Hotel cyber security fails in the joins. Not usually inside the property management system, not inside the payment terminal, but in the gaps between the reservation platform, the door-lock encoder, the guest network and the agency staff member who started on Friday night. A hotel runs more third-party systems per employee than almost any other small business, runs them twenty-four hours a day, and hands part of its network to strangers by design.

That combination is why generic advice lands badly here. A control set written for an office assumes one building, one network, one working day and one set of employees who were all onboarded properly. If you manage residential blocks rather than bedrooms, the sibling cyber security checklist for property management companies covers the same discipline for a different estate. This hotel cyber security guide is the hospitality version, and it is deliberately vendor-neutral.

What follows is a hotel cyber security checklist of 20 controls, grouped into five domains, each with a plain evidence test you can run in about ten minutes. There is a scorecard, a cost table, a worked example for a three-property group, a 90-day sequence, and a mapping to Cyber Essentials, PCI DSS and UK data protection law. Nothing in it requires a security team. It requires somebody to own it.

Why a hotel cyber security checklist is not a generic one

hotel cyber security checklist 20 controls uk b room service tray

A cyber security checklist written for a professional services firm assumes one office, one network and one working day. Hotels break all three assumptions at once, and the breakage is structural rather than accidental. Every gap below is a design feature of the business model, which is exactly why a hotel cyber security programme has to start from the estate rather than from a framework.

The guest network is a deliberate hole in the perimeter

Every other business spends money keeping unknown devices off its network. A hotel advertises the opposite. Several hundred unmanaged devices join each night, and the venue that offers the worst connectivity loses the booking. That inversion means hotel cyber security cannot rely on the network boundary as its main control, and has to push the work into identity, segmentation and monitoring instead.

Staffing patterns defeat annual processes

Hospitality turnover in the UK ran at 67% in the 2025 Pineapple and Sona benchmark, down from 75% the year before but still far above almost any other sector. An annual access review is close to meaningless when two thirds of the people it covers have changed. Seasonal and agency cover makes it worse, because the fastest way to get a new starter working on a busy Friday is to hand over an existing login.

The estate contains equipment nobody calls IT

Front-desk PCs and laptops get patched. The self check-in kiosk, the EPOS terminals in the bar, the key-card encoder behind reception, the building management controller, the lift panel and the in-room TVs frequently do not. They were installed by a supplier, they run software the hotel cannot see, and nobody owns their updates. That is where a hotel cyber security review usually finds its worst scores.

Third parties hold the data, not the hotel

The reservation record, the loyalty profile, the payroll file and the back-office reporting stack usually sit in somebody else’s cloud. BWH Hotels disclosed that attackers had access to a reservation web application from 14 October 2025 until 22 April 2026, roughly six months, exposing names, emails, phone numbers and reservation details across a group of more than 4,000 hotels. Otelier, a hotel back-office platform, was breached in January 2025 with around 437,000 email addresses taken and data belonging to Marriott, Hilton and Hyatt properties caught in it.

Generic assumptionWhat a hotel actually hasControls most affected
One trusted networkGuest, staff, payments, IoT and building systems, often on one flat VLAN9, 10, 11, 12
Staff sit at desksReception, housekeeping, kitchen, night audit, all shift-based2, 3, 4, 18
IT owns every deviceEPOS, kiosks, encoders and TVs owned by suppliers5, 6, 7, 17
Data lives on our systemsPMS, channel manager, CRM and payroll all SaaS1, 13, 14, 16
Nine to five incident responseA duty manager at 03:00 with no escalation path19, 20

The exposure is measurable, and it is external

Trustwave’s April 2025 hospitality scan found 95,040 vulnerabilities across the sector, 3,884 unique CVEs, 14,318 of them critical and 1,521 already listed by CISA as known exploited. More usefully for this hotel cyber security checklist: 61.5% of observed initial access attempts targeted publicly exposed services. That is the single strongest argument for control 11, and it explains why external exposure sits so early in the 90-day plan below.

