This typical petroleum retail point of sale has connections to the fuel dispensers residing in the forecourt, allowing consumers to pay for directly at the pump / fueling station. This is similar to an unattended terminal. However, pay at the pump also offers fleet card holders the ability to pay with their fleet card and other information such as a Driver or Vehicle ID number.
Outside at the fuel island: The consumer presents their card to the fuel dispenser card reader (wave, tap, or insert). The card reader sends the payment information to the fuel/site controller, which then sends the payment information to the EPS, which then sends the payment information to the payment processor / acquirer.
Inside the convenience store: The consumer presents their card to the PIN Pad/Payment terminal card reader (wave, tap, or insert). The PIN pad sends the payment information either to the POS system or directly to the Electronic Payment Server (EPS), which then sends the payment information to the payment processor / acquirer.

Where is your card data at risk?

How do criminals get your card data?

How do you start to protect card data today?
Click on the icons below for the Guide to Safe Payments and information about these security basics. For simple definitions of payment and security terms, see our Glossary.

Change default passwords, use strong passwords, Multi-factor Authentication (MFA)

Ask your PCI Qualified Integrator & Reseller (QIR) or your hardware/software vendor for help

Use secure payment systems

Protect card data and only keep what you need

Protect in-house access to your card data

Protect all systems from the Internet

Regularly inspect your payment terminals for modification, changes, or other visual clues that suggest tampering or alteration

Limit remote access for your vendor partners – don’t give hackers easy access

Use anti-virus or “application allow” software

Install patches from your payment terminal vendor

Get regular vulnerability scanning

Make your card data useless to criminals

Use a robust, business grade firewall appliance with unified threat management

Protect network and USB ports