Why this review matters
Hotels depend on reservation, payment, door-access, Wi-Fi, property-management, and vendor systems. A cyber event can affect guest information and also interrupt check-in, room access, payment, and revenue.
Information to prepare
- Systems that store guest, employee, and payment data
- Vendor and franchise technology dependencies
- Multi-factor authentication, backups, patching, and access controls
- Incident-response and business-continuity plans
- Prior incidents, testing, and corrective action
Decisions to discuss
- Privacy, network security, and breach-response limits
- Business interruption and dependent-system coverage
- Cybercrime and social-engineering considerations
- Retention, waiting periods, and vendor-related terms
Common pitfalls
- Treating cyber as only a data-breach issue
- Ignoring franchise and vendor dependencies
- Failing to test backups and manual procedures
- Using one shared account for critical systems
Frequently asked questions
Why is cyber business interruption relevant to a hotel?
A system outage can disrupt reservations, check-in, payments, room access, and communications even when the physical property is undamaged.
Should third-party systems be listed?
Yes. Reservation, payment, franchise, payroll, and property-management vendors can be critical dependencies and should be discussed during the review.
Coverage descriptions are general. Availability, eligibility, limits, exclusions, and policy terms vary. Review actual policy documents and requirements with an appropriate insurance professional.
