10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us

Holiday Travel Brings Joy — and Cyber Risks: Is Your Website Secure?

  • Automatic
  • 28 January 2025
  • 4 minute read
Total
0
Shares
0
0
0

This article was written by Hospitality Technology. Click here to read the original article

image

For many, the holiday season is a time for family, celebration and travel — and unfortunately, a coinciding surge in cyberattacks. Travel booking websites experience a spike in traffic and transactions during the holiday months, creating opportunities for threat actors to exploit overwhelmed systems and distracted travelers. 

To protect both travelers and their businesses, organizations must prioritize securing their systems with solutions like tokenization. This includes preparing to meet updated standards from the Payment Card Industry Security Standards Council — known as PCI DSS 4.0 — which are raising the bar for safeguarding payment data. 

The security flaws putting travel businesses at risk

Travel booking sites remain lucrative targets for cybercriminals since customers must input sensitive payment data and personally identifiable information (PII) when reserving hotels, flights and rental cars. 

To make matters worse, a recent analysis uncovered serious security flaws across the Top 10 travel and hospitality websites, including exposed internal systems and public-facing vulnerabilities. 

These security gaps provide cybercriminals a clear path to exploit security flaws, leading to a disruption in operations and potentially data theft which threat actors will likely sell on the black market fueling further fraudulent activity. 

The expenses of inaction are only growing, with the average cost of a hospitality data breach reaching $3.82 million in 2024 — up from $3.36 million in 2023. And while this alone is a devastating figure for most businesses, it doesn’t account for diminished customer trust and lost business opportunities. 

Trending
How visual search is reshaping travel discovery

As the cost of breaches climbs, so does pressure to meet evolving regulatory standards. The deadline to comply with PCI DSS 4.0 is fast approaching. Key updates include enhanced protections for e-commerce websites, stricter authentication requirements for accessing sensitive environments, and stronger safeguards for protecting cardholder data.

It’s time to secure your website and systems before it’s too late.

5 steps to protect your site during the holiday travel rush and beyond

A proactive approach to security is critical for safeguarding customer data and maintaining compliance with evolving standards. Here are five ways to secure your systems, support compliance and reduce your risk of becoming the next holiday hack victim:

  1. Identify and patch vulnerabilities.

The first step in securing your website is to map out every touch point where sensitive data is collected, stored and processed, such as payment pages, data inputs and storage systems. From there, conduct an internal and external penetration test with a reputable third party to identify potential vulnerabilities. 

These evaluations help identify security vulnerabilities like unpatched software or misconfigured servers, giving you the opportunity to resolve them before attackers can exploit them. It’s just as important to maintain strong patch management and ongoing vulnerability scanning processes to ensure your environment is regularly evaluated and updated with the latest security patches. 

  1. Shore up fraud prevention measures.

Reduce the risk of account takeovers and unauthorized transactions by leveraging security like PCI-3DS. PCI 3-D Secure (3DS) services support compliance efforts and add an extra layer of protection by verifying consumers’ identities with their card issuer during online, card-not-present transactions. 

  1. Devalue your data.

No matter how strong your cybersecurity defenses are, determined attackers will always find their way in. That’s why you have to make the data they’re after worthless. Partner with a reputable payment security or tokenization provider to identify a solution that secures data both in storage and in transit.   

For example, tokenization replaces sensitive data with randomized tokens that have no meaningful value, while encryption transforms data into unreadable code that can only be deciphered with the proper decryption key. These solutions ensure that even if attackers breach your systems, they can’t make use of your data. By handling only encrypted and tokenized data, you limit which systems interact with sensitive data, reducing the scope — and complexity — of PCI DSS compliance. 

  1. Avoid handling non-tokenized data.

Another way to reduce risk is to avoid handling sensitive payment data and PII altogether. By embedding an inline frame (i.e., iframe) into your website, users can securely input their information, which is then redirected to a trusted data security provider. This allows your payment processor to collect and process the sensitive data directly so it bypasses your servers entirely — reducing your exposure and shrinking your PCI DSS compliance scope.