Exposed services found across hospitality estates (Trustwave, April 2025 scan)
SNMP 9,627
HTTPS on 443 and 8443 6,438
NTP 5,525
HTTP 4,372
Bars scaled against the largest count. A management protocol nobody meant to publish is the most common finding.

How to use this hotel cyber security checklist

hotel cyber security checklist 20 controls uk c wardrobe two doors

Scoring a hotel cyber security control out of ten produces a number nobody can defend. This hotel cyber security checklist uses three ratings and one rule: a rating is only valid if you can produce the evidence in about ten minutes without asking a supplier. That rule is what separates a real control from an intention, and it is the same standard an assessor applies.

The three ratings

Red means the control does not exist, or exists only as a policy sentence. Amber means it exists at one property, or for one system, or for the people who happen to remember it. Green means it applies across every property and every system in scope, and somebody can show you the evidence today. Twenty hotel cyber security controls, three ratings, no averages.

Why the evidence test matters more than the rating

Most groups already believe their hotel cyber security covers half of this. The evidence test is what surfaces the difference between belief and reality. Asking “do we have MFA?” gets a yes. Asking “show me the sign-in report for the channel manager for last month” gets a much more interesting answer, and it takes about the same amount of time.

RatingWhat it meansWhat you must be able to show
RedAbsent, or written down but never appliedNothing
AmberPartial: one property, one system, or one keen managerEvidence for part of the estate only
GreenApplied everywhere in scope and verifiableA report, export or screenshot dated this month

Set the scope before you score anything

Write down every property, every trading entity and every system that touches guest or payment data, including the ones the head office bought without telling the general managers. Hotel cyber security scoping goes wrong in the same place every time: somebody excludes the guest network and assumes that removes the equipment sitting on it. It does not, unless that equipment is genuinely segregated and cannot reach the corporate estate.

Hotel cyber security controls 1-4: identity and access

hotel cyber security checklist 20 controls uk d till drawer slot knob

Identity is where hotel cyber security is usually won or lost. Verizon’s 2026 Data Breach Investigations Report puts the human element in 62% of breaches, and software-flaw exploitation has now overtaken stolen credentials as the top initial entry point at 31%. In hospitality, the two arrive together: a phished or reused credential on a supplier portal that a hotel never monitors.

Control 1: MFA on every cloud service, without exceptions

The list is longer than people expect. The PMS, the channel manager, the booking engine, the CRM and loyalty platform, the EPOS back office, the payroll system, the email tenant, the accounting package, the door-lock management console and every supplier portal a manager logs into. Phishing-resistant methods are better, and FIDO2 authenticators count. Evidence test: an MFA registration report showing every named user on the two systems that hold the most guest data.

Control 2: named accounts at the front desk

The shared “reception” login is the single most common finding in hotel cyber security reviews, and it destroys every downstream control. You cannot investigate an incident, prove who cancelled a booking, or remove a leaver’s access when eleven people share one password taped inside a drawer. Named accounts also make control 4 cheap. Evidence test: the account list for the PMS, with a person’s name against every entry.

Control 3: a verified reset process for the 24/7 help desk

After the 2025 attacks on UK retailers, the NCSC told organisations to “review helpdesk password reset processes, including how the helpdesk authenticates staff members credentials before resetting passwords, especially those with escalated privileges.” Hotels are unusually exposed here, because somebody is always on shift and a plausible caller at 02:00 gets helped. Write down what a caller must prove before a reset. Evidence test: the written verification steps, plus one recent reset logged against them.

Control 4: joiners, movers and leavers that keep up with the rota

With sector turnover around 67%, a quarterly review is not a control. Access removal has to be attached to the payroll or rota process so a leaver loses the PMS, the EPOS, the email account and the door-lock profile on their last shift, not at the next audit. Agency and seasonal staff need the same treatment on a shorter clock. Evidence test: three leavers from the last month, and the timestamp their accounts were disabled.

