Englishالعربية Soon
Under attack?
ATM and payment device testing

An ATM is a computer with cash inside it and a queue in front of it.

Testing across the whole chain rather than the enclosure alone: device hardening, peripherals, the card reader, the network path, the connection to the host and the transaction logic behind all of it.

Attack classes

Black box, jackpotting and card data attacks, tested rather than assumed.

Physical and logical attacks are attempted the way criminal groups attempt them: dispenser commands from an unauthorised source, boot and kiosk protection bypass, skimming and shimming, and manipulation of the transaction itself.

Payment infrastructure

The device is one half. The switch behind it is the other.

POS terminals, payment switches, card management systems and host security assessed alongside the devices, with findings mapped to PCI DSS and PCI-S3 requirements your acquirer will ask about.

Scope of work

What the assessment covers

The tests a device has to survive before it is put on a street corner with money in it.

Device hardening review

Operating system build, kiosk lockdown, USB and peripheral controls, patch state and local privilege boundaries.

Boot and protection bypass

Attempts to escape kiosk mode, boot alternative media, disable protection software and reach the underlying system.

Dispenser and peripheral attacks

Unauthorised dispense commands, peripheral communication tampering and physical interface abuse attempted end to end.

Card reader attacks

Skimming and shimming feasibility, card data handling in memory and on disk, and EMV implementation weaknesses.

Network path testing

What the device can reach and what can reach it, including segmentation, exposed services and management access.

Host connection and transaction logic

Manipulation of messages between device and host, authorisation bypass attempts and transaction integrity checks.

Encryption and key management

Cryptographic implementation, key injection, storage and rotation examined against the standard rather than the brochure.

POS terminal testing

Terminal hardening, communications, tamper response and integration with the payment application.

Switch and card management review

Payment switch, card management system and host configuration assessed for the paths that reach them.

How it works

From a device on a test bench to a remediation plan for the fleet

One device model is assessed properly, then the findings are applied across every unit of that build.

ATMsKiosksPOS terminalsPayment switchHSMCard management
01
Scope
Models, builds, locations and boundaries agreed, with test devices provided in a controlled environment.
02
Physical
Enclosure, ports, peripherals and tamper response examined, and physical access paths attempted.
03
Logical
Kiosk escape, privilege escalation, protection bypass and unauthorised peripheral command attempts.
04
Transaction
Communications with the host intercepted and manipulated to test authorisation and integrity controls.
05
Report
Findings per build with severity, exploitation detail and a fleet-wide remediation plan, plus retest.
Testing is performed on devices you provide in a controlled environment, with cash removed. Nothing is attempted against a live unit in service.
Engagement model

Assessment

A defined engagement per device build: physical, logical and transaction testing, with a fleet remediation plan and retest.

Talk to us →

Engagement model

Ongoing assurance

Reassessment on each build change or vendor update, so a hardened fleet does not quietly drift back.

Governance and compliance →

Related

Related work

Penetration testing

The network the devices sit on deserves the same scrutiny as the devices themselves.

Source code review

Payment application logic is best examined where it is written, not only where it runs.

PCI DSS and PCI-S3

Findings map directly to the requirements your acquirer and card schemes assess you against.

Test one device model first.

We assess a single build in a controlled environment, then apply the findings across every unit that shares it.