Hotel IT audit work has a reputation problem. It sounds like paperwork, it usually arrives as a spreadsheet nobody reads, and it competes for attention with a broken lift and a coach party arriving at four. Yet almost every expensive hotel technology failure — the reservations outage on a bank holiday, the card terminal that stops taking payments, the door lock system nobody can reach the supplier about — was visible months earlier to anyone who bothered to look.
This checklist is the looking. It sets out thirty specific checks, grouped into six areas, that a UK hotel can run against its own estate without buying anything first. Each one names what to examine, what evidence proves it, and what actually breaks when it is wrong. Nine of the thirty exist purely because of deadlines already in the diary: the analogue phone network switches off on 31 January 2027, Windows Server 2016 leaves support eleven days earlier, and the Cyber Essentials question set changed in April 2026.
The other twenty-one are the ordinary, unglamorous things that decide whether a Tuesday morning goes well. There is no scoring app and no certification at the end. There is a list, a torch, and a couple of days.
If you are arriving here from the wider hospitality series, the companion pieces sit underneath this one: the hotel network design blueprint covers how the estate should be built, the hotel VLAN design guide covers how many networks it needs, and the hotel disaster recovery plan covers what happens when this checklist was ignored.
Table of contents
- What a Hotel IT Audit Is, and What It Is Not
- Why the Hotel IT Audit Matters More in 2026 Than It Did in 2023
- How to Run the Hotel IT Audit: Scope, Cadence and Evidence
- Hotel IT Audit Checks 1 to 5: The Asset Register
- Hotel IT Audit Checks 6 to 10: Network and Connectivity
- Hotel IT Audit Checks 11 to 15: The Systems That Take Money
- Hotel IT Audit Checks 16 to 20: Identity, Access and Leavers
- Hotel IT Audit Checks 21 to 25: Backup, Recovery and Continuity
- Hotel IT Audit Checks 26 to 30: Physical, Legacy and the 2027 Deadlines
- Mapping the Hotel IT Audit to the Frameworks You Already Report Against
- Turning Hotel IT Audit Findings Into a Plan Somebody Will Fund
- Hotel IT Audit Mistakes That Waste the Whole Exercise
- Hotel IT Audit Questions UK Operators Ask Most
- References
What a Hotel IT Audit Is, and What It Is Not
A hotel IT audit is a structured walk through everything with a plug or an IP address, comparing what exists against what the business believes exists. It is not a penetration test, it is not a certification assessment, and it is not a sales survey dressed up as advice.
It is a reconciliation, not an opinion
The core of the exercise is boring and powerful: list what is really there, then compare it with the asset register, the supplier contracts, the network diagram and the licence count. Almost every finding in a hotel IT audit comes out of a gap between those two lists rather than from any clever technical discovery.
It is scoped to a property, not a brand
Group standards matter, but they are audited centrally. A property-level hotel IT audit looks at this building: this comms room, these access points, these tills, this leaver list. A brand-wide statement that “all properties use MFA” is a claim to be tested here, not evidence.
It is deliberately not a penetration test
Penetration testing answers “can this be broken into”. A hotel IT audit answers “do we know what we have, is it supported, is it backed up, and can we prove it”. The second question is cheaper, and in UK hospitality it finds more real risk, because the sector’s most common failures are unpatched public-facing systems and stale accounts rather than exotic exploits.
How the hotel IT audit differs from a standard office review
| Factor | Standard office IT audit | Hotel IT audit |
|---|---|---|
| Maintenance window | Evenings and weekends | None; the building trades 24 hours |
| Who is on the network | Employees on managed devices | Hundreds of unmanaged guest devices nightly |
| Who owns the kit | Mostly the business | Split across brand, owner, operator and vendors |
| Critical systems | Email, files, finance | PMS, POS, payment terminals, door locks, fire panel lines |
| Cost of one hour down | Lost productivity | Lost revenue, refused check-ins, refunded bookings |
| Physical estate | One or two floors | Risers, roof plant, back of house, car park, leisure club |
| Regulatory pressure | UK GDPR | UK GDPR, PCI DSS, licensing, Martyn’s Law, hotel records |
Why the Hotel IT Audit Matters More in 2026 Than It Did in 2023
Two things changed. The estate got more connected, and the deadlines stacked up in the same eighteen months.
