Your busiest quarter lands on the systems you can least afford to change. Harden your point of sale before the holiday freeze — on purpose — so the season runs on the plan you set, not the incident you didn’t.
No form, no email required — read it before the rush, not during it.
For multi-site retail, the holiday peak is the one stretch of the year when the point-of-sale environment is busiest, most exposed, and least touchable. Once the season starts, the payment network is the last thing you want to change — which means the work has to happen before the freeze.
This is a plain, calm checklist for doing exactly that. It is built around three moves — harden before the freeze, know your PCI obligations, and set a change freeze — and it is deliberately free of scare tactics and fabricated numbers. The stores that get through the holidays quietly aren’t lucky. They decided early.
It is aligned to public standards: the payment-security requirements published by the PCI Security Standards Council (PCI DSS v4.0) and the ransomware-hardening guidance in CISA’s #StopRansomware program. It is a general framework, not a substitute for a plan built for your specific environment — and it’s free, with no email address required.
Everything below hangs on these three. Do them in order, and do them before the season locks the environment for you.
Patch it, separate the payment network from everything else, and put strong sign-in on anyone who can reach it — while you still can touch it.
Your card environment has rules — what to isolate, what to log, who gets in. Meet them on purpose, not after a call from your bank.
Lock the environment through your peak, and keep one tested way back in case something still slips through.
The pre-season hardening pass — done on an ordinary day, while the environment is still safe to change:
If you take cards, you have obligations under the PCI Data Security Standard. Meet them on purpose. This is the qualitative map — your acquirer and your assessor set the specifics:
This is general guidance drawn from the public PCI DSS framework, not a compliance assessment. Your specific requirements are set by the PCI Security Standards Council standard, your acquiring bank, and, where applicable, a Qualified Security Assessor.
Once the environment is hardened, protect it by not touching it. A change freeze is a decision you make in September so the peak runs quietly:
The public standards this checklist is built on
The PCI Data Security Standard (PCI DSS v4.0), published by the PCI Security Standards Council, sets the security requirements for organizations that handle payment cards — segmentation, access control, logging, and secure configuration among them. This checklist references it qualitatively; it does not reproduce or interpret specific requirement numbers on your behalf.
CISA’s #StopRansomware guidance, from the U.S. Cybersecurity and Infrastructure Security Agency, is the public playbook for reducing ransomware risk: patch, use MFA, segment networks, and keep tested, recoverable backups. The three moves above are that guidance, applied to the retail holiday peak.
The full checklist — print-ready to work from, no form and no email required.
A straight read on where your point of sale is exposed and what to shore up first — no pitch. In Los Angeles, Pro Link Systems has kept businesses running since 1999: in-house, US-based, and answering the phone live, around the clock, right through the busiest nights.