
by Kerry Medina
Last updated: 8:00 PM ET, Wed March 13, 2019
According to AT&T Business' 5 Cybersecurity Trends to Expect in 2019, cybersecurity ranked a top tech priority for many organizations in 2018, but it was actually the most underperforming Information Technology (IT) area for many organizations. And, the hospitality industry is certainly not immune to the issue.
For more than a decade, global hotel companies have been suffering from data breaches resulting in the theft of millions of guests' personal information. Marriott International was the most recent hotel group to fall victim to malicious data hacking; the hotel organization revealed late last fall that a breach exposed the private details of up to 400 million customers over the course of four years. The situation cost the hotel giant $28 million in the fourth quarter of 2018.
The situation certainly exposed the gravity of the issue for the hotel industry while also highlighting that hotel companies will continue to be plagued by data breaches. But what goes unaddressed in these situations is how travel agents should respond when their clients' personal information is potentially exposed by a third party.
Henry Wu, president of Toronto-based Liverton Hotels International Inc. and a member of Preferred Hotel Group's Board of Directors, pointed out that while his company, like so many others in hospitality, focus on best practices like acquiring and retaining as little customer data as securely and for as short a time as possible, "one can never be sure that enough has been done or that any strategy or team is 100 percent adequate," as cybercriminals are only becoming more sophisticated.
He recommends agents inquire, at both the property level and corporate level, if the hotels implement industry best practices such as staying compliant with PCI-DSS standards and employ the latest electronic payment technology like 'chip and pin' and 'tokenization' to safeguard credit card information.
Daniela Trava Albarran, general manager at Grand Residences Riviera Cancun, admits that "no hotel is immune" to the threat of cyber attacks. But she advises travel professionals to also check the privacy policy on a hotel's website in order to understand how a guest's personal information will be used, noting that the Cancun property protects guest data by maximizing internal, proprietary security controls.
The reality is that, unfortunately, there is little that travel agents can do for their clients in these circumstances. Moreover, the media may report on major hacking incidents when they affect international hotel brands, but small hotel groups, as well as independent properties, are also targeted.
"They're not going after large companies, but system failures where they can find them," said Tanya Duelfer, managing director, U.S. operations at Turks and Caicos' Ocean Club Resorts. "We only hear about large hotel companies because fewer credit cards would be affected."
She, too, notes that there's little that agents can do in order to safeguard their clients. However, common sense practices such as not providing credit card details via email are still essential. Duelfer added, "either use a secure booking engine or give credit card information over the phone because it's entered into a secure system immediately."
Travel professionals can also go to the Sabre Consumer website for more details on how potentially affected clients can protect themselves from a data breach.
For the latest travel news, updates and deals, subscribe to the daily TravelPulse newsletter.
Topics From This Article to Explore