The sector under-invests in attention, not money
The UK government’s Cyber Security Breaches Survey 2026, published on 30 April 2026 from fieldwork with 2,112 businesses, found 43% of businesses had experienced a breach or attack. The sector split is the number worth pinning to a wall: only 30% of food and hospitality businesses treat cyber security as a high priority for senior management, against 72% of businesses overall. That gap is what a hotel IT audit is designed to close.
The failure mode is exposure, not sophistication
Trustwave’s 2025 Risk Radar for hospitality gives the clearest breakdown of how attackers get in: exploitation of a public-facing application 61.5%, phishing 23.4%, and valid accounts 15.1%. Two of those three are inventory problems. You cannot patch a public-facing system you forgot you owned, and you cannot disable an account you never knew existed.
The same report counted more than 14,000 publicly exposed vulnerabilities affecting the sector, and found SNMP exposed roughly twice as often as the next most exposed service. Neither finding needs a specialist to reproduce. Both fall out of the first ten checks of a hotel IT audit, because both are consequences of an estate list that stopped being accurate somewhere around the last refurbishment.
The deadlines are real and close
Nine of the thirty checks below exist because of a fixed date. The analogue telephone network is withdrawn on 31 January 2027. Windows Server 2016 reaches end of extended support on 12 January 2027. Windows 10 already reached end of support on 14 October 2025. Cyber Essentials moved to the Danzell question set for applications registered from 26 April 2026. A hotel IT audit run today has eighteen months of runway; one run in mid-2027 has none.
What a hotel IT audit costs against what an outage costs
Take a 136-bedroom regional UK property. Using Knight Frank’s UK Hotel Dashboard figures for regional UK — occupancy 75.9%, ADR £107.50, TRevPAR £124.70 and GOPPAR £38.50 — that property turns over £16,959.20 a day in total revenue (136 × £124.70) and makes £5,236.00 a day in gross operating profit (136 × £38.50).
A thorough hotel IT audit of that property is roughly two days on site and a day and a half writing up. At £795 a day that is £2,782.50 — about £20.46 per bedroom, once a year, or 7.4 pence per occupied room night across 37,595 occupied room nights (103 rooms × 365).
Now the comparison. A three-day outage of reservations and payments puts £50,877.60 of revenue and £15,708.00 of gross operating profit at risk. That is more than eighteen times the cost of the audit. And if the property saw what MGM Resorts reported to the SEC after its 2023 incident — September occupancy of 88% against 93% the prior year — a five-point occupancy fall held for a month would be £21,930 (136 × 30 × 0.05 × £107.50).
How to Run the Hotel IT Audit: Scope, Cadence and Evidence
Before the thirty checks, four decisions make the difference between a useful hotel IT audit and a document that gets filed.
Scope: four zones, not one building
Divide the property into guest-facing, revenue-taking, back-of-house and building-services zones, and walk each one separately. Mixing them produces a list where a failed door lock battery sits next to an expired TLS certificate and neither gets fixed. Zones also map cleanly onto owners, which is how findings actually get closed.
Cadence: not everything is annual
Six of the thirty checks are worth doing monthly, eleven quarterly, and thirteen annually. Spreading them means the annual hotel IT audit becomes a verification pass rather than a discovery expedition, and the monthly items catch the things that drift fastest — accounts, backups and firmware.
Evidence: a finding without proof is an argument
Every check in this hotel IT audit needs a named artefact. A photograph of the comms room, a screenshot of the admin user list, an exported firmware report, a signed restore test note. Without one, the finding becomes a debate between the general manager and the supplier, and the supplier has more time to argue.
