Skip to main content

Home/ Hospitality Technology/ Group items tagged cyber-security

Rss Feed Group items tagged

espence13

Marriott Hotels: Series Of Data Breaches Reveals Lack Of Security Awareness - 0 views

  • The data breach hitting Marriott Hotels Group was huge. The joint-second largest to have ever taken place, in fact, after Yahoo’s disastrous 2013 breach (and on par with Yahoo’s 2014 breach). While the amount of data that was taken from Starwood Hotels’ reservation systems (a company acquired by Marriott in 2016) was vast, what’s most staggering is the fact the breach went undetected for four years, and an acquisition also took place but the alarm still wasn’t raised. Since news originally broke of the release, it’s also been revealed that the hotel group’s own security team was hit by an attack in June 2017. Clearly something has gone amiss.
  • The issue is compounded by the fact that security is still not high enough up the list of priorities for business leaders. Despite well-known organizations frequently hitting the headlines for data breaches (in 2018 alone we’ve had Ticketmaster, Quora, British Airways, Under Armour and plenty more) and a ‘when not if’ warning  being peddled by the security industry for years, many businesses still haven't got to grips with just how critical proper security is. The fact that reviewing security may not have been part of the acquisition process of Starwood by Marriott – and if it was, not well enough – is further evidence of this apparent blindness to the impact of poor security. So, what’s going wrong? A research report from security company Bromium earlier this year suggested that the average large enterprise spends $16.7 million per annum on security, with the vast majority found to be on ‘the human cost of maintaining cyber security systems’. While most firms clearly aren’t 2,000 people sized enterprises, the research provides a good indication that spending on security isn’t the issue. Instead, it’s people.
  • We need to look at different approaches to skills development and, in many ways, imitate cyber criminals themselves who are continually iterating ideas to solve problems, rewarding perseverance and curiosity as well as encouraging further development. The ‘white hats’ need to approach their roles the same way – not rely on what they heard in a classroom six months previously.
  •  
    The recent cyberattack at Marriott International Inc. has many hoteliers wondering what are the legal and business risks associated with security attacks? The recent breach at Marriott further proves the point that businesses should prepare now or be willing to pay for it later. In November 2018, the Bethesda, MD-based hotel company revealed there had been unauthorized access to the Starwood guest reservation database, which contained guest information relating to reservations at Starwood properties on or before Sept. 10, 2018. Businesses face a multitude of risk when looking at the potential consequences resulting from a cyberattack or breach. As we've seen recently with the Marriott breach, there can be significant impact to brand equity in the marketplace. This impact can be far reaching for publicly traded businesses, resulting in material impacts to businesses and business valuation, and long-term impact to user adoption. In addition to the downside risk from the market, businesses must also mount expensive defenses against litigation that increasingly takes the form of class actions. Reputation is important in every trade but is especially important in the hospitality industry. This, coupled with the fact that consumers are becoming more sensitive to privacy and security related issues, means that businesses in the hospitality industry must manage against these types of risk and allocate appropriate levels of funding toward information security. What should hoteliers learn from the Marriott breach? Pay attention. Marriott was aware that there was a potential issue shortly after it acquired Starwood, but did not, apparently, investigate in detail. Marriott may not have created the problem, but it bought the problem and didn't treat it with the seriousness that was necessary.
afigu115

Data Security in Hospitality: Risks and Best Practices | By Limon Wainstein - Hospitali... - 0 views

  • Information security is a pivotal aspect of many industries, not least the hospitality industry due to the nature of the data collected by companies operating within hospitality.
  • hospitality appears to offer an ideal target vector for conducting crimes such as identity theft and credit card fraud due to the existence of multiple databases and devices
  • ybercriminals use this reliance on cards to infect point-of-sale (POS) systems with malware that steals credit and debit card information by scraping the data.
  • ...5 more annotations...
  • Restaurants, hotels, and other companies in the hospitality sector often have complex ownership structures in which theres a franchisor, an individual owner or group of owners, and a management company that acts as the operator.
  • A vital part of protecting data is training staff to securely gather and store personal information.
  • The high level of turnover and high degree of staff movement between different locations makes it a real challenge to maintain teams of well-trained staff
  • Industry and political regulators are becoming stricter in governing how organizations process and store personal data.
  • This type of data risk is more subtle and it involves employees selling data to third parties without the knowledge of the organization that employs them.
  •  
    Information security is absolutely crucial within the Hospitality industry. There is so much important guest and customer information that is submitted via technology. This includes, credit card details, addresses, and phone numbers, with so much of this information being sensitive companies need to install security systems. The hospitality industry depends strongly on credit card as a form of payment which is why the POS needs to be secure. It is also extremely important that staff members are trained to gather and store guests personal information. The industry overall has become stricter in the ways that information gets gathered and processed in order to avoid cyber attacks. The last thing that companies must keep an eye on are insider threats, a lot of the time it's the employees from the company that are giving away valuable and confidential information to third parties. This is why I believe that technology has had a great impact on this industry but there needs to be strong security systems in order to avoid cyber attacks.
teresaricks