Hotel cyber security controls 5-8: devices and the on-property estate

hotel cyber security checklist 20 controls uk e reception desk bell

The estate is where hotel cyber security stops resembling office IT. Cyber Essentials v3.3 is blunt about the boundary: a device the organisation owns is in scope even when a customer uses it, which puts the lobby iPad, the business-centre PC and the self check-in kiosk firmly inside. Guest-owned devices are out. So are wireless devices where an attacker must be within signal range, but very little in a modern hotel qualifies.

Control 5: an inventory that includes the equipment nobody calls IT

If it has an IP address and it is on your property, it belongs on the list: EPOS terminals, kiosks, key-card encoders, in-room TVs, building management controllers, CCTV, lift panels, digital signage and the tablet the restaurant uses for orders. Record who supplies it, who patches it, and how it is reached for support. Evidence test: the inventory, with a supplier and a patching owner in every row.

Control 6: updates applied within 14 days on anything internet-facing

The Cyber Essentials Plus test specification fails a device carrying a vendor critical or high patch, or one scoring CVSS v3 of 7 or above, where a fix has been available for more than 14 days. It also states plainly that “virtual patching is not an acceptable mitigation.” Apply the same rule internally whether or not you certify. Evidence test: the patch status report for front-desk and back-office devices, plus the last update date for the booking engine.

Control 7: a plan for the equipment you cannot patch quickly

Some hotel equipment cannot be fixed on a 14-day cycle, and pretending otherwise produces a false green. The Unsaflok research disclosed flaws affecting more than three million dormakaba Saflok locks across 13,000 properties in 131 countries, and about 36% had been updated at the point of disclosure. The reason is operational rather than negligent: locks need a software update or replacement, every key card has to be reissued, front-desk software and encoders need upgrading, and lift, parking and payment integrations may follow.

Where the fix is genuinely slow, the control is compensating: put the device on a segregated network that cannot reach the internet or the corporate estate, restrict who can physically reach it, and set a dated remediation plan. Evidence test: a named list of equipment that cannot meet 14 days, each with its compensating control and target date.

Control 8: malware protection and application control where it counts

Front-desk and back-office PCs handle email, browse the web and touch guest records, which makes them the highest-value endpoints in the building. They need malware protection that is actually enabled and reporting centrally, plus a restriction on what staff can install. Kitchen and bar tablets should be locked to their app. Evidence test: the endpoint console, filtered to show any device that has not reported in the past seven days.

Hotel cyber security controls 9-12: network and guest connectivity

hotel cyber security checklist 20 controls uk f milestone marker stone

This is the most hotel-specific domain in the hotel cyber security checklist, and the one with the most recent evidence behind it. Guest connectivity is a service the hotel sells, so the controls have to protect the business without making the WiFi worse. Our hotel WiFi security guide covers the design in depth; the four controls below are the checklist version.

Control 9: separate the guest network from everything that runs the hotel

Guest, staff, payments, IoT and building systems each need their own segment, with traffic between them denied by default and allowed only where a documented flow requires it. This is the highest-value control in the whole hotel cyber security checklist because it caps the damage from everything else. The VLAN segmentation design sets out the switch-level detail, including the two VLAN-hopping mechanisms worth testing for. Evidence test: a network diagram plus one failed ping from the guest network to the EPOS network.

Control 10: harden the captive portal and the gateway behind it

Microsoft published its CaptiveCrunch analysis on 31 July 2026, describing a campaign that compromised captive-portal gateway appliances and used them to manipulate DNS for every device on the network. Because the appliance is the DHCP-assigned resolver, the attacker owns name resolution without touching a single endpoint. ReliaQuest traced compromised gateways in several countries, mostly hotels, and both vendors point at internet-facing admin consoles and weak or reused credentials as the likely way in.

