Hotel business continuity is the part of the plan nobody rehearses, because it starts at the exact moment the clever technology stops helping. The property management system will not load. The card terminals are declining everything. The phones are dead because they are voice over IP and the broadband is down. There are forty arrivals due from three o’clock, a wedding party in the function room, and two hundred people already asleep upstairs who have no idea anything is wrong.

That moment is not an IT problem. It is an operating problem, and it is answered by a different document than the one your IT provider owns. Recovery engineering — backups, failover, restore times — decides how long the outage lasts. Hotel business continuity decides what the building does while it lasts, which is the half that guests actually experience and the half that determines whether you take money on Tuesday.

This guide covers that half. It sets out how to work out which functions genuinely cannot stop, how to run reception, payments, keys, food and housekeeping without the systems that normally run them, who decides what in the first hour, what belongs in a downtime kit, and how to get everything back into the system afterwards without losing a night’s revenue in the reconciliation. It uses a worked 112-bedroom model so the numbers are checkable rather than rhetorical.

If you are arriving from the wider hospitality series, the companion pieces sit either side of this one: the hotel disaster recovery plan covers the engineering that shortens an outage, the hotel IT audit checklist style groundwork sits under both, and the property-sector equivalent of this article is disaster recovery for property management companies, which asks the same question of a different building type.

What Hotel Business Continuity Actually Means

hotel business continuity when technology goes offline b step ladder five rungs

Hotel business continuity is the discipline of keeping the business trading through a disruption, using whatever is still available. It is deliberately not a technology plan. It assumes the technology has already failed and asks what the humans do next.

Continuity, recovery and response are three different documents

These three get merged constantly, usually into one file called “the DR plan”, and the merge is why so many hotels have a plan that answers none of the questions asked at three in the morning. A hotel business continuity plan is owned by operations and describes how the hotel functions without its systems. A disaster recovery plan is owned by IT and describes how the systems come back. An incident response plan is owned by whoever handles security events and describes containment, evidence and notification.

DimensionBusiness continuityDisaster recoveryIncident response
Question it answersHow do we keep trading right now?How do we get the systems back?What happened and how do we stop it?
OwnerGeneral manager and heads of departmentIT team or managed providerSecurity lead, with IT
Unit of planningA business functionA system and its dataAn event and its evidence
Primary outputManual operating proceduresRTO, RPO, backups, failoverContainment, notification, forensics
Success measureGuests served, revenue still takenSystems restored inside the targetAttack stopped, duties met
Typical triggerAnything that stops tradingLoss of a system, site or supplierConfirmed or suspected compromise
When it startsMinute one, at the deskMinute one, in a different roomOnly for security events

The standard behind hotel business continuity

The formal reference is ISO 22301, published as BS EN ISO 22301:2019, “Security and resilience. Business continuity management systems. Requirements”. Two of its terms are worth borrowing even if you never certify. MTPD — maximum tolerable period of disruption — is the point at which the impact of an outage becomes unacceptable to the business. RTO — recovery time objective — is the target time within which an activity must be resumed.

The rule that matters for hotel business continuity is that the RTO must always sit inside the MTPD, with margin. If your provider quotes an eight-hour recovery target for a system whose function becomes unacceptable after four, you do not have a plan, you have a countdown.

Hotel business continuity is a legal expectation, not just good practice

UK GDPR Article 32 requires “the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services” and “the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident”. It also requires “a process for regularly testing, assessing and evaluating the effectiveness” of those measures. Availability is written into the security duty, and testing is written in alongside it — which is the plainest justification you will ever need for spending two days a year on a hotel business continuity exercise.

For card payments, PCI DSS v4.0.1 requirement 12.10.1 obliges merchants to hold an incident response plan that explicitly covers business continuity and recovery procedures, and 12.10.2 requires that plan to be reviewed and tested at least annually. Hotel business continuity is therefore already inside the scope of an assessment most properties are doing anyway.

Why Hotel Business Continuity Is Different From Every Other Sector

hotel business continuity when technology goes offline c bucket single handle

Every business says downtime hurts. Hotels are one of a small number where the customers are physically inside the building, asleep, and cannot be asked to come back tomorrow.

There is no maintenance window and no closing time

An office can lose email at 6pm and nobody notices until morning. A hotel trades every hour of every day. There is no window in which a hotel business continuity event is cheap, and no hour in which “we will look at it first thing” is an acceptable answer. The night audit, the 3am fire alarm and the 6am breakfast service all sit in the same twenty-four hours as the outage.

The guest is your hostage as well as your customer

A retailer with a dead till loses a sale. A hotel with a dead PMS still has three hundred people who need beds, breakfast, keys and hot water, and who have already paid. That asymmetry is the core of hotel business continuity: the obligation continues at full strength while the ability to meet it collapses. You cannot close the doors and try again on Thursday.

