Cyber Security
Hospitality cyber security: the attack paths that actually get used
The attack paths actually used against hotel and restaurant groups, the defences that work, and what to do in the first hour of a suspected incident.
Hospitality cyber security fails most often through people and third parties, not exotic technical flaws: phishing aimed at finance, social engineering of help desks, and vendor remote access into venues. MicroNet Global secures hotel, restaurant and club estates across the UK, US and UAE, where high staff turnover and shared networks widen the attack surface.
What is an attack path?
An attack path is the route an attacker takes from first contact to their objective, usually money or data. It is rarely a single clever exploit. In hospitality it is typically a chain: a convincing email, a reused password, a poorly separated network and a system nobody owns, joined together until it reaches finance or guest records. Break any link and the path fails.
Credential phishing and business email compromise
The highest-value target in most hospitality groups is not the venue. It is the finance inbox. Attackers impersonate suppliers, landlords and senior leaders, and the request is always plausible: an updated bank account, an urgent deposit, a payroll change before a bank holiday.
Defences that hold: phishing-resistant multi-factor authentication on all mailboxes, a written rule that bank detail changes are confirmed by a call to a number already on file, mail flow rules that flag external senders and lookalike domains, and alerting on mailbox forwarding rules. The verification rule matters most, because it works even when the email is convincing.
Social engineering of the help desk and front of house
Hospitality trains its people to be helpful, accommodating and fast. That is the right culture for guests and a hard one for security, particularly with seasonal and agency staff who cannot recognise every colleague by voice.
Attackers exploit this by posing as staff needing an urgent password reset, or as a contractor needing access. The defence is procedural: a documented identity check for every reset or access change, no exceptions for urgency or seniority, callback to a known number, and manager approval for anything privileged. Make it explicit that nobody is ever penalised for verifying. Our [[24/7 managed IT support desk]{.underline}](about:blank) applies a fixed standard because urgency is the pressure attackers use.
Remote access and third-party vendor connections
A single venue can carry a dozen suppliers with their own access: PMS, EPOS, kitchen display, AV and lighting, building management, CCTV, signage, music. Each was connected during fit-out, often by a different contractor, and each may still have a live route in.
Controls that work: an inventory of every third-party connection with a named internal owner, access brokered through your own gateway rather than vendor-installed tools, MFA and time-limited sessions, and logging of who connected and when. Review the list annually. Integration work is where these paths appear, which is why [[what breaks in PMS and EPOS integrations]{.underline}](about:blank) is also a security question.
Unmanaged and end-of-life devices
Venue estates accumulate hardware: a back-office PC behind a door, a manager's laptop, a kiosk, a tablet on the pass. Unmanaged devices receive no patches, carry no monitoring and sit on the same network as everything else.
The defence is unglamorous. Keep an asset register per site, enrol every device in management, and fund a replacement cycle rather than replacing on failure. Operating systems past support are a standing risk, and the [[Windows 10 end of support position for venues]{.underline}](about:blank) is the current example: unsupported devices should be isolated or replaced.
Ransomware reaching shared file stores and group finance
Ransomware in hospitality rarely starts in the till. It starts on a back-office machine, then spreads to shared drives holding rotas, HR files, supplier contracts and management accounts, and from there towards group finance systems.
What limits the damage: least-privilege access so one account cannot reach every share, network separation between venues and head office, immutable or offline backups tested by restoring them, and endpoint detection that is monitored rather than merely installed. Backups you have never restored are a plan you have never tested, the central argument in [[disaster recovery for multi-site hospitality]{.underline}](about:blank).
Exposed guest data in marketing and reservations platforms
Guest data spreads further than most operators expect: the booking engine, the CRM, email marketing tools, loyalty platforms, review software, and whatever a marketing agency uses. Much of it sits outside the estate your IT team manages.
Keep a register of every platform holding guest data, with its owner, retention period and access list. Enforce MFA on all of them, remove leavers on their last day, delete data you no longer need, and confirm contractually what any agency may hold. Most guest data incidents are access and retention failures rather than technical breaches.
The physical layer
The comms cupboard propped open during a delivery, the live network port in a public corridor, the reception PC left signed in. Physical access removes many of the barriers built into the network.
Lock comms rooms and control the keys. Disable unused ports, and never leave a live port accessible in a guest area. Enforce short screen-lock timeouts front of house, and require contractors to be signed in and escorted. These are cheap, visible during a walk-round, and consistently the last thing anyone checks.
Attack paths and defences at a glance
| Attack path | What it targets | Primary defence |
|---|---|---|
| Credential phishing / BEC | Finance inbox, supplier payments | Phishing-resistant MFA, callback on bank changes |
| Help desk social engineering | Account access via resets | Documented identity checks, no urgency exceptions |
| Vendor remote access | PMS, EPOS, AV, BMS | Owned inventory, brokered access, MFA, logging |
| Unmanaged / end-of-life devices | Back office, kiosks, tablets | Asset register, enrolment, funded replacement |
| Ransomware | Shared drives, group finance | Least privilege, segmentation, tested backups |
| Exposed guest data | CRM, booking, marketing tools | Platform register, MFA, retention limits, leaver removal |
| Physical access | Comms rooms, live ports, terminals | Locked rooms, disabled ports, escorted contractors |
The first hour of a suspected incident
Speed matters, but so does evidence. Isolate affected devices from the network and leave them powered on, because shutting down destroys information investigators need. Do not delete suspicious messages or files.
Escalate to a named incident lead rather than a group chat, and open a written timeline from the first minute: who noticed what, when, and what was done. Preserve logs before anything is rebuilt. Assume email may be compromised, switch channels, and pause any outbound payment run. Decide early who speaks to staff, guests and suppliers.
Reporting duties in the UK
Where a breach involves personal data and poses a risk to individuals' rights and freedoms, UK GDPR requires notification to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware. If the risk is high, affected individuals must be told too. Card incidents also trigger obligations to your acquirer, as set out in the [[PCI DSS hospitality checklist]{.underline}](about:blank).
The Cyber Security and Resilience Bill is before Parliament and is not yet law. As drafted it would extend NIS-style oversight to managed service providers, data centres and designated critical suppliers, and proposes 24-hour initial notification with a 72-hour full report for in-scope entities. Watch its progress rather than assume it applies today. Reporting duties depend on your structure and sector, and legal advice is worth taking before an incident rather than during one. Our [[cyber security services]{.underline}](about:blank) cover the technical preparation.
Frequently asked questions
Credential compromise. An attacker obtains a working username and password through phishing or reuse, then signs in rather than breaking in. Because the login looks legitimate, it often goes unnoticed for weeks. Phishing-resistant multi-factor authentication on every account, especially finance and administrative ones, removes most of this risk at modest cost.
Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.