Scoring: three states and one hard rule
Score every check red, amber or green. The hard rule that stops everything drifting to amber: a check is green only if the evidence exists and is dated within the cadence period. Not “we do that” — dated evidence, or it is amber at best.
| Score | Definition | Owner | Deadline |
|---|---|---|---|
| Red | Control absent, or a supported product is now unsupported | General manager, with IT | 30 days, or a dated written plan |
| Amber | Control exists but evidence is missing, stale or partial | IT or the named supplier | 90 days |
| Green | Control exists and dated evidence is inside the cadence period | Re-verified at next cadence | No action |
Hotel IT Audit Checks 1 to 5: The Asset Register
Every framework starts here for the same reason: nothing downstream is provable without it. CIS Critical Security Controls v8.1 makes asset inventory Control 1 and software inventory Control 2. PCI DSS v4.0.1 requirement 12.5.1 requires an inventory of in-scope system components including a description of function and use, kept current.
Check 1: A hardware inventory that includes the things nobody calls IT
List every device with an IP address or a plug that matters: servers, switches, access points, tills, card terminals, kiosks, digital signage, door lock controllers, CCTV recorders, the building management panel, the lift line, and the fire alarm dialler. Most hotel IT audit engagements find between fifteen and forty devices that appear on no list anywhere.
Check 2: A software and SaaS inventory, including the subscriptions on someone’s card
Record every application and cloud service in use, its owner, its renewal date and who holds the admin credentials. Include the booking engine, the channel manager, the review platform, the rota tool, the allergen system and the marketing suite. In practice, the shadow subscriptions found during a hotel IT audit are almost always paid for on a departmental card and known to one person.
Check 3: An ownership map across brand, owner, operator and vendor
For each system, write down who owns the hardware, who holds the contract, who patches it and who to ring at 3am. Managed franchises routinely have four different answers, and the gap between them is where outages live longest.
Check 4: A supplier and contract register with real renewal dates
Capture the contract end date, notice period, support hours and escalation path for every supplier in the estate. A hotel IT audit finding of “support expired in 2024” is common and entirely preventable, and it is usually discovered during an incident rather than before one.
Check 5: A current network diagram that matches the building
One page, drawn this year, showing circuits, firewalls, VLANs, the wireless controller and where each system sits. If the diagram predates the last refurbishment, it is fiction. This single artefact makes every later check in the hotel IT audit faster.
| # | Check | Evidence that closes it | Cadence |
|---|---|---|---|
| 1 | Hardware inventory | Exported list with make, model, location, serial | Quarterly |
| 2 | Software and SaaS inventory | List with owner, renewal date, admin holder | Quarterly |
| 3 | Ownership map | One row per system, four named parties | Annually |
| 4 | Supplier and contract register | Contract dates, notice periods, escalation numbers | Annually |
| 5 | Network diagram | Dated single-page diagram matching the walk | Annually |
Hotel IT Audit Checks 6 to 10: Network and Connectivity
The network is where a hotel IT audit produces its most visible wins, because guest complaints and card failures usually resolve to the same three or four causes.
Check 6: Circuits, failover and what happens when the main line drops
Confirm how many internet circuits the property has, whether the second one is a genuinely different carrier and path, and whether failover has ever been tested with the primary physically unplugged. A backup circuit that has never carried live traffic is a hypothesis.
Check 7: Segmentation proof, not segmentation intent
Guest, staff, payment, CCTV, door locks and building services should be on separate networks. Prove it during the hotel IT audit by plugging a laptop into the guest network and attempting to reach a till, the PMS server and the CCTV recorder. Read the hotel VLAN design guide for the target design, and the network segmentation guide for the test method.
Check 8: A wireless walk and a rogue access point sweep
Walk every floor, the function rooms, the leisure club and the car park with a survey app, and separately scan for access points that are not yours. PCI DSS v4.0.1 requirement 11.2.1 requires testing for authorised and unauthorised wireless access points at least once every three months, with requirement 11.2.2 requiring an inventory of the authorised ones. Evil-twin risk on guest networks is covered in the hotel captive portal security guide.
Check 9: Firmware currency on switches, access points and firewalls
Export the firmware version of every network device and compare it against the vendor’s current release. This is the check that most often turns a hotel IT audit into a funded project, because the answer is usually “these were installed in 2019 and never touched”. The hotel WiFi upgrade cost guide prices the outcome.