Cyber Security In The Hotel Industry | protel - 4 views

  • And phishing isn’t the only strategy these computer thugs use, either. Just about every hotel in the world could be vulnerable to malware, ransomware, spam, hacking and social engineering. 
  • The argument for educating staff on cybersecurity is a simple one: if staff don’t know how to recognize a security threat, how can they be expected to avoid it, report it, or remove it?
  • the 2019 State of IT Security Survey found that email security and staff training were listed as the top problems faced by IT security professionals.
  • ...16 more annotations...
  • Yet, more than 30% of staff surveyed by Wombat Security Technologies didn’t even know what phishing or malware was. This is probably why scams like the Business Email Compromise (BEC) result in whopping losses of over $3 billion (according to the FBI).
  • But as humans, hoteliers make mistakes, they’re trusting of fake identities, tempted by clickbait, and vulnerable to other sneaky tactics used by criminals to gain access to company information.
  • Staff need cybersecurity training to protect themselves and the hotel against cyberattacks.
  • By making employees aware of security threats, the impact they might have on your business, and what procedures to follow when a threat has been identified, you’re strengthening the most vulnerable links in the chain.
  • The World Economic Forum in their latest report, The Global Risks 2019, puts cyber-attacks and data theft into the higher-than-average likelihood bracket during 2019.
  • To achieve these record levels of data breaches and cyber-threats, cybercriminals are focusing their attention on the manipulation of human behavior.
  • So how do we counter these threats? Education, education, education. 
  • Security awareness training is not a point event or solution, it is a process. Security awareness comes out of a series of ideas, thoughts, and preparations that are used to develop a holistic security awareness training program.
  • Identify the Specific Cybersecurity Needs of the Hotel/Property   
  • Include Cybersecurity Awareness Training During Onboarding
  • Cover Relevant Topics
  • Make Staff Cybersecurity Training An Ongoing Process
  • We all make mistakes and occasionally slip up. It is really important that staff know that they can come to you and that they are free to report problems without there being a risk of them losing their jobs. This will come from your personal management style. 
  • Cybersecurity is everyone’s responsibility, whether you are C-level, management, accounting, housekeeping, maintenance, or reception, it does not matter. Everyone needs to be made aware of the hotel’s individual cybersecurity policies, attitude, and culture. 
  • Continuously send reminders via email, Slack, or any other messenger your hotel may be using with reminders to change passwords, to update anti-virus programs, and with information about the latest phishing techniques.
  • If you create a culture of cybersecurity awareness within your organization, then the chances of your organization becoming a victim are greatly reduced.
  •  
    This article stresses the importance of providing cybersecurity training to staff in the hospitality industry.
laura kaczkowski

Restaurants, Beware: Hackers Want Your Customer Data - 1 views

  • The simple fact is that cyber criminals today want information that they can use to make money
  • We found that nearly 90 percent of attacks were designed to steal customer information including cardholder data, e-mail addresses and account information.
  • many restaurants and franchise businesses, unsecure and public WiFi networks are conveniently (for the criminal) connected to point of sale systems.
  • ...14 more annotations...
  • but the number one is that they all process credit cards.
  • assets targeted by criminals were point-of-sale software systems
  • Think of the scenario of a hotel that maintains a restaurant, a spa, as well as other services all connected to one POS system
  • The risk is even greater when hotels are part of a hotel chain with interconnected systems.
  • Franchise businesses are particularly at risk primarily because franchises tend to have the same POS system duplicated at all locations
  • Most of the time these business don’t have trained security professionals on staff; instead most assume their IT personnel are taking care of all of their security needs.
  • 76 percent of environments we investigated had a third party introduce a security flaw within the environment that contributed to criminals being able to compromise data.
  • Another alarming trend we found in our investigations was that self-detection of breaches decreased in 2011, and only 16 percent of victimized organizations actually detected the breach themselves.
  • The best intrusion detection systems are neither security experts nor expensive technology, but employees.
  • Very often businesses ignore that fact that while their employees might not be security experts,
  • the POS screen looked differently than it had the day before.
  • The cashier reported it to the company’s security hotline and sure enough there was a cybercriminal on the system.
  • When working with third parties, always build in security requirements into the contract and impose policies and procedures such as good password policies to ensure tight control and better security.
  • The quicker an organization can identify an issue and respond to a breach, the less likely they will experience the deep penalties, both financial and to their brand.
  •  
    The article I read was called, "Restaurants, Beware: Hackers Want Your Customer Data." In the article it talked about how cyber criminals want credit card information from people so that they can make money off of them. Criminals find new ways everyday to breach systems and steal information from guests staying at hotels or eating in restaurants. It states that many restaurants and franchise businesses use unsecure and public WiFi networks are connected to the point of sale system. "Franchise businesses are particularly at risk primarily because franchises tend to have the same POS system duplicated at all locations." A lot of times businesses don't have trained security on staff, they just assume that their IT person will be talking care of the security. According to the article the best detection systems are neither the technology nor the security but it's the employees who work there. The employees can tell when something has changed in the system and as soon as they realize that, they need to report it to their manager. I never even considered people breaking into the systems and stealing credit card information but it does happen and it's important to know what to do in these kinds of situations.
anaferia

