A story we hear too often
The Saturday night the front desk could not make a room key
the general manager of a 140-room independent hotel with two restaurants
Marisol has run the hotel on the river for nine years. One hundred forty rooms, two restaurants, a wedding most Saturdays. Tonight the ballroom holds 180 guests and the bar is three deep.
At 9:50 the front desk cannot cut a key. The property system is frozen, then a message appears. The restaurant terminals still work, which is worse: the attacker has been in the network long enough to choose what to stop. It started nine days earlier with a phone call to the help desk, a friendly voice asking to reset a manager’s password.
In the version that ends badly, guests sleep in the lobby, the card data from both restaurants has been leaving since Tuesday, the wedding party posts about it, and the brand’s franchise office calls Monday.
In Marisol’s version, the help-desk reset never happened because the desk had to call the manager back on a known number. The protection agent flagged the attempt, the engineer traced the caller’s earlier probing and closed the vendor VPN account that started it. The keys cut. The bride never knows.
The restaurant terminals still work, which is worse: the attacker has been in the network long enough to choose what to stop.
What changes the ending
- A call-back rule for every password reset, however friendly the voice (CIS Controls 14 and 5, Security Awareness and Account Management)
- Property, restaurant and guest Wi-Fi networks separated, with the card terminals on their own (CIS Control 12, Network Infrastructure Management)
- Vendor and remote-access accounts inventoried and watched, not left on after the install (CIS Control 15, Service Provider Management)