The hotel industry is the third most frequent target of cyberattacks worldwide, right after healthcare and the financial sector. The reason is simple: hotels process payment cards, travel documents and personal data of thousands of guests every year. Yet their IT security is surprisingly weak.
Why hotels are such an attractive target
Attackers go where there is data and where defences are weak. Hotels meet both conditions:
- 🔴 Guest payment cards - thousands of transactions annually, PCI-DSS compliance is complex
- 🔴 Copies of passports and certificates - The hotel reception is one of the few places where passports are physically copied.
- 🔴 Open Wi-Fi for guests - if not properly segmented, it serves as an entry point to the entire network
- 🔴 PMS systems - often outdated, running Windows 7, without updates, and connected to everything
- 🔴 Seasonal staff turnover - access is not granted or collected systematically
Case study from practice (2025): An attack on the network of a four-star hotel in Prague came via tablets at the reception which had not been updated. The attackers gained access to the PMS and, with it, to the data of 8 000 guests including card numbers. GDPR fine: 2.8 mil. Kč. Reputational damage: incalculable.
The 5 biggest security gaps in hotels
1. Unsegmented network
The biggest problem and the simplest fix. If guests share the network with the reception system, cash registers or CCTV, any compromised guest laptop can become an entry point into the entire infrastructure. Solution: separate VLANs for guests, operations (PMS, tills), IoT (TV, key systems) and management.
2. Outdated PMS system
A large proportion of hotels in the Czech Republic still operate their PMS on Windows 7 or Windows Server 2012, systems for which Microsoft has ceased issuing security patches. Every day of operation is a gamble. Yet migration to a cloud-based PMS or at least updating the OS to Windows Server 2022 is today a matter of days, not months.
3. Shared and weak passwords
Hotel2024", "recepcePW" or passwords shared via WhatsApp with casual staff. A classic that costs hotels millions. The solution: a password manager for the team, unique access credentials for every employee, and automatic removal of access upon termination of cooperation.
4. Missing deposits
Ransomware attacks on hotels work as follows: encrypt the PMS, lobby displays and restaurant system, then demand a ransom. If you have backups from yesterday, the issue is restoring systems (days of work). If you have no backups, you pay. Backups should be automatic, daily, tested and stored off-site.
5. Missing staff training
90% of successful attacks on hotels begin with a phishing email. Attackers pose as booking platforms (Booking.com, Expedia), suppliers, or companies claiming an "unpaid invoice". Receptionists and accountants are the first line of defence, and if they are not trained, they become the first point of breach.
GDPR and NIS2: what are the penalties for non-compliance?
Hotels are obliged to protect guests' personal data under GDPR. A data breach without implemented measures may result in:
- 💶 GDPR fine up to 4% of annual turnover or €20 million (whichever is higher)
- 📰 Mandatory notification to ÚOOÚ within 72 hours of detecting a leak
- 📧 Informing affected guests - reputational impact
- ⚖️ Civil lawsuits from guests whose data was leaked
From 2025, Act No. 264/2025 Coll. (transposition of NIS2) applies in the Czech Republic, extending obligations to operators of accommodation facilities above a certain size. If your hotel has more than 50 employees or turnover exceeding 10 mil. EUR, it likely applies to you.
Practical checklist: what to do today
Immediate measures (no cost)
- ✅ Check that all devices with access to the PMS are updated
- ✅ Change all shared passwords to unique ones for each employee
- ✅ Verify that guest WiFi is isolated from the internal network
- ✅ Run a test: send yourself a phishing email: who clicked on it?
Short-term measures (1–4 weeks)
- 🔵 Implement a backup solution with an off-site copy
- 🔵 Segment the network into VLANs (guests / operations / IoT / management)
- 🔵 Enable two-factor authentication for PMS and email
- 🔵 Carry out an inventory of all devices with internet access
Medium-term measures (1–3 months)
- 🟡 Migrate your PMS to a current operating system or a cloud solution
- 🟡 Carry out a security audit of the entire IT infrastructure
- 🟡 Introduce regular staff training (minimum once a year)
- 🟡 Check PCI-DSS compliance of payment terminals
What is the total cost?
Hotels sometimes ask: "How much will security cost us?" A better question is: "How much will a lack of security cost us?
| Measures | Indicative price | Frequency |
|---|---|---|
| Network segmentation (VLAN) | 15 000-30 000 Kč | One-off |
| Backup solution | 5 000-15 000 Kč | Annually |
| Safety audit | 20 000-50 000 Kč | Once every 2 years |
| Staff training | 8 000-20 000 Kč | Annually |
| IT monitoring | 3 000-8 000 Kč/month | Continuously |
For comparison: average GDPR fine for a hotel data breach in the EU (2024): 1.2 million EUR.
Don't know where to start?
We offer a free IT infrastructure security audit for hotels in Prague. We check network segmentation, the status of PMS systems, backups and access rights. You receive a concrete report, without unnecessary fluff.
Book a free audit →