The biggest cyber attacks of 2022 | BCS - 0 views

  • In a year of global inflation and massive rises in energy costs, it should come as no surprise that the cost of a data breach has also reached an all-time high.
  • average total cost of $4.5m
  • Amongst the 550 companies that IBM contacted that had experienced a data breach, a disappointing 83% had experienced more than one in the same period
  • ...9 more annotations...
  • common attack vector remains credential theft (19%) then phishing (16%), misconfigured cloud (15%) and vulnerabilities in third-party software (13%).
  • Russia has, for many years, attacked Ukrainian infrastructure such as power grids, internet infrastructure and banks. Since the outbreak of physical hostilities, this has extended to systems related to government administration and the military.
  • The Russia-linked cyber gang known as Conti managed to cause major disruption to financial operations throughout Costa Rica in April.
  • Ransomware, while not the overwhelming headline grabber it was a year ago, is still a major and terrifying threat to many companies
  • A group known as Lapsus$ began 2022 with a string of high profile targets including Nvidia, Ubisoft, Samsung and Microsoft. In each case, data was stolen and in many cases leaked online. Their operating model is extortion where access is most often gained through phishing and then they seek out the most sensitive data they can find and steal it. Often, they do not deploy encrypting software at all.
  • Hacking back is where offensive security experts will attempt to compromise attacker’s machines. This can be legally murky as often the attacking machines are compromised third parties.
  • June this year, a former Amazon employee, Paige Thompson, was convicted for her role in the 2019 Capital One breach. While working for Amazon Web Services (AWS), she exploited her knowledge of cloud server vulnerabilities and stole personal information of over 100 million people.
  • cripple Costa Rica’s import/export business.
  • The main attack vectors continue to be credential theft and phishing emails so it is vital to continue to raise awareness through corporate training and public ad campaigns. Finally, the conflict in Ukraine is showing how effective cyber weapons can be in disrupting command and control in a war.
  •  
    To summarize, this article states that, it should not come as a surprise that the cost of a data breach has also increased to an all-time high in a year marked by significant increases in energy prices and worldwide inflation. According to IBM's Cost of Data Breaches Report 2022, the average overall cost is $4.5 million. Additionally, even if ransomware isn't garnering as much attention as it did a year ago, it still poses a serious danger to many businesses. Credential theft and phishing emails are still the major threat vectors, therefore it's critical to keep spreading awareness through public awareness campaigns and business training. Finally, the situation in Ukraine is demonstrating the potency of cyber weapons in sabotaging command and control in a fight.
areut002

Cyber-security: are hotels serious about it? - 1 views

  • data management has become one of the top priorities
  • guests preferences, interests, social life and much more is available, useable and, most importantly, storable.
  • sensitive information is of great importance.
  • ...9 more annotations...
  • Operational activities such as reservation
  • cloud-based and offer many possibilities for a hacker to intrude
  • access to confidential information.
  • their exposure and dependence on third-party software that may be vulnerable.
  • Marriott, Hyatt and Sheraton released a list of twenty affected properties between March 2015 and June 2016.
  • 95% of all data breaches can be traced to human causes.
  • poorly trained against cyber-attacks due to a lack of global risk vision from the management.
  • As stated by one of the speakers, hotel companies are still reflecting on what shall be done if they suffer a cyber-attack and not what should be done when they suffer a cyber-attack.
  • How can non computer-savvy directors and board members take strategic cyber-security decisions? Who is responsible: the property, the owner, the chain? One thing remains certain : it is time to get serious about security!
  •  
    Hotels will gather a large amount of information from guests, from their interests to their credit cards and this is potentially sotred in their systems. Needless to say, their information is sensative. It is said that many hotels use cloud based technologies for check-ins, reservations, etc. and this typically has a high chance of hackers or they may use a third party, which is just as equally questionably safe. This article highlights three main hotels brands, Mariott, Hyatt, and Sheraton, that had numerous issues from 2015 to 2016. EHotelier stated that a whopping 95% of breaches can be traced to human cause and this could be due thanks to a poorly trained front line staff. During a confrence, it was brought to attention many hotels think it is a big if, opposed to what should be done when it an attack occurs or how to prevent it.
tredunbar

Cybersecurity Best Practices for Restaurants | QSR magazine - 0 views

  • In the case of a restaurant, a cyber attack would likely be seeking;Employee details stored by the restaurantCustomer bank details obtained by the restaurantThe restaurant’s business bank account details
  • A restaurant’s POS system could see hundreds of different bank account details every day
  • Internal software used by restaurant staff is likely to contain sensitive information such as employee details (on an HR system), as well as accounting information for the restaurant
  • ...8 more annotations...
  • Restaurant owners and/or accountants who use online banking facilities must be aware of the possibility of this being targeted
  • Shoulder-surfing is a very real security concern, and hackers have been known to place recording devices in computer rooms, enabling them to physically see passwords being entered
  • Restaurants that use a website on which customers can order food need to consider its security. If cybercriminals manage to hack into the site, they will be able to obtain customers’ personal information such as addresses and bank details
  • Create a human firewall by educating your staff
  • Use reputable, recommended providers and suppliers
  • Keep computers away from the front of house
  • Carry out background checks on employees
  • Introduce unique identification numbers for staff
  •  
    The focus of this article is to point out why restaurants are targets for cyber attacks, what information hackers are looking to obtain and to identify what steps can be taken to protect consumer information. Hackers target a restaurant's POS system for the large amount of bank data it may record as well as any online banking occuring in the restaurant. The personal information from employees as well as any app or website utilized by guests, is prone to cyber attacks. The most important solutions rely on conducting background checks on employees and making sure that they are trained on what to look for. Restaurants can also put practices in place that involve using unique employee numbers, keeping computers out of guests' view, and using vendors with a stellar reputation.
jchac014

Highly connected hotel industry continues to be vulnerable to cyber attacks | PhocusWire - 0 views