  1. Enforce website content security.

Content security policies (CSPs) are a critical yet often-overlooked aspect of website security. A robust CSP ensures that only scripts and resources from trusted sources can load on your site, reducing the risk of threats like skimming attacks and malicious code injections.

This is particularly important in light of new PCI requirements for e-commerce transactions, such as 6.4.3 and 11.6.1, that aim to prevent attacks originating from compromised websites.  

‘Tis the season to safeguard your site

For those in the travel industry, the holiday rush is both a business boon and a security headache. While your site may be a prime target for cybercriminals, modern security solutions like tokenization ensure this data remains inaccessible to attackers.

These security measures require time and investment, but the consequences of inaction far outweigh these costs. By securing your systems now, you can protect customer data, comply with evolving standards and give travelers peace of mind that their data is safe from digital threats. 

Please click here to access the full original article.

Total
0
Shares
Share 0
Tweet 0
Pin it 0
You should like too
View Post
  • Innovation

A Growing Cost Center: Monitoring and Managing the Rise in Technology Expenditures 

  • Robert Mandelbaum John Pomposello and Adam Barry
  • 25 July 2025
View Post
  • Innovation

TrustYou at RBOT 2025: Empowering Tourism Observatories with Smart, AI-Driven Solutions

  • Cara Lai Miles
  • 25 July 2025
View Post
  • Innovation

Maestro PMS Alternatives in Canada – Enterprise-Grade Cloud PMS for Hoteliers

  • Vanshikha Dhar
  • 25 July 2025
View Post
  • Innovation

AI in Hospitality: How Sage’s Chief Creative Officer Uses Tech Without Losing the Human Touch – Jessica Werner, Sage Hospitality Group

  • Automatic
  • 25 July 2025
View Post
  • Innovation

From Grand Lobbies to Micro Living: Inside A Few of Sage Hospitality’s Innovative Denver Projects – Jessica Werner, Sage Hospitality Group

  • Automatic
  • 25 July 2025
View Post
  • Innovation

ChatGPT Booked My Hotel While I Made My Coffee

  • Automatic
  • 25 July 2025
View Post
  • Innovation

ChatGPT Booked My Hotel While I Made My Coffee

  • Automatic
  • 25 July 2025
View Post
  • Innovation

Is Your Network Ready for Wi-Fi 7 and Beyond?

  • Automatic
  • 25 July 2025
Sponsored Posts
  • The Future of Revenue Management Is Strategic Leadership – LodgIQ

    View Post
  • Influence Society Publishes Q2 Edition of Societies Quarterly for Visionary Hoteliers

    View Post
  • Case Study: Refinery Hotel Redefines Revenue Management with LodgIQ

    View Post
Last Posts
  • A Growing Cost Center: Monitoring and Managing the Rise in Technology Expenditures 
    • 25 July 2025
  • A definitive blow threatens more than a million seasonal rentals in Spain
    • 25 July 2025
  • TrustYou at RBOT 2025: Empowering Tourism Observatories with Smart, AI-Driven Solutions
    • 25 July 2025
  • Rebel Hotel Company Adds Domain Sunnyvale to Its Portfolio
    • 25 July 2025
  • Hunter Hotel Advisors Brokers Sale of Hilton Garden Inn Springfield
    • 25 July 2025
Sponsors
  • The Future of Revenue Management Is Strategic Leadership – LodgIQ
  • Influence Society Publishes Q2 Edition of Societies Quarterly for Visionary Hoteliers
  • Case Study: Refinery Hotel Redefines Revenue Management with LodgIQ
Contact informations

contact@10minutes.news

Advertise with us
Contact Marjolaine to learn more: marjolaine@wearepragmatik.com
Press release
pr@10minutes.news
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
  • 📰 Columns
  • About us
Discover the best of international hotel news. Categorized, and sign-up to the newsletter

Input your search keywords and press Enter.