Skip to main content

Home/ Hospitality Technology/ Group items tagged cyber-security

Rss Feed Group items tagged

anonymous

The Hospitality Industry Under Attack - 0 views

  • According to a study by the Ponemon Institute, the average consolidated total cost of a data breach is now $3.8 billion, representing a double-digit increase in recent years. In the United States, the country hardest hit by cybercrime, the average cost of a computer breach is now $6.5 million, well ahead of the global average.
  •  
    In order to combat cyber attacks within the hospitality industry, the National Restaurant Association and PCI Security Standards Council have partnered. They have created.. "Small Merchant Taskforce, which raises payment card security awareness for the hospitality industry." With cybercrime increasing it is a necessary step to take, not all businesses, especially small, can afford the "best" cyber security systems. This task force will help educate various members and help find solutions to protect businesses and customers. "A study by Verizon stated that 99 percent of breaches in 2014 were caused by known vulnerabilities with fixable patches." That being said, all business operators need to take the initiative and be proactive when it comes to handling customers' private information.
  •  
    I think one the biggest issues related to cyber attacks is that owners are not aware of the issue. So it is important to educate them and help them understand the importance to budget cyber security into their expenses. I am glad that the task force is taking that step to help protect business owners and customers from cyber attacks.
Cindy Saunders

Hotel Cyber-Security | Past Issues | Lodging Magazine - 0 views

  • Hotel cyber-security is facing increasing scrutiny from federal regulators. Case in point, last June the Federal Trade Commission sued Wyndham Worldwide hotels after apparently unsophisticated hackers allegedly stole the credit card information of more than 600,000 customers leading to a more than $10.6 million fraud loss.
  • So what are reasonable data security measures? The FTC itself has stated that the data security measures it considers reasonable “will depend on the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the information at issue.” In other words, it is nearly impossible to know if your data security is adequate until the FTC tells you it is inadequate. While data security has been a hallmark of compliance for healthcare providers and banks for more than a decade, the hospitality industry has not been subjected to the same regulatory framework.
  • Review your privacy policy immediately
  • ...4 more annotations...
  • Stay one step ahead.
  • Data security work is often outsourced
  • If there is a breach, act quickly and decisively
  • Ask your attorney and IT professional to work together
  •  
    This article discusses how banking and healthcare have been held to a historically high level of cyber security, but only recently has the hospitality industry. It highlights a cyber attack on Wyndham Hotels and their reluctant response to take corrective action. The article offers steps that a hospitality company should take to protect themselves as they launch and work to protect their guests, their information and their company.
jlewinsky

Hotels: Are Your Cyber Defenses Ready for 2021? | Hospitality Technology - 0 views

  • Two of the top five biggest data breaches made public in 2020 were at hotel chains. Attackers stole personal information including names, emails and addresses from 5.2 million guests at Marriott and 10.6 million guests of MGM Resorts.
  • To ensure a swift recovery from COVID-19, the hospitality industry must shore up its cybersecurity protections — or risk more headline-making breaches in the future.
  • Risk is especially high at hotels because attackers have multiple points of entry.
  • ...14 more annotations...
  • Breaches undermine hospitality brands’ reputations and erode customer trust. Eighty-one percent of consumers will stop engaging with a brand after a breach, according to a 2019 study.
  • When it comes to cybersecurity, companies today have two options: Defend the fort or devalue the data. The former is the more traditional approach. By strengthening the digital “walls” around your data — via firewalls, intrusion detection, 24/7 monitoring and other security protections — the defend-the-fort approach works to keep attackers from accessing your systems at all.
  • However, one of the biggest vulnerabilities may be on the hotel grounds themselves.
  • hotels have multiple point of sale (POS) terminals across different locations, from the front desk to restaurants, all of which are connected to each other. If a POS device is not properly secured, attackers can use malware or other attack vectors to steal clear-text credit card numbers and other data.
  • POS attacks remain one of the most common causes of data breaches in accommodations and food services.
  • Guests may share their credit card numbers with the hotel in advance via a booking app or website, opening up the possibility of web-based attacks. Loyalty programs are another source of online vulnerability, with an estimated $1 billion a year lost to account fraud and related crimes.
  • One important and underutilized aspect of cyberdefense is employee training.
  • Make sure your employees use strong passwords and know how to spot fraud and spear phishing attacks. You may also want to limit employee access to confidential data, so if an account gets hacked, private guest information doesn’t go with it
  • You should also make sure your software is up to date with all security patches, as attackers often exploit known weaknesses in programs. Isolating POS devices from the rest of the network can also limit the damage from malware infections at that entry point.
  • it’s unlikely that even the strongest digital “walls'' will prevent all incursions. Defenses are important, but the ever-changing nature of technology means that new, hard-to-catch vulnerabilities will pop up all the time.
  • important to devalue your data, rendering it unusable to attackers who gain access to your systems. One way to do this is to implement point-to-point encryption (P2PE) by encrypting payment information from the moment it enters your network at the POS
  • Encrypted data is unintelligible to anyone who doesn’t have the right digital key. Implementing P2PE is the only way to ensure that clear-text payment data doesn’t fall into the hands of attackers targeting POS systems with malware.
  • Data that’s stored for the long term, like passport information or credit card numbers saved to a loyalty program, can also be devalued through tokenization. Data that’s tokenized gets replaced with an alphanumeric pseudonym, so the actual sensitive information isn’t stored on your servers. This method helps secure guest information beyond the initial transaction at the POS.
  • Hotels that reckon with their security vulnerabilities now will protect themselves from fines and other fallout from data breaches as business rebounds. They’ll also build deeper, more trusting relationships with customers by keeping their personal information secure. By strengthening security protections and devaluing their data, hotels can set themselves up for a brighter future. 
  •  
    This article describes the vulnerabilities in the security systems of the hotel Industry. The POS system was recognized as one of the most vulnerable areas that are more targeted by hackers. This is due to the multiple stations where the POS systems are located on the premises of the hotel. Likewise having POS systems independent of the hotels security system left the system open to hackers. Two options to defending the cyber-defense, are digital walls and employee training. Digital walls works by keeping hackers from accessing the systems. Although even with a strong firewall it is recommended to implement point-to-point encryption (P2PE), this encrypts payment information of guest. the other is tokenization. This uses alphanumeric pseudonym to protect data stored for long periods of time. Another way to prevent cyberattacks is employee training, encourage the use of strong passwords an dhow to detect fraud and phishing attacks.
Henrique Rodrigues

