What to do if your hotel's IT system has been hacked?
Every hotelier's nightmare: arriving at the reception in the morning to find a ransom demand from encryption Trojans instead of the usual desktop background, making all data on the computer unusable. Then the phone rings, and the first guest complains that the credit card data they used last week at the hotel has been misused.
In such crisis situations, it is crucial to have a clear plan. We support you with our free crisis management checklist. Additionally, our security experts are available for a fast, free initial assessment.
- Keep a printed crisis plan at the reception
- Tips for immediate emergency response
- First steps in crisis situations
What threats do hotels need to protect against?
The need for security arises from both economic foresight and legal requirements. On the one hand, hotels are exposed to a variety of IT risks. On the other hand, as collection points for financial and personal data, hotels are subject in particular to the following regulations:
- Federal Data Protection Act (BDSG) / EU General Data Protection Regulation (GDPR)
- Digital Services Act (DDG)
- Commercial Code (HGB)
- Payment Card Industry Data Security Standard (PCI-DSS)
These laws regulate, among other things, the obligation to take technical and organizational measures to protect personal data. Non-compliance can lead to fines and the obligation to inform affected parties of data theft.
When protecting your hotel, we work closely with other entities such as data protection officers, IT service providers, or insurance companies, providing professional advice or conducting audits as a neutral third party. Particular focus in hotel protection is placed on the website,
Current Threats to Hotels
- Bank and credit card theft
- Encryption Trojans (Ransomware)
- Website sabotage via defacement
- Wi-Fi eavesdropping
- Industrial espionage
How can aramido help your hotel?
Hotel Security Check
The security check was specifically developed by us for the typical conditions found in hotels. It examines the most important points in a hotel IT security concept:
- Homepage security audit
- On-site IT infrastructure audit (Wi-Fi, software, PCs, etc.)
Let us find your security gaps before criminals do. If you successfully complete the security check, you will receive a certificate that you can use for marketing purposes.
PCI-DSS Certification Preparation
All hotels that accept credit cards are subject to the requirements of PCI-DSS, the consortium of the largest credit card companies. These regulations apply even if you have commissioned an external service provider for credit card processing. In this case, you are even obligated to verify that the service provider itself is PCI-DSS compliant.
Read more in our background article on PCI-DSS certification for hotels. aramido supports you in conducting a so-called Self Assessment.
Employee Training
One of the most important pillars in a hotel's security concept is the staff. They are often the target of so-called social engineering attacks by digital intruders. aramido knows how to introduce employees to the topic of IT security in an entertaining way, ensuring a genuine gain in security.
- Live hacking to increase security awareness
- Establishing rules of conduct
- Security as part of service quality
IT Security Officer for Hotels
The closest form of cooperation is appointing an IT security expert from aramido as your IT Security Officer. According to the BSI IT-Grundschutz catalog, this person is responsible for the following points:
- Creating an IT security concept
- Coordinating external service providers
- Training employees
- Regularly reviewing security-relevant systems
- First point of contact for security incidents
Do you want to secure your hotel against IT security risks? Use the free initial consultation to clarify your security needs.
