Hotel cyber security fails in the joins. Not usually inside the property management system, not inside the payment terminal, but in the gaps between the reservation platform, the door-lock encoder, the guest network and the agency staff member who started on Friday night. A hotel runs more third-party systems per employee than almost any other small business, runs them twenty-four hours a day, and hands part of its network to strangers by design.
That combination is why generic advice lands badly here. A control set written for an office assumes one building, one network, one working day and one set of employees who were all onboarded properly. If you manage residential blocks rather than bedrooms, the sibling cyber security checklist for property management companies covers the same discipline for a different estate. This hotel cyber security guide is the hospitality version, and it is deliberately vendor-neutral.
What follows is a hotel cyber security checklist of 20 controls, grouped into five domains, each with a plain evidence test you can run in about ten minutes. There is a scorecard, a cost table, a worked example for a three-property group, a 90-day sequence, and a mapping to Cyber Essentials, PCI DSS and UK data protection law. Nothing in it requires a security team. It requires somebody to own it.
Table of contents
- Why a hotel cyber security checklist is not a generic one
- How to use this hotel cyber security checklist
- Hotel cyber security controls 1-4: identity and access
- Hotel cyber security controls 5-8: devices and the on-property estate
- Hotel cyber security controls 9-12: network and guest connectivity
- Hotel cyber security controls 13-16: data, payments and the booking chain
- Hotel cyber security controls 17-20: people, suppliers and response
- The hotel cyber security scorecard: all 20 controls in one table
- What hotel cyber security actually costs
- A worked example: hotel cyber security across a three-property group
- The 90-day hotel cyber security plan
- Hotel cyber security mistakes that still pass an audit
- How this hotel cyber security checklist maps to Cyber Essentials, PCI DSS and UK law
- Who owns hotel cyber security in a small hotel group
- Hotel cyber security checklist FAQ
- References and Further Reading
Why a hotel cyber security checklist is not a generic one
A cyber security checklist written for a professional services firm assumes one office, one network and one working day. Hotels break all three assumptions at once, and the breakage is structural rather than accidental. Every gap below is a design feature of the business model, which is exactly why a hotel cyber security programme has to start from the estate rather than from a framework.
The guest network is a deliberate hole in the perimeter
Every other business spends money keeping unknown devices off its network. A hotel advertises the opposite. Several hundred unmanaged devices join each night, and the venue that offers the worst connectivity loses the booking. That inversion means hotel cyber security cannot rely on the network boundary as its main control, and has to push the work into identity, segmentation and monitoring instead.
Staffing patterns defeat annual processes
Hospitality turnover in the UK ran at 67% in the 2025 Pineapple and Sona benchmark, down from 75% the year before but still far above almost any other sector. An annual access review is close to meaningless when two thirds of the people it covers have changed. Seasonal and agency cover makes it worse, because the fastest way to get a new starter working on a busy Friday is to hand over an existing login.
The estate contains equipment nobody calls IT
Front-desk PCs and laptops get patched. The self check-in kiosk, the EPOS terminals in the bar, the key-card encoder behind reception, the building management controller, the lift panel and the in-room TVs frequently do not. They were installed by a supplier, they run software the hotel cannot see, and nobody owns their updates. That is where a hotel cyber security review usually finds its worst scores.
Third parties hold the data, not the hotel
The reservation record, the loyalty profile, the payroll file and the back-office reporting stack usually sit in somebody else’s cloud. BWH Hotels disclosed that attackers had access to a reservation web application from 14 October 2025 until 22 April 2026, roughly six months, exposing names, emails, phone numbers and reservation details across a group of more than 4,000 hotels. Otelier, a hotel back-office platform, was breached in January 2025 with around 437,000 email addresses taken and data belonging to Marriott, Hilton and Hyatt properties caught in it.