Check 10: Cabling, patching and the state of the comms room
Photograph every rack. Check that patch panels are labelled, that nothing is daisy-chained through a desk switch under reception, and that no cable runs through a fire door. A hotel IT audit that skips the physical layer misses the single most common cause of intermittent faults.
Hotel IT Audit Checks 11 to 15: The Systems That Take Money
If reservations and payments stop, everything else is irrelevant. These five checks carry more revenue risk than the other twenty-five combined.
Check 11: PMS version, support status and who can actually patch it
Record the property management system version, the vendor’s supported-version list, the last patch date and whether the property or the vendor applies updates. Detail on protecting the reservation and guest data inside it is in the hotel PMS cyber security guide.
Check 12: A payment device register with make, model, location and serial
PCI DSS v4.0.1 requirement 9.5.1.1 requires a current list of point-of-interaction devices including make and model, location, and serial number or other unique identifier. Every hotel IT audit should count the terminals physically and reconcile that count against the list, including the ones in the spa, the bar and the mobile trays.
Check 13: Tamper inspection of every card terminal
Requirement 9.5.1.2 requires periodic inspection of those devices for tampering or substitution. In practice this means a named person checking serial numbers against the register on a defined schedule and recording the result. It takes fifteen minutes a month and it is almost never being done when the hotel IT audit asks for the log.
Check 14: The card data flow, written down in one diagram
Draw where card data enters, where it travels and where it is stored. If the answer includes an email inbox or a written note at reception, that is a red finding. PCI DSS v4.0.1 requirement 4.2.2 prohibits sending unprotected card numbers by email, SMS or chat. The PCI DSS for hotels guide covers the eligibility questions this raises.
Check 15: The interface list between PMS, POS and everything else
List every integration: the channel manager, the booking engine, the door lock system, the till, the payment gateway, the accounting export, the guest WiFi authentication. Note the credential each uses and when it was last rotated. The hotel POS security guide covers the restaurant end of this chain.
| # | Revenue-system check | What breaks when it is wrong | Standard reference |
|---|---|---|---|
| 11 | PMS version and support status | Unpatchable reservations platform | CIS v8.1 Control 2 |
| 12 | Payment device register | Untracked terminal swapped for a skimmer | PCI DSS 9.5.1.1 |
| 13 | Terminal tamper inspection | Substitution goes unnoticed for months | PCI DSS 9.5.1.2 |
| 14 | Card data flow diagram | Card numbers sitting in a shared mailbox | PCI DSS 4.2.2 |
| 15 | Interface and credential list | A rotated password silently stops arrivals | ISO 27001 A.5.21 |
Hotel IT Audit Checks 16 to 20: Identity, Access and Leavers
Hospitality has high turnover, seasonal staff and shared workstations. That combination makes identity the area where a hotel IT audit finds the largest number of open findings per hour spent.
Check 16: Named accounts, and a list of every shared one
Export the full user list and mark every account that is shared between people — reception, reservations, duty manager, the kitchen PC. Shared logins are sometimes operationally unavoidable, but they must be known, owned and password-managed rather than written on a laminated card.
Check 17: Multi-factor authentication coverage, counted not claimed
Count the accounts with MFA enforced and divide by the total. The Cyber Security Breaches Survey 2026 found only 47% of businesses use two-factor authentication at all. Cyber Essentials now treats missing MFA on cloud services as an automatic assessment failure, so this hotel IT audit check has a certification consequence as well as a security one.
Check 18: An admin account register with a named human against each
List every account with administrative rights across the PMS, the POS, Microsoft 365, the firewall, the wireless controller and the door lock system. Any admin account that cannot be attributed to a named current employee is a red finding. The Microsoft 365 for hotels security checklist covers the tenant side in detail.
Check 19: A leaver test using a real name from the last quarter
Pick someone who left three months ago and try to find their access. Check Microsoft 365, the PMS, the POS, the door system, the WiFi, the booking engine and any SaaS tool. This is the single most persuasive test in the whole hotel IT audit, because the result is either clean or immediately alarming.