The controls are unglamorous: change default credentials, take the admin interface off the public internet, patch the appliance, and never let the portal offer software updates. Our captive portal attack analysis has the full chain and the indicators. Evidence test: the appliance’s firmware version and the source addresses permitted to reach its management page.

Control 11: nothing management-related faces the public internet

Given that 61.5% of hospitality initial access attempts targeted publicly exposed services, this control earns its place near the top of the plan. Scan your own external addresses, list every port that answers, and justify each one. Remote support access belongs behind a VPN or a broker with MFA, never on an open port with a shared password. Evidence test: an external scan output for every property, dated this quarter.

Control 12: control physical access to network ports and equipment

A network port in a lobby, meeting room or corridor is an unauthenticated seat on your network. Disable unused ports, put the ones that must stay live on the guest segment, and lock the comms cabinet. The key-card encoder deserves particular attention: it is the device that turns a small compromise into a room-entry problem. Evidence test: the switch port configuration for one public area, and a photograph of the comms cabinet lock.

Hotel cyber security controls 13-16: data, payments and the booking chain

Payment and guest data is where a hotel cyber security incident turns into a regulatory event. PCI DSS v4.0.1 has been in force since June 2024, and the 51 future-dated requirements became mandatory on 31 March 2025, so there is no grace period left to plan against. Meanwhile UK data protection law moved: the Data (Use and Access) Act 2025 brought its main data-protection provisions into force on 5 February 2026.

Control 13: know where card data actually flows

Draw the flow: booking engine, channel manager, OTA, phone reservations, deposits, group bookings, no-show charges, function invoices and the terminal at the bar. Then find the informal paths, because they are the ones that fail an assessment. Card numbers written on a diary page, emailed booking forms and voicemail messages with a long card number in them are all common and all avoidable. Evidence test: the flow diagram, plus a search of the shared reservations mailbox for card details.

Control 14: delete guest data you no longer need

Retention is the cheapest hotel cyber security risk reduction available, because data you have deleted cannot be stolen. Set a retention period for reservation records, CCTV, ID scans, allergy and accessibility notes, loyalty history and unsuccessful applications, then automate the deletion. Under the DUAA framework the calculation of the one-month response window for subject access changed, so the process needs to be quick as well as documented. Evidence test: the retention schedule and one system showing records actually removed.

Control 15: backups you have restored, held where ransomware cannot reach

Most hotel systems are SaaS, which tempts people to skip this entirely. It should not: the PMS export, the EPOS configuration, the door-lock database, the finance records and the email tenant all need a copy the supplier’s account compromise cannot touch. A backup nobody has restored is a hypothesis. Evidence test: the date of the last successful test restore, and what was restored.

Control 16: encryption and least privilege on the guest database

Encrypt devices and removable media, and make sure the guest database is not readable in bulk by every user who can log in. A receptionist needs today’s arrivals, not an export of five years of guest history with dietary notes and card tokens. Loyalty data is particularly attractive because points behave like currency. Evidence test: the permissions matrix for the PMS, and confirmation that bulk export is restricted to named users.

Hotel cyber security controls 17-20: people, suppliers and response

The final hotel cyber security domain is the one that decides how bad a bad day gets. The 2025/2026 Cyber Security Breaches Survey found 43% of UK businesses had experienced a breach or attack, with medium businesses at 65% and large at 69%, yet only 25% had a formal incident response plan and only 31% had a board member responsible for cyber security. Hotels sit inside those numbers, not outside them.

Control 17: supplier assurance proportionate to the data they hold

Your PMS provider, channel manager, EPOS vendor, door-lock supplier and back-office platform each hold or reach data you are accountable for. Ask for certification, breach-notification commitments, sub-processor lists and the contractual right to be told quickly. The NCSC’s Cyber Essentials Supply Chain Playbook, published on 12 December 2025, is written specifically to help buyers require this without building a procurement bureaucracy. Evidence test: the supplier register, with a certificate or assurance date against the top five.

