A story we hear too often
The Tuesday the card terminals at the Naperville store went quiet
the owner of a three-location boutique
Maya owns three stores. The original on Armitage in Lincoln Park, the one in Evanston her sister runs, and the newest in Naperville that finally turned a profit in March. Tuesday mornings she does the numbers from the back office with the door open so she can hear the register.
At 10:40 the terminals in Naperville stop taking cards. The manager there calls, calm, and says the payment vendor’s portal shows a login from another country at 3 a.m. and a new ‘remote support’ user nobody created. The online store shares the same admin password. Maya realizes she is holding the whole business in one line of an email thread.
Here is where it usually goes badly. Card data skimmed for weeks, a breach notice to every customer, the processor’s fine, the local news. Instead, the protection agent had already cut the strange session at 3:04 a.m., locked the shared admin account and paged the engineer on watch. The Naperville outage was the engineer forcing a password reset on the terminal network before opening.
Maya finishes the numbers by noon. The terminals are back by 11:15. Nobody in Naperville ever learns how close it was, which is the point.
The online store shares the same admin password, and Maya realizes she is holding the whole business in one line of an email thread.
What changes the ending
- Unique accounts and MFA for every store, vendor portal and the online store (CIS Controls 5 and 6, Account and Access Control Management)
- Card terminals on their own network segment, separated from office Wi-Fi and back-office PCs (CIS Control 12, Network Infrastructure Management)
- Someone watching the logs at 3 a.m. with authority to cut a session (CIS Control 13, Network Monitoring and Defense)