Where Should You Be Spending Your Cybersecurity Budget? - 0 views

    • Henrique Rodrigues
       
      This article focuses on what should be the goal on a cyber security budget. Cyber security has become a very sensitive matter these days and even though there is an in creasing number of software to protect the companies, there are also newer attacks going on. Therefore, how do we choose and evaluate what should be the focus of this budget? The article displays different threats and how companies should identify the most critical material and data that should be protected and how to do so. Many of the risks will come from the three main vectors: external threats, internal threats, or the supply chain threats. The importance of employee training, cyber insurance, risk management framework, and other allocations that the cyber budget should be geared for.
  • The goal of cybersecurity is to help mitigate or prevent a cyber attack that could cause significant harm to your business, your operations, your financial performance, or your customers.
  • But organizations with mature cybersecurity programs are increasingly aware of the fact that they cannot address every cyber threat since bad actors will continually find ways to hack and mine data. Instead, they choose to focus on preventing catastrophic attacks from taking place.
  • ...1 more annotation...
  • With this in mind, your cybersecurity budget should be geared toward identifying the most critical material risks to your organization which could be caused through cyber means—and reducing, mitigating, or transferring those risks.
anonymous

Insiders suspected in Saudi Aramco cyber attack | SciTech | GMA News Online | The Go-To... - 0 views

  • Hackers from a group called "The Cutting Sword of Justice" claimed responsibility for the attack. They say the computer virus gave them access to documents from Aramco's computers,
  • The hacking group that claimed responsibility for the attack described its motives as political
  • the group said Saudi Aramco was the main source of income for the Saudi government, which it blamed for "crimes and atrocities" in several countries, including Syria and Bahrain.
  • ...9 more annotations...
  • According to analysis of Shamoon by computer security firm Symantec, the way the virus gets into networks may vary, but once inside it tries to infect every computer in the local area network before erasing files to render PCs useless.
  • Yet those sources say such protections could not prevent an attack by an insider with high-level access.
  • insiders were implicated in just 4 percent of cases last year.
  • Saudi Aramco has said that only office PCs running Microsoft Windows were damaged. Its oil exploration, production, export, sales and database systems all remained intact as they ran on isolated and heavily protected systems.
  • Because the virus wiped the hard drives, it is difficult for Saudi Aramco to determine exactly what information the hackers obtained.
  • The Shamoon virus is designed to attack ordinary business computers
  • . It does not belong to the category of sophisticated cyber warfare tools
  • The hackers behind the Shamoon attack siphoned off data from a relatively small number of computers, delivering it to a remote server
  • It is standard industry practice to shield plant operating networks from hackers by running them on separate operating systems that are protected from the Internet.
  •  
    Saudi Arabias national oil company, Aramco, was attacked by a computer virus, Shamoon, and it is suspected that an insider or employee assisted the hackers. The virus spread through the network and infected about 30,000 PC business computers and wiped their hardrives. This is one of the worst attacks against a single business. The hackers who claimed responsibility, The Cutting Sword of Justice, were politically motived. The companies more important documents including plant operating networks were not affected by the virus because they were on a separate and higher security network. Recently, other Middle Eastern natural gas firms with relations to Saudi Arabia have been hit by cyber attacks. Because the Aramco hackers admitted their motives against the Saudi Arabian government income sources, I think that all the cyber attacks may be politically motivated. As a Middle Eastern oil company with relations to Saudi Arabia, this is a major indication to take precautionary measures and increase network security. This attack demonstrates that no matter how much security you have in place, if an insider is willing to assist hackers or provide hackers with necessary information, you are no longer protected. It would seem imperative that employees with this access are chosen carefully or network access is very limited.
cpaez007

Hotel sector faces 'cyber crime wave' - 0 views

  • Hilton Hotels, Starwood Hotels & Resorts, Mandarin Oriental and the Trump Collection have all admitted that their payments systems were compromised this year as hackers hunting for credit card details switch their attention to the leisure industry. This week Hilton and Starwood said guests’ personal details had been taken after hackers gained access via payment systems.
  •  
    Hotel industries have been under attack from excessive hacking, as seen with Hilton being targeted for private financial information from guests. In 2014, it was noticed that hackers had been targeting Hilton throughout the course of 17 weeks. They state that the industry itself has not really focused budgeting on cyber security. It seems that the process is done by integrating a virus into these hotels POS system. The virus was actively attacking the Micros program, which was being used in more than 300,000 hotels and resorts. An ultimate treasure chest for information, some of which was not even encrypted. In addition, the virus appears in the system as a legitimate software, and then it obtains over 90 percent of stored information. This hacking is being conducted by organized groups, who moved from the retail industry because it had indeed improved its cyber security. With hotels it seems that the concept has not been taken as seriously. There are many hotels susceptible to such an attack. As long as there is a sales software, then someone is looking to get into it. A person could be sitting inside of your location, and infiltrating a guests' wireless internet, and they would not even know. In order to engage this threat, locations must be proactive in attempting to stop what is occurring. The only question is, how much are they willing to invest in cyber security?
kelseybarton