| Generic assumption | What a hotel actually has | Controls most affected |
|---|---|---|
| One trusted network | Guest, staff, payments, IoT and building systems, often on one flat VLAN | 9, 10, 11, 12 |
| Staff sit at desks | Reception, housekeeping, kitchen, night audit, all shift-based | 2, 3, 4, 18 |
| IT owns every device | EPOS, kiosks, encoders and TVs owned by suppliers | 5, 6, 7, 17 |
| Data lives on our systems | PMS, channel manager, CRM and payroll all SaaS | 1, 13, 14, 16 |
| Nine to five incident response | A duty manager at 03:00 with no escalation path | 19, 20 |
The exposure is measurable, and it is external
Trustwave’s April 2025 hospitality scan found 95,040 vulnerabilities across the sector, 3,884 unique CVEs, 14,318 of them critical and 1,521 already listed by CISA as known exploited. More usefully for this hotel cyber security checklist: 61.5% of observed initial access attempts targeted publicly exposed services. That is the single strongest argument for control 11, and it explains why external exposure sits so early in the 90-day plan below.
How to use this hotel cyber security checklist
Scoring a hotel cyber security control out of ten produces a number nobody can defend. This hotel cyber security checklist uses three ratings and one rule: a rating is only valid if you can produce the evidence in about ten minutes without asking a supplier. That rule is what separates a real control from an intention, and it is the same standard an assessor applies.
The three ratings
Red means the control does not exist, or exists only as a policy sentence. Amber means it exists at one property, or for one system, or for the people who happen to remember it. Green means it applies across every property and every system in scope, and somebody can show you the evidence today. Twenty hotel cyber security controls, three ratings, no averages.
Why the evidence test matters more than the rating
Most groups already believe their hotel cyber security covers half of this. The evidence test is what surfaces the difference between belief and reality. Asking “do we have MFA?” gets a yes. Asking “show me the sign-in report for the channel manager for last month” gets a much more interesting answer, and it takes about the same amount of time.
| Rating | What it means | What you must be able to show |
|---|---|---|
| Red | Absent, or written down but never applied | Nothing |
| Amber | Partial: one property, one system, or one keen manager | Evidence for part of the estate only |
| Green | Applied everywhere in scope and verifiable | A report, export or screenshot dated this month |
Set the scope before you score anything
Write down every property, every trading entity and every system that touches guest or payment data, including the ones the head office bought without telling the general managers. Hotel cyber security scoping goes wrong in the same place every time: somebody excludes the guest network and assumes that removes the equipment sitting on it. It does not, unless that equipment is genuinely segregated and cannot reach the corporate estate.
Hotel cyber security controls 1-4: identity and access
Identity is where hotel cyber security is usually won or lost. Verizon’s 2026 Data Breach Investigations Report puts the human element in 62% of breaches, and software-flaw exploitation has now overtaken stolen credentials as the top initial entry point at 31%. In hospitality, the two arrive together: a phished or reused credential on a supplier portal that a hotel never monitors.
Control 1: MFA on every cloud service, without exceptions
The list is longer than people expect. The PMS, the channel manager, the booking engine, the CRM and loyalty platform, the EPOS back office, the payroll system, the email tenant, the accounting package, the door-lock management console and every supplier portal a manager logs into. Phishing-resistant methods are better, and FIDO2 authenticators count. Evidence test: an MFA registration report showing every named user on the two systems that hold the most guest data.
Control 2: named accounts at the front desk
The shared “reception” login is the single most common finding in hotel cyber security reviews, and it destroys every downstream control. You cannot investigate an incident, prove who cancelled a booking, or remove a leaver’s access when eleven people share one password taped inside a drawer. Named accounts also make control 4 cheap. Evidence test: the account list for the PMS, with a person’s name against every entry.
Control 3: a verified reset process for the 24/7 help desk
After the 2025 attacks on UK retailers, the NCSC told organisations to “review helpdesk password reset processes, including how the helpdesk authenticates staff members credentials before resetting passwords, especially those with escalated privileges.” Hotels are unusually exposed here, because somebody is always on shift and a plausible caller at 02:00 gets helped. Write down what a caller must prove before a reset. Evidence test: the written verification steps, plus one recent reset logged against them.
