Skip to main content
MicroNet Global

Cyber Security

Hospitality cyber security: the attack paths that actually get used

The attack paths actually used against hotel and restaurant groups, the defences that work, and what to do in the first hour of a suspected incident.

7 min readBy the MicroNet Global team

Hospitality cyber security fails most often through people and third parties, not exotic technical flaws: phishing aimed at finance, social engineering of help desks, and vendor remote access into venues. MicroNet Global secures hotel, restaurant and club estates across the UK, US and UAE, where high staff turnover and shared networks widen the attack surface.

What is an attack path?

An attack path is the route an attacker takes from first contact to their objective, usually money or data. It is rarely a single clever exploit. In hospitality it is typically a chain: a convincing email, a reused password, a poorly separated network and a system nobody owns, joined together until it reaches finance or guest records. Break any link and the path fails.

Credential phishing and business email compromise

The highest-value target in most hospitality groups is not the venue. It is the finance inbox. Attackers impersonate suppliers, landlords and senior leaders, and the request is always plausible: an updated bank account, an urgent deposit, a payroll change before a bank holiday.

Defences that hold: phishing-resistant multi-factor authentication on all mailboxes, a written rule that bank detail changes are confirmed by a call to a number already on file, mail flow rules that flag external senders and lookalike domains, and alerting on mailbox forwarding rules. The verification rule matters most, because it works even when the email is convincing.

Social engineering of the help desk and front of house

Hospitality trains its people to be helpful, accommodating and fast. That is the right culture for guests and a hard one for security, particularly with seasonal and agency staff who cannot recognise every colleague by voice.

Attackers exploit this by posing as staff needing an urgent password reset, or as a contractor needing access. The defence is procedural: a documented identity check for every reset or access change, no exceptions for urgency or seniority, callback to a known number, and manager approval for anything privileged. Make it explicit that nobody is ever penalised for verifying. Our [[24/7 managed IT support desk]{.underline}](about:blank) applies a fixed standard because urgency is the pressure attackers use.

Remote access and third-party vendor connections

A single venue can carry a dozen suppliers with their own access: PMS, EPOS, kitchen display, AV and lighting, building management, CCTV, signage, music. Each was connected during fit-out, often by a different contractor, and each may still have a live route in.

Controls that work: an inventory of every third-party connection with a named internal owner, access brokered through your own gateway rather than vendor-installed tools, MFA and time-limited sessions, and logging of who connected and when. Review the list annually. Integration work is where these paths appear, which is why [[what breaks in PMS and EPOS integrations]{.underline}](about:blank) is also a security question.

Unmanaged and end-of-life devices

Venue estates accumulate hardware: a back-office PC behind a door, a manager's laptop, a kiosk, a tablet on the pass. Unmanaged devices receive no patches, carry no monitoring and sit on the same network as everything else.

The defence is unglamorous. Keep an asset register per site, enrol every device in management, and fund a replacement cycle rather than replacing on failure. Operating systems past support are a standing risk, and the [[Windows 10 end of support position for venues]{.underline}](about:blank) is the current example: unsupported devices should be isolated or replaced.

Ransomware reaching shared file stores and group finance

Ransomware in hospitality rarely starts in the till. It starts on a back-office machine, then spreads to shared drives holding rotas, HR files, supplier contracts and management accounts, and from there towards group finance systems.

What limits the damage: least-privilege access so one account cannot reach every share, network separation between venues and head office, immutable or offline backups tested by restoring them, and endpoint detection that is monitored rather than merely installed. Backups you have never restored are a plan you have never tested, the central argument in [[disaster recovery for multi-site hospitality]{.underline}](about:blank).

Exposed guest data in marketing and reservations platforms

Guest data spreads further than most operators expect: the booking engine, the CRM, email marketing tools, loyalty platforms, review software, and whatever a marketing agency uses. Much of it sits outside the estate your IT team manages.

Keep a register of every platform holding guest data, with its owner, retention period and access list. Enforce MFA on all of them, remove leavers on their last day, delete data you no longer need, and confirm contractually what any agency may hold. Most guest data incidents are access and retention failures rather than technical breaches.

The physical layer

The comms cupboard propped open during a delivery, the live network port in a public corridor, the reception PC left signed in. Physical access removes many of the barriers built into the network.

Lock comms rooms and control the keys. Disable unused ports, and never leave a live port accessible in a guest area. Enforce short screen-lock timeouts front of house, and require contractors to be signed in and escorted. These are cheap, visible during a walk-round, and consistently the last thing anyone checks.

Attack paths and defences at a glance

Attack pathWhat it targetsPrimary defence
Credential phishing / BECFinance inbox, supplier paymentsPhishing-resistant MFA, callback on bank changes
Help desk social engineeringAccount access via resetsDocumented identity checks, no urgency exceptions
Vendor remote accessPMS, EPOS, AV, BMSOwned inventory, brokered access, MFA, logging
Unmanaged / end-of-life devicesBack office, kiosks, tabletsAsset register, enrolment, funded replacement
RansomwareShared drives, group financeLeast privilege, segmentation, tested backups
Exposed guest dataCRM, booking, marketing toolsPlatform register, MFA, retention limits, leaver removal
Physical accessComms rooms, live ports, terminalsLocked rooms, disabled ports, escorted contractors

The first hour of a suspected incident

Speed matters, but so does evidence. Isolate affected devices from the network and leave them powered on, because shutting down destroys information investigators need. Do not delete suspicious messages or files.