Protecting the Hospitality Sector With Security Intelligence - 1 views

  • A decade ago in 2009, hospitality was — by some reports — the most widely attacked industry of all. And while other industries have now surpassed it, a 2019 report by Trustwave still ranks hospitality as the third most-breached industry, accounting for 10% of all breaches.
  • the average hospitality data breach costs $1.99 million to contain, at a cost per record of $123. These high costs are due in part to the time needed to adequately respond to a breach. On average, it takes 200 days to identify a hospitality data breach and a further 75 days to contain it
  • attacks targeting the hospitality industry are mostly aimed at stealing payment card data.
  • ...10 more annotations...
  • Why Is Hospitality So Hard to Secure?
  • 1. They often have large, complex networks.
  • 2. Customers are onsite — and attackers could be too.
  • 3. Staff churn.
  • 4. Franchising.
  • 5. Third-party risk.
  • Protecting the hospitality industry from cyber threats isn’t an easy job. Security professionals in the industry are tasked with defending highly complex networks with many endpoints against a constant barrage of attacks and a constantly churning workforce. On top of all of that, they have limited security resources to work with.
  • Comprehensive security intelligence helps security teams identify unknown threats to the organization, and make informed decisions about how and where to allocate time and resources for maximum effect.
  • Threat intelligence provides the context analysts need to quickly distinguish between valuable alerts and false positives, drastically improving their ability to respond to genuine cyber threats.
  • Threat intelligence can help security teams drastically reduce the time needed to identify and contain a breach by alerting them the moment stolen assets (e.g., guest or passenger data) are made available for sale via the dark web.
  •  
    (1 of 2) "The hospitality sector has always been a popular target for cyberattacks." This is the first line of this Recorded Future article published in January. The article discusses breaches that happened for both Marriott and British Airways and how this is a regular occurrence in the industry as it is such a big target with so many possible points that can be attacked. While the statistics for the hospitality industry have improved greatly in the last decade, in 2019, they were still accounting for 10% of all breaches. Not only does a breach affect the way an organization operates, but also it also severely effects their bottom-line and takes quite a but of time for them to recover. "According to Ponemon's 2019 Cost of a Data Breach Report, the average hospitality data breach costs $1.99 million to contain, at a cost per record of $123. These high costs are due in part to the time needed to adequately respond to a breach. On average, it takes 200 days to identify a hospitality data breach and a further 75 days to contain it." The article continues by stating that hackers are typically seeking payment card data when compromising the hospitality industry.
  •  
    (2 of 2) The article then discusses the many reasons why it is so difficult for hospitality-oriented companies to secure their assets versus other organizations of similar stature. Some of these reasons include the large, complex networks which are typically publicly accessible and contain many customers in the databases, the fact that customers are always onsite and so are attackers, the high turnover leading to inconsistent training and sharing of credentials, franchisers owning the responsibility of security yet not knowing much about it, and the risk associated with all of the various third parties the hotels do business with. While intelligence has come a very long, "security professionals in the industry are tasked with defending highly complex networks with many endpoints against a constant barrage of attacks and a constantly churning workforce… [AND] they have limited security resources to work with." Comprehensive security intelligence systems are now capable of protecting many aspects of the organization. Some of these updated features include responding rapidly to security incidents, blocking online brand abuse and impersonation, managing third-party risk, reducing breach containment times, and better allocating security resources. Property data security is so important to the hospitality industry. If a business does not take the proper precautions to protect their systems and their customers, then it could lead to a devastating event for the business. While security intelligence has progressed within the last decade, a business needs to make sure that they have chosen a reliable agent to partner with who will produce consistent service. If the business keeps up with their system updates and protections, they should not have to worry about their security system failing.
kimmumford

HPE Newsroom | Why Securing Connected Sports Stadiums Is a Must - 1 views

  • pturing a few credit card numbers at the corner cafe when they can do the same to thousands of people in one place?
  • The NFL monitored for scam websites before the event and brought in a cybersecurity team to track all data activity during the game. And it worked—so far, no cyber crimes have been reported.
  • eams, says creating secure applications and focusing on point-of-sale and other important data exchanges is just half of the cybersecurity solution, though. Patron participation is the other, starting at the gate, physical screenings should go hand-in-hand with cyber screenings.
  • ...6 more annotations...
  • Stadiums need to segregate all that traffic from the important stuff,” such as credit card information and passwords.
  • focusing less on the Snapchats and more on point-of-sale transactions during events.
  • IT professionals should monitor and restrict these growing digital access points in the building as well.
  • Avoiding cyber attacks at sporting events comes down to educating patrons about the risks
  • the next few years new technologies will arise to offer better, more cost-effective encryption options (possibly through quantum computing technologies) to help mitigate cyber cri
  • o date, though, it seems cyber safety will continue to rely heavily on the fans entering the stadium.
alexsolano36

