AccuSights
PartnersBlogAbout
Book my 30-minute demo

Restaurants, Hotels & Hospitality · Cybersecurity, compliance and GRC, in plain English

A Saturday night with 180 guests is not the time to find out.

The attack on MGM Resorts started with a ten-minute phone call to a help desk and cost about $100 million. Yours would start the same way, with a friendly voice and a manager’s password reset, and end with terminals that cannot take cards and a front desk that cannot cut keys. We put the call-back rule in place, separate the guest, restaurant and property networks, review the terminals against PCI DSS v4.0.1 and watch it all through the wedding.

PCI DSS v4.0.1 review includedBuilt for independents and franchise ownersSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The Saturday night the front desk could not make a room key

the general manager of a 140-room independent hotel with two restaurants

Marisol has run the hotel on the river for nine years. One hundred forty rooms, two restaurants, a wedding most Saturdays. Tonight the ballroom holds 180 guests and the bar is three deep.

At 9:50 the front desk cannot cut a key. The property system is frozen, then a message appears. The restaurant terminals still work, which is worse: the attacker has been in the network long enough to choose what to stop. It started nine days earlier with a phone call to the help desk, a friendly voice asking to reset a manager’s password.

In the version that ends badly, guests sleep in the lobby, the card data from both restaurants has been leaving since Tuesday, the wedding party posts about it, and the brand’s franchise office calls Monday.

In Marisol’s version, the help-desk reset never happened because the desk had to call the manager back on a known number. The protection agent flagged the attempt, the engineer traced the caller’s earlier probing and closed the vendor VPN account that started it. The keys cut. The bride never knows.

The restaurant terminals still work, which is worse: the attacker has been in the network long enough to choose what to stop.

What changes the ending

  1. A call-back rule for every password reset, however friendly the voice (CIS Controls 14 and 5, Security Awareness and Account Management)
  2. Property, restaurant and guest Wi-Fi networks separated, with the card terminals on their own (CIS Control 12, Network Infrastructure Management)
  3. Vendor and remote-access accounts inventoried and watched, not left on after the install (CIS Control 15, Service Provider Management)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

Can money be stolen through the card terminals in our restaurants and at the front desk?

Yes, and it usually runs for weeks: malware on the terminal network or a compromised back-office PC copies card numbers as they pass. Segmented terminal networks, encrypted readers and someone watching the logs stop it, and PCI DSS v4.0.1 has required those controls in full since March 2025.

What happens to our guests if the property management system goes down for a week?

You go to paper, you cannot cut keys and you cannot charge cards, which is what a US hotel chain lived through for more than a week in 2024. The assessment tests whether your backups, your vendor’s recovery commitments and your manual procedures are real before a Saturday night proves it.

Our hotel management platform holds our guest data. If they are breached, is it our notice to send?

Usually yes: the guests are yours, and state breach laws look at the business the guest gave the data to. Vendor review, contract terms and your own copy of the guest data are what turn a vendor’s breach into a manageable notice instead of a reputational event.

What you hold, and why someone wants it

Your data protection needs, by the data.

Card data at the front desk, the restaurants and the bar

Every check-in and every check passes card numbers that resell in minutes. Segmented terminal networks and PCI DSS v4.0.1 controls protect them.

Guest profiles and reservations

Names, stays, IDs, loyalty numbers and travel patterns of your best customers. MFA, encryption and vendor review protect them.

The property management and point-of-sale systems

Take them down and you cannot make a key or a sale. Backups, network segmentation and watched vendor access protect them.

Employee records, tips and payroll

High-turnover staff records with direct-deposit details. Payroll-change verification protects them.

Guest and event Wi-Fi

A shared network is a bridge from a laptop in room 214 to the front desk. Network separation protects it.

$100M
in lost adjusted earnings reported by MGM Resorts after a September 2023 attack that started with one phone call to its help desk
Source: MGM Resorts SEC Form 8-K, October 2023, reported by The Record
7.8 TB
of hotel data, including guest reservations and personal details for Marriott, Hilton and Hyatt properties, taken from a hotel-management vendor between July and October 2024
Source: BleepingComputer, January 2025, on the Otelier breach
48%
of breaches involved a third party; for a hotel that is the PMS vendor, the booking engine, the installer’s VPN account and the franchise office
Source: Verizon 2026 Data Breach Investigations Report

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

PCI DSS v4.0.1
PCI Security Standards Council
Front desk, restaurants, bar and the online booking engine all fall under the standard; the future-dated requirements became mandatory March 31, 2025.
State privacy and breach notification laws
State attorneys general
Guest records trigger notification in all 50 states; comprehensive privacy laws in twenty states add access and deletion rights for guests.
FTC Act Section 5
Federal Trade Commission
The October 2024 order against a global hotel brand set a twenty-year security program requirement; the FTC treats poor guest-data security as an unfair practice.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • A help-desk reset from a friendly caller that hands over a manager’s account, then the property system.
  • Card data leaving the restaurant and front-desk terminals for weeks before the processor calls.
  • The booking engine or online ordering going dark on the busiest weekend, as a national doughnut chain found in November 2024.

It happened to businesses like yours

A September 2023 attack that began with a ten-minute phone call to MGM Resorts’ IT help desk locked slot machines, room keys and reservations across its Las Vegas properties; MGM told the SEC it cost about $100 million.

September 2023 · The Record

A March 29, 2024 ransomware attack took Omni Hotels & Resorts’ reservation, room-key and point-of-sale systems down for more than a week across its properties; the Daixin gang later claimed the stolen data.

March to April 2024 · BleepingComputer

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a hospitality business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your front desk, sales and accounting inboxes, where the fake vendor invoice and the group-booking scam arrive.
  • Every front-desk PC, back-office workstation and manager laptop.
  • The property management server and the file share holding guest and event files.
  • The website and the online booking engine, including the payment connection.
  • The card terminals’ network in the restaurants and at the desk, segmented and watched.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Hospitality

Built on the CIS Controls v8.1 IG1 and scoped from what a hotel or a restaurant stands to lose: the terminals, the property system and the guest’s trust. Findings are ranked by property and written for an operator, with the PCI review folded in rather than sold twice.

  • Inventory of every terminal, front-desk PC, kiosk, back-office workstation and cloud app across properties (CIS Controls 1 and 2)
  • Network review: property, restaurant, back-office and guest Wi-Fi separation, with card terminals on their own segment (CIS Control 12)
  • PCI DSS v4.0.1 gap review for the front desk, the restaurants and the online booking engine
  • Account and vendor audit: help-desk reset rules, remote-access accounts left by installers, MFA on the PMS and POS (CIS Controls 5, 6 and 15)
  • Backup and manual-operations test: can you check guests in, cut keys and take payment if the PMS is down (CIS Control 11)
  • Ranked remediation plan by property, with a rehearsed response plan for a Saturday night
Start with the 3-minute test

Packages

Built for hospitality businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

How do hackers steal credit cards from restaurants?
Through malware on the terminal network or the back-office PC that copies card numbers as they pass, or through a compromised online-ordering platform. In late 2025 patrons of restaurants using one POS platform received extortion emails from the attacker directly. Segmentation, encrypted readers and monitoring are the fix.
What is PCI compliance for a restaurant or hotel?
PCI DSS is the card brands’ standard for any business that takes cards. Most independents self-assess with a questionnaire; the assessment gets the terminals, the network and the booking engine to the point where the questionnaire is true, and keeps the evidence.
Is guest Wi-Fi a security risk?
Only when it shares a network with the front desk or the terminals, which is common in older properties. Separating guest, event, restaurant and back-office traffic is a one-time project with a lasting payoff, and it is the first thing we check.

People also search: cybersecurity for restaurants near me · hotel cybersecurity services in Chicago · for a 140-room independent hotel · for a restaurant group with four locations · PCI compliance help for restaurants · cybersecurity for a boutique hotel in the suburbs · for a franchise hotel owner with three properties · point-of-sale security for bars and restaurants

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test