Control 4: joiners, movers and leavers that keep up with the rota
With sector turnover around 67%, a quarterly review is not a control. Access removal has to be attached to the payroll or rota process so a leaver loses the PMS, the EPOS, the email account and the door-lock profile on their last shift, not at the next audit. Agency and seasonal staff need the same treatment on a shorter clock. Evidence test: three leavers from the last month, and the timestamp their accounts were disabled.
Hotel cyber security controls 5-8: devices and the on-property estate
The estate is where hotel cyber security stops resembling office IT. Cyber Essentials v3.3 is blunt about the boundary: a device the organisation owns is in scope even when a customer uses it, which puts the lobby iPad, the business-centre PC and the self check-in kiosk firmly inside. Guest-owned devices are out. So are wireless devices where an attacker must be within signal range, but very little in a modern hotel qualifies.
Control 5: an inventory that includes the equipment nobody calls IT
If it has an IP address and it is on your property, it belongs on the list: EPOS terminals, kiosks, key-card encoders, in-room TVs, building management controllers, CCTV, lift panels, digital signage and the tablet the restaurant uses for orders. Record who supplies it, who patches it, and how it is reached for support. Evidence test: the inventory, with a supplier and a patching owner in every row.
Control 6: updates applied within 14 days on anything internet-facing
The Cyber Essentials Plus test specification fails a device carrying a vendor critical or high patch, or one scoring CVSS v3 of 7 or above, where a fix has been available for more than 14 days. It also states plainly that “virtual patching is not an acceptable mitigation.” Apply the same rule internally whether or not you certify. Evidence test: the patch status report for front-desk and back-office devices, plus the last update date for the booking engine.
Control 7: a plan for the equipment you cannot patch quickly
Some hotel equipment cannot be fixed on a 14-day cycle, and pretending otherwise produces a false green. The Unsaflok research disclosed flaws affecting more than three million dormakaba Saflok locks across 13,000 properties in 131 countries, and about 36% had been updated at the point of disclosure. The reason is operational rather than negligent: locks need a software update or replacement, every key card has to be reissued, front-desk software and encoders need upgrading, and lift, parking and payment integrations may follow.
Where the fix is genuinely slow, the control is compensating: put the device on a segregated network that cannot reach the internet or the corporate estate, restrict who can physically reach it, and set a dated remediation plan. Evidence test: a named list of equipment that cannot meet 14 days, each with its compensating control and target date.
Control 8: malware protection and application control where it counts
Front-desk and back-office PCs handle email, browse the web and touch guest records, which makes them the highest-value endpoints in the building. They need malware protection that is actually enabled and reporting centrally, plus a restriction on what staff can install. Kitchen and bar tablets should be locked to their app. Evidence test: the endpoint console, filtered to show any device that has not reported in the past seven days.
Hotel cyber security controls 9-12: network and guest connectivity
This is the most hotel-specific domain in the hotel cyber security checklist, and the one with the most recent evidence behind it. Guest connectivity is a service the hotel sells, so the controls have to protect the business without making the WiFi worse. Our hotel WiFi security guide covers the design in depth; the four controls below are the checklist version.
Control 9: separate the guest network from everything that runs the hotel
Guest, staff, payments, IoT and building systems each need their own segment, with traffic between them denied by default and allowed only where a documented flow requires it. This is the highest-value control in the whole hotel cyber security checklist because it caps the damage from everything else. The VLAN segmentation design sets out the switch-level detail, including the two VLAN-hopping mechanisms worth testing for. Evidence test: a network diagram plus one failed ping from the guest network to the EPOS network.