  • cyber threats in hospitality, which claims there have been 13 “notable data breaches” in the industry in the past three years.
  • PwC’s Hotels Outlook report 2018 to 2022 which says hospitality has the second-largest number of cybersecurity breaches after the retail sector.
  • factors which make them attractive to fraudsters such as the volume of financial transactions that hotels carry out, the sensitive and valuable personal data collected, use of loyalty programs and their national and international spread.
  • ...5 more annotations...
  • dark web “chatter’ breakdown reveals Hilton had a 31% share of mentions on hacker forums followed by Marriott at 28% and IHG at 19%
  • Marriot recently revealed that its data security breach had cost the company $28 million.
  • It’s unsurprising that as the aviation industry grows and airlines look to adapt their distribution models, cyber attacks and other fraudulent activity also increases.
  • Air Europa says that as it went through its digital transformation, it needed to handle fraud more efficiently.
  • the airline industry saw a 29% decrease in fraud attacks in 2018, but the company attributes that the large data hacks involving passport details have not yet “been reused to commit air travel fraud.” 
  •  
    This article talks about how the hospitality industry has become more susceptible to cyber-attacks. Hotel companies like the Marriott have faced costly fraudulent cases online and have implemented new programs to ensure safety and security.
Mary White

The Rise of Cyber Theft - Subway Loses Millions - 8 views

  •  
    A relatively unsophisticated group of hackers stole millions from Subway by hacking through their poorly secured POS systems. These franchise businesses possibly failed to adhere to the standard required by Subway Corporation and failed to establish two points of entry for remote access into the POS system, making it easy for hackers to steal credit card information. These types of crimes are likely to increase in the future as hackers from around the world take advantage of sub-par security systems. Businesses can no longer concern themselves only with the sale of an item, they also need to offer a sense of security to their customers and accept the reality that cyber theft is a rising problem.
  • ...2 more comments...
  •  
    I definitely agree that businesses need to accept the fact that cyber theft is a rising problem. Cyber theft is so common, we now have to guard and protect our computers with various anti-virus protection; which serves no purpose to a very professional hacker. The fact that a company like Subway experience losses through poorly secured systems, say a lot about their management in regards to protecting their brand and their customers. It's very mind blowing to think that the Subway corporation was just focusing their attention in what they view as important. This is just another wake up call and alert to everyone, who seems to layout their information carelessly. I also hope that Subway refocus themselves in regards to this matter.
  •  
    I have seen a few restaurants more so lately place messaging on the registers or pos system stating that their wireless networks are in fact secure by outside firms or services. With the rise of cyber theft and the increasing awareness about its effect, especially at the small business level, I thought it was a saavy move by this restaurant to assure its customers that at the very least they take the issue seriously. I personally know that no system is 100% safe, but as a consumer it means alot to me knowing they have that proactive approach.
  •  
    It seems everybody should check their online accounts frequently=_=
  •  
    Jeremy, I can appreciate the transparency of those restaurants. I wish more businesses would be open about their security. People are wound pretty tight about money right now and need to feel that the business world does care enough to protect their information.
armanyleblanc767