Escalate to a named incident lead rather than a group chat, and open a written timeline from the first minute: who noticed what, when, and what was done. Preserve logs before anything is rebuilt. Assume email may be compromised, switch channels, and pause any outbound payment run. Decide early who speaks to staff, guests and suppliers.

Reporting duties in the UK

Where a breach involves personal data and poses a risk to individuals' rights and freedoms, UK GDPR requires notification to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware. If the risk is high, affected individuals must be told too. Card incidents also trigger obligations to your acquirer, as set out in the [[PCI DSS hospitality checklist]{.underline}](about:blank).

The Cyber Security and Resilience Bill is before Parliament and is not yet law. As drafted it would extend NIS-style oversight to managed service providers, data centres and designated critical suppliers, and proposes 24-hour initial notification with a 72-hour full report for in-scope entities. Watch its progress rather than assume it applies today. Reporting duties depend on your structure and sector, and legal advice is worth taking before an incident rather than during one. Our [[cyber security services]{.underline}](about:blank) cover the technical preparation.

Frequently asked questions

Credential compromise. An attacker obtains a working username and password through phishing or reuse, then signs in rather than breaking in. Because the login looks legitimate, it often goes unnoticed for weeks. Phishing-resistant multi-factor authentication on every account, especially finance and administrative ones, removes most of this risk at modest cost.

Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.

Keep reading

Related insights

All insights
New openings6 min read

The technology checklist for a new hospitality opening

The questions operators should answer before the opening team arrives on site, from connectivity and suppliers to handover and live support.

Read article
Managed IT5 min read

Why hospitality needs a different IT support model

Hospitality does not operate in office hours. A useful support model is built around service, sites and the commercial cost of disruption.

Read article
Cyber security7 min read

A practical guide to hospitality cyber security

A plain-English starting point for protecting guest data, payment systems and the people who keep venues running.

Read article
Managed IT7 min read

What hotel IT support actually covers, and what it doesn't

What hotel IT support covers: systems in scope, who owns the PMS and door locks, contract tiers, exclusions and how response targets really work.

Read article
Managed IT7 min read

Why PMS and EPOS integrations break, and how to catch it early

Why PMS and EPOS integrations fail: stopped interface services, expired certificates, room status and API changes, and the checks that catch silent errors.

Read article
Managed IT7 min read

In-house IT team or hospitality IT partner: an honest comparison

In-house IT team or outsourced hospitality IT partner? An even-handed comparison of cover, cost, breadth, openings and the co-managed middle ground.

Read article
Networks & Wi-Fi7 min read

Why guest Wi-Fi generates complaints, and how to design it out

Why guest Wi-Fi draws complaints in hotels and restaurants, and how to design it out --- surveys, AP placement, captive portals, segmentation and peak load.

Read article
Networks & Wi-Fi7 min read

Wi-Fi 7 and the 6 GHz band: what actually changed for venues in 2026

Ofcom opened the full 6 GHz band in July 2026. What Wi-Fi 7 changes for hotels, restaurants and clubs, what it costs, and when waiting is the better call.

Read article
Managed IT7 min read

Disaster recovery when there are 180 covers booked tonight

Business continuity for hotels and restaurants with covers booked tonight. RTO and RPO explained, the failure scenarios that happen and what restores service.

Read article
Compliance7 min read

PCI DSS for restaurants and hotel groups: the practical checklist

A practical PCI DSS checklist for multi-site restaurants and hotels: who enforces it, scope reduction, segmentation, phone orders and v4.x deadlines.

Read article
Compliance7 min read

Martyn's Law for venues: what it requires, and where technology helps

What Martyn's Law means for hospitality operators: the standard and enhanced tiers, the SIA's role, and where technology genuinely supports the duties.

Read article
Openings & Rollouts7 min read

The IT critical path for opening a restaurant, hotel or club

A week-by-week IT timeline for opening a restaurant, hotel or club, from circuit lead times and cabling first fix to soft launch and day-one support.

Read article
Managed IT7 min read

Microsoft 365 when most of your workforce never sits at a desk

How to licence Microsoft 365 across hotel and restaurant teams, covering frontline worker tiers, shared device sign-in, identity, offboarding and backup.

Read article
Managed IT7 min read

Windows 10 end of support: the estate you cannot see

Windows 10 support ended in October 2025 and ESU Year 1 expires this October. A practical refresh plan for back-office, EPOS-adjacent and AV control PCs.

Read article

Put this into practice

Services and sectors this touches

Secure, scalable and seamless IT wherever hospitality takes you.