The estate is owned by four different parties

In most properties the brand owns some systems, the owner owns the building, the operator owns the staff and a chain of vendors owns the rest — locks, lifts, the spa booking tool, the car park barrier, the digital signage. When something breaks at 2am, hotel business continuity depends on knowing which of those four to phone, and that knowledge is usually in one person’s head rather than in a document.

Regulatory duties do not pause

The Immigration (Hotel Records) Order 1972 still applies during an outage. Article 4 requires every guest over sixteen to “inform the keeper of the premises of his full name and nationality”, with passport or document details for non-UK and non-Irish nationals, and Article 5 requires the keeper to “keep for a period of at least 12 months a record in writing of the date of arrival”. A cloud PMS that is offline does not suspend that duty, which is precisely why blank registration cards belong in a drawer at reception.

The failure modes are physical as well as digital

Hotels have plant rooms, risers, roof kit, car parks and leisure clubs. A flooded basement, a failed transformer or a contractor through a fibre duct takes systems down as effectively as ransomware, and far more often. Any hotel business continuity plan written only around cyber attack is a plan for the minority of real events.

What Actually Goes Offline: The Hotel Business Continuity Risk Register

hotel business continuity when technology goes offline d suitcase upright handle

Before writing procedures, be honest about causes. The evidence says the boring ones dominate.

The sector-neutral picture

The Business Continuity Institute’s Horizon Scan Report 2025, published on 19 November 2025, ranks the concerns of continuity professionals for the year ahead as cyberattacks first, extreme weather second, IT and telecom outages third, data breaches fourth, and third-party or critical infrastructure failure fifth. Looking back rather than forward, the picture is different again: extreme weather was the single largest cause of actual disruption over the previous twelve months, for the first time since 2017.

What continuity professionals expect to matter most over five to ten years (BCI Horizon Scan 2025)
Cyber security and data-related threats — 63.6%
Climate risk and extreme weather — 40.7%
The role of AI in operational risk — 30.5%
Geopolitical change — 28.8%
Supply chain disruption — 26.3%

Outages are getting rarer and more expensive

Uptime Institute’s eighth Annual Outage Analysis, released on 13 May 2026, reports that outage rates per site have declined for the fifth consecutive year, but that “the pace of improvement has slowed”. The cost distribution is the part to pin to the wall: 57% of respondents said their most recent major outage cost more than $100,000, and “for the second consecutive year, 1 in 5 reported costs exceeding $1 million”. Around one in ten said their last outage had serious or severe impacts.

On causes, Uptime is blunt: power remains the leading cause of impactful outages, with “failures involving UPS systems, transfer switches and generators” dominant. External infrastructure is rising, and “outages linked to fiber and connectivity issues are rising” and are more likely to cause extended disruption. Where humans are the cause, “failures to follow established procedures remain the leading driver” — which is an argument for a rehearsed hotel business continuity plan rather than a longer one.

Reported cost and severity of the most recent major outage (Uptime Institute, May 2026)
Cost more than $100,000 — 57%
Cost more than $1 million — 20%
Serious or severe business impact — 10%

Three recent events every hotel plan should be tested against

The CrowdStrike update of 19 July 2024 is the purest hotel business continuity case study available, because nothing was hacked and nothing was flooded. A faulty Falcon configuration update went out at 04:09 UTC and was reverted at 05:27 UTC, but Microsoft estimated 8.5 million Windows devices were affected. In hotels the visible consequence was key-card encoders refusing to work, staff escorting guests to rooms by hand, and at least one property reduced to photocopying credit cards to complete check-outs. The last of those is a data protection incident invented on the spot by people with no procedure to follow.

The AWS US-EAST-1 event of 19 to 20 October 2025 shows the third-party version. AWS attributed it to “a latent race condition in the DynamoDB DNS management system that resulted in an incorrect empty DNS record for the service’s regional endpoint”, and the disruption ran roughly fourteen and a half hours across more than a hundred services. If your PMS, channel manager, door-lock platform or booking engine is hosted there, your hotel business continuity plan inherits that failure mode whether or not it is written down.

Storm Éowyn on 24 January 2025 is the physical version. Around a million homes and businesses lost power across the UK and Ireland at peak, with 715,000 in Ireland and more than 93,000 in Northern Ireland; 99% were reconnected by 27 January, but 5,200 were still off. A hotel with a generator traded. A hotel without one did not.

The switch-off nobody has budgeted for

The analogue telephone network is being withdrawn, with January 2027 the completion target for most customers. GOV.UK’s guidance notes that “2023 saw 20% more service incidents on the PSTN compared to 2022, resulting in a 60% increase in the number of service hours lost”, and warns that connected devices — alarm systems, telecare, lift alarms and card payment systems — must be checked individually, because “communications providers will not know which devices are connected to their network”.

The hotel business continuity sting is in the tail: digital landlines do not work in a power cut without battery backup, while the analogue line they replace did. Any hotel business continuity plan that assumes “the phones still work when the power goes” is describing a building that no longer exists.