Data Security in Hospitality: Risks and Best Practices - 0 views

  • Best practices for companies in the hospitality sector to protect data include:
  • Always encrypt payment card information. Operate a continuous training program in cybersecurity to maintain a well-trained workforce. Always adhere to relevant regulations, such as PCI DSS. Use cybersecurity measures such as firewalls, network monitoring, anti-malware, and traffic filtering to protect against common threats. Conduct tests against your organization’s cybersecurity defenses in which you mirror the behavior of an actual hacker. Know where your data is and enforce the principle of least privileges to limit access to sensitive information.
  • groups may use different computer systems to store information, and the information can also frequently move across those systems.
  • ...23 more annotations...
  • five of the biggest data security concerns in the hospitality industry and highlights some best practices for protecting hospitality data.
  • Data Security Concerns in Hospitality
  • complex ownership structures
  • From the perspective of cybercriminals, hospitality appears to offer an ideal target vector for conducting crimes such as identity theft and credit card fraud due to the existence of multiple databases and devices containing both Payment Card Information (PCI) and Personally Identifiable Information (PII).
  • challenge to maintain teams of well-trained staff.
  • t was reported in 2017 that out of 21 of the most high-profile hotel company data breaches that have occurred since 2010, 20 of them were a result of malware affecting POS systems.
  • can go unnoticed for months.
  • High Staff Turnover
  • In the U.K., for example, the job turnover rate in hospitality is as high as 90 percent.
  • Reliance on Paying By Card
  • t involves employees selling data to third parties without the knowledge of the organization that employs them.
  • Insider Threats
  • Compliance
  • Hotels, motels, resorts, and rented apartment complexes all gather and electronically store a range of sensitive personal guest data, such as names, phone numbers, addresses, and credit card details.
  • The high level of turnover and high degree of staff movement between different locations makes it a real challenge to maintain teams of well-trained staff
  • Each of these groups may use different computer systems to store information, and the information can also frequently move across those systems.
  • ospitality appears to offer an ideal target vector for conducting crimes such as identity theft and credit card fraud due to the existence of multiple databases and devices containing both Payment Card Information (PCI) and Personally Identifiable Information (PII).
  • ybercriminals use this reliance on cards to infect point-of-sale (POS) systems with malware that steals credit and debit card information by scraping the data
  • A case in point was the Wyndham Worldwide breaches of 2008 and 2010. Hackers gained access to the systems of an individual operating company through easily guessed passwords, and the attack easily proliferated through the entire corporate network, with the result that 619,000 customers had their information compromised.
  • While GDPR protects individual data within the EU and EEA, its ramifications have rippled through industries globally, and organizations are realizing the need to put greater compliance measures in place. PCI DSS is another important global regulation that protects credit card data, and fines for non-compliance begin at $500,000 per incident. The risk here is not just to data security but to the future survivability of hospitality companies, many of which would not be able to absorb the s
  • This type of data risk is more subtle and it involves employees selling data to third parties without the knowledge of the organization that employs them
  • Always encrypt payment ca
  • rd information. Operate a continuous training program in cybersecurity to maintain a well-trained workforce. Always adhere to relevant regulations, such as PCI DSS. Use cybersecurity measures such as firewalls, network monitoring, anti-malware, and traffic filtering to protect against common threats. Conduct tests against your organization’s cybersecurity defenses in which you mirror the behavior of an actual hacker. Know where your data is and enforce the principle of least privileges to limit access to sensitive information.
  •  
    This article highlights several important security issues in the hospitality industry, followed by the practice of protecting data from loss. The data structure of the hotel industry is complex, customers mainly use bank cards to pay, and the staff turnover rate is high. There are certain internal threats. In order to solve these problems and avoid data loss, it is not enough to strengthen network security. It is also important that employees are trained and familiar with and comply with relevant regulations.
  • ...3 more comments...
  •  
    Data security is a major issue in the hospitality industry. A lot of personal information is stored on the computers specifically credit card information of the guests staying at the hotel. It is the responsibility of the hotel to ensure that the data is protected. High turnover rate in the industry can make this an even bigger challenge. Ensuring that your staff is properly trained to ensure the highest level of security is maintained is highly important.
  •  
    This article speaks about the data security concerns in hospitality. Restaurants, hotels, and other companies in the hospitality sector often have complex ownership structures in which there's a franchisor and a management company that acts as the operator. Businesses use different computer systems to store information. The nature of the hospitality industry is such that it is extremely reliant on cards as a form of payment. Cybercriminals use this reliance on cards to infect point-of-sale (POS) systems with malware that steals credit and debit card information by scraping the data. A vital part of protecting data is training staff to securely gather and store personal information. Well-trained staff also know how to recognize social engineering attempts and they understand an organization's compliance requirements. Data security risks in the hospitality industry extend far beyond the reputation hit that a hotel can take if guests' data is compromised. Industry and political regulators are becoming stricter in governing how organizations process and store personal data. Some of the best practices for companies in the hospitality industry to use are: always encrypt payment card info, operate training programs in cybersecurity regularly to keep everyone informed, adhere to regulations, know where the data is, and enforce limit access to sensitive info, and more.
  •  
    This article explains how data security is at an all time high in the hospitality industry. Focuses on the 5 security concerns and what are some practices that leadership can help employees detect when someone is trying to hack into sensitive information. Also, making sure employees are in compliance with company policy when leaving the company if they have access to sensitive data and making sure employees are not using to their advantage when leaving the company.
  •  
    Hospitality offers an ideal target vector for conducting Cyber crimes such as identity theft and credit card fraud due to the existence of multiple databases and devices containing both Payment Card Information (PCI) and Personally Identifiable Information (PII). Restaurants, hotels, and other companies in the hospitality sector often have complex ownership structures with an individual owner or group of owners, and a management company that acts as the operator. Each of these groups may use different computer systems to store information, and the information can also frequently move across those systems.
  •  
    In this article, we learn about the top five data security risks as well as best practices to help prevent data breaches. According to the article, the hospitality industry is a prime target since it stores a vast amount of sensitive guest information like names, phone numbers, addresses, and credit card numbers. Some of the five risks included complex ownership structures, reliance on paying by card, and insider threats to name a few. In order to avoid these threats, the article suggest that companies become PCI compliant, use cybersecurity measures like firewalls, and know where exactly their data is stored.
deranique

Experts at Davos 2023 sound the alarm on cybersecurity | World Economic Forum - 0 views

  • 2023 will be a consequential year for cybersecurity.
  • "There's a gathering cyber storm,"
  • "This storm is brewing, and it's really hard to anticipate just how bad that will be."
  • ...17 more annotations...
  • cyberattacks such as phishing, ransomware and distributed denial-of-service (DDoS) attacks are on the rise.
  • Cloudflare
  • a major US cybersecurity firm that provides protection services for over 30% of Fortune 500 companies
  • "There's been an enormous amount of insecurity around the world,"
  • "I think 2023 is gonna be a busy year in terms of cyber attacks."
  • Experts warned that cyberattacks are increasing in sophistication and frequency.
  • “This is a global threat, and it calls for a global response,”
  • “This is a global threat, and it calls for a global response and enhanced and coordinated action,” Jürgen Stock, the Secretary-General of the International Criminal Police Organization (INTERPOL),
  • “The key to winning the battle against cybercrime is, of course, to work together to make it a priority across the geopolitical fault lines.”
  • This concern has been raised particularly around critical infrastructure sectors like energy, public transportation and manufacturing. SecurityScorecard, a US cybersecurity rating and analysis firm, reported recently that 48% of critical manufacturing companies surveyed were at significant risk of a cyber breach.
  • “Vulnerabilities within the critical manufacturing sector haven’t gone unnoticed by cybercriminals either,” said Aleksandr Yampolskiy, SecurityScorecard's CEO.
  • The Forum's report also notes that the potential targets for cyberattacks are increasing. Today, targets include not only government agencies or major corporations, but largely any organization that handles consumer data—no matter how small.
  • There is no such thing as a hundred percent security. It's about resilience in the face of insecurity.”
  • Consumers, too, need to increase their cybersecurity awareness in 2023, experts say.
  • As more things get connected to the internet there's just more risk. ”— Matthew Prince, Cloudflare CEO
  • Zero Trust approach to cybersecurity, which creates a framework that eliminates implicit trust and ensures that any user—even those who are supposed to be inside an organization's network—is authenticated and validated at every turn.
davidclark33

