.

Getting a consistent baseline across every device is exactly the kind of thing the government-backed Cyber Essentials scheme is designed to check, and it is a sensible standard for a shop to aim for.

Give every member of staff their own login

A shared login where everyone knows the same password is convenient right up until it isn’t. When a member of staff leaves, when something goes missing from the till, or when you need to know who did what, a shared account tells you nothing.

  • Give each person their own account on the till and back-office systems.
  • Turn on multi-factor authentication (MFA) wherever it is offered, especially for email, accounts software and anything cloud-based. MFA is the single most effective step you can take to stop stolen passwords being used against you, and it is a mandatory requirement under Cyber Essentials for cloud services.
  • Use a password manager so staff can have strong, different passwords without writing them on a sticky note under the till. A tool such as Proton Pass lets you store and share logins securely across the team.
  • When someone leaves, disable their accounts the same day.

Back up what you can’t afford to lose

Imagine the back-office PC is stolen overnight, or a ransomware attack locks every file. What would you lose? Sales history, stock records, supplier details, accounts, VAT records. For most shops that would be genuinely serious.

A good backup routine follows the well-known 3-2-1 rule: three copies of your data, on two different types of storage, with one copy kept off-site or in the cloud. Cloud accounting and till systems help here, but do not assume they cover everything, and remember that Microsoft 365 email and files need their own backup too.

Most importantly, test that a backup actually restores. A backup you have never tested is a hope, not a plan. Our guide to 3-2-1 backups and disaster recovery goes into the detail.

Don’t forget business continuity on the day

Think about what keeps you trading if something breaks:

  • If your internet drops, can you still take card payments? Some cloud tills work offline; some don’t. Ask your provider, and consider a mobile card reader on a separate mobile connection as a fallback.
  • If a till fails on a Saturday, who do you call and how fast can they respond?
  • Is there a written note of your key suppliers, account numbers and support contacts that is not stored only on the machine that might fail?

A little planning here is the difference between a five-minute wobble and losing a day’s trade.

A simple retail checklist

  • Card payments handled by a compliant provider, never written down or typed into spreadsheets
  • Annual PCI self-assessment completed
  • Separate guest and private Wi-Fi networks
  • Tills and back-office PCs updated, protected and not used for personal browsing
  • Individual staff logins with MFA turned on
  • A password manager instead of sticky notes
  • Daily, tested backups with an off-site or cloud copy
  • A plan for taking payment if the internet goes down

Where DACROS fits in

Most shop owners do not want to become IT experts, and they shouldn’t have to. As a Leeds and Yorkshire managed IT and cyber security provider, we set this up properly once, keep it maintained, and are on the end of the phone when something goes wrong on a busy Saturday.

If you would like a straightforward review of how your shop is set up, with no jargon and no pressure, get in touch and we will talk it through in plain English.

Frequently asked questions

Do I have to worry about PCI DSS as a small shop?

Yes, but for most small shops it is lighter than it sounds. If you use a reputable card terminal or payment provider, they handle the heavy technical work and you complete a short self-assessment questionnaire (SAQ) each year. The key rule to remember: never write down, type or store full card numbers yourself. Let the provider's device do it.

Can I let customers use the shop Wi-Fi?

You can, as long as it is a separate guest network that has no path to your tills, card terminals or back-office PCs. Most business routers support a guest or second network in a few clicks. Keeping the two apart means a customer's infected phone can never reach the systems that run your shop.

What happens to my till system if the internet goes down?

It depends on the system. Many modern cloud tills keep taking card and cash payments offline and sync when the connection returns, but not all do. Ask your provider directly, and keep a backup way to take payment, such as a mobile card reader on a separate 4G/5G connection.

How often should a shop back up its data?

Daily is a sensible minimum for sales records, stock and accounts, with at least one copy kept off-site or in the cloud. If losing a day's data would cause real pain, back up more often. The important part is testing that a backup actually restores, not just that it runs.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.