System by System: What Hotel Business Continuity Can Still Rely On

hotel business continuity when technology goes offline e tent triangular shelter

The single most useful page in a hotel business continuity plan is a table of what genuinely keeps running. Most staff assume everything dies together. It does not.

Property management systems

A cloud PMS dies completely and instantly when the internet fails, and there is nothing local to fall back on. An on-premise PMS often survives a broadband failure — the local server and LAN are unaffected — but loses its interfaces first, so rates stop flowing from the channel manager while the screens still look normal. That intermediate state is more dangerous than a clean outage, because staff carry on trusting numbers that stopped updating an hour ago. The hotel PMS cyber security guide covers what that system holds; here the only question is what it does when it goes quiet.

Oracle’s OPERA Cloud documentation names the reports worth printing nightly for exactly this scenario: Arrivals: Detailed (res_detail), Arrivals and Checked In Today (arrchkinbyroom), Routing Details (routing_details), Membership Pre-Check (arrprecheckinmem), Arrivals with Scheduled Activities (resarr_activities), and the Police report (police_report), which is described as printed daily for all guests whose check-in date equals the business date. That last one is a hotel business continuity artefact and a compliance artefact at the same time.

Point of sale

Oracle Simphony is unusually well documented here and worth understanding even if you run something else, because the architecture is typical. The Check and Posting Service, CAPS, “is a required service that runs on-premises at the property” and “acts as the bridge between the Enterprise and the property, providing resiliency”. The consequence is the good news of the whole article: “in the event of a WAN outage, POS clients are largely unaffected as they continue to post transactions to the on-premises CAPS”, and “when the WAN connection is restored, CAPS posts the information to the Enterprise”.

Below that, Simphony distinguishes two degraded states. In yellow mode “the workstation can communicate with other workstations and services”, typically because the property has lost contact with the central database over the wide area network. In red mode “the workstation cannot communicate with other workstations or services” — a genuinely isolated till. Reporting is degraded in both. Knowing which colour you are in tells the F&B manager whether to keep taking orders on the screen or move to paper, and that single distinction saves an evening. Our hotel POS security guide covers the security side of the same estate.

Doors, locks and keys

This is the reassuring one. Electronic hotel locks are almost always battery powered and take their access decisions at the door, from data written onto the card, so the locks themselves keep working when the network and the mains do not. What fails is the encoder at reception, because it needs a working PC and usually a live link to the PMS. So existing guests can get into their rooms and new arrivals cannot get a key. That is the exact failure the CrowdStrike outage produced, and it is solved with pre-encoded master and floor cards held in the duty manager’s safe plus a controlled mechanical override key.

SystemWhat it depends onWhat fails firstWhat keeps workingManual fallback
Cloud PMSInternet and browserEverything, at onceNothing localPrinted arrivals, registration cards
On-premise PMSLocal server and LANInterfaces, then screensLocal terminals if the server livesSame, plus a frozen rate sheet
POS with on-site CAPSLocal service and till networkEnterprise reportingOrdering and posting to CAPSPaper dockets and a manual tab list
Payment terminalsBroadband or mobile dataOnline authorisationOffline floor-limit authorisationStandalone 4G terminal, pay-by-link
Door locksBattery at the doorThe encoder at receptionEvery lock in the buildingPre-encoded masters, mechanical override
Guest WiFiISP, controller, portalPortal authenticationNothing useful to the guestSignage, mobile data, honest apology
VoIP phonesBroadband and mains powerAll internal and external callsNothing without battery backupMobiles and a printed contact tree
Lift alarm and fire panel linesPSTN or IP signallingAutomatic dial-out to the monitorLocal sounders and panelManned point, waking watch
CCTV and recorderMains power and networkRemote viewing and alertsLocal recording while poweredManned patrol, incident log by hand

The Business Impact Analysis Behind a Hotel Business Continuity Plan

hotel business continuity when technology goes offline f megaphone wide cone

The business impact analysis is where hotel business continuity stops being a document and starts being a set of decisions. It asks one question of every function: how long can this stop before the damage is unacceptable?

Rank hotel business continuity by function, not by system

IT plans list systems. A hotel business continuity plan lists functions, because a function can often be delivered a different way. “Check a guest in” survives without a PMS. “Take a card payment” survives without the fixed broadband. “Signal a lift entrapment to a monitoring centre” does not survive without a working line, which is why it sits at the top of the list and gets a different kind of answer.

Set MTPD first, then work the RTO inwards

Agree the maximum tolerable period of disruption with the general manager, in the language of the business — refunded bookings, refused check-ins, a licensing or safety failure — and only then ask IT what recovery time they can actually deliver. Doing it the other way round produces a plan built around whatever the current backup product happens to do.