Check 20: Shared mailboxes, role addresses and where they forward
Reservations, info, events, accounts and duty manager mailboxes are the ones attackers target, because nobody personally owns them. Confirm who has access, whether MFA applies, and whether any forwarding rules exist. The hotel phishing guide explains why role mailboxes attract campaigns built specifically for them.
Hotel IT Audit Checks 21 to 25: Backup, Recovery and Continuity
Backup is the area where confidence and reality diverge most. Every property believes it is backed up; a minority can prove a restore.
Check 21: Backup coverage mapped against the asset register
For every system on the check 1 and check 2 lists, record whether it is backed up, by whom, how often and to where. The systems that fail this test in a hotel IT audit are predictable: the door lock server, the CCTV recorder, the building management PC and anything a supplier hosts.
Check 22: A restore test with a date and a signature
Not a backup report — an actual restore of an actual file or system, performed within the last quarter, with someone’s name on it. Only 25% of UK businesses have a formal incident response plan according to the 2026 survey, and the restore test is the cheapest part of one.
Check 23: One copy that ransomware cannot reach
Confirm at least one backup copy is immutable or offline, and that the backup system does not authenticate with the same directory as everything else. The hotel ransomware guide explains why a domain-joined backup server is the same as no backup at all.
Check 24: Agreed recovery time and recovery point objectives per system
Ask the general manager how long the property can trade without the PMS, and how much booking data it can afford to lose. Write the answers down and compare them with what the backup design actually delivers. A hotel IT audit that surfaces a two-hour expectation against a twenty-four-hour capability has earned its fee.
Check 25: A runbook, printed, with out-of-band contact details
If Microsoft 365 is down, the recovery instructions must not live in Microsoft 365. Print the runbook, include supplier numbers and account references, and store a copy at reception and off site. The hotel disaster recovery plan guide sets out what belongs in it.
| # | Continuity check | Green means | Cadence |
|---|---|---|---|
| 21 | Backup coverage map | Every asset row has a backup answer | Quarterly |
| 22 | Restore test | Dated, signed restore inside 90 days | Quarterly |
| 23 | Immutable or offline copy | Separate credentials, cannot be deleted in place | Monthly |
| 24 | RTO and RPO per system | Written, signed by the general manager | Annually |
| 25 | Printed runbook | Hard copy at reception and off site | Annually |
Hotel IT Audit Checks 26 to 30: Physical, Legacy and the 2027 Deadlines
The last five checks are the ones that cause the most expensive surprises, because they involve equipment installed by builders rather than by IT.
Check 26: The comms room, its lock, its heat and its water risk
Open the door. Is it locked, is anyone’s cleaning equipment stored in it, is there a fan coil unit above the rack, is the temperature sane, and does anything drip? ISO/IEC 27001:2022 devotes fourteen of its ninety-three Annex A controls to physical security, and a hotel IT audit that never opens the comms room cannot speak to any of them.
Check 27: UPS batteries, runtime and the last time it was load-tested
Every UPS has a battery with a service life, and in most properties it expired years ago. Record the install date, the reported runtime and whether the unit has ever been tested under load. A UPS that fails at the moment of a power cut is worse than none, because everything shut down believing it was protected.
Check 28: Every analogue line in the building, before 31 January 2027
This is the most time-critical check in the hotel IT audit. Openreach withdraws the analogue telephone network on 31 January 2027, and its own figures put roughly 2.8 million lines still on the old network, including over 500,000 business premises, more than 12,000 lift lines and around 500 CCTV lines. In Openreach’s words, “There’s no time left to stall.”
Walk the building and list every analogue line: lift emergency phones, the fire alarm dialler, the intruder alarm, disabled refuge points, the roof plant, the card terminal backup line, the fax nobody admits to and any old room telephony. Openreach has also confirmed a rising price schedule on legacy lines — 20% from 1 April 2026, a further 40% from 1 July 2026 and another 40% from 1 October 2026 — so waiting costs money before it costs service.
Check 29: Operating systems and applications past end of support
Windows 10 reached end of support on 14 October 2025. Windows Server 2016 reaches end of extended support on 12 January 2027 — nineteen days before the phone network switches off. List every machine, including the back-office PC in the kitchen and the PMS workstation at reception, and mark anything that is already out of support red.