Control 18: training that matches what the role actually faces

Generic annual training does not change hotel cyber security behaviour at 23:00. Reception needs to recognise pretext calls asking to change bank details or unlock a room. Finance needs the invoice-fraud version. General managers need the “urgent, confidential, from the owner” version. Phishing was the most common breach type at 38% and the most disruptive for 69% of affected organisations, so this is not a soft control. Evidence test: completion records by role, not one figure for the whole group.

Control 19: logging and monitoring somebody actually reads

Turn on sign-in logging for the PMS and the email tenant, keep it for a defined period, and give somebody the job of looking at exceptions: impossible-travel sign-ins, out-of-hours administrative changes, bulk exports, new mailbox rules. The NCSC’s post-incident advice to retailers included watching for risky sign-ins and logins from atypical sources such as residential-range VPN services. Evidence test: last month’s exception review, with a name against it.

Control 20: an incident plan the duty manager can run at 03:00

The hotel cyber security incident plan needs to be one page, laminated, and behind reception. Who to call, in what order, what to disconnect and what not to power off, how to keep the hotel trading on paper, and who talks to guests. Personal data breaches must reach the ICO within 72 hours where reportable, so the clock starts long before the office opens. Rehearse it once a year with the people who will actually be on shift. Evidence test: the one-page plan, and the date of the last rehearsal.

The hotel cyber security scorecard: all 20 controls in one table

Print this hotel cyber security scorecard, walk the estate, and rate each row red, amber or green using the evidence test rather than the conversation. A first pass across a small group usually takes half a day per property and produces more reds than anyone expects, which is normal and useful.

#ControlEvidence testDomain
1MFA on every cloud serviceRegistration report for your two biggest data systemsIdentity
2Named accounts at the front deskPMS user list with a person per entryIdentity
3Verified help desk reset processWritten steps plus one logged resetIdentity
4Leavers removed on the last shiftThree leavers and their disable timestampsIdentity
5Full estate inventorySupplier and patch owner in every rowDevices
6Updates within 14 daysPatch report plus booking engine update dateDevices
7Plan for equipment you cannot patchNamed list, compensating control, target dateDevices
8Malware protection and app controlDevices not reporting in seven daysDevices
9Guest network separated from operationsDiagram plus one failed cross-segment pingNetwork
10Captive portal and gateway hardenedFirmware version and admin source listNetwork
11No management interfaces exposedExternal scan output per propertyNetwork
12Physical access to ports and cabinetsPort config for one public areaNetwork
13Card data flow mappedFlow diagram plus mailbox searchData
14Retention and deletion enforcedSchedule plus evidence of removalData
15Tested, isolated backupsDate and content of last test restoreData
16Encryption and least privilegePermissions matrix and export restrictionData
17Supplier assuranceRegister with assurance dates for top fivePeople
18Role-based trainingCompletion records split by rolePeople
19Logging and exception reviewLast month’s review with an ownerPeople
20Rehearsed incident planOne-page plan and last rehearsal datePeople

How to read your result

Count the greens rather than averaging. Fewer than eight means the estate is effectively unprotected against an ordinary criminal campaign, and controls 1, 9 and 11 should start on Monday. Eight to fourteen is the normal position for an independent hotel that has been sensible without being systematic. Fifteen or more means hotel cyber security is being managed, and the remaining gaps are usually supplier assurance and rehearsal.

What hotel cyber security actually costs

Most of this hotel cyber security checklist is configuration rather than purchase. The costs that do appear are concentrated in three places: a device or two that has to be replaced, the time to build the inventory and the network segments, and certification if you want it. Cyber Essentials certification is priced by size, at £320 plus VAT for micro organisations, £440 for small, £500 for medium and £600 for large, and it includes £25,000 of cyber liability cover for UK businesses under £20m turnover. Cyber Essentials Plus starts from around £1,400 plus VAT for a micro organisation.