Why Cybersecurity Isn't Only a Tech Problem - 0 views

  • By now, most accept that they need to invest significant cash and resources into cybersecurity capabilities
  • ather than the full C-suite and board.
  • we’re failing at cybersecurity
  • ...27 more annotations...
  • today as comparable to trench warfare in World War I.
  • First, no company has all of the resources to fix every cybersecurity issue, and not all fixes are equally important.
  • starting with a company’s most critical business activities and how cyber attacks could disrupt them that one can start to prioritize this whole process of risk mitigation.
  • skip the ste
  • focusing on individual technologies t
  • without ever addressing the fundamental issue, which is protecting the business activities for which the computers were procured.
  • hey translate in their minds being compliant with requirements as equivalent to being adequately protected.
  • nds up actually diminishing the security of these companies, as opposed to achieving its goal of increasing protection.
  • cybersecurity has been, it’s come out of the technology department.
  • versus one that’s related to any other complex business risk that a company might face.
  • eally large cybersecurity budgets, don’t nearly get the cyber protection benefit that they should, given the dollars that they spend.
  • with r
  • Another avenue that companies can take is, is there anything about the business that the company is in, the way in which it operates, that might attract some sort of attacker.
  • And that really starts with looking at cyber risks as a business risk that could come and occur as a result of a cyber attack.
  • to help quantify what those risks are, and bringing an IT department and your cybersecurity resources to understand what the threat environment might by that might affect those risks in some way or make them to come about.
  • this perception on the part of non-technical business leaders that the cybersecurity field is so complex, so impenetrable that they would never be able to understand
  • And so, the cybersecurity team decided to put the network used for the development of new automobiles inside their corporate network, because they thought, ah, at attacker would need to go through two networks in order to be able to then steal information.
  • cybersecurity people had no idea how the companies that they worked for actually design cars, and so they proposed security mechanisms that both interfered with work and ended up resulting in the company being more vulnerable because all of these outsiders now had complete access to the corporate intranet globally.
  • You know, we’ve found that cybersecurity writ large is full of platitudes that seem obvious and compelling at first read, but if you think about them more thoughtfully, they’re sometimes misinformed.
  • , informing employees about the cybersecurity implications of their own work
  • but also who your adversaries are. H
  • $3 million a year on cyber threat intelligence.
  • In all areas of risk, whether it be financial risk, physical risk, or cyberrisk, there are no guarantees that what you do will be sufficient to fend off the attack that you actually face.
  • , you need to have cybersecurity reviews as you change your business, just like you look at other risks when you’re making changes to your business.
  • Based on our experience, when a company is looking for a home for the cybersecurity organization, they should first look at where their most significant cyber risks reside.
  • A company needs to have the technical capabilities to respond to the most likely forms of cyber attack on their most critical business activities.
  • instead of telling me what vulnerabilities need to be fixed with whatever priority
  •  
    This article talks about how companies make the grave mistake of thinking that cybersecurity is merely an issue that should be addressed by an IT team and that no one else is responsible for addressing risks and understanding them. Most C-suite employees don't understand what the risks are, and usually these risks vary from company to company. It is not that you should only consider that you can get hacked, but you should consider and identify what kinds of information can get hacked and why. The article denotes an example of an Asian automobile company that needed to implement a new system to mitigate security risks and in the process, ended up locking up other companies who needed to use their systems to find out about their products. So those companies started to create fake profiles to try and access the information -- all so that they could just do their job. This showed that people are more interested in just getting their job done than understanding cybersecurity and why certain systems are in place. The way of thinking up security systems should be creative and involve all parts of an organization. Departments won't know what their role is until they identify what information is important to them, what their purpose is in the company, and what is valuable to them. By identifying this, they can come up with ways to secure this information and monitor its delivery. Businesses don't look at cybersecurity as a risk of their business just as a shipping company would look at weather risks as a potential threat to their revenue. It is looked at as more of an abstract concept and this stops people from implementing successful strategies to keep their information safe. Cybersecurity shouldn't be viewed as "so impenetrable" that no one would ever understand it. This requires everyone to get involved and understand the implications of cybersecurity on their own work, specifically, and identify who their main adversaries may be.
ldevaul

How the travel industry can fight back against cyberthreats | SmartBrief - 1 views

  • Travel and hospitality businesses have become lucrative targets in recent years for cybercriminals who have stolen from the industries in attacks that often take more than half a year to identify.
  • In the past three years alone, the hotel industry has faced 13 serious attacks, according to an IntSights study.
  • The travel and leisure sectors suffered a 155.9% year-over-year rise in suspected online fraud attempts worldwide in the second quarter, according to a TransUnion study, compared with a 16.5% increase in overall alleged intrusions.
  • ...21 more annotations...
  • The hotel industry attracts cybercriminals because it handles so many financial transactions in so many countries.
  • The top threat to hotels is phishing, a scam in which hotel guests may receive fake phone calls claiming to be from the front desk. The caller could claim that there is an issue with the credit card on file and that they need to re-verify the payment method. 
  • DarkHotel hacks are another significant threat. These target travelers via hotel Wi-Fi. Digital certificates are sent to guests, like a familiar adobe update, which will retrieve sensitive information. Hotel chains are combating these hacks by suggesting that guests use a virtual private network.
  • Malware (malicious software) is something criminals email employees, under the guise of the attachment or link looking innocent or legitimate. But when the user opens the file or clicks on the link, their system (and more) can be hacked into by the criminal.
  • IT department should routinely update operating systems and back up data and files, and every employee should double-check sources when asked for software administrative permissions. Also, strong firewalls can limit bad traffic and provide security. 
  • Software and hardware can help prevent breaches, but employee training is also an essential part of any hotel’s cybersecurity.
  • In 2018, a Marriott reservation system was hacked. More than 500 million customer records, including credit card information and passport numbers, were stolen. The company said the hack went back four years prior to the discovery and, when it was noticed, the company started using computer and mobile device monitoring software.
  • “Guests can enroll in a service called WebWatcher, which monitors the sites where personal information may be shared and alerts guests if evidence of their personal data is found,”
  • Hotels are not alone in being targeted by cybercriminals: The airline industry has faced serious cyberattacks as well, and many airlines still aren’t equipped to handle them.
  • only around 35% of airlines and 30% of airports are prepared for cyberattacks.
  • "The proliferated effect of the attack on SITA is yet another example of how vulnerable organizations can be solely on the basis of their connections to third-party vendors,"
  • The aviation industry faces dangers such as ransomware and distributed-denial-of-service attacks. Following the SITA attack, HackerOne solutions architect Shlomie Liberow stressed that airlines need to prepare for the worst. 
  • traditional enterprises like airlines have always been an attractive target since few are digital-first businesses, and therefore have relied on legacy software, which is more likely to be out-of-date or have existing vulnerabilities that can be exploited."
  • The airline industry needs to keep third-party vendors in check when it comes to protecting information. Given the high stakes involved, experts suggest that blind trust is not an option. 
  • “You simply cannot know whether your third parties meet your company’s security controls and risk appetite until you’ve completed a full vendor security assessment on them,
  • It’s important to note that the best practice is not a ‘one-and-done’ activity, but through real-time, continuous monitoring.”
  • In 2015, hackers targeted Polish airline LOT’s ground operations system, affecting 1,400 passengers. The hackers made it impossible to create flight plans and flights. It was the first attack of its kind, and it caused concern about cyberattacks one day remotely taking control of planes.
  • To address the threat, the standard advice is to back up and store data in multiple places, including off your physical premises, and have one copy of it be offline
  • Multifactor authentication and long, complicated passwords will take longer to crack. Updating and patching systems regularly helps companies avoid being victimized when a new exploit is discovered.
  • Treating cybersecurity as a companywide concern, not an IT concern, encourages each employee to take ownership of their actions and knowledge and to seek help proactively instead of making an “innocent” mistake that costs the company millions of dollars.
  • Finally, companies should avoid simply throwing money at the problem: Not all cybersecurity solutions work together, which wastes money and increases the risk of a breach.
  •  
    This article discusses ways that the travel industry can combat cyberthreats. The main cyber concern for hotels' is phishing, which is a scam that collects credit card information by pretending to be apart of a hotel's front desk staff. The article mentions that IT departments should do routinely updates to operating systems and back up data and files. Employees should also be trained to help prevent data breaches. The author briefly touched on what to do when your hotel system is hacked and even dives into how the airline industry is still very unequipped to handle cyberattacks and threats. This is a great read to learn how to keep up with best security practices in the hospitality and tourism industry.
kjeewan

