Tech-Savvy Innovative Hotels Are More Vulnerable to Data Breaches

The race to become the most innovated and tech-savvy hotel is on. Hotels have increasingly begun working with technology companies to offer more innovative and enhanced guest experiences.
Guests at many hotels can now bypass the need to go to the front desk by using their mobile devices to select a room, check-in, receive texts when their room is ready, and even unlock the door to their room. Guests can also customize their stay by requesting items, ordering room service, planning activities, or purchasing upgrades.
Everything a guest may want is only a few clicks or taps away, and soon, the data collected by these programs will allow hotel operators to anticipate guests’ requests and needs. These services along with public WiFi networks, data-sharing with OTAs, smartphone key cards, and other interconnected systems makes the hospitality industry particularly vulnerable to a data breach.
According to Trustwave’s 2016 Global Security Report, the hospitality industry accounted for the second largest share of data breach incidents by industry at 14% of the incidences investigated by Trustwave and was followed by the food and beverage industry at 10%.[1] The amount of data hotel operators can gather and store about their guest can be a double edged sword. Hoteliers should be aware of potential complications that come with these added conveniences, such as the responsibility to protect their guests’ personal information, as well as the physical security of the guests’ rooms from a privacy event or data breach.
A privacy event or data breach triggers certain “clean up” protocol, regardless of the cause or the materiality of the breach. There are two aspects to any clean up. One side is the legal compliance with the various laws and regulations that are triggered and the other side is the public relations management.
The 2016 Ponemon Cost of Data Breach Study: United States (sponsored by IBM) found that the average cost per lost or stolen record in the United States is $221 and the average total cost of a single data breach was $7.01 million in the United States.[2] A “breach coach,” who is often a lawyer, can help determine if there was a breach, what needs to be done to comply with the legal regulations, what forensic investigation is needed, and what else needs to be done to best manage any potential liability and public relations.
Cyber security laws are constantly evolving, but for the foreseeable future, these laws will likely be constantly behind the development of new technology. Therefore, it is important for hoteliers to be forward thinking and prepare for changes to the laws in the future. Currently, each state, territory, and the District of Columbia varies on its notification and reporting requirements, as well as the fines and penalties related to a breach. Notification to the affected individual must be made in compliance with the laws in the state in which the affected individual resides.
A single hotel could be exposed to more than fifty different notice requirements, more than fifty different state actions by more than fifty different state regulators, and more than fifty different fines and penalties.