Hotel functionMTPDRTO targetRPO targetManual fallback viable?
Fire and life-safety signallingZeroImmediateNot applicableNo — waking watch or evacuate
Card payment authorisation2 hours30 minutesZeroPartly — standalone terminal
Room key issue for arrivals4 hours1 hourNot applicableYes — pre-encoded cards
Food and beverage ordering8 hours2 hours4 hoursYes — paper dockets
Guest check-in and check-out12 hours4 hours1 hourYes — printed arrivals pack
Channel manager and OTA rates24 hours8 hours4 hoursPartly — manual extranet edits
Housekeeping allocation24 hours8 hours24 hoursYes — printed room list
Night audit and reporting48 hours24 hours24 hoursYes — defer and catch up

Write the hotel business continuity dependency behind each row

Every row above hides a dependency that belongs in the hotel business continuity plan: which supplier, which contract, which phone number, which account. A hotel business continuity plan that says “restore the PMS” without naming the vendor’s out-of-hours number and the account reference they will ask for is a plan that costs you forty minutes at the worst possible time. The groundwork for this lives in the hotel network design blueprint and the hotel VLAN design guide, both of which document what depends on what.

The First Sixty Minutes of a Hotel Business Continuity Event

Most of the damage in an outage is done in the first hour, and almost none of it is technical. It is caused by nobody deciding anything.

Minute zero to ten: declare or stand down

Somebody has to say the words “this is an incident” out loud. Until that happens, three departments each quietly assume IT is on it and carry on trying to work normally, which is how a fifteen-minute glitch becomes a two-hour queue. Give the duty manager unambiguous authority to declare, and make it explicit that declaring wrongly costs nothing.

Minute ten to thirty: switch modes, then communicate

Reception opens the printed pack. F&B moves to dockets. Maintenance checks power, the comms room and the UPS. Nobody waits for a diagnosis, because hotel business continuity is not conditional on knowing the cause. The general manager gets one message with four facts: what is down, what still works, what we are doing, when we will next update.

Minute thirty to sixty: hold the line and set the clock

By the end of the first hour there should be a named person owning the timeline, a stated next-update time, and a decision about whether to keep selling. A hotel that keeps taking bookings it cannot honour turns a systems outage into a customer service failure that outlives the fix by weeks.

RoleFirst action, 0–10 minutesDecision they ownWho they tell
Duty managerDeclare the incident or stand it downWhether this is an incident at allGM and every head of department
Reception leadOpen the printed arrivals packCheck-in method and queue handlingDuty manager
Food and beverage leadMove service to paper docketsContinue, limit or pause serviceDuty manager and kitchen
MaintenanceCheck mains, UPS and comms roomWhether the cause is physicalDuty manager
IT or managed providerTriage and give a first timelineRecovery route and order of restoreDuty manager, then GM
General managerOwn the clock and the messageCompensation and whether to keep sellingOwner, brand, insurer
Night manager, out of hoursAll of the above, condensedWhen to wake the general managerGM, by phone, not by email

Hotel Business Continuity at Reception: Running Without a PMS

Reception is where an outage becomes visible, so this is the procedure to write first and rehearse hardest.

The printed pack is the whole hotel business continuity trick

At the end of every night audit, print and file four things: tomorrow’s detailed arrivals with rates and payment method, the current in-house list by room, the departures list, and the room status report from housekeeping. Store them in a locked drawer at reception and shred the previous set. With those four sheets a competent front office can run for a full day. Without them, the team is reconstructing the hotel from memory and OTA emails.

Check in on paper, in a fixed sequence

Find the guest on the printed arrivals sheet, complete a paper registration card capturing the details the Immigration (Hotel Records) Order requires, allocate a room from the printed status list and cross it off on the master copy only, issue a pre-encoded key or escort the guest, take payment by whichever fallback is live, and put the card in a numbered downtime folder. One master copy, one person allowed to write on it. Double allocations are the most common self-inflicted injury in hotel business continuity, and they come from two people working off two copies.

Say something honest and early

Guests forgive outages and remember being lied to. A short sign at the desk and a line for the team to use — what is affected, what it means for them, what you are doing — is worth more than any technical fix in the first hour. Train the team to avoid the word “hacked” unless the general manager has confirmed it, and to avoid promising a restoration time nobody has given them.

Protect the data you are creating

Paper registration cards, printed arrivals and handwritten payment notes are personal data the moment they exist. They need the same care as the database: locked storage during the incident, a numbered set so nothing goes missing, and cross-cut shredding once the details are back in the system. An outage that ends with a stack of guest details in a back-office tray has replaced a technology problem with an information governance one.

Taking Payment: Hotel Business Continuity at the Card Machine

Payment is the function with the shortest tolerance and the highest compliance risk, so it deserves its own rehearsed answer rather than improvisation at the desk.

