By Frank Ziller, Chief Technology Officer at Cloud5 Communications – 8.31.2026
In over 30 years working in hospitality technology, I’ve learned one important lesson about threats: they don’t give us time to prepare, they show up when we least expect them. Cybersecurity has shown up in a manner that every hotel IT leader needs to take seriously.
Hospitality sits squarely among the most targeted industries for cyberattacks. The average cost of a data breach in hospitality reached $4.03 million in 2025. For many hotel groups, a single breach could mean the difference between a profitable year and a devastating one. And the damage goes beyond the balance sheet. Research shows that 84% of guests lose trust in a brand after a data breach. Once that confidence is gone, they don’t come back.
Security Beyond the Firewall
In our industry, like many others, PCI compliance is standard operating procedure. Compliance alone, however, won’t protect you. Hotels operate in an expansive digital environment including payment systems, Guest Wi-Fi, Internet of Things (IoT) devices like locks and thermostats, reservations platforms, and other third-party integrated services. Every one of those is a doorway. Recent research found that 82% of North American hotels experienced a successful breach last summer, with payment and POS systems topping the risk list.
AI-driven threat detection is becoming a viable resource in hospitality, not just a concept people talk about at conferences. AI threat detection can monitor behavior to identify malicious activity before it escalates. That said, technology is only part of the equation. According to the 2025 Verizon Data Breach Investigations Report, 68% of all data breaches involve a human element. Phishing emails, weak passwords, a well-meaning employee clicking the wrong link. That’s how most breaches start.
Hospitality makes this especially complex. We have high staff turnover, seasonal workers and a culture built around being helpful. Attackers know this. They use social engineering because it works. The best firewall in the world can’t stop an employee from handing over credentials to someone who sounds like they’re from the front desk. Training has to be ongoing, practical and realistic. Not a once-a-year compliance video everyone clicks through.
Resilience in the Face of Disaster
I’ve seen this play out more than once: a hotel’s property management system goes down, and suddenly there’s no way to check guests in, process payments or access reservation data. The scramble that follows is expensive and messy. I’ve lived through enough crises in this industry to know how this story ends. The organizations that recovered fastest all had one thing in common: they’d planned for the worst before it happened.
A hybrid backup strategy works best: on-site backups for fast local recovery, paired with cloud-based backups for geographic redundancy. If ransomware encrypts your local servers, your cloud backup becomes your lifeline. If a natural disaster takes out your physical location, on-site copies at another property fill the gap.
Two terms every IT leader should be able to answer without hesitation: your Recovery Time Objective (RTO) and your Recovery Point Objective (RPO). RTO is how quickly you need systems back online. RPO is how much data you can afford to lose. For a hotel processing thousands of transactions daily, an RPO of 24 hours might be unacceptable. For a back-office reporting system, it might be fine. Defining these numbers forces honest conversations about priorities. It’s the kind of planning that feels tedious until the day you need it.
When Security Becomes a Revenue Driver
Most people view cybersecurity as simply an additional cost center. One way to spend money to avoid potential negative consequences. However, the numbers tell a different story when you consider the actual benefits that come from implementing robust cybersecurity measures.
Start with the direct costs. On average hotel data breaches result in damages of approximately $3.36 million in the U.S., and that doesn’t account for the operational chaos that follows. Downtime can prevent guests from checking-in, freeze the ability to process payments and keep the property’s reservation systems offline for extended periods. For a highly occupied hotel, each hour of downtime equates to a dollar amount of lost revenue.
Then there’s the guest trust factor. We have learned that 84% of guests lose confidence in a brand after a data breach. What we do not hear as much about is the loss of long-term value associated with each guest that leaves. Each guest has the potential to become a repeat customer that books directly, returns annually and sends referrals to friends and family. Losing that trust will have exponential lasting financial impacts on the revenue stream of your hotel.
Cyber insurance is another area where proactive security pays off. Insurers are scrutinizing hospitality companies more closely than ever. Properties that have implemented strong security measures such as endpoint protection, conduct regular vulnerability assessments and maintain written incident response plans are seeing significantly lower premiums for their cyber insurance. Hotels that do not have these security measures in place may be faced with extremely higher premiums, or face challenges finding coverage at all.
Hotels that are doing this correctly are not viewing cybersecurity as a line item to reduce. They’re treating it as infrastructure that protects revenue, reduces operating costs and gives them a real edge over competitors that have yet to implement similar security measures.
Looking Ahead
Cybersecurity and emerging technology aren’t separate conversations. The hotels that treat security as a cost center will keep falling behind. The ones that build security into their strategy from the start will find themselves with stronger operations, better guest experiences and healthier margins.
In our work with leading global hotel brands and management companies, I’ve seen this firsthand. The properties that invest in solid infrastructure, train their people and use data to guide decisions don’t just survive disruptions. They come out of them stronger.
The threats are serious. The tools available to us are better than they’ve ever been. And the gap between hotels that take this seriously and those that don’t will only keep growing. Start with the basics: know your vulnerabilities, protect your data, train your staff and build a technology foundation that can grow with you. The rest will follow.
Frank Ziller is Chief Technology Officer at Cloud5 Communications, a leading technology strategy and innovation for one of North America’s largest providers of hospitality IT services. The company’s fast, reliable Internet solutions and flexible voice systems enhance the guest experience at more than 5,000 hotels across the United States, Canada and CALA. Cloud5’s award-winning Contact Center combines innovation with skilled agents to deliver white label hotel reservations, sales, guest relations and service that add value across any channel. The company’s comprehensive Managed IT and Managed Security Services (MSP/MSSP) support all the technology-related components of a successful hotel operation and act as an extension of a property’s IT department. With more than 25 years of experience in managed services and enterprise IT, Ziller helps hotel organizations strengthen technology infrastructure, cybersecurity, and operational resilience.
Are you an industry thought leader with a point of view on hotel technology that you would like to share with our readers? If so, we invite you to review our editorial guidelines and submit your article for publishing consideration.
Related
