Safer remote payment operations

How can a merchant secure a virtual terminal?

A merchant can make a virtual terminal safer by controlling who can sign in, requiring strong authentication, using managed devices and trusted networks, limiting sensitive-data handling, reviewing activity, and preparing a clear response process. The available settings differ by provider, so each safeguard should be confirmed against the documentation for the specific virtual terminal and payment workflow.

Start with individual access

Give each authorized employee a separate account whenever the platform supports it. Shared usernames make it difficult to connect a payment, refund, setting change, or failed sign-in to the person who performed it. Individual accounts also make offboarding more direct when an employee changes roles or leaves the business.

Match permissions to job duties. A person who only keys approved payments may not need the ability to add users, change account settings, export reports, issue refunds, or modify settlement details. NIST describes least privilege as limiting access to the minimum needed for assigned tasks, while the FTC advises businesses to restrict sensitive-data and administrative access to people with a legitimate need. Review users and roles regularly, and remove access promptly when it is no longer required.

Strengthen sign-in protection

Turn on multifactor authentication

CISA recommends multifactor authentication for business accounts and advises prioritizing administrative and sensitive-data access. Enable the strongest method the provider supports, give each user their own factor, and never approve an unexpected prompt.

Use unique credentials

Create a long, unique password for the virtual terminal and store it through an approved password manager. Do not reuse a password from email, accounting, ecommerce, or personal accounts, and do not send passwords or one-time codes through chat or email.

Verify recovery options

Confirm that recovery email addresses, phone numbers, administrators, and provider contacts remain current. Treat an unexpected reset notice or sign-in alert as a reason to use a known portal or verified support channel rather than links in the message.

Use a controlled device and network

Access the virtual terminal from a business-managed computer or tablet that receives supported operating-system, browser, and security updates. Limit unnecessary browser extensions and software, use screen locking, and keep the device physically controlled. Avoid entering payments on a shared public computer or a personal device that the business cannot manage.

Use a trusted, password-protected business network. The FTC recommends separating guest Wi-Fi from the business network and keeping security software current. If remote work is necessary, follow the business's approved remote-access process and the virtual-terminal provider's documented requirements. Public Wi-Fi, improvised remote-control tools, or unverified browser warnings should trigger a pause rather than a workaround.

Keep payment data inside the approved workflow

  • Collect only what the transaction requires. Follow the fields and prompts in the approved virtual terminal instead of copying payment details into notes, spreadsheets, email, or messaging tools.
  • Do not retain security codes. Avoid recording a card security code or other sensitive authentication information outside the authorized transaction flow.
  • Use test data for training. Demonstrate procedures with provider-approved test tools or clearly fictitious information, never a customer's live payment details.
  • Protect the conversation. When taking a payment by phone, prevent unauthorized people from seeing or hearing the details and do not repeat sensitive information unnecessarily.

The FTC's business guidance emphasizes collecting only information that is needed, restricting access to sensitive data, and protecting information throughout its lifecycle. Exact handling requirements depend on the merchant's providers and circumstances; this page offers operational guidance, not a compliance determination.

Review activity and high-impact actions

Use the reports and alerts available from the provider to look for unexpected sign-ins, repeated failed access attempts, unusual keyed transactions, refunds, voids, user changes, and configuration changes. Availability varies, so document which events the current platform records and who is responsible for reviewing them.

Create a second-review step for unusual or high-impact actions when the workflow supports it. A review should consider the customer's request, the business purpose, prior activity, and fulfillment context rather than treating one signal as proof of fraud. Record decisions without copying complete card numbers, credentials, or other unnecessary sensitive data into the review notes.

Prepare for suspicious access

Employees should know how to stop using the affected session or device, preserve useful timestamps and non-sensitive details, notify an internal decision-maker, and contact the virtual-terminal provider through a previously verified channel. Do not rely on contact information supplied by a suspicious caller, email, or pop-up.

If an account, device, or network may be compromised, follow the responsible provider's current instructions and involve qualified security help as appropriate. Avoid making unverified configuration changes that could erase evidence or expand exposure. After the issue is contained, review users, recovery methods, permissions, devices, and staff procedures before normal use resumes.

Continue with related payment guidance

Audit one virtual terminal workflow

List every current user, permission level, approved device, network, authentication method, available alert, and escalation contact. Remove access that is no longer needed, enable supported protections, and ask the provider to confirm the documented controls for that exact account and workflow.

When contacting Payments Max about virtual terminal options, describe the business's payment channels, staff roles, transaction flow, and operational requirements. Do not submit cardholder data, passwords, bank credentials, complete account numbers, one-time codes, or secret API keys through a general inquiry form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US