Control 10: harden the captive portal and the gateway behind it
Microsoft published its CaptiveCrunch analysis on 31 July 2026, describing a campaign that compromised captive-portal gateway appliances and used them to manipulate DNS for every device on the network. Because the appliance is the DHCP-assigned resolver, the attacker owns name resolution without touching a single endpoint. ReliaQuest traced compromised gateways in several countries, mostly hotels, and both vendors point at internet-facing admin consoles and weak or reused credentials as the likely way in.
The controls are unglamorous: change default credentials, take the admin interface off the public internet, patch the appliance, and never let the portal offer software updates. Our captive portal attack analysis has the full chain and the indicators. Evidence test: the appliance’s firmware version and the source addresses permitted to reach its management page.
Control 11: nothing management-related faces the public internet
Given that 61.5% of hospitality initial access attempts targeted publicly exposed services, this control earns its place near the top of the plan. Scan your own external addresses, list every port that answers, and justify each one. Remote support access belongs behind a VPN or a broker with MFA, never on an open port with a shared password. Evidence test: an external scan output for every property, dated this quarter.
Control 12: control physical access to network ports and equipment
A network port in a lobby, meeting room or corridor is an unauthenticated seat on your network. Disable unused ports, put the ones that must stay live on the guest segment, and lock the comms cabinet. The key-card encoder deserves particular attention: it is the device that turns a small compromise into a room-entry problem. Evidence test: the switch port configuration for one public area, and a photograph of the comms cabinet lock.
Hotel cyber security controls 13-16: data, payments and the booking chain
Payment and guest data is where a hotel cyber security incident turns into a regulatory event. PCI DSS v4.0.1 has been in force since June 2024, and the 51 future-dated requirements became mandatory on 31 March 2025, so there is no grace period left to plan against. Meanwhile UK data protection law moved: the Data (Use and Access) Act 2025 brought its main data-protection provisions into force on 5 February 2026.
Control 13: know where card data actually flows
Draw the flow: booking engine, channel manager, OTA, phone reservations, deposits, group bookings, no-show charges, function invoices and the terminal at the bar. Then find the informal paths, because they are the ones that fail an assessment. Card numbers written on a diary page, emailed booking forms and voicemail messages with a long card number in them are all common and all avoidable. Evidence test: the flow diagram, plus a search of the shared reservations mailbox for card details.
Control 14: delete guest data you no longer need
Retention is the cheapest hotel cyber security risk reduction available, because data you have deleted cannot be stolen. Set a retention period for reservation records, CCTV, ID scans, allergy and accessibility notes, loyalty history and unsuccessful applications, then automate the deletion. Under the DUAA framework the calculation of the one-month response window for subject access changed, so the process needs to be quick as well as documented. Evidence test: the retention schedule and one system showing records actually removed.
Control 15: backups you have restored, held where ransomware cannot reach
Most hotel systems are SaaS, which tempts people to skip this entirely. It should not: the PMS export, the EPOS configuration, the door-lock database, the finance records and the email tenant all need a copy the supplier’s account compromise cannot touch. A backup nobody has restored is a hypothesis. Evidence test: the date of the last successful test restore, and what was restored.
Control 16: encryption and least privilege on the guest database
Encrypt devices and removable media, and make sure the guest database is not readable in bulk by every user who can log in. A receptionist needs today’s arrivals, not an export of five years of guest history with dietary notes and card tokens. Loyalty data is particularly attractive because points behave like currency. Evidence test: the permissions matrix for the PMS, and confirmation that bulk export is restricted to named users.
Hotel cyber security controls 17-20: people, suppliers and response
The final hotel cyber security domain is the one that decides how bad a bad day gets. The 2025/2026 Cyber Security Breaches Survey found 43% of UK businesses had experienced a breach or attack, with medium businesses at 65% and large at 69%, yet only 25% had a formal incident response plan and only 31% had a board member responsible for cyber security. Hotels sit inside those numbers, not outside them.