Data Security in the Hospitality Industry: Post-COVID Era | LoginRadius Blog - 0 views

  • The frequency of cyberattacks against business databases can be attributed to the fact that the hospitality industry largely depends on credit cards as a medium of payment. This may increase the chances of a hacker receiving access to sensitive information. Investing in proper data security in hospitality can work to protect not only the consumer but also the business from losing large sums of profit.
  • databases in the hospitality industry also happen to be the most vulnerable to data breaches.
  • The aforementioned reliance on payment cards can greatly increase the chances of information leaking. However, other virtual methods of payment like online payment and more can create the potential for cyber attacks.
  • ...6 more annotations...
  • The data collected and the people who can access it differ from country to country.
  • Staff training is restricted to the service aspect of the business. However, training employees to carry out processes in maintaining data security in hospitality like data collection and storage in the right manner is overlooked.
  • This process can involve the addition of two-factor authentication that will protect the data from being accessible to non-employees. This encryption can prevent identity theft.
  • : Employees will require thorough vetting regarding the importance of proper data storage. This training can also work towards reducing the chances of insider attacks as only a few employees will have access to the databases.
  • This includes the addition of firewalls, traffic filters, and network monitors to guard against malware present online.
  • , investing in proper data security in hospitality can work to protect not only the consumer but also the business from losing large sums of profit.
  •  
    Personal information collected can range from generic data like names and phone numbers to sensitive data like bank accounts. Databases in the hospitality industry are the most vulnerable to data breaches. Reliance on payment cards or virtual payments can increase the chances of information leaking or potential for cyber attacks. Staff training in maintaining data security is overlooked. two-factor authentication, Employees training to reduce insider attacks, and cyber security measures such as adding of firewalls, traffic filters, and network monitors to guard against malware present online can ensure data security for consumers and the business.
linanzhang

12 Ways to Increase Hotel Security - LODGING - 1 views

  • “When department managers and other employees think more about safety and security, you can prevent a lot of theft and minimize dangers.”
  • 1. Update locks. Locks that can track who goes in and out of rooms can serve as a deterrent to theft.
  • 2. Make time for safety meetings. Perhaps as part of a regular meeting, schedule time to talk about guest safety
  • ...3 more annotations...
  • 3. Monitor activity with software. Having closed-circuit television to monitor the property doesn’t matter too much if no one is looking at the monitors.
  • 4. Evaluate and improve—quickly.
  • 5. Meet and greet. One of simplest, but most effective, ways of securing a property is to provide excellent customer service.
  •  
    This article talks about ways to increase hotel security. Although hotels may have proper security and policies in place to protect the property, they are often subject to cyber cyber-attacks, break- ins, theft, fraud, and other crimes. Lack of proper security in hotels may lead to increased guests losing belongings to theft. As vice president of global safety, Callaghan spent 35 years with Marriott International. He was responsible for properties throughout the United States, Latin America, and the Caribbean. During his career, he could manage everything from the integration of new technologies such as electronic locks and computer surveillance systems to implementing anti-terrorism procedures. The following list shares Callaghan tips on guest safety, internal theft, and cyber security that can help owners and operators avoid down time, reputation loss, liability, and lawsuits. This ensures property security and that information in up to date.
  •  
    Security is really important in the hospitality industry. It's vulnerable to cyber attacks, break-ins, theft, fraud, and other crimes. The security means a better, safer, guest experience. Since the Las Vegas shooting, we need to pay more attention to the safety and security. There are many ways to increase hotel security. Like the update locks. Locks that can track who goes in and out of rooms can serve as a deterrent to theft. Make time for safety meetings. Monitor activity with software. We also can use closed-circuit television to monitor the property doesn't matter too much if no one is looking at the monitors. We can evaluate and improve. For the Las Vegas shooting, hotel said that they should do something immediately to protect from another event happening. We also can use meet and greet to improve the security problem. It's the effective and simplest way. Employees should also look out for people who don't fit the profile of the hotel's typical guest.
msant228

Hotel Security: How to Optimise It | By Lillian Connors - Hospitality Net - 0 views