Know which link has actually failed

A payment terminal can fail for three unrelated reasons: the hotel’s internet is down, the terminal’s own connection is down, or the acquirer is down. Each has a different answer, and the fastest diagnostic is a second terminal on a different connection. If a 4G terminal in the safe works while the counter terminal does not, the fault is yours; if neither works, it is upstream and you are waiting.

The four hotel business continuity payment fallbacks, in order of preference

FallbackWorks whenCompliance exposurePractical limit
Terminal offline authorisationTerminal has power, acquirer link is downLow — the card data stays in the terminalFloor limits apply; declines surface later
Standalone 4G terminalFixed line or broadband is downLow — separate path, same encryptionNeeds a live SIM and a tested merchant account
Pay-by-link to the guest’s phoneAny device with mobile dataLow — the guest keys their own cardSlow at a queue; needs guest cooperation
Manual key entry on a working terminalOne terminal is aliveMedium — keyed entry, higher feesCard-not-present rules and chargeback risk
Writing the card number downGenuinely nothing else worksHigh — paper card data in full scopeLocked storage, shredding, never the CVV

The rule that stops an outage becoming a breach

If you end up with card details on paper, PCI DSS requirement 9.4 governs what happens next: paper media with account data must be stored securely, for example in a locked drawer, cabinet or safe, and destroyed by cross-cut shredding, incineration or pulping when it is no longer needed, so the data cannot be reconstructed.

The absolute hotel business continuity rule is simpler still — never write down the card security code printed on the signature strip, because sensitive authentication data must not be retained after authorisation under any circumstances. Photocopying a card, as happened during the CrowdStrike outage, breaks both rules at once. Our PCI DSS for hotels guide covers the wider obligation.

Decide the money questions before the day

Who may authorise a guest leaving without paying? What is the maximum tab you will carry? Do you take a signature and a phone number, or nothing at all? A hotel business continuity plan that leaves those to a 22-year-old on a night shift is not a plan, it is a hope.

Doors, Keys and Life Safety in a Hotel Business Continuity Plan

Two of these are inconvenient. One of them is not negotiable.

Keys are a hotel business continuity kit item, not an improvisation

Hold a controlled set of pre-encoded master and floor cards in the duty manager’s safe, signed in and out, replaced on a fixed cadence. Hold the mechanical override key under the same control, because it opens every door in the building and is therefore the single highest-value object in your hotel business continuity kit. Test both quarterly on a real door, not on a spreadsheet.

Lifts and entrapment

Lift alarms traditionally auto-dial a monitoring centre over an analogue line. As those lines are withdrawn, the failure mode changes: the alarm may still sound locally while nobody outside hears it. Confirm in writing what your lift alarm uses, what happens when its connection fails, and what your manned alternative is. During any outage where signalling is uncertain, a physical check regime is the answer.

Fire systems override everything

If the fire panel’s signalling path is down, the response is procedural and immediate: notify the alarm receiving centre, put a waking watch or manned point in place per your fire risk assessment, and record the decision and the times. This is the one row of the impact analysis with an MTPD of zero and no manual workaround that trades. Everything else in hotel business continuity can wait an hour; this cannot wait five minutes.

Communications: The Loudest Part of Hotel Business Continuity

When the systems are down, the volume of questions goes up and the means of answering them goes down.

Assume the phones are part of the outage

Almost every UK hotel is now on voice over IP, which means the phone system shares a fate with the broadband and the mains. Hotel business continuity therefore needs a printed contact tree — mobile numbers for every head of department, the general manager, the IT provider, the PMS and POS vendors with account references, the acquirer, the lock supplier, the lift company and the alarm receiving centre. Print it, keep a copy off site, and refresh it quarterly. A contact list that lives only in a cloud address book is not a contact list.

Three audiences, three messages

Guests in the building need to know what still works and what to do about breakfast, keys and checkout. Guests not yet arrived need to know whether to come, and by what channel you will confirm. Staff need to know who is deciding and when the next update is. Sending one message to all three produces a message that helps none of them.

The OTA channel is a hotel business continuity risk in itself

If the channel manager stops updating, availability keeps selling on the OTAs while you have no way to see it. Decide in advance whether you close availability manually in each extranet — and who holds those logins — or accept overbooking and manage it on arrival. Both are defensible; discovering you never chose is not. Email compromise adds a second dimension here, covered in the phishing attacks against hotels guide, because an outage is exactly when a convincing “urgent payment” message lands.

Guest WiFi will be the loudest complaint

It is also the least consequential. Have a sign, have a line, and have the honesty to say it is out. The hotel WiFi security and hotel WiFi upgrade cost guides cover making it resilient in the first place; during an incident, the only sensible action is to stop people asking the same question forty times.

Food, Beverage and Housekeeping Under Hotel Business Continuity

Rooms get the attention, but the departments that keep a hotel feeling normal during an outage are the ones with the fewest screens.