Control 17: supplier assurance proportionate to the data they hold
Your PMS provider, channel manager, EPOS vendor, door-lock supplier and back-office platform each hold or reach data you are accountable for. Ask for certification, breach-notification commitments, sub-processor lists and the contractual right to be told quickly. The NCSC’s Cyber Essentials Supply Chain Playbook, published on 12 December 2025, is written specifically to help buyers require this without building a procurement bureaucracy. Evidence test: the supplier register, with a certificate or assurance date against the top five.
Control 18: training that matches what the role actually faces
Generic annual training does not change hotel cyber security behaviour at 23:00. Reception needs to recognise pretext calls asking to change bank details or unlock a room. Finance needs the invoice-fraud version. General managers need the “urgent, confidential, from the owner” version. Phishing was the most common breach type at 38% and the most disruptive for 69% of affected organisations, so this is not a soft control. Evidence test: completion records by role, not one figure for the whole group.
Control 19: logging and monitoring somebody actually reads
Turn on sign-in logging for the PMS and the email tenant, keep it for a defined period, and give somebody the job of looking at exceptions: impossible-travel sign-ins, out-of-hours administrative changes, bulk exports, new mailbox rules. The NCSC’s post-incident advice to retailers included watching for risky sign-ins and logins from atypical sources such as residential-range VPN services. Evidence test: last month’s exception review, with a name against it.
Control 20: an incident plan the duty manager can run at 03:00
The hotel cyber security incident plan needs to be one page, laminated, and behind reception. Who to call, in what order, what to disconnect and what not to power off, how to keep the hotel trading on paper, and who talks to guests. Personal data breaches must reach the ICO within 72 hours where reportable, so the clock starts long before the office opens. Rehearse it once a year with the people who will actually be on shift. Evidence test: the one-page plan, and the date of the last rehearsal.
The hotel cyber security scorecard: all 20 controls in one table
Print this hotel cyber security scorecard, walk the estate, and rate each row red, amber or green using the evidence test rather than the conversation. A first pass across a small group usually takes half a day per property and produces more reds than anyone expects, which is normal and useful.
| # | Control | Evidence test | Domain |
|---|---|---|---|
| 1 | MFA on every cloud service | Registration report for your two biggest data systems | Identity |
| 2 | Named accounts at the front desk | PMS user list with a person per entry | Identity |
| 3 | Verified help desk reset process | Written steps plus one logged reset | Identity |
| 4 | Leavers removed on the last shift | Three leavers and their disable timestamps | Identity |
| 5 | Full estate inventory | Supplier and patch owner in every row | Devices |
| 6 | Updates within 14 days | Patch report plus booking engine update date | Devices |
| 7 | Plan for equipment you cannot patch | Named list, compensating control, target date | Devices |
| 8 | Malware protection and app control | Devices not reporting in seven days | Devices |
| 9 | Guest network separated from operations | Diagram plus one failed cross-segment ping | Network |
| 10 | Captive portal and gateway hardened | Firmware version and admin source list | Network |
| 11 | No management interfaces exposed | External scan output per property | Network |
| 12 | Physical access to ports and cabinets | Port config for one public area | Network |
| 13 | Card data flow mapped | Flow diagram plus mailbox search | Data |
| 14 | Retention and deletion enforced | Schedule plus evidence of removal | Data |
| 15 | Tested, isolated backups | Date and content of last test restore | Data |
| 16 | Encryption and least privilege | Permissions matrix and export restriction | Data |
| 17 | Supplier assurance | Register with assurance dates for top five | People |
| 18 | Role-based training | Completion records split by role | People |
| 19 | Logging and exception review | Last month’s review with an owner | People |
| 20 | Rehearsed incident plan | One-page plan and last rehearsal date | People |
How to read your result
Count the greens rather than averaging. Fewer than eight means the estate is effectively unprotected against an ordinary criminal campaign, and controls 1, 9 and 11 should start on Monday. Eight to fourteen is the normal position for an independent hotel that has been sensible without being systematic. Fifteen or more means hotel cyber security is being managed, and the remaining gaps are usually supplier assurance and rehearsal.
