Offensive Security
POS Penetration Testing
Security testing of point-of-sale terminals and payment applications, covering PCI PTS POI and terminal attack surfaces, to protect cardholder data at the point of sale, under written authorization.
Overview
POS penetration testing assesses the security of point-of-sale terminals, payment applications, and their connections to back-office and payment systems. It answers whether an attacker could capture cardholder data, tamper with transactions, or compromise the terminal environment.
Testing considers the PCI PIN Transaction Security (PTS) Point of Interaction requirements alongside payment application and terminal attack surfaces. Scope can include terminal hardening, application security, communication encryption, and integration with the wider retail and payment environment.
Benefits
- Identifies weaknesses that could expose cardholder data at the point of sale.
- Assesses payment applications and terminal configuration against tampering and data capture.
- Reviews encryption and communication between terminals, back office, and payment systems.
- Supports card data protection goals with clear, prioritized remediation guidance.
Methodology
- 01
Scoping and Authorization
Agree target terminals, applications, test transactions, rules of engagement, and written authorization before testing begins.
- 02
Terminal and Configuration Review
Assess terminal hardening and configuration against PCI PTS POI considerations and known attack surfaces.
- 03
Payment Application Testing
Examine the payment application for insecure storage, weak cryptography, and tampering opportunities.
- 04
Communication Testing
Review encryption and integrity of traffic between terminals, back office, and payment systems.
- 05
Exploitation
Safely demonstrate confirmed issues with proof of concept using test data rather than live cardholder data.
- 06
Reporting and Retesting
Provide prioritized remediation guidance and validate fixes through retesting.
Deliverables
- 01Executive Summary
- 02Technical Findings
- 03Risk Ratings
- 04Proof of Concept
- 05Remediation Recommendations
- 06Final Report
- 07Retesting Validation Report
Related offensive security services
- Red TeamingGoal-based adversary simulation that tests how well your people, processes, and technology detect and respond to a realistic, multi-stage attack, performed under written authorization.
- Web Application Penetration TestingManual and tool-assisted testing of web applications and APIs against the OWASP Testing Guide and ASVS to find exploitable flaws before attackers do, performed under written authorization.
- Network Penetration TestingExternal and internal network testing guided by PTES and NIST SP 800-115 to find and safely exploit weak services, poor segmentation, and paths to sensitive systems, under written authorization.