Coronavirus cybercrime can attack your restaurant system, too | National Restaurant Ass... - 0 views

  • Protecting your business from a data breach is a constant struggle, and it’s even more important during a disaster.
  • Eliot, director of education and strategic initiatives for the NCSA, says cyber incidents and attacks, such as coronavirus-themed email phishing scams, increased as much as 300% to 350% in the first quarter of 2020 and adds that cyber scammers are now trying to target restaurant companies in particular.
  • Cybercriminals have mostly directed malicious emails at telework employees or people donating time and money to those impacted by coronavirus. “We're seeing a huge increase of cyber-related scams promoting coronavirus information or relief efforts. “It’s a big issue.”
  • ...4 more annotations...
  • The PCI Security Standards Council claims that since March, malicious virus-related reports are up 475%. The reason for the uptick is that cybercriminals are trying to take advantage of rapid changes to the payment-card data environment. In addition, 41% of small businesses have said they’ve suffered breaches costing more than $50,000 to fix.
  • Contactless payment is one of the big changes within the payment data environment. Several restaurant companies – from chains to independents – are offering it because it reduces customers' physical interaction with the restaurant's POS system. As part of this move, some businesses have eliminated credit-card PIN numbers.
  • Eliot says malicious email is usually the easiest way for cybercriminals to access your networks. The emails typically show up as urgent requests for sensitive information, often pretending to be from the Small Business Administration or the Centers for Disease Control and Prevention. When the intended victim types in his or her credentials and clicks on a specific link or downloads an attachment, criminals are in.
  • Anyone looking for easy-to-implement security tips can try these six to start. Reduce areas where payment-card data is stored. The best way to protect against a data breach is to avoid storing any card information at all. With many small operators offering curbside pickup and accepting payment over the phone instead of through face-to-face transactions, it’s important they train employees not to write down payment card details. Instead, have them enter numbers directly into a secure terminal. Use strong passwords. Using weak and default passwords is one of the leading causes of payment data breaches among businesses. Effective passwords must be strong and updated regularly. The most recent guidance is: the longer, the better. Think of it almost as a “passphrase” rather than a password. Use it in the form of a sentence, but mix in different characters within the phrase. It’s much harder to break a long passphrase than it is a short, complex password. Weak and vendor default passwords often result in small business data breaches. Also, don’t repeat your passwords. Update your software often. Criminals look for outdated software to exploit flaws in unpatched systems. Timely installations of security patches are crucial to minimizing the risk of a breach. Whenever updates are available, use them. They will improve performance and close out some of the vulnerabilities cybercriminals are searching for. Enable two-factor authentication. It's so important for restaurateurs, especially where their POS systems or any of their sensitive databases are concerned, to have two-factor or multi-factor authentication enabled. If an instance where credentials are stolen occurs, there will be a second layer of verification the operator can rely on to potentially reduce the chances that information will be breached. Segment your networks. If you are going to store payment data, make sure your POS system has its own separate, secure network. Do not store sensitive documents on public cloud services such as Google Docs or DropBox. If you’re going to store sensitive documents, house them in an encrypted, locked down location.   Be hyper-vigilant. Criminals are going to try to take advantage of this pandemic situation as much as possible. You can protect yourself by not giving out sensitive information, especially within unsolicited emails. Don’t click on links you’re not expecting and do everything in your power to protect all sensitive information.
  •  
    This article is about data breaching and cyber crime in the restaurant business. The article specifically talks about the increase in cyber crime during a crisis, and in this case, a pandemic. It talks about contactless payment as a great form of protection for restaurants as well as customers. At the end of the article, it lists six easy to implement security tips.
erinkieltyka

Suspected Ransomware Attack on InterContinental Hotels Affected Over 4,000 Guests | Spi... - 0 views

  • Ransomware generally entails infiltration and compromise, exfiltration of data, and the encryption of data/systems/networks. Hospitality was the eighth most targeted sector by ransomware groups between March 2021 and April 2022.
  • 4,053 ICH users and 15 of its 325,000 employees were compromised in the attack whose perpetrator remains unknown.
  • The company was unable to accept online bookings
  • ...7 more annotations...
  • determine whether the latest cyberattack is more significant than the 2016 breach of the ICH systems. Initially thought to have been a minor breach that affected 12
  • Between September 29 to December 29, 2016, 1,175 properties were infected by malware designed to steal credit card data
  • Marriott International has been breached thrice, resulting in the compromise of the personally identifiable information of up to 338 million guests
  • Marriott was also fined £18.4 million ($23.8 million) by the U.K’s data regulator Information Commissioner’s Office for failing to protect the data of the 338 million guests
  • This is yet another reminder of the damaging impacts of cybercrime. Not only is IHG potentially getting held to ransom for its data access, but it is also losing out on customer bookings
  • Organizations should use this as a warning to never gamble with their cyber defenses. After all, the cost of preparing and preventing an attack is far less than the cost of recovering from one
  • Data breaches, on average, cost organizations $4.25 million in 2022, according to IBM’s 2022 Cost of Data Breach report.
  •  
    This article discusses a recent cyber-attack on ICH that is believed to have been a ransomware attack. It's stated that hospitality is the 8th most targeted sector for ransomware as of recently. The recent attack on ICH 4,053 users and 15 employees were compromised, which is actually far less than their last attack in 2016 that effected 1,175 properties. Hotels must take as much precaution as possible against cyber attacks because not only does it decrease their bookings, but they can also be charged millions in fines for information breaches.
biancafavilli