What hotel cyber security actually costs
Most of this hotel cyber security checklist is configuration rather than purchase. The costs that do appear are concentrated in three places: a device or two that has to be replaced, the time to build the inventory and the network segments, and certification if you want it. Cyber Essentials certification is priced by size, at £320 plus VAT for micro organisations, £440 for small, £500 for medium and £600 for large, and it includes £25,000 of cyber liability cover for UK businesses under £20m turnover. Cyber Essentials Plus starts from around £1,400 plus VAT for a micro organisation.
| Control group | Main cost | Typical effort for a small group |
|---|---|---|
| Identity (1-4) | Usually licensed already | 2-4 days of configuration and account cleanup |
| Devices (5-8) | Replacement of unsupported equipment | 1 day per property for the inventory walk |
| Network (9-12) | Switch or firewall refresh if the kit is old | 2-5 days per property depending on cabling |
| Data (13-16) | Backup storage; occasionally a PMS module | 3-5 days across the group |
| People (17-20) | Training platform, optional | 2 days plus a half-day rehearsal |
| Certification | £320-£600 + VAT, or from ~£1,400 for Plus | 2-6 weeks elapsed, mostly waiting on evidence |
Where the money is usually wasted
Two hotel cyber security spending patterns recur. The first is buying a monitoring product before anyone has been made responsible for reading it, which converts an unowned risk into an unowned subscription. The second is cybersecurity insurance bought as a substitute for the controls rather than a backstop behind them; insurers increasingly ask about MFA, backups and patching at renewal, and the answers have to match reality.
A worked example: hotel cyber security across a three-property group
Numbers make the hotel cyber security checklist concrete. Take a UK group with three properties: 110, 78 and 52 bedrooms, so 240 bedrooms in total, with 165 staff across the group and a small head office. Nothing below is a survey figure; it is arithmetic on the estate you would find.
Counting the accounts
165 staff accounts, plus 22 shared or generic logins that grew up around reception and the bar, plus 9 administrative accounts across the PMS, EPOS, email and network kit. That is 196 accounts, of which 31 are either shared or privileged. Control 2 alone removes the 22, and control 1 covers the remaining 174.
Counting the endpoints
Per property: 4 front-desk PCs, 5 back-office PCs, 6 EPOS terminals, 2 kiosks, 1 key-card encoder and 3 duty-manager mobiles, which is 21 devices. Across three properties that is 63, plus 12 head-office laptops for a total of 75 endpoints. The 18 EPOS terminals, 6 kiosks and 3 encoders are 27 of those 75, just over a third, and they carry almost all of the remediation work under controls 6 and 7.
Counting the suppliers
One PMS, one channel manager, one booking engine, one CRM and loyalty platform, three EPOS estates under one vendor, one payroll system, one email tenant, one door-lock platform and one building management contract gives nine core platforms. Add roughly fourteen smaller SaaS tools that individual managers bought and the group has about 23 supplier relationships touching operational or guest data. Control 17 applies fully to the nine and proportionately to the rest.
The 90-day hotel cyber security plan
Sequence matters more than speed in hotel cyber security. The first month buys the largest reduction for the least money, the second month fixes the estate, and the third month makes the whole thing repeatable. This is the order a hotel cyber security programme should run in, and it is deliberately achievable alongside a normal trading month.
Days 1-30: stop the bleeding
Turn on MFA everywhere (control 1), remove shared logins at reception (control 2), write the help desk verification steps (control 3), scan your external addresses and close what should never have been open (control 11), and change default credentials on the captive portal gateway (control 10). Seven controls of the twenty are realistically green by day 30, and they are the seven an opportunistic attacker relies on.
Days 31-60: fix the estate
Walk every property and build the inventory (control 5), get patching onto a 14-day cycle (control 6), write the compensating-control list for equipment you cannot patch (control 7), confirm endpoint protection is reporting (control 8), and design and implement segmentation (control 9) with physical port control alongside it (control 12). That takes the running total to about 14 of 20.
