Home / What Happens After a POS Data Breach: A Restaurant's Response and Claims Process
Cyber Liability Insurance Guide

What Happens After a POS Data Breach: A Restaurant's Response and Claims Process

Quick Answer

Disconnect the affected payment terminals or network segment immediately, call your cyber insurer's breach hotline before you do anything else, and preserve system logs instead of wiping them. From there, your insurer typically assigns a forensic investigator and breach counsel who direct notification timing and vendor coordination, while your policy's first-party coverage picks up investigation, notification, and credit monitoring costs along the way.

What to Do in the First 24 Hours After a POS Data Breach

The moment someone flags unusual card activity, a processor alert, or a POS terminal behaving strangely, the instinct is to start troubleshooting. Resist it. Unplugging and rebooting can overwrite the exact log data a forensic investigator needs to determine what happened and when.

The FTC Data Breach Response Guide lays out the sequence in this order: secure your operations first, fix the vulnerability second, notify affected parties third. Applied to a restaurant POS breach, that looks like:

  • Isolate the affected terminals or network segment (disconnect from the internet, do not power down) so the intrusion cannot spread to your reservation system, back-office accounting, or other locations.
  • Call your cyber insurer's breach response line, not your general agent's voicemail. Most cyber policies include a 24/7 hotline specifically because hour one matters.
  • Do not restore from backup, reimage a terminal, or delete suspicious files. That destroys the evidence a forensic firm needs.
  • Change credentials for POS admin accounts, remote access tools, and any third-party vendor logins, but do this after your insurer's forensic team has imaged the affected systems, not before.
  • Keep a written timeline starting now. Who noticed what, when, and what actions were taken. Claims adjusters and regulators will both ask for this later.

If early evidence points to your own systems being locked or encrypted rather than card data being skimmed, the response sequence changes meaningfully. See Does Cyber Insurance Cover Ransomware That Locks Down Your Own Restaurant's POS or Reservation System? for that scenario specifically.

Cyber Insurer, Forensic Investigator, or Card Processor: Who Do You Call First?

A restaurant owner's instinct is often to call the POS vendor first. That is usually backwards once cyber coverage is in place. The correct order, and the order most cyber policies are written to enforce through a "duty to cooperate" clause, is:

  • Your cyber insurer's breach hotline, immediately.
  • The forensic investigation firm the insurer assigns or approves. Many policies require using a carrier-panel vendor; hiring your own IT consultant first can create a coverage dispute later.
  • Breach counsel, an attorney the insurer typically assigns, who directs the legal side of notification and often makes the forensic firm's findings privileged.
  • Your card processor and acquiring bank, who will open their own investigation track tied to PCI DSS compliance.
  • Law enforcement, generally the FBI's Internet Crime Complaint Center for a card-skimming incident, once your insurer and counsel confirm it will not interfere with the forensic timeline.

Calling the POS vendor or a local IT shop first is not wrong in a panic, but it can complicate the claim. If that vendor's technician touches the compromised system before the assigned forensic firm images it, you may lose evidence the investigation needs, and in rare cases the insurer may question why an unapproved vendor was engaged.

State Breach Notification Laws: What You Must Tell Customers and Regulators

Every state requires businesses to notify consumers after a breach involving their personal or payment data, but the specifics differ significantly by state. The NCSL Security Breach Notification Laws tracker confirms all 50 states, plus DC and the territories, have some version of this requirement, and no two are identical.

According to the IRMI Data Breach Notification Laws glossary, these state statutes generally address four components:

  • What triggers the duty: which specific types of data count as protected personal information.
  • Who must be notified: affected individuals, and in many states the attorney general or a consumer reporting agency.
  • How quickly: commonly a specific number of days, though some states use a "reasonable time" standard instead.
  • What the penalties are for non-compliance.

This is exactly why breach counsel matters. A restaurant with locations in three states may face three different notification deadlines and three different definitions of "personal information" for the same breach.

Your insurer's assigned counsel tracks this so you do not have to guess. The notification letters, call center setup, and credit monitoring offer are typically coordinated as a single package rather than something the restaurant drafts alone.

If the forensic investigation determines the breach originated from a staff member's credentials rather than an external card-skimming device, the notification obligations can shift again. That scenario is covered separately in Does Cyber Liability Insurance Cover Data Breaches Caused by Employees?

