A third party IT company with little security skills configured POS systems across multiple locations.
Why is a shared, identical password across all POS locations a security risk?
Using the same easily-guessable password across every point-of-sale terminal at every location means a single breach at one site, or at the shared corporate file server, can compromise every location simultaneously.
- In one case, a franchisee's third-party IT vendor set up hundreds of restaurant locations with identical POS credentials, all connected to a shared corporate file server.
- This centralized architecture prioritized operational convenience but eliminated any containment between locations, turning one weak password into an enterprise-wide exposure.
- Unique, complex credentials per location and per system limit the blast radius of any single compromised password.
- Vetting IT vendors for actual security expertise, not just installation capability, is critical when centralizing POS or file-sharing infrastructure across multiple sites.
Quick Answer: Why Is Sharing One Server Across Multiple Franchise Locations Risky
Connecting all franchise locations to a single shared file server creates a single point of failure, meaning one breach can compromise every store's cardholder data at once.
- Identical, easily-guessable default POS passwords across all restaurant locations made the entire network easy to compromise.
- If an attacker accesses the corporate file server, every connected restaurant becomes vulnerable to card compromise.
- Consistent configuration across locations simplifies management but can create widespread security exposure if not done securely.
- Ask your POS installer about unique credentials and segmentation before consolidating locations onto shared infrastructure.
Linking 100 restaurants through one insecure server connection is a bad idea.
The following post is a segment in the Auditing Archives series. Hopefully the security failures I’ve seen while auditing businesses will help inspire better practices to ensure your own business security.
I have a sad story to tell. An unfortunate franchisee with hundreds of restaurant locations hired a third party IT company with little security skills to configure their restaurant point-of-sale (POS) systems across multiple locations. By allowing every restaurant access to the same programs and files back at corporate headquarters, it promoted process consistency across each restaurant management system, making information exchange easy, but also opening security holes.
Want to read more Auditing Archives stories?
The sad part of the story is, the IT company configured every in-store POS system identically … with the same easily-guessable password. (Read more about vendor default passwords.) And each of those stores were connected to a common file server back at corporate. Now, if a bad guy can get into the corporate network and on to the file share server, every single restaurant owned by that franchisee is at risk for card compromise.
See also: 7 Questions To Ask Your POS Installer
Check out the case study below.
Auditing Archives: The Case of the File Sharing Franchisee from SecurityMetrics




