Dubai, UAE · Written by George Stoyanov, Platform Chairman · 7 min read
A hotel’s Property Management System and Point of Sale network sit at the centre of almost everything the operation does — reservations, guest payment data, room access, F&B revenue. That makes them one of the more attractive targets in the building, and one of the least consistently secured.
Why Hotels Specifically Are Exposed
Hotels combine several things attackers look for: a high volume of card transactions, a constant flow of new guest devices connecting to the network, third-party integrations with booking platforms and loyalty systems, and — in many properties — legacy PMS or POS software that hasn’t been meaningfully updated in years. Add distributed properties each with their own local IT setup, and the attack surface multiplies quickly.
Where the Real Vulnerabilities Sit
Flat network architecture
Guest WiFi, back-office systems, and the PMS/POS network are sometimes still on the same network segment, meaning a compromised guest device can potentially reach systems it should never touch.
Vendor and third-party access
PMS and POS vendors, along with loyalty and booking-engine integrations, often hold standing remote access credentials that outlive the project they were created for.
Legacy systems and default credentials
Older POS terminals and back-office servers running unsupported software, sometimes still on default or weak administrative credentials, remain more common than operators expect.
“The pattern we see most often isn’t a sophisticated attack. It’s a known vulnerability that was never patched, on a system nobody remembered was still connected to the network.”
— George Stoyanov, Platform Chairman
What a Sensible Baseline Looks Like
- Segment the network — Guest WiFi, back-office systems, and PMS/POS infrastructure should sit on genuinely separate network segments, not just different WiFi names on the same backbone.
- Audit vendor access regularly — Every third party with remote access to PMS or POS systems should be on a reviewed, time-bound access list, not a standing credential set up years ago.
- Patch on a schedule, not a memory — A documented patching cadence for PMS, POS, and the servers underneath them, with a clear owner, rather than relying on it happening whenever IT has time.
- Test access controls, not just passwords — Role-based access reviews for who can view or export guest payment and personal data, and how often that access is checked.
- Plan the incident response before you need it — A defined process for containment, guest notification, and regulatory reporting if a breach does occur, tested rather than filed away.
Compliance Alone Isn’t the Same as Secure
PCI DSS compliance for card data handling is necessary, but it is a minimum standard, not a security programme. We regularly see properties that pass a PCI assessment on paper while still running a flat network architecture or holding unreviewed vendor access — technically compliant, and still meaningfully exposed.
Where PMS/POS Risk Fits Into a Broader Technology Risk Programme
PMS and POS security shouldn’t sit in isolation from the rest of a hotel’s IT governance. It connects directly to broader IT general controls — access management, change management, and vendor governance — the same disciplines that apply across the rest of the technology environment. Treating it as a standalone checklist item is usually where gaps start.
When Did You Last Review Your PMS/POS Security?
We assess PMS and POS environments specifically for hospitality operations — network architecture, vendor access, and patching discipline — as part of a broader IT audit or as a standalone review.