Tourism security in an age of cyber threats | NTA Courier - 0 views

shared by biancafavilli on 13 Feb 20 - No Cached
kmert005 liked it
  • the safety of clients and staff has to be the No. 1 priority.
  • leisure travel is an expendable industry, and there is nothing that can destroy the industry’s reputation more effectively than a lack of security or safety.
  • it is essential to dispel the idea that tourism security is static.
  • ...4 more annotations...
  • hat means contingency plans must be updated on a regular basis and security plans must show adequate flexibility to incorporate good customer service and proper protection.
  • the latest threat to the industry was underlined by the hacking of Marriott International’s Starwood database, potentially exposing the personal information of approximately half a billion people.
  • This cyberbreach serves as an example that the world of tourism security is fast-changing.
  •  It is essential that every tourism entity assume that, at some point, it will suffer some form of attack, whether physical or cyber. Do not wait for an attack to occur to begin to figure out how to mitigate the damage. Remember that an attack not only damages the client, but it also harms the entire industry.
  •  
    In this article, the author emphasizes that security in the tourism industry should be number one. With the advent of technology, cyber contingency plans must be a part of the overall security plans of tourism businesses. The author also admonishes hospitality businesses to be proactive when dealing with cyber security breaches to withstand malware and infections as well as to be honest with customers when security breaches occur to maintain the customer's trust.
jiayi017

Stopping Data Breaches in Hospitality | Impact Networking - 0 views

  • Nearly half of all cyberattacks target SMBs, a number which is expected to increase.
  • Human error is the number one cause of data breaches from cyberattacks, with 52% of incidents directly attributable to them.
  • The majority of attacks that occur within businesses happen because somewhere along the line, someone made a mistake. Perhaps they opened an attachment they shouldn’t have or visited a risky website.
  • ...7 more annotations...
  • 93% of companies without a disaster recovery plan who suffer a major data disaster are out of business within one year.
  • SMBs simply don’t have the resources to survive breaches and are risking their entire business by not fully preparing against attacks.
  • Research suggests that 70% of consumers would stop doing business with a company if it experienced a data breach.
  • even for businesses who can survive a breach and save their data, long-term consequences can be dire.
  • Consider a true next-gen antivirus for everyone under your network to minimize the potential for attack.
  • By keeping all your data periodically backed up in secure data centers, you can rest a lot more easily knowing that should the worst happen, you can respond quickly and effectively.
  • One of the most effective ways of counteracting the dangers of cyberthreats is by training employees and establishing policies around a security strategy.
  •  
    This article describes the destructive effects of cyber attacks on enterprises, especially small and medium-sized enterprises. Because it does not have sufficient prevention and sufficient resources for disaster recovery. The most direct cause of current cyber attacks is that people open some risky websites or emails in the wrong place. For the hospitality industry, there is a large amount of customer privacy and sensitive information. Once attacked, its destructiveness is unimaginable. And to protect consumer data, most service industries just comply with local state laws, but most state laws have not made greater progress in information protection. Therefore, enterprises should protect themselves and their customers from cyber threats from the three aspects of their own network endpoints, disaster recovery and education.
chadidscha

Cyberattacks are surging. CT's workforce isn't keeping up - 0 views

  • A growing wave of cyberattacks is threatening governments, businesses and everyday residents. Across the globe, there is a critical shortage of skilled professionals to guard against these criminals.
  • The state’s cybersecurity workforce increased by only 1 percent between 2015 and 2020, which was the seventh slowest rate in the nation, according to data from the Bureau of Labor Statistics. By comparison, the ranks of these key professionals more than doubled in a dozen states over that timeframe.
  • Globally, cybersecurity experts are in extraordinarily high demand. An analysis from Cyberseek, a public-private partnership that measures cybersecurity workforce shortages in the United States, notes the talent gap is severe in every state besides Maine.
  • ...1 more annotation...
  • Nationally, the number of unfilled cybersecurity jobs is estimated to be 464,000, including 3,800 in Connecticut, according to Cyberseek, which is backed by a subdivision of the U.S. Department of Commerce.
  •  
    Cyber-attacks has become an increasing problem within the US and the lack of unfulfilled jobs regarding cyber security poses just as big, if not bigger, of a problem. All states, besides Maine, are in dire need to fulfill jobs across the private business sector and government related positions. At this point, many companies, including the government, offer free training (acquiring proper certifications) in hopes of gaining more employees to help with the fight against cyber war.
kteme001