  • Invest in surveillance software It's not easy operating in the dark, so the first thing you want to do is to obtain a pair of eyes that will allow you to monitor the activity in your hotel, and catch any illegal activity should it occur.
  • This will not only help your guests feel safer, but it will also discourage anyone who's up to no good to proceed with their plan. Likewise, it will give you a clear overview and allow you to keep a tight ship the guests will want to board.
  • Hold regular security meetings Security meetings should be the staple of your customer safety efforts.
  • ...10 more annotations...
  • you want to use these meetings to familiarize yourself with any potential weak points you might have in your security system, and improve where needed. You will also get the opportunity to strategize your next move should a situation arise.
  • Upgrade the locks One of the most important aspects of hotel security is lock quality, durability, and upkeep. The hotel room lock is the last line of defence against assailants and thieves.
  • Likewise, make sure you keep a reliable 24-hour locksmith on speed dial to address any problems as soon as they arise. From lock malfunctions to replacements and upgrades, and even fixing the locks after a break-in, having a locksmith who can come at a moment's notice is imperative.
  • Improve constantly Trial and error breed success, but only if you work hard to improve on your past mistakes.
  • So make sure you always think of new ways you can improve your customer's safety.
  • Meet your customers One of the most effective ways to keep a close eye on what's going around in your hotel is to meet your guests.
  • This is not only a chance for you to check out the type of people staying at your hotel, but it's also a chance to ask them if there is anything you can do to improve their overall experience.
  • Prevent cyber attacks Nowadays, cyber-attacks are becoming more frequent than ever, and you want to ensure your guests' data is protected from malicious activity. To this end, you want to form an IT department that will work on improving the hotels cyber security, and be on call to help your guests with any IT related issues. This will help you provide a better service, and increase your brand's reputation.
  • Do background checks of your staff Finally, you need a reliable staff by your side to make all of the aforementioned tactics work.
  • This way, you will be able to prevent any criminals from infiltrating your business and elevate the overall security of your hotel.
  •  
    No matter how much hotels invest in security, there are still vulnerable areas where hotels should improve to prevent thefts, break-ins, fraud, hacking, and numerous other crimes from happening. In this article, the author has introduced certain ways to optimize hotel security, including increasing the invests in surveillance software, holding regular security meetings, upgrading the locks, meeting your customers, paying attention to cyber-attacks, and carrying on background checks of staff.
  •  
    This article is about hotel security and different ways to optimise it to meet your needs. Some of the topics discussed were the integration of surveillance software, the importance of regularly scheduled security meetings, lock upgrades, and customer interaction. The article touches upon each of the topics mentioned and explains how the integration of all of these practices helps create a safer and more cohesive security system. I liked how it focuses on the need to interact with customers as they are the ones you are protecting the most. I think that interaction really makes a difference.
galca008

Improving data security in the hotel industry lets guests sleep peacefully | Hotel Mana... - 1 views

  • The hospitality industry is quickly growing as a favored target of hackers and cybercriminals. In fact, according to the 2016 Trustwave Global Security Report, hospitality is the vertical industry with the second-highest number of data breaches, behind only the retail industry.
  • Hotels are high-value targets for cybercriminals because they not only hold payment card information on guests, but also a wealth of other sensitive personal data that can be used to steal their identity.
  • The fallout from a widespread data breach that compromises guests’ payment card data or personally identifiable information can be disastrous for a hotel chain. The average cost of a data breach in 2016 was $4 million. This figure encompasses everything from breach mitigation to crisis team management costs, business losses and even the more intangible consequences: damages to brand reputation.
  • ...6 more annotations...
  • However, with more countries migrating to chip cards and EMV-compliant POS systems, attackers have shifted their focus to card-not-present fraud and are targeting industries where consumers are making their payments and reservations over the phone—such as hotel contact centers.
  • If guests aren’t convinced that the hotel is keeping their personal and financial data secure, they will take their business elsewhere. In order to protect their brand reputation and their business, hotels need to create a culture of security throughout their entire organization that focuses on protecting guests’ digital property in addition to their physical property. One of the best places to start is their contact center.
  • In an era of increasing cyberattacks, hotels can make themselves less of a target by adopting technology to ensure that payment card data and other personally identifiable information is kept secure and segregated from the contact center.
  • With such an approach, customers calling to make a reservation or order additional services discreetly type their card numbers into the telephone keypad, rather than reading them out loud to the agent on the phone line. The data is securely routed to the payment gateway or a more secure server so it is never shared with the agent and is not held in the contact center infrastructure. This ensures that there is no possible spillover of the data to the unsecured or unmonitored areas of the business. It also reduces the number of individuals with access to the sensitive data, and makes the hotel contact center a less attractive target for cybercriminals. As an added benefit, this approach makes it easier for the hotel to comply with Payment Card Industry Data Security Standards by reducing the scope of compliance. By keeping payment card data out of the contact center, hotels can significantly reduce the high costs and extensive time associated with maintaining PCI DSS compliance.  
  • With stronger security practices for handling guests’ sensitive data, the hotel industry as a whole can transform itself from being one of the most likely targets for data breaches to becoming a model for data security, thereby ensuring that fewer customers ever have to go through the experience
  • Guests can sleep peacefully knowing that their data is secure, and the hotel can rest assured that its name won’t be making headlines as victim of a costly data breach.
  •  
    The hospitality industry is a major target for cyberattacks, resulting in sensitive guest information being compromised. When these attacks happen it leaves guests restless, because they know or believe their information is not safe. This article discusses this issue and how security can be improved to avoid these attacks.
  •  
    The article titled, "Improving data security in the hotel industry lets guests sleep peacefully" shows how the breach of data security can be anywhere. As technologies improve, so do ways in which cyber security can become at stake. According to this article, "Hotels are obligated to maintain the physical security of guests and their belongings during their stay-if guests don't feel safe staying in their room or leaving their belongings there, they won't continue to patronize that hotel brand. The same thinking applies to data security: If guests aren't convinced that the hotel is keeping their personal and financial data secure, they will take their business elsewhere". Thus, hotels need to make sure they are safeguarding information such as their payment information as well as other confidential information. Hackers are becoming even more sophisticated, where they can target specific industries, such as hotel industries since guests speak with hotel representatives over the phone to provide payment information. In the even that a hotel's data has been compromised, what is its responsibility? First, they should send the client a letter of apology, and then handle the complete process efficiently, so the client can at least feel they re supported. The avoidance and handling of data breach is becoming even more common nowadays with the rise of technology.
klint005