Control groupMain costTypical effort for a small group
Identity (1-4)Usually licensed already2-4 days of configuration and account cleanup
Devices (5-8)Replacement of unsupported equipment1 day per property for the inventory walk
Network (9-12)Switch or firewall refresh if the kit is old2-5 days per property depending on cabling
Data (13-16)Backup storage; occasionally a PMS module3-5 days across the group
People (17-20)Training platform, optional2 days plus a half-day rehearsal
Certification£320-£600 + VAT, or from ~£1,400 for Plus2-6 weeks elapsed, mostly waiting on evidence

Where the money is usually wasted

Two hotel cyber security spending patterns recur. The first is buying a monitoring product before anyone has been made responsible for reading it, which converts an unowned risk into an unowned subscription. The second is cybersecurity insurance bought as a substitute for the controls rather than a backstop behind them; insurers increasingly ask about MFA, backups and patching at renewal, and the answers have to match reality.

A worked example: hotel cyber security across a three-property group

Numbers make the hotel cyber security checklist concrete. Take a UK group with three properties: 110, 78 and 52 bedrooms, so 240 bedrooms in total, with 165 staff across the group and a small head office. Nothing below is a survey figure; it is arithmetic on the estate you would find.

Counting the accounts

165 staff accounts, plus 22 shared or generic logins that grew up around reception and the bar, plus 9 administrative accounts across the PMS, EPOS, email and network kit. That is 196 accounts, of which 31 are either shared or privileged. Control 2 alone removes the 22, and control 1 covers the remaining 174.

Counting the endpoints

Per property: 4 front-desk PCs, 5 back-office PCs, 6 EPOS terminals, 2 kiosks, 1 key-card encoder and 3 duty-manager mobiles, which is 21 devices. Across three properties that is 63, plus 12 head-office laptops for a total of 75 endpoints. The 18 EPOS terminals, 6 kiosks and 3 encoders are 27 of those 75, just over a third, and they carry almost all of the remediation work under controls 6 and 7.

Where the 75 endpoints sit in a three-property group
EPOS terminals 18
Back-office PCs 15
Front-desk PCs 12
Head-office laptops 12
Duty-manager mobiles 9
Self check-in kiosks 6
Key-card encoders 3
Shares of 75 endpoints. The bottom three rows are 27 devices, a third of the estate, and the hardest third to patch.

Counting the suppliers

One PMS, one channel manager, one booking engine, one CRM and loyalty platform, three EPOS estates under one vendor, one payroll system, one email tenant, one door-lock platform and one building management contract gives nine core platforms. Add roughly fourteen smaller SaaS tools that individual managers bought and the group has about 23 supplier relationships touching operational or guest data. Control 17 applies fully to the nine and proportionately to the rest.

The 90-day hotel cyber security plan

Sequence matters more than speed in hotel cyber security. The first month buys the largest reduction for the least money, the second month fixes the estate, and the third month makes the whole thing repeatable. This is the order a hotel cyber security programme should run in, and it is deliberately achievable alongside a normal trading month.

Days 1-30: stop the bleeding

Turn on MFA everywhere (control 1), remove shared logins at reception (control 2), write the help desk verification steps (control 3), scan your external addresses and close what should never have been open (control 11), and change default credentials on the captive portal gateway (control 10). Seven controls of the twenty are realistically green by day 30, and they are the seven an opportunistic attacker relies on.

Days 31-60: fix the estate

Walk every property and build the inventory (control 5), get patching onto a 14-day cycle (control 6), write the compensating-control list for equipment you cannot patch (control 7), confirm endpoint protection is reporting (control 8), and design and implement segmentation (control 9) with physical port control alongside it (control 12). That takes the running total to about 14 of 20.

Days 61-90: make it durable

Map the card data flow (control 13), set retention (control 14), test a restore (control 15), tighten permissions (control 16), collect supplier assurance (control 17), run role-based training (control 18), start the monthly exception review (control 19) and rehearse the one-page incident plan (control 20). At that point all twenty are in place and the job becomes maintenance.