Days 61-90: make it durable
Map the card data flow (control 13), set retention (control 14), test a restore (control 15), tighten permissions (control 16), collect supplier assurance (control 17), run role-based training (control 18), start the monthly exception review (control 19) and rehearse the one-page incident plan (control 20). At that point all twenty are in place and the job becomes maintenance.
Hotel cyber security mistakes that still pass an audit
Some hotel cyber security failures survive because they look like compliance. These are the ones worth hunting deliberately, because a clean paper trail hides all of them.
Treating the guest network as an exclusion that covers everything on it
IASME guidance does allow a segregated guest network to be excluded from a Cyber Essentials scope, and it names a hotel as the example. That does not extend to the hotel’s own equipment that happens to be reachable from it, and an assessor is expected to verify the segregation by technical means rather than take it on trust.
Confusing an eavesdropping control with an access control
Enhanced Open, or OWE, gives every client on a password-free SSID its own encryption, which is a genuine improvement. It provides no network access control and does not authenticate the client, so it protects the guest from the person in the next room rather than protecting the hotel from either of them.
Believing the supplier’s certificate covers your obligations
Under the cloud shared-responsibility split, a SaaS provider may run the firewalls, updates and malware protection, but user access control is always the customer’s responsibility across every service model. The PMS vendor’s certification does not create your MFA, your leaver process or your permissions matrix.
Scoring the flagship property and assuming the rest
Sample sizes in real assessments follow variation, not headcount. If the third property was refurbished by a different contractor with different equipment, it is a different estate and it needs its own walk. Hotel cyber security scores taken at the biggest site are consistently the most flattering ones available.
Writing an incident plan for people who will not be there
If the plan assumes the IT manager answers the phone, it fails at 03:00 on a bank holiday. The test is whether a duty manager who has never seen it can take the first three actions correctly.
How this hotel cyber security checklist maps to Cyber Essentials, PCI DSS and UK law
None of these frameworks is a substitute for the others, but the overlap is large enough that doing this hotel cyber security checklist properly puts you most of the way through all three. If certification is the goal, our Cyber Essentials guide for hotels covers scoping, evidence and the v3.3 changes in detail.
| Controls | Cyber Essentials | PCI DSS | UK data protection |
|---|---|---|---|
| 1-4 Identity | User access control; MFA on all cloud services | MFA and unique IDs for access to cardholder data | Security of processing |
| 5-8 Devices | Security update management; malware protection; secure configuration | Patching and anti-malware in scope systems | Appropriate technical measures |
| 9-12 Network | Firewalls and internet gateways; sub-set segregation | Segmentation for scope reduction; quarterly rogue AP checks | Data minimisation by design |
| 13-16 Data | Not directly assessed; backups are out of scope | Storage, retention and protection of account data | Storage limitation; integrity and confidentiality |
| 17-20 People | Supports the annual declaration | Service provider management; testing programmes | Processor contracts; 72-hour breach reporting |
The public-sector angle worth knowing
Procurement Policy Note 014 explicitly names travel booking as a service where a supplier handling government employees’, ministers’ or special advisers’ personal information must meet Cyber Essentials requirements, with evidence required before contract award and renewed annually. If your group takes public sector or travel management company business, that is the clearest commercial reason to certify rather than merely comply.
Where regulation is heading
The Cyber Security and Resilience Bill entered the Lords on 25 June 2026 and pulls managed service providers and data-centre operators into statutory regulation for the first time, with a reporting clock starting at 24 hours. Hotels are not in scope directly, but their IT suppliers increasingly will be, which will change what those suppliers can be asked for in a contract.