Food and beverage runs on paper better than anything else

Duplicate dockets, a numbered tab sheet at the bar, a fixed limited menu agreed in advance and a written record of every table are all that is needed for a full service. The two failure points are pricing and posting: without the POS, staff need a printed price list, and every docket must be captured for later entry. Agree the limited menu before the incident, not during it, and keep a printed copy with the dockets.

Housekeeping needs one printed list and one runner

A printed room status list plus a nominated runner between reception and floors replaces the handheld system entirely. It is slower, and it works. The discipline is the same as at reception: one master copy of the list, one person writing on it.

Stock, deliveries and the kitchen

Chilled and frozen stock are a hotel business continuity issue in a power event, not a data one. Know which units are on the generator or UPS, know your temperature-recording fallback, and know at what point stock is condemned. This belongs in the hotel business continuity plan because the decision is expensive and time-limited, and because the person who has to make it at 2am should not be discovering the policy then.

The Hotel Business Continuity Downtime Kit

The kit is the difference between a plan that exists and a plan that works. It is cheap, physical, and needs an owner and a cadence or it silently rots.

ItemWhere it livesRefresh cadenceWho checks it
Printed arrivals, in-house and departuresLocked reception drawerEvery night auditNight manager
Blank registration cards and foldersLocked reception drawerMonthlyFront office manager
Pre-encoded master and floor key cardsDuty manager safe, signed outWeeklyDuty manager
Mechanical override keyControlled key safeQuarterly test on a real doorGeneral manager
Charged standalone 4G card terminalReception safeWeekly test transactionFront office manager
4G router with an active SIMComms room and receptionMonthly failover testIT or managed provider
Printed contact tree with account refsReception, back office, off siteQuarterlyGeneral manager
Paper dockets, tab sheets, price listKitchen pass and barMonthlyFood and beverage manager
Torches and spare batteriesReception and comms roomQuarterlyMaintenance
Printed downtime procedure, one page per roleEvery departmentAfter every exerciseDuty manager

Hotel business continuity is one page per role, not one binder

Nobody reads a ninety-page plan during an incident. The usable form of hotel business continuity is a single laminated page per role, written in the imperative, listing the first five actions and the three phone numbers that matter. The long document exists for auditors and for the annual review; the laminated page exists for the event.

Give the kit an owner and a date

Every row in the table above has a named owner and a cadence for a reason. Kits fail quietly: the terminal battery dies, the SIM lapses, the contact tree lists someone who left in March, the printed pack is nine months old. A five-minute monthly check by a named person is the cheapest line in the whole budget.

Coming Back Up: The Hotel Business Continuity Recovery Phase

The outage ending is not the incident ending. The hours after restoration are where the revenue is actually lost.

Reconcile in a fixed hotel business continuity order

Enter arrivals and registrations first so the in-house list is right, then charges and payments, then housekeeping status, then anything deferred. Doing payments before arrivals produces charges with nowhere to post. Nominate one person to own the reconciliation and give them the numbered downtime folders in sequence.

Expect the interfaces to fight you

Rates, availability and third-party feeds all resume with stale data, and the channel manager may push yesterday’s picture back out. Check availability and rates in each extranet by hand before trusting the automated feed again — this is the step most often skipped, and it is where overbookings and rate errors are born.

Destroy the paper properly

Once every registration card and payment note is in the system, cross-cut shred the lot. Record that you did it, and when. This closes the loop that PCI DSS requirement 9.4 opens, and it is the item most likely to be forgotten during the relief of being back online.

Debrief within seven days

Hold a short review while people still remember: what worked, what was missing from the kit, which phone number was wrong, which decision took too long. Then change the hotel business continuity plan. An undebriefed incident teaches nothing, and Uptime Institute’s finding that failures to follow established procedures remain the leading human cause of outages is really a finding about procedures nobody rehearsed.

Testing a Hotel Business Continuity Plan Without Closing the Hotel

Testing is the requirement people skip, and the one both UK GDPR Article 32 and PCI DSS 12.10.2 explicitly ask for.

The three-level hotel business continuity test ladder

A desktop walkthrough takes an hour and checks that the hotel business continuity plan matches the building: names, numbers, systems, ownership. A tabletop exercise takes half a day and puts department heads through a scenario with injects and a clock. A live drill takes a shift and actually switches reception to the printed pack for two hours on a quiet Tuesday. Most properties should run one walkthrough a quarter, one tabletop a year, and one live drill a year.

Hotel business continuity scenarios worth using

Rotate them so the hotel business continuity plan is not tuned to one failure: broadband down for six hours with the PMS in the cloud; a power cut with the generator failing to start; ransomware with the systems intact but untrusted; a supplier outage where nothing of yours is broken; and a payment-only failure on a Saturday night. The supplier scenario is the one most plans handle worst, because there is nothing to fix and no one to phone.

Measure something

Time to declare, time to switch reception to paper, number of guests checked in per hour on paper, time to first guest communication, and time to complete reconciliation afterwards. Numbers make the next hotel business continuity exercise comparable, and they turn “we should do better” into a target.