Cyber Security Threats Facing the Hospitality Industry - 0 views

  • Cyber-criminals are targeting the hotel industry
  • Not having the proper security measures in place can become a huge public relations nightmare.
  • You have to update both the infrastructure and the processes to keep your organization safe.
  •  
    Hotels are at risk for cyber attack. It can cause a customer to lose trust in your brand and make public relations difficult to control. There are different types of attacks that are more prominent for hotels and that includes: Phishing attacks, ransomware, POS and credit card attacks, and DDoS. In order to protect your hotel you need a CISO to monitor the system and make updates. In addition you will need infrastructure updates and secure procedures to protect against attacks.
  •  
    Inthe hospitality/tourism industry it's so easy for cyber threats to come up and this year it has been increasing in the industry. Cyber hackers find it easy to target places like hotels for instance where there are overnight shifts of people inputing valuable and sensitive information in the computers the hackers have felt like they hit the jackpot knowing this so it's important for businesses to have security with their techonology.
msoma003

HNN - 4 cyber security threats looming over hotels - 0 views

  • The world of cyber security is seemingly in a state of constant flux, making the sources of possible threats hard to nail down for hoteliers.
  • The world of cyber security is seemingly in a state of constant flux, making the sources of possible threats hard to nail down for hoteliers.
    • msoma003
       
      Always changing
  • The velocity of change of threat landscape is very challenging for organizations.
  • ...11 more annotations...
  • But the practice is growing more and more sophisticated, panelists said, and phishing attacks are increasingly targeting high-ranking executives, including those in the hotel industry.
  • without checking with multiple sources and having face-to-face conversations.
  • In such phishing emails, the scammers will order subordinates to authorize large wire transactions under the guise of the transfer being for some sort of acquisition or other major transaction.
    • msoma003
       
      An employee will follow the orders from their boss
  • projects (they’ll do), along with the methods and styles of communication
    • msoma003
       
      They study the target, this takes time and sophistication
  • take over the email accounts
  • Ransomware is the practice of finding some vulnerability in a company’s systems to abduct their information or the functions of those systems and then keep it hostage until someone gets a payoff.
    • msoma003
       
      This is new but it can cost the firm a lot of money
  • breach of your point-of-sale systems and loss of customer payment card information.
    • msoma003
       
      Most common and what most consumers are scared of
  • extent of your insurance coverage in the case of such an attack
    • msoma003
       
      Many managers do not look at this
  • Braun called point-of-sale attacks the single biggest cyber security threat to the hotel industry.
  • denial of service, or DDoS attacks
  • hijacked and then used to send little pulses to bring down systems.”
    • msoma003
       
      A firm can be attacked by all sources
  •  
    This article discussed some of the biggest cyber security threats to the hotel industry. One of the biggest threats is that of the POS system, this is not new but we should still watch over it. Another threat that is old is a phishing scam the scams are getting more sophisticated now, hackers get into the email accounts of executives and order large transactions to be made. Internal protocols cannot wipe of the hack but can minimize the risk of employees falling for the fake emails. Ransomware and DDos are also hacks though not as common they still carry big risks.
jordanskj

10 Ways to Reduce Cybersecurity Risk for Your Organization | UpGuard - 0 views

  • ‍Cybersecurity breaches have been on the rise, and it's expected that by 2023, they'll have grown to 15.4 million
  • Make sure all your sensitive data is encrypted
  • Saving your data in normal-text format only makes it easy for hackers to access
  • ...10 more annotations...
  • Some data encryption software even lets you know when other people try to alter or tamper with the information
  • You should also conduct regular backups for your important information
  • statistics show that over 3.4 billion phishing emails are sent globally
  • a hacker may send an email impersonating leaders in the organization asking for personal details
  • make sure you use a patch management system to automatically manage all updates and uphold information security
  • over 80% of organizational data breaches result from weak passwords
  • Chances are that your cyber security is highly dependent on third-party vendors, which is why you can’t afford to ignore vendor risk management
  • Conduct a security assessment and determine whether your critical infrastructure is safe from security breaches.
  • have your IT security teams analyze all server logs frequently and conduct cybersecurity framework audits to make sure their integrity is intact.
  • you should defend your networks from cyber attacks by installing firewalls
  •  
    In this article, the author discusses many different ways to help a business reduce their risk for cyber attacks. The article touches on a statistic about cybersecurity, stating "During the first half of 2021 alone, over 118 million people were impacted by data breaches". There is quick talk about how the policies that a business implements is the make or break of the cybersecurity for your business. For example, one of the main tips to reduce cyber attacks in your business is to make sure your data is encrypted. "Saving your data in normal-text format only makes it easy for hackers to access. Data encryption, on the other hand, limits data access to parties that have the encryption key". Another tip to prevent cyberattacks highlighted in the article is to keep all your employees educated and informed about malicious emails. Conducting regular employee trainings about the dangers of these types of emails could save your business. These types of emails are known to send links that could hack the system, as well as pretend to be higher-up employees in the company asking for personal data or financial information. The article is extremely educational to every business, as well as just the everyday consumer. Keeping your confidential information as confidential as physically possible is very much doable, as long as you make sure you follow these 10 simple tips.
llibe010

The Top Five Cyberthreats Hotel Brands and Franchisees Need to Know About | Netsurion - 0 views