Who owns hotel cyber security in a small hotel group
The single best predictor of a good hotel cyber security score is not budget. It is whether one named person owns the hotel cyber security checklist and has the authority to say no to a supplier. Only 31% of UK businesses have a board member responsible for cyber security, and hotel groups are worse than average because operations naturally dominates the agenda.
| Role | Owns | Should not own |
|---|---|---|
| Owner or board member | The decision to fund it; the annual review | Day-to-day configuration |
| Operations or group manager | Scorecard, evidence, supplier register | Firewall and switch changes |
| General manager | Property walk, leavers, training completion | Deciding what is in scope |
| IT partner or MSP | Patching, segmentation, monitoring, restores | Accepting risk on the hotel’s behalf |
| Duty manager | First three incident actions | Investigation or supplier negotiation |
If you outsource, outsource the work and keep the accountability
An IT partner can hold every technical hotel cyber security control on this list. What no supplier can take is the accountability for guest data, the decision on scope, or the acceptance of a risk. Our IT support for hotels and hospitality page sets out how that split usually works in practice, and managed IT services covers the wider operating model.
Hotel cyber security checklist FAQ
How long does a first pass through the 20 controls take?
Half a day per property for the walk and the evidence gathering, plus a day at group level for suppliers and policy. A three-property group can complete an honest first hotel cyber security score in a week without stopping trading.
Do we need Cyber Essentials to use this hotel cyber security checklist?
No. The hotel cyber security checklist stands alone and is deliberately broader than certification, since it covers retention, backups, monitoring and rehearsal that Cyber Essentials does not assess. Certification is worth having when a corporate client, travel management company or public sector buyer asks for it.
Our PMS is cloud-based. Does that reduce our scope?
It changes what you control, not whether you are accountable. Cloud services cannot be excluded from a Cyber Essentials scope, and user access control remains the customer’s responsibility in every cloud model, so controls 1, 2, 4 and 16 apply exactly as they would on-premise.
What about franchised properties?
Score them separately. A franchise agreement usually fixes some systems centrally and leaves the local network, devices and staff processes to the operator, so the estate genuinely differs. Record which controls are brand-mandated and which are yours.
Which control should we do first if we can only do one?
MFA on every cloud service. It is the cheapest, fastest hotel cyber security control on the list, it defeats the credential attacks that dominate hospitality incidents, and it takes days rather than months.
How often should we re-score?
Twice a year for the full hotel cyber security checklist, plus a lightweight identity and patching check each quarter. High staff turnover means the identity domain degrades faster than anything else on the list.
References and Further Reading
NCSC: Incidents impacting retailers – recommendations from the NCSC
NCSC: Cyber Essentials overview
NCSC: 10 Steps to Cyber Security
NCSC: Small Organisations Guide to Cyber Security
NCSC: Device Security Guidance
NCSC: Multi-factor authentication for your corporate online services
NCSC: Password administration for system owners
NCSC: Phishing attacks – defending your organisation
NCSC: Mitigating malware and ransomware attacks
NCSC: Offline backups in an online world
NCSC: Supply chain security guidance
NCSC: Cyber Essentials Supply Chain Playbook
NCSC: Cyber Security Board Toolkit
NCSC: Risk management guidance
DSIT: Cyber Security Breaches Survey 2025/2026
Cyber Security and Resilience Bill collection
Data (Use and Access) Act 2025
ICO: Report a personal data breach
PCI Security Standards Council: PCI DSS
PCI SSC: Adopting the future-dated requirements of PCI DSS v4.x
IASME: Defining the scope of your Cyber Essentials assessment
Verizon Data Breach Investigations Report
Trustwave: 2025 Hospitality Risk Radar Report
Unsaflok: Saflok lock vulnerability research
SecurityWeek: Saflok lock vulnerability can be exploited to open millions of doors
SecurityWeek: BWH Hotels says hackers had access to reservation data for six months
Infosecurity Magazine: Data of half a million hotel guests exposed
Infosecurity Magazine: CaptiveCrunch campaign targets hotel networks
Help Net Security: Midnight Blizzard targets hotel networks
CIS Critical Security Controls
NIST SP 800-61r3: Incident Response Recommendations and Considerations
UKHospitality: Cyber security isn’t just an IT problem any more