Plan for a lost device or suspicious event
Before deployment, document who can disable access, revoke a user session, locate or remotely manage the mobile device, contact the payment provider, and decide whether equipment may return to service. Test the contact path without exposing credentials. An employee who notices loss, tampering, an unexpected app, an unfamiliar transaction, or a suspicious support request should know how to stop acceptance and escalate promptly.
Do not erase, reset, reconnect, or discard suspicious equipment until the responsible provider or incident lead gives an approved instruction. Those actions can affect records or make review harder. Preserve basic facts such as the time, device identifier, last known user, and observed condition without copying cardholder data into a ticket, email, chat, or general form.