Check 30: Door locks, CCTV and building services on the network
Electronic door locks, CCTV recorders, the building management system and car park barriers are now IP devices with firmware, default passwords and vendor remote access. Confirm each one’s firmware version, whether default credentials were changed, and exactly how the supplier connects in. This is the check where a hotel IT audit most often finds a permanent inbound remote-access tool nobody documented.
| Deadline | Date | What it hits in a hotel | Audit check |
|---|---|---|---|
| Windows 10 end of support | 14 October 2025 | Reception, back office, kitchen and spa PCs | 29 |
| Cyber Essentials Danzell question set | Applications from 26 April 2026 | Certification scope, MFA on all cloud services | 17 |
| Windows Server 2016 end of extended support | 12 January 2027 | On-premises PMS, POS back office, file servers | 29 |
| PSTN and analogue line withdrawal | 31 January 2027 | Lifts, fire panel, alarms, refuge points, room phones | 28 |
| Martyn’s Law duties commence | At least 24 months from 3 April 2025 | Public capacity 200 plus, procedures and systems | 30 |
Mapping the Hotel IT Audit to the Frameworks You Already Report Against
Nothing above is invented. Each of the six areas maps onto standards the property is probably already claiming to follow, which makes the hotel IT audit reusable as evidence rather than extra work.
ISO/IEC 27001:2022 and its ninety-three controls
The 2022 edition restructured Annex A into 93 controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological, down from 114 controls in 14 domains in the 2013 edition. Clause 9.2 requires internal audit at planned intervals, which is precisely what this checklist delivers at property level.
CIS Critical Security Controls v8.1
Published in June 2024, v8.1 opens with Control 1, inventory and control of enterprise assets, and Control 2, inventory and control of software assets. Checks 1 and 2 of this hotel IT audit are those two controls expressed in hotel language.
PCI DSS v4.0.1
Requirements 12.5.1, 11.2.1, 11.2.2, 9.5.1.1, 9.5.1.2 and 4.2.2 are all directly represented in the thirty checks. If the property completes a self-assessment questionnaire annually, this hotel IT audit produces most of the underlying evidence.
Cyber Essentials under the Danzell question set
The Danzell question set, published on 13 February 2026 and applying to applications registered from 26 April 2026, is assessed against Requirements for IT Infrastructure v3.3. It requires an accurate scope, which is checks 1 to 5, and MFA on cloud services, which is check 17. The Cyber Essentials for hotels guide covers certification end to end.
| Audit area | Checks | ISO 27001:2022 | CIS v8.1 | PCI DSS v4.0.1 |
|---|---|---|---|---|
| Asset register | 1–5 | A.5.9, A.5.21 | Controls 1 and 2 | 12.5.1 |
| Network and connectivity | 6–10 | A.8.20, A.8.22 | Controls 12 and 13 | 11.2.1, 11.2.2 |
| Revenue systems | 11–15 | A.5.21, A.8.9 | Controls 2 and 4 | 9.5.1.1, 9.5.1.2, 4.2.2 |
| Identity and access | 16–20 | A.5.16, A.5.18, A.8.5 | Controls 5 and 6 | 7.2, 8.4 |
| Backup and continuity | 21–25 | A.8.13, A.5.30 | Control 11 | 12.10.1 |
| Physical and legacy | 26–30 | A.7.1–A.7.14 | Control 1 | 9.1, 9.2 |
Turning Hotel IT Audit Findings Into a Plan Somebody Will Fund
A list of thirty red and amber items is not a plan. Converting findings into funded work is where most audits quietly die, and it is mostly a writing problem rather than a technical one.
Sort by revenue exposure, not by technical severity
A missing patch on an internal print server and an untested restore of the reservations database are not the same size of problem, however similar their CVSS scores look. Rank hotel IT audit findings by what stops the property trading, then by what breaches a regulatory obligation, then by everything else.
