10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us

Holiday Travel Brings Joy — and Cyber Risks: Is Your Website Secure?

  • Automatic
  • 28 January 2025
  • 4 minute read
Total
0
Shares
0
0
0

This article was written by Hospitality Technology. Click here to read the original article

image

For many, the holiday season is a time for family, celebration and travel — and unfortunately, a coinciding surge in cyberattacks. Travel booking websites experience a spike in traffic and transactions during the holiday months, creating opportunities for threat actors to exploit overwhelmed systems and distracted travelers. 

To protect both travelers and their businesses, organizations must prioritize securing their systems with solutions like tokenization. This includes preparing to meet updated standards from the Payment Card Industry Security Standards Council — known as PCI DSS 4.0 — which are raising the bar for safeguarding payment data. 

The security flaws putting travel businesses at risk

Travel booking sites remain lucrative targets for cybercriminals since customers must input sensitive payment data and personally identifiable information (PII) when reserving hotels, flights and rental cars. 

To make matters worse, a recent analysis uncovered serious security flaws across the Top 10 travel and hospitality websites, including exposed internal systems and public-facing vulnerabilities. 

These security gaps provide cybercriminals a clear path to exploit security flaws, leading to a disruption in operations and potentially data theft which threat actors will likely sell on the black market fueling further fraudulent activity. 

The expenses of inaction are only growing, with the average cost of a hospitality data breach reaching $3.82 million in 2024 — up from $3.36 million in 2023. And while this alone is a devastating figure for most businesses, it doesn’t account for diminished customer trust and lost business opportunities. 

King Kamehameha Kona Beach Resort Announces New Director of Sales & Marketing
Trending
King Kamehameha Kona Beach Resort Announces New Director of Sales & Marketing

As the cost of breaches climbs, so does pressure to meet evolving regulatory standards. The deadline to comply with PCI DSS 4.0 is fast approaching. Key updates include enhanced protections for e-commerce websites, stricter authentication requirements for accessing sensitive environments, and stronger safeguards for protecting cardholder data.

It’s time to secure your website and systems before it’s too late.

5 steps to protect your site during the holiday travel rush and beyond

A proactive approach to security is critical for safeguarding customer data and maintaining compliance with evolving standards. Here are five ways to secure your systems, support compliance and reduce your risk of becoming the next holiday hack victim:

  1. Identify and patch vulnerabilities.

The first step in securing your website is to map out every touch point where sensitive data is collected, stored and processed, such as payment pages, data inputs and storage systems. From there, conduct an internal and external penetration test with a reputable third party to identify potential vulnerabilities. 

These evaluations help identify security vulnerabilities like unpatched software or misconfigured servers, giving you the opportunity to resolve them before attackers can exploit them. It’s just as important to maintain strong patch management and ongoing vulnerability scanning processes to ensure your environment is regularly evaluated and updated with the latest security patches. 

  1. Shore up fraud prevention measures.

Reduce the risk of account takeovers and unauthorized transactions by leveraging security like