Skip to content
Griffin IT Group griffin markOakville IT ServicesPowered by Griffin IT Group

Industry

Retail, Hospitality and Community Organisations

These organisations share a pattern: payment or donor data that must be protected, public-facing networks, seasonal or volunteer staffing, and budgets that leave no room for waste.

At a glance

  • Payment systems isolated to control PCI scope
  • Guest Wi-Fi fully separated from operations
  • High-turnover onboarding and offboarding
  • Non-profit licensing and grant-aware planning

Payments and public networks

Point-of-sale systems belong on their own network segment with restricted rules, so the rest of the environment stays out of PCI scope and a compromise elsewhere cannot reach the payment path. Where the payment provider offers point-to-point encryption or tokenisation, using it removes stored card data from the equation entirely.

Guest and customer Wi-Fi is separated from everything operational, with client isolation, bandwidth limits and terms of use. Shared networks between guests, payment terminals and back-office systems remain one of the most common findings in these environments.

  • POS segmentation and rule documentation
  • P2PE and tokenisation where supported
  • Isolated guest Wi-Fi with client isolation
  • IoT and building device separation

Staffing turnover and shared devices

Seasonal staff, volunteers and shift workers make account lifecycle the dominant risk. Provisioning needs to be fast and standardised; removal needs to be immediate and evidenced. Shared devices are configured so individual accountability survives — no shared credentials for anything touching payments or personal data.

  • Rapid standardised onboarding
  • Same-day access removal with records
  • Shared device configuration with individual sign-in
  • Short practical training for non-technical staff

Donor and member data

Non-profits and member organisations hold donor records, payment details and sometimes sensitive personal circumstances. Protection follows the same principles as anywhere else — least privilege, encryption, tested backup, logging — with recognition that budget is constrained. Non-profit licensing programmes and grant funding cycles both influence what is affordable and when, and we plan around them rather than ignoring them.

Questions

Frequently asked questions

Does offering guest Wi-Fi put us in PCI scope?
Not if it is genuinely separated from the payment environment. If it shares a network with payment terminals, it does — which is precisely why segmentation matters.
Can you work with non-profit budgets?
Yes. We use non-profit licensing programmes where eligible and sequence work so the highest-risk items are addressed first within available funding.
Do you support multiple locations?
Yes, with consistent configuration, central management and remote support, plus on-site attendance where physical work is required.

Protect payments and keep the doors open

Segmentation, scope control and practical support sized to a real budget.