Put a date on every red finding, or a written reason there is not one
Reds get thirty days or a dated written plan approved by the general manager. That second option matters — some fixes genuinely need a capital cycle, and the honest answer “March, in the refurbishment budget” is a valid audit outcome. “Ongoing” is not.
Bundle small items into one supplier visit
Firmware updates, labelling, a UPS battery swap and a comms room tidy are individually trivial and collectively a day’s work. Bundling turns fifteen amber findings into one purchase order, which is the difference between a hotel IT audit that gets actioned and one that gets forgotten.
Re-audit the reds at ninety days, not next year
Book the follow-up before leaving site. A short re-check of only the red items keeps momentum, and it costs a fraction of the original hotel IT audit because the scoping work is already done.
Hotel IT Audit Mistakes That Waste the Whole Exercise
Five failure patterns account for most audits that produce nothing.
Auditing the documentation instead of the building
Reading the network diagram and ticking the box is not an audit. If nobody physically opened the comms room, counted the card terminals and walked the car park for access points, the hotel IT audit did not happen.
Accepting “the supplier looks after that”
That sentence is a finding, not an answer. Ask which supplier, under which contract, with what response time, and when they last provided evidence. In managed franchise estates this question alone routinely uncovers systems with no support at all.
Running it during a quiet week and calling it representative
Test failover, wireless coverage and payment resilience when the building is busy, or at least model it. A guest network that performs beautifully with forty devices tells you nothing about a full house with four hundred.
Producing a report nobody in the hotel can read
Write findings in the language of the property. “Unsupported operating system on the reception terminal that takes card payments” lands; “EOL OS on WKSTN-04” does not. The general manager funds the fix, so the general manager is the audience for the hotel IT audit report.
Never testing the leaver process
Of all thirty checks, check 19 is the one most often skipped and the one that most reliably finds live access belonging to someone who left months ago. It takes twenty minutes.
Hotel IT Audit Questions UK Operators Ask Most
How long does a hotel IT audit take?
For a single property of 100 to 200 bedrooms, budget two days on site and a day and a half of write-up. Multi-property groups get faster after the first, because the ownership map and supplier register are largely shared.
Who should carry out the hotel IT audit?
Someone independent of whoever runs the estate day to day. That can be an internal group IT function auditing a property, or an external provider — but the person auditing should not be marking their own homework, which is the same principle ISO/IEC 27001 clause 9.2 applies to internal audit.
How often should the full checklist run?
Once a year end to end, with the monthly and quarterly items run on their own cadence in between. Six checks monthly, eleven quarterly and thirteen annually keeps the annual hotel IT audit to a verification pass.
Does this replace penetration testing or Cyber Essentials?
No. It feeds both. The scope and inventory work in checks 1 to 5 is what a penetration test needs to be worth buying, and what a Cyber Essentials application needs to be accurate.
What is the single most valuable check?
Check 19, the leaver test. It is cheap, it is unambiguous, and a failure demonstrates the gap between policy and practice more convincingly than any other item in the hotel IT audit.
What should a small independent hotel do first?
Checks 1, 2, 22 and 28: know what you have, know what you subscribe to, prove you can restore, and find your analogue lines before January 2027. Those four cover the highest-consequence unknowns for the least effort, and they need no budget beyond time. Progressive Robot’s managed IT services and IT support in Chester teams run this checklist for hospitality clients across the North West.
References
Openreach: Time for a big switch-up as PSTN switch-off looms
DSIT Cyber Security Breaches Survey
Microsoft Lifecycle: Windows Server 2016
Microsoft Lifecycle: Windows 10 Enterprise and Education
IASME: Changes to Cyber Essentials for April 2026
BSI: ISO/IEC 27001:2022 Information Security Management Systems Requirements
CIS Critical Security Controls
CIS Control 1: Inventory and Control of Enterprise Assets
PCI Security Standards Council Document Library
NCSC 10 Steps to Cyber Security
NCSC Asset Management Guidance
NCSC Response and Recovery Guidance for Small Organisations
Trustwave 2025 Risk Radar Report: Hospitality Sector
Verizon Data Breach Investigations Report
IBM Cost of a Data Breach Report
Knight Frank UK Hotel Dashboard Q3 2025