Cybersecurity and the hospitality industry - Las Vegas Review-Journal - 0 views

  • 42 million visitors last year
  • nearly half of cyberattacks worldwide in 2015 were against small businesses with fewer than 250 workers.
  • the average consolidated total cost of a data breach is now $3.8 billion
  • ...3 more annotations...
  • A study by Verizon stated that 99 percent of breaches in 2014 were caused by known vulnerabilities with fixable patches.
  • all working together in an atmosphere that prioritizes data security
  • PCI and our partners are working together to educate our members, find solutions to prevent cybercrime and ensure our work-force and our patrons’ data remains secure.
  •  
    This article highlights a meeting that will be held to gather the world's cyber security experts to discuss and troubleshoot potential threats. Las Vegas specifically is at high risk for intrusion with the high amount of room and restaurant reservations made in this location. The hospitality industry in general is at high risk for cybercriminals to invade their data. Especially small business, the article stated that half of the cyber attacks made in 2015 were against businesses with 250 employees. The data being breached has reached the outrageous total of $3.8 billion. The main point is that most of these issues are preventable, it's all about knowing what can and can't protect you. Investing in the proper technology and dedicated staff can make all the difference. Las Vegas' efforts to prevent these intrusions should set an example for others.
anonymous

Cybersecurity: A Hospitality Industry Reality - AETHOS Consulting Group - 0 views

  • Cyber thieves are crafty and persistent in finding ways to breach security to gain access to personal information. The hospitality industry, hoteliers, restaurants and other such businesses that rely on the use of personal information to provide service to their customers are particularly at risk.
  • Initial steps in the risk-management process Hospitality companies should first focus on developing a robust internal risk-management program, including the establishment of strong policies and procedures; training and insurance can reduce the chances of a data breach and mitigate the damages if a breach occurs.
  • In general, an organization should review the following areas to begin developing a well-rounded risk-management program: Corporate security policy Asset classification and control Personnel security Computer-network and management protocols for vulnerability System access controls Privacy and regulatory compliance
  • ...10 more annotations...
  • Then, ask yourself, “What does our company have in place to mitigate our exposures?”
  • Do we have an effective privacy policy?
  • Do we have an effective privacy-breach response plan?
  • Do we continuously test our disaster-response and business-continuity plans?
  • Franchise concerns
  • Franchise agreements should address several important data-security concerns, cyber-insurance, breach notification and PCI (payment card industry) compliance.
  • Franchise agreements should require franchisees to purchase a specified amount of cyber insurance coverage in the event of a data breach.
  • In addition, the franchisee should be required to promptly notify the franchisor of all breaches in security and immediately notify the franchisor of all breaches of sensitive information.
  • The franchisor may also want to consider being notified of any impermissible uses or disclosures
  • Cyber attack realities The ramifications of a cyber breach could be both financially and operationally catastrophic to any hospitality company. Losses could include costs associated with litigation expenses and fines as well as defense. The cost of business interruption and loss of income could be debilitating.
  •  
    This is an article providing a very high-level introduction to the potential risks faced by the hotel industry from cybersecurity. It outlines some initial steps that hotel companies might consider in their risk-management process and also gives some very specific examples of risk related to franchise contracts.
lethannelson268

FBI Warns of Cyber Security Risk for Workers on Hotel WI-Fi | The National Interest - 0 views

  • The FBI has now issued a warning that those working in that manner may face extra risk of being hacked, and that they should be vigilant about protecting their devices and information while working on hotel Wi-Fi
  • The Federal Bureau of Investigation is issuing this announcement to encourage Americans to exercise caution when using hotel wireless networks (Wi-Fi) for telework
  • accessing sensitive information from hotel Wi-Fi poses an increased security risk over home Wi-Fi networks
  • ...2 more annotations...
  • The report states that hotel Wi-Fi often has more lax security than other types of common Wi-Fi networks, and that attacks are frequently interested in obtaining guests’ information, including credit-card numbers, as well as business data
  • “Evil twin” attacks, in which hackers create fake Wi-Fi networks similar to those of the actual hotel, can also happen
  •  
    This article highlights the need for hotel guests to be weary of the fact that the use of a hotel's Wi-Fi is not always secure. With more hotels opening up for guests to use their rooms and spaces as work offices, the FBI has stated that with the limited cyber security that hotel Wi-Fi has, it is possible for hackers to create fake Wi-Fi networks and steal or damage guest data. The article makes it known that it is much safer to use the network at home, that that at a hotel.
amdelgad

All Bets Are Off on Casinos and Cybersecurity | UpGuard - 0 views

  • better malware tools and access to deep funding make today's cyber criminals more than a bad movie, especially when lucrative payloads are for the taking.
  • In May 2015, attackers were able to steal cardholder names, credit card numbers, and CVV codes belonging to hotel guests and customers. In 2016 they suffered similar incidents due to malware being installed on POS systems, allowing attackers to steal customers' credit card information.
  • It may come as no surprise that casinos and gaming firms are ideal cyber attack targets, but how competent are these enterprises when it comes to rudimentary security?
  • ...1 more annotation...
  • Online gambling upstart Ignition Casino offers Blackjack, Slots, Poker on its website; fortunately, the company has also taken the requisite security measures for bolstering its website security and email security.
  •  
    This article focused on cybersecurity in hotel casinos. They mention how casinos seem to be a target for a lot of cyber attackers because they tend to not invest as they should on protecting themselves. Casinos hold a TON of financial data; customer info., bank info., and credit card info. I enjoyed the article because they even went as far as giving a few casinos a "security score" in how well/bad they are in staying secure.
« First ‹ Previous 41 - 60 of 166 Next › Last »
Showing 20 items per page