Controls completed by the end of each stage (of 20)
Day 30 7
Day 60 14
Day 90 20
Cumulative controls green, as a share of the twenty in this hotel cyber security checklist.

Hotel cyber security mistakes that still pass an audit

Some hotel cyber security failures survive because they look like compliance. These are the ones worth hunting deliberately, because a clean paper trail hides all of them.

Treating the guest network as an exclusion that covers everything on it

IASME guidance does allow a segregated guest network to be excluded from a Cyber Essentials scope, and it names a hotel as the example. That does not extend to the hotel’s own equipment that happens to be reachable from it, and an assessor is expected to verify the segregation by technical means rather than take it on trust.

Confusing an eavesdropping control with an access control

Enhanced Open, or OWE, gives every client on a password-free SSID its own encryption, which is a genuine improvement. It provides no network access control and does not authenticate the client, so it protects the guest from the person in the next room rather than protecting the hotel from either of them.

Believing the supplier’s certificate covers your obligations

Under the cloud shared-responsibility split, a SaaS provider may run the firewalls, updates and malware protection, but user access control is always the customer’s responsibility across every service model. The PMS vendor’s certification does not create your MFA, your leaver process or your permissions matrix.

Scoring the flagship property and assuming the rest

Sample sizes in real assessments follow variation, not headcount. If the third property was refurbished by a different contractor with different equipment, it is a different estate and it needs its own walk. Hotel cyber security scores taken at the biggest site are consistently the most flattering ones available.

Writing an incident plan for people who will not be there

If the plan assumes the IT manager answers the phone, it fails at 03:00 on a bank holiday. The test is whether a duty manager who has never seen it can take the first three actions correctly.

How this hotel cyber security checklist maps to Cyber Essentials, PCI DSS and UK law

None of these frameworks is a substitute for the others, but the overlap is large enough that doing this hotel cyber security checklist properly puts you most of the way through all three. If certification is the goal, our Cyber Essentials guide for hotels covers scoping, evidence and the v3.3 changes in detail.

ControlsCyber EssentialsPCI DSSUK data protection
1-4 IdentityUser access control; MFA on all cloud servicesMFA and unique IDs for access to cardholder dataSecurity of processing
5-8 DevicesSecurity update management; malware protection; secure configurationPatching and anti-malware in scope systemsAppropriate technical measures
9-12 NetworkFirewalls and internet gateways; sub-set segregationSegmentation for scope reduction; quarterly rogue AP checksData minimisation by design
13-16 DataNot directly assessed; backups are out of scopeStorage, retention and protection of account dataStorage limitation; integrity and confidentiality
17-20 PeopleSupports the annual declarationService provider management; testing programmesProcessor contracts; 72-hour breach reporting

The public-sector angle worth knowing

Procurement Policy Note 014 explicitly names travel booking as a service where a supplier handling government employees’, ministers’ or special advisers’ personal information must meet Cyber Essentials requirements, with evidence required before contract award and renewed annually. If your group takes public sector or travel management company business, that is the clearest commercial reason to certify rather than merely comply.

Where regulation is heading

The Cyber Security and Resilience Bill entered the Lords on 25 June 2026 and pulls managed service providers and data-centre operators into statutory regulation for the first time, with a reporting clock starting at 24 hours. Hotels are not in scope directly, but their IT suppliers increasingly will be, which will change what those suppliers can be asked for in a contract.

Who owns hotel cyber security in a small hotel group

The single best predictor of a good hotel cyber security score is not budget. It is whether one named person owns the hotel cyber security checklist and has the authority to say no to a supplier. Only 31% of UK businesses have a board member responsible for cyber security, and hotel groups are worse than average because operations naturally dominates the agenda.