How to File a Cyber Insurance Claim After a POS Breach, Step by Step

Filing a cyber claim is not a single form. It is closer to opening a case file that grows as the investigation proceeds.

  1. Initial notice of circumstance. Even before you know the scope, most policies want notice as soon as you have a reasonable suspicion of a breach. Waiting until you have "all the facts" can itself create a late-notice problem with the carrier.
  2. Assignment of the response team. The insurer typically assigns, or approves your choice from an approved panel of, a forensic investigator and breach counsel. These costs are usually covered under the policy's first-party breach response coverage, subject to your deductible.
  3. Scoping the incident. The forensic firm determines what data was accessed, how many records, over what time window, and how the intrusion occurred. This report becomes the backbone of the claim file and the notification decision.
  4. Documenting the loss. Track notification and call center costs, credit monitoring enrollment costs, any PCI fines or card brand assessments issued by your processor, and lost income if systems were down. Keep every invoice; adjusters reconcile the claim against actual receipts, not estimates.
  5. Proof of loss and settlement. Once costs are documented, the carrier issues payment for covered items up to your sub-limits, most commonly with separate caps for forensic costs, notification costs, and ransomware payments if applicable.

A claim can move in weeks for a straightforward, small-scope breach, or drag on for months if litigation from affected customers or a card brand assessment dispute follows. Staying inside the process your policy defines, rather than improvising, is what keeps the claim moving on the faster end of that range.

PCI DSS Compliance and Card Brand Assessments: What They Mean for Your Liability

Every restaurant that accepts card payments agreed to PCI DSS compliance the day it signed a merchant services agreement, whether or not anyone at the restaurant has ever read the standard. PCI DSS sets baseline requirements for protecting cardholder data, including:

  • Network segmentation between POS systems and the rest of your business network
  • Restricted access to stored card data
  • Regular vulnerability scanning

After a breach, your processor and the card brands ask two separate questions:

  1. Were you PCI compliant at the time of the breach?
  2. Even if so, did the breach happen anyway?

Being compliant does not guarantee you avoid card brand assessments, but being found non-compliant after the fact changes the financial exposure substantially. Non-compliance is also a standard exclusion on most cyber policies specifically for payment card breaches, meaning the restaurant, not the insurer, absorbs fines tied to that gap.

Practically, this means the forensic report following a breach often becomes a compliance audit by another name. An unpatched POS system, a default admin password never changed, or cardholder data stored somewhere it should not have been can affect both the card brand assessment and how your insurer processes the claim going forward.

Business Interruption Coverage: Recovering Lost Revenue During POS Downtime

A POS breach rarely stays confined to a data problem. Terminals get taken offline for forensic imaging, sometimes for days, and a restaurant that cannot run cards is a restaurant losing revenue during the exact window it also needs cash for response costs.

Business interruption coverage under a cyber policy is meant to bridge that gap. It reimburses lost income tied to the system outage itself, generally measured against a comparable prior period.

This is a distinct coverage from the breach response costs (forensics, notification, credit monitoring). Expect the claim to track these as separate line items even though they stem from the same incident.

Practically, this is also where having a manual card-processing fallback (a standalone terminal or backup processor account not tied to the compromised network) shortens the interruption window considerably. Insurers frequently ask about this kind of contingency during underwriting for exactly this reason.

How a POS Breach Claim Affects Your Cyber Insurance Renewal and Premium

Once a claim resolves, most restaurants find their next renewal looks different. Expect the carrier to ask pointed questions about what was fixed:

  • Was multi-factor authentication added to POS admin access?
  • Was the vulnerability that caused the breach actually patched?
  • Was staff retrained on phishing recognition?

A claims history without a corresponding remediation story tends to push premiums up or narrow available limits at renewal.

It is worth treating the forensic report as a punch list rather than filing it away once the claim is paid. The FTC's guidance frames the "fix vulnerabilities" step as an ongoing discipline, not a one-time task tied to a single incident, and carriers underwrite renewals the same way.

More on Cyber Liability Insurance

Get restaurant insurance built around how you actually operate.

Tell us your concept, your coverage questions, and your state — and we'll put together the coverage that actually applies.

Get a Cyber Liability Quote