Hotels are prime targets because they concentrate card data and rich guest identity data (passports, addresses, travel patterns) across a sprawling estate — PMS, POS, booking engine, guest Wi-Fi, loyalty, and building/IoT systems — often on legacy tech under franchise models. The drivers are PCI DSS (annual internal/external + segmentation testing) and the PDPL over guest data, plus corporate brand standards. A hotel test covers the PMS, POS, booking & payment flows, loyalty, guest Wi-Fi segmentation, and building/IoT systems (door locks, room controls), with heavy focus on segmentation between guest/corporate/payment zones and guest-data access controls. Details below; the payment-driver detail is in pentesting for retail.
// 01 Why hospitality is a prime target
Hotels sit on an unusually rich data hoard: payment cards from every stay, restaurant and bar tab, plus deep guest identity data — names, passport and ID details, home addresses, travel patterns and preferences. That combination is directly monetisable for fraud and identity theft. The attack surface is huge and uneven: a single property runs a property management system (PMS), POS across outlets, an online booking engine, guest and corporate Wi-Fi, loyalty systems, and increasingly networked building systems — often on legacy technology, frequently under franchise or management-company models where security standards vary property to property. The sector's long history of major card-data breaches via POS malware and compromised booking systems is no accident, which is why regulators expect real testing. In the GCC, where hospitality is a flagship, tourism-driven industry, the exposure is especially high.
// 02 What to test
PMS & POS
The property management system and point-of-sale across front desk, restaurants and bars — the payment and guest-data core.
Booking & payments
The online booking engine and its checkout — skimming, payment logic and guest-account takeover.
Guest Wi-Fi
Segmentation isolating guests from corporate and payment networks — a prime pivot risk.
Building & IoT
Door locks, room controls, HVAC and building management — both target and pivot point.
Beneath these sit the web, API, network and wireless layers, plus loyalty and guest-profile systems where access-control flaws expose one guest's data to another.
// 03 The regulatory & brand drivers
Two regulators and one commercial force drive hotel testing. PCI DSS applies to any property handling payment cards, requiring internal and external tests annually and after significant change, plus segmentation testing to isolate the cardholder data environment — the full detail is in PCI DSS requirements. The regional PDPLs (UAE and Saudi) govern the extensive guest data hotels hold, including passport and identity information — a serious obligation given how much personal data a hotel accumulates; see PDPL requirements. On top, international hotel groups impose their own corporate security standards across properties, and enterprise or event clients may ask for a recent test. For a sizeable GCC property, that's a recurring obligation spanning payments and personal data.
// 04 Guest Wi-Fi, door locks & the pivot problem
The part of a hotel test that surprises operators is how much risk lives outside the obvious payment systems. Guest Wi-Fi is a shared network with untrusted users by design — so the critical question is whether it's properly segmented from corporate and payment networks. If a guest (or an attacker who joins the guest network) can reach the PMS or POS, that's a direct path to card and identity data; a hotel test validates that isolation with wireless testing. Meanwhile building and IoT systems — electronic door locks, room automation, HVAC, building management — increasingly sit on the network and are both a target (imagine door-lock compromise) and a pivot into more sensitive zones. These operational systems, like the OT in other sectors, are approached carefully and included in a thorough engagement rather than ignored.
// 05 How a hotel-group engagement runs
Hospitality shares retail's distributed-estate challenge: a group has many properties, possibly across countries, each with its own PMS, POS, Wi-Fi and building systems, plus central booking and loyalty platforms. Testing every device in every property is neither practical nor needed; the approach is representative scoping — test a representative sample of property configurations, validate the segmentation that keeps guest, corporate and payment zones apart, and concentrate depth on the central systems every property depends on (booking engine, loyalty, corporate network). Get segmentation wrong at one weak property and a breach there can reach the group. Engagements follow our standard shape — scoped rules of engagement, manual-led testing, reporting mapped to PCI and PDPL — per our methodology, and mirror the model in retail testing.
// 06 Frequently asked questions
Why is hospitality a target?
Hotels combine high card-transaction volumes with rich guest data — passports, IDs, addresses, travel patterns — across a sprawling estate of PMS, POS, booking engines, Wi-Fi and building systems, often on legacy tech under franchise models. The sector has a long history of large card-data breaches via POS malware and compromised booking systems, and the payment/identity concentration is directly monetisable.
What should a hotel pentest cover?
The PMS, POS across outlets, the booking engine and payment flow, loyalty and guest-profile systems, guest and corporate Wi-Fi, and building/IoT systems like door locks and room controls — across web, API, network and wireless layers. Card-data segmentation between guest, corporate and payment zones, and guest-data access controls, are central.
Which regulations apply to GCC hotels?
PCI DSS for any hotel handling cards (annual internal/external testing plus segmentation), and the UAE and Saudi PDPLs over the extensive guest data including passport/ID information. International groups also apply corporate security standards, and enterprise or event clients may ask for a recent test. Most sizeable properties have a recurring obligation.
Are guest Wi-Fi and building systems tested?
They should be — a major, often overlooked surface. Guest Wi-Fi must be segmented from corporate and payment networks so a guest or attacker can't reach sensitive systems; testing validates that isolation. Building and IoT systems (door locks, room automation, HVAC, BMS) connect to the network and can be target and pivot. A thorough engagement includes wireless testing and their segmentation.
// 07 Related reading
- Penetration testing for retail & POS — the shared payment-and-estate playbook.
- PCI DSS requirements and PDPL requirements.
- Wireless testing and the requirements finder.