  • ay for guests, it also opens hotels to digital threats perpetrated by malicious actors. Consequently, hotel operators should be aware of the types of cyber attacks, which can significantly hurt their brand reputation and bottom line, not to mention the safety and welfare of employees and guests.
  • In January, for example, cyber criminals took over a luxurious Austrian hotel’s computer-controlled key-card system, locking 180 guests out of their rooms until hotel managers paid a nominal ransom
  • A ransomware attack may disable or alter performance of hotels’ computer-driven systems such as air conditioning and lighting, putting guests’ comfort and, worse yet, safety at risk. In addition, booking systems are extremely vulnerable to ransomware attacks because they process information belonging to the hotels, third-party applications and their customers.
  • ...18 more annotations...
  • 1. Ransomware:
  • hey present further ransomware opportunities to hackers by using computers to automate functions.
  • distributed denial of service, or DDoS
  • One of the largest data breaches in history was conducted through a third-party vendor when hackers stole data from 70 million credit cards by gaining access to a mega-retailer’s network through credentials belonging to an HVAC contractor.
  • 2. Remote hacking through third-party vendors:
  • 4. DDoS attacks on the hotel network:
  • 3. Phishing scam targeting customers and hotels:
  • Train employees. Hotels should train employees to not open suspicious emails or links inside them as they may contain malware.
  • Statistics indicate that such incidents will become more frequent, so it is not a matter of if but when the next cyber attack will occur.
  • Integrate a managed SIEM. Hotels should bring on a managed security information and event management (SIEM) platform for their remote locations to be warned right away of cyber attacks. They may also want it for inside the perimeter if they lack the expertise and resources to properly use SIEM internally.
  • Maintain PCI compliance. The Payment Card Industry Security Standards Council (PCI SSC) has put forth a set of stipulations, the Payment Card Industry Data Security Standard (PCI DSS), in response to rapid PCI expansion. Hotels should make sure they are compliant with these regulations, which require businesses to send credit-card information in a secure environment, to prevent paying heavy fines and losing data, revenue, and customer trust.
  • Install antivirus on all devices. Hotels should ensure they have reliable anti-virus and anti-malware software installe
  • 5. Theft of personal information over public Wi-Fi.
  • According to the FBI, the number of cyber threat occurrences quadrupled to 4,000 per day last year from 1,000 per day in 2015
  • The number of cybersecurity incidents worldwide increased 38 percent in 2015 from 2014, according to the Global State of Information Security Survey 2016 by PwC, CIO, and CSO.
  • In addition, there are large volumes of payment card transactions between restaurants, on-site shops, spas, parking, and the front-desk, ensuring there is plenty of customer data for a hacker to compromise.
  • Hotels are especially vulnerable to this type of attack where a type of malware disrupts access to a system until a ransom is paid. This is because they often use integrated POS systems
  • Hackers can break into hotels’ payment systems through a remote access point belonging to one of its vendors, so they should closely monitor third-party access to their networks
  •  
    This article outlines some of the main cyber attacks on the Hospitality industry. It exposes the threats due to the wealth of data stored in PMS, POS and CRM and suggests steps to take to protect against malware and randsomeware. The article further highlights the necessity for antivirus software on all devices.
  •  
    The article describes the five most common cybersecurity risks for hotel brands such as ransomware, remote hacking and DDoS attacks. The operational elements of each risk have also been discussed. It also covers best practices that hotels and other hospitality organizations can adopt to curb breaches.
hchiebooth

Hotel Data: 5 Strategies For Safeguarding Your Customers' Data - 4 views

  •  
    This article highlights 5 different strategies to strengthen data security. They make very great points such as the data security begins with the employees. Teaching employees how to handle and process sensitive data is the first step. Training employees on how to spot data breaches and report them is just as important. Another great tactic that the author presents is to test your own network. In order to implement strict barriers for cyber security, the limitations have to be known. If a company knows their cyber security limitations on data they can build a stronger foundation to prevent outside cyber data breaches. Additionally since cyber attacks are not 100% preventable, purchasing Cybersecurtiy insurance seems like the most responsible thing any hospitality or customer focused entity can do.
  • ...2 more comments...
  •  
    I have to agree with the article and believe that the future will be an executive dedicated to cyber security. I see no other way with the rise of hacks & breaches.
  •  
    Breaches can lead to a high cost of out of pocket expense for the company. Which is why it is always wise for a company to have tools and policies and procedures implemented to avoid these security breaches. Cybersecurity training of at least every 6-12 months, and continuous communications regarding attempted breaches will give employees clarity on how consistent and clever the threats can be.
  •  
    Well said in many aspects. It is not if there will be an attack or breach, it is how the company deals with it and prevents it as best as possible to deter the assailants. Data security in a hotel or operation is also very important. There must be many measures in place to ensure that guests data is safe. It is very serious and can affect business just as bad as food poisoning or fires.
  •  
    I completely agree. Having a proactive approach to data security should be the standard because the attacks are inevitable.
irinadolgopolova

How to Prevent Malware Attacks and Promote Cybersecurity at Your Hotel - 0 views

  • Each time a hotel’s guest records get breached, the property is burdened with financial strain and faces broken trust with guests. As a hotelier, you don’t need to be an expert in cybersecurity, but you absolutely need to understand the basics to protect your business and your guests.
  • hotels process lots of transactions and store tons of guest data. A hacker can simultaneously target a property’s point-of-sale and property management system to capture payment card information as well as personal data, like passport numbers and email addresses.
  • Research from Symantec, a cybersecurity firm, found that more than 65% of hotels are routinely leaking booking reference codes through third-party sites. Why is this important? Because the information shared through these codes would allow a bad actor to login to a reservation, view personal details, and even cancel a booking altogether. When this happens, your guest information is vulnerable and you risk destroying the guest relationship.
  • ...3 more annotations...
  • Compliance with the Payment Card Industry Data Security Standard (PCI-DSS) not only helps to ensure that data security software, hardware, and practices are safer, but also helps to protect against fines and penalties when a breach occurs,
  • The right technology is only half the equation; over the years, security experts have also identified employees as part of the problem. Hotels must train their staff to handle personal information security, comply with privacy policies, and change user access credentials regularly.
  • Even with a great PMS/POS system and the right training, it’s important to perform routine penetration testing and risk assessments. There’s no straightforward answer as to how often you should pen test your network, but experts warn once a year probably isn’t frequently enough
  •  
    The article is about the reasons why the hotels are attractive for hackers, the author also explains the key concepts in the cyber security. Then, the biggest cyber attacks in hotel industry are described in the article. At the end, the author tells us how hoteliers can improve the security measures.
‹ Previous 21 - 40 of 166 Next › Last »
Showing 20 items per page