Skip to content

Offensive Security

POS Penetration Testing

Security testing of point-of-sale terminals and payment applications, covering PCI PTS POI and terminal attack surfaces, to protect cardholder data at the point of sale, under written authorization.

Discuss this service

Overview

POS penetration testing assesses the security of point-of-sale terminals, payment applications, and their connections to back-office and payment systems. It answers whether an attacker could capture cardholder data, tamper with transactions, or compromise the terminal environment.

Testing considers the PCI PIN Transaction Security (PTS) Point of Interaction requirements alongside payment application and terminal attack surfaces. Scope can include terminal hardening, application security, communication encryption, and integration with the wider retail and payment environment.

Benefits

  • Identifies weaknesses that could expose cardholder data at the point of sale.
  • Assesses payment applications and terminal configuration against tampering and data capture.
  • Reviews encryption and communication between terminals, back office, and payment systems.
  • Supports card data protection goals with clear, prioritized remediation guidance.

Methodology

  1. 01

    Scoping and Authorization

    Agree target terminals, applications, test transactions, rules of engagement, and written authorization before testing begins.

  2. 02

    Terminal and Configuration Review

    Assess terminal hardening and configuration against PCI PTS POI considerations and known attack surfaces.

  3. 03

    Payment Application Testing

    Examine the payment application for insecure storage, weak cryptography, and tampering opportunities.

  4. 04

    Communication Testing

    Review encryption and integrity of traffic between terminals, back office, and payment systems.

  5. 05

    Exploitation

    Safely demonstrate confirmed issues with proof of concept using test data rather than live cardholder data.

  6. 06

    Reporting and Retesting

    Provide prioritized remediation guidance and validate fixes through retesting.

Deliverables

  • 01Executive Summary
  • 02Technical Findings
  • 03Risk Ratings
  • 04Proof of Concept
  • 05Remediation Recommendations
  • 06Final Report
  • 07Retesting Validation Report