RoleOwnsShould not own
Owner or board memberThe decision to fund it; the annual reviewDay-to-day configuration
Operations or group managerScorecard, evidence, supplier registerFirewall and switch changes
General managerProperty walk, leavers, training completionDeciding what is in scope
IT partner or MSPPatching, segmentation, monitoring, restoresAccepting risk on the hotel’s behalf
Duty managerFirst three incident actionsInvestigation or supplier negotiation

If you outsource, outsource the work and keep the accountability

An IT partner can hold every technical hotel cyber security control on this list. What no supplier can take is the accountability for guest data, the decision on scope, or the acceptance of a risk. Our IT support for hotels and hospitality page sets out how that split usually works in practice, and managed IT services covers the wider operating model.

Hotel cyber security checklist FAQ

How long does a first pass through the 20 controls take?

Half a day per property for the walk and the evidence gathering, plus a day at group level for suppliers and policy. A three-property group can complete an honest first hotel cyber security score in a week without stopping trading.

Do we need Cyber Essentials to use this hotel cyber security checklist?

No. The hotel cyber security checklist stands alone and is deliberately broader than certification, since it covers retention, backups, monitoring and rehearsal that Cyber Essentials does not assess. Certification is worth having when a corporate client, travel management company or public sector buyer asks for it.

Our PMS is cloud-based. Does that reduce our scope?

It changes what you control, not whether you are accountable. Cloud services cannot be excluded from a Cyber Essentials scope, and user access control remains the customer’s responsibility in every cloud model, so controls 1, 2, 4 and 16 apply exactly as they would on-premise.

What about franchised properties?

Score them separately. A franchise agreement usually fixes some systems centrally and leaves the local network, devices and staff processes to the operator, so the estate genuinely differs. Record which controls are brand-mandated and which are yours.

Which control should we do first if we can only do one?

MFA on every cloud service. It is the cheapest, fastest hotel cyber security control on the list, it defeats the credential attacks that dominate hospitality incidents, and it takes days rather than months.

How often should we re-score?

Twice a year for the full hotel cyber security checklist, plus a lightweight identity and patching check each quarter. High staff turnover means the identity domain degrades faster than anything else on the list.

References and Further Reading

NCSC: Incidents impacting retailers – recommendations from the NCSC

NCSC: Cyber Essentials overview

NCSC: 10 Steps to Cyber Security

NCSC: Small Organisations Guide to Cyber Security

NCSC: Device Security Guidance

NCSC: Multi-factor authentication for your corporate online services

NCSC: Password administration for system owners

NCSC: Phishing attacks – defending your organisation

NCSC: Mitigating malware and ransomware attacks

NCSC: Offline backups in an online world

NCSC: Incident management

NCSC: Exercise in a Box

NCSC: Supply chain security guidance

NCSC: Cyber Essentials Supply Chain Playbook

NCSC: Cyber Security Board Toolkit

NCSC: Risk management guidance

DSIT: Cyber Security Breaches Survey 2025/2026

Cyber Security and Resilience Bill collection

Data (Use and Access) Act 2025

ICO: Report a personal data breach

ICO: A guide to data security

PCI Security Standards Council: PCI DSS

PCI SSC: Adopting the future-dated requirements of PCI DSS v4.x

IASME: Defining the scope of your Cyber Essentials assessment

Verizon Data Breach Investigations Report

Trustwave: 2025 Hospitality Risk Radar Report

Unsaflok: Saflok lock vulnerability research

SecurityWeek: Saflok lock vulnerability can be exploited to open millions of doors

SecurityWeek: BWH Hotels says hackers had access to reservation data for six months

Infosecurity Magazine: Data of half a million hotel guests exposed

Infosecurity Magazine: CaptiveCrunch campaign targets hotel networks

Help Net Security: Midnight Blizzard targets hotel networks

Wi-Fi Alliance: Security

CIS Critical Security Controls

NIST SP 800-61r3: Incident Response Recommendations and Considerations

UKHospitality: Cyber security isn’t just an IT problem any more