Fold it into what you already do

If you are working through Cyber Essentials for hotels or a Microsoft 365 for hotels hardening project, the hotel business continuity exercise costs far less bolted onto that work than run as a separate initiative. The same is true of a hotel ransomware tabletop, which shares most of its script.

What Hotel Business Continuity Costs Against What an Outage Costs

Numbers make this decision quickly. The model below uses a 112-bedroom regional UK property and Knight Frank’s regional UK dashboard figures — 75.9% occupancy, ADR £107.50, TRevPAR £124.70, GOPPAR £38.50.

The property’s baseline

At 112 bedrooms and TRevPAR of £124.70, total revenue is £13,966.40 a day (112 × £124.70), and gross operating profit is £4,312.00 a day (112 × £38.50). Spread across twenty-four hours of trading, that is £581.93 an hour. The property sells 31,028 occupied room nights a year (112 × 365 × 75.9%).

What an outage costs at this size

112-bedroom property: total revenue exposed by outage length
12 hours — £6,983.20
1 day — £13,966.40
3 days — £41,899.20
7 days — £97,764.80

Those are the ceilings, not the losses. What hotel business continuity changes is the fraction of that ceiling you actually forfeit. Take a three-day outage. A property with no manual procedures, no printed pack and no payment fallback loses perhaps 60% of total revenue across those days — £25,139.52. A property that switches to a rehearsed manual mode within an hour loses perhaps 15% — £6,284.88. The difference, £18,854.64, is what the preparation is worth in a single event.

Three-day outage at the modelled property: prepared against unprepared
No manual procedures, 60% of revenue lost — £25,139.52
Rehearsed manual mode, 15% of revenue lost — £6,284.88

What the preparation costs

LineOne-offAnnual
Business impact analysis and plan writing£2,400—
Printed downtime packs, folders, stationery£180—
Two 4G routers with automatic failover£880—
Standalone 4G card terminal£320—
Manual payment stationery and secure folder£145—
UPS for reception and the comms room£1,450—
First facilitated tabletop exercise£1,200—
Mobile data SIMs for routers and terminal—£468
Backup terminal rental and scheme fees—£240
Two live drills a year—£1,600
Plan maintenance and quarterly pack refresh—£950
UPS battery testing and replacement provision—£310
Totals£6,575£3,568

Year one therefore costs £10,143, and every year after that costs £3,568. Per bedroom that is £90.56 in year one and £31.86 thereafter. Per occupied room night it is 32.7 pence in year one and 11.5 pence thereafter — less than the cost of the shortbread on the tray.

Where the year-one hotel business continuity budget goes
Plan, analysis and printed documentation — £3,530
Exercises and live drills — £2,800
Connectivity and payment fallback — £2,053
Power resilience — £1,760

The hotel business continuity comparison in one line

The £18,854.64 that preparation saves in a single three-day outage is 1.86 times the entire year-one budget and 5.28 times the annual running cost. Even if the property never has a three-day outage, one twelve-hour event handled well covers the annual figure. That is the whole hotel business continuity business case, and it does not depend on anybody being attacked.

Ten Mistakes That Break a Hotel Business Continuity Plan

These are the recurring ones, in roughly the order they cause damage.

One: assuming the IT plan covers hotel business continuity

A disaster recovery plan describes system restoration. It does not tell reception how to check in a coach party on paper. Both are needed, and they are written by different people.

Two: keeping hotel business continuity only in the cloud

A hotel business continuity plan stored in SharePoint or a shared drive is unreachable in exactly the scenario it was written for. Print it, and keep one copy off site.

Three: never printing the arrivals pack

This is the highest-value, lowest-cost control in the article, and it is missed more often than any other. It costs a printer and a locked drawer.

Four: a contact tree that is out of date

Numbers change, people leave, vendors get acquired. A quarterly refresh takes fifteen minutes and saves forty at the worst moment.

Five: no payment fallback that has ever been tested

A standalone terminal in a safe with a lapsed SIM is worse than nothing, because the team believes they have an answer.

Six: treating paper as outside the rules

Registration cards and payment notes are personal and cardholder data. Lock them, number them, shred them, and never record the security code.

Seven: forgetting the interfaces on the way back up

Restoring the PMS is not the end. Rates, availability and OTA feeds all need checking by hand before you trust them again.

Eight: one hotel business continuity plan for two very different buildings

Scope hotel business continuity to the property. Group templates are a starting point, not a substitute for knowing this building’s lift line and this building’s generator.

Nine: no authority to declare

If only the general manager can declare an incident and the general manager is asleep, hotel business continuity starts at 8am. Give the duty manager the authority and the words.

Ten: never testing, because the hotel is always busy

The hotel will always be busy. A two-hour live drill on a quiet Tuesday is the cheapest insurance premium in the building, and it is the one thing that turns a written plan into something that works when reception is dark and the phones are silent.

Hotel Business Continuity: Frequently Asked Questions

How long does it take to write a hotel business continuity plan?

For a single property, expect two to three days of focused work: half a day of business impact analysis with the heads of department, a day drafting the manual procedures and role cards, and half a day building and stocking the downtime kit. The first tabletop exercise adds another half day and always produces changes.

Do we need ISO 22301 certification?

Almost no independent hotel needs the certificate. The value is in the vocabulary and the structure — MTPD, RTO, the impact analysis, the testing cycle. Borrow those, and certify only if a corporate client or brand standard actually requires it.

Who should own hotel business continuity, IT or operations?

Operations, with IT as a major contributor. A hotel business continuity plan is about how the building trades, and the decisions in it — whether to keep selling, what to comp, when to declare — belong to the general manager. IT owns the recovery plan that sits alongside it.

What is the single most valuable thing to do first?

Print the arrivals, in-house and departures lists at every night audit and file them in a locked drawer. It costs almost nothing, requires no project, and it is the difference between running the hotel and reconstructing it.

How often should a hotel business continuity plan be tested?

At minimum annually, which is what PCI DSS 12.10.2 requires for the incident response plan that includes continuity, and what UK GDPR Article 32 implies through its testing duty. A quarterly desktop walkthrough plus one live drill a year is the realistic target for a single property.

Does a cloud PMS make us more or less resilient?

Both. A cloud PMS removes the on-site server failure mode and gives you a vendor with real engineering behind it, but it makes your connectivity the single point of failure and hands part of your continuity to a third party. Dual connectivity with automatic 4G failover is the mitigation, and it is why the Microsoft 365 setup for hotels work and the hotel business continuity work belong in the same conversation.

What should we tell guests during an outage?

What is affected, what it means for them specifically, what you are doing, and when you will next update. Avoid speculation about causes, avoid the word “hacked” until it is confirmed, and never quote a restoration time you were not given in writing.

Is business continuity the same conversation as cybersecurity?

They overlap but they are not the same. Good cybersecurity reduces how often you need the hotel business continuity plan; that plan is what carries the business through everything else — power, weather, suppliers, faulty updates. Most properties are better protected by doing a competent job of both than an excellent job of either. Tools like Microsoft Copilot for hotels and better captive portal security belong to the first conversation; the printed pack belongs to the second.

Where to Start With Hotel Business Continuity This Week

If a hotel business continuity plan does not exist yet, three actions this week will move a property further than a quarter of meetings. Start printing the arrivals pack tonight. Put a charged standalone card terminal and a set of pre-encoded master keys in the safe tomorrow. Book a two-hour tabletop exercise for a quiet week, and invite the general manager, the front office manager, the food and beverage manager, maintenance and the IT provider.

Everything else in hotel business continuity is refinement. Those three cover the functions with the shortest tolerance, cost under two thousand pounds between them, and can be done without a project plan. If you want help building the impact analysis or running the first exercise, our IT support for hotels and hospitality team does exactly this work, and the VLAN segmentation and captive portal attacks guides cover the network groundwork that makes the whole estate easier to keep running.

References

BS EN ISO 22301:2019 Security and resilience. Business continuity management systems. Requirements

Complex and Interconnected Risk: The BCI Horizon Scan 2025

BCI Horizon Scan Report 2025

Uptime Announces Annual Outage Analysis Report 2026

Uptime Institute Annual Data Center Outages Analysis 2026

Uptime Intelligence: Annual Outage Analysis 2026

UK GDPR Article 32: Security of processing

The Immigration (Hotel Records) Order 1972

Terrorism (Protection of Premises) Act 2025

PCI Security Standards Council: PCI Data Security Standard

PCI Security Standards Council: Point-to-Point Encryption

GOV.UK: UK transition from analogue to digital landlines

Openreach: Time for a big switch up as PSTN switch off looms

Oracle OPERA Cloud: Arrivals Reports

Oracle Simphony: Check and Posting Service (CAPS)

Oracle Simphony: Workstation Online and Offline Modes

Oracle Hospitality Integration Platform Overview

AWS Post-Event Summary: Service Disruption in the Northern Virginia Region

2024 CrowdStrike-related IT outages

Met Office: Amber weather warning issued as Storm Eowyn approaches

NCSC: Incident Management

NCSC: Small Organisations Guide to Cyber Security

NCSC: Cyber Essentials Overview

NCSC: 10 Steps to Cyber Security

NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations

ICO: Personal data breaches, a guide

ICO: A guide to data security

Cyber Security Breaches Survey 2025/2026

Trustwave 2025 Risk Radar Report: Hospitality Sector

IBM Cost of a Data Breach Report

Knight Frank UK Hotel Dashboard

Knight Frank Hotels Research

Microsoft Lifecycle: Windows Server 2016

BS EN ISO/IEC 27001:2022 Information security management systems. Requirements

UKHospitality