1 / 4100%
Introduction
Hotel security does not extend to just physical security. Digital
assets need to be accessed and secured as well. In 2018, The
Marriot reported that hackers breached digital information. The
Federal Trade Commission mentions, “. . . the hackers accessed
people’s names, addresses, phone numbers, email addresses,
passport numbers, dates of birth, gender, Starwood loyalty program
account information, and reservation information.” (Federal Trade
Commission, 2018)
Recently Padgett-Beale Hotels have experienced a similar incident.
Padgett-Beale has a system used for hotel staff to input specific
requests such as maintenance, housekeeping, or dietary needs that
food service personnel may need to review when preparing a
guest’s meal. Guests may put in these specific requests via a web-
based form or contact the front desk. Unfortunately, some
anonymous staffers who entered some of this information included
"outrageous guest requests" under the "Humor" section of
employee bulletin boards in the Resort Operations staff locker
rooms. Alarmingly, some of these postings have included guest
names and room numbers along with names and ages of children.
Padgett-Beale takes these actions seriously and will outline a few
ways to rectify this situation. Below are several recommendations
for best practices to improve its data breach response policy and
plans
Cyber Liability Insurance
Cyber incidents can be very costly to a company in time, resources,
or finances. In fact, IBM reports that “The most common initial
attack vector, compromised credentials, was responsible for 20% of
breaches at an average breach cost of USD 4.37 million.” (IBM,
2021) One solution is to enroll in a cyber liability insurance plan
which can cover a broad range of remedies and services. Traveler’s
insurance mentions from their website, “Those costs can include
such things as lost income due to a cyber event, costs associated
with notifying customers affected by a breach, costs for recovering
compromised data, costs for repairing damaged computer systems
and more.” (Travelers, 2022) Insurance such as this alleviates the
complexity associated with such incidents and could help target
Padgett-Beale’s shortcomings for such events.
Restrict Remote Access
Remote access for help desk assistance has been on the rise for
several uses. These applications have been used for tech support or
live chat services. Padgett-Beale should make a conscious effort to
restrict this practice from users and only enable this for authorized
staff members. Oftentimes, scams are conducted through phishing
attempts and can lead to malicious actors gaining valuable
information. QuickBooks highlights this event by saying, “Tech
support scammers often impersonate trusted companies that you
already interact with to gain access to your systems and sensitive
data. These scammers may ask you to download and initiate a
remote access service like LogMeIn, TeamViewer, or GoToMyPC.”
(QuickBooks, 2019) Padgett-Beale IT staff should make efforts to
block all unregistered remote services at the firewall in the event a
compromised internal host attempts to utilize these services.
Validate Electronic Transmission
In addition to encryption of stored media, secure electronic
transmission protocols are recommended to use for devices
communicating important information across the network. The
Federal Trade Commission (FTC) recommends using Transport Layer
Security (TLS) when transmitting financial information or sensitive
personal information. (Federal Trade Commission, N/D) When using
TLS, the data is encrypted throughout the connection process and
prevents the information from showing up in cleartext.
Limit Social Media Access
The potential for unintended malicious interactions on social media
platforms remains a very common threat across all platforms. Hotels
can be held liable for postings made on these sites. Global
Hospitality Group (GHS) highlights this concern and says, “. . . hotels
can be held responsible for postings, both those that a firm makes
intentionally – for example, in response to a customer review – and
those made without clear authorization, like postings by a hotel
employee.” (Global Hospitality Group, 2012) Padgett-Beale IT staff
may want to block these commonly accessed sites at the firewall or
allow only authorized users to access these sites. If a staff member
is authorized to access a social media site and make a post, then
Padgett-Beale needs to set clear and concise guidelines for social
media use including language, use of hotel information,
descriptions of events, misuse of hotel guest information, etc.
Specify the Data Collected
Hotels require a lot of information for its guests to stay. Some of
this information includes data such as name, phone numbers, home
address, employment address, credit card numbers, and many other
data points. However much of this information may not need to be
stored such as gender, purchase history, or marital status. Instead,
Padgett-Beale may want to have a third-party store this
information. The Better Business Bureau (BBB) recommends the use
of third-party providers when discussing advertising analytics and
payment processors. Additionally, the use of these services need to
accessible to staff and customers alike.
Summary
In conclusion, Padgett-Beale should establish a clear and concise
policy regarding data breach incidents. Preventative safeguards for
technical, personal, and financial concerns can be established using
insurance services such as Travelers Cyber Liability Insurance.
Additionally, IT staff can enhance the network by limiting the use of
remote access applications and social media. The use of TLS on the
network ensures safe and reliable encrypted communications.
Lastly, data that is collected should be specified. Different types of
data may be outsourced to third parties, but will need to be
accessible to partners, staff members, and guests in a detailed
description of its uses.
References
Better Business Bureau. (2020) “BBB Tip: Writing an Effective
Privacy Policy for Your Business' Website.” Better Business Bureau.
https://www.bbb.org/article/news-releases/21390-bbb-tip-writing-
an-effective-privacy-policy-for-your-small-business-website
Federal Trade Commission. (2018) “The Marriott data breach.”
Federal Trade Commission. https://consumer.ftc.gov/consumer-
alerts/2018/12/marriott-data-breach
Federal Trade Commission. (N/D) “Protecting Personal Information:
A Guide for Business.” Federal Trade Commission.
https://www.ftc.gov/business-guidance/resources/protecting-
personal-information-guide-business
Global Hospitality Group. (2012) “Hotel Liability for Guest
Information — What you need to know and how to avoid liability.”
Global Hospitality Group.
https://hotellaw.jmbm.com/liability_for_guest_information_.html
IBM. (2021) “How much does a data breach cost?” IBM.
https://www.ibm.com/security/data-breach
QuickBooks. (2019) “How you can help protect your business from
fraud.” QuickBooks. https://quickbooks.intuit.com/r/operations-
technology/how-to-protect-your-small-business-from-fraud/
Travelers. (2022) “Prepare Your Business with Cyber Insurance
Coverage and Solutions.” Travelers.
https://www.travelers.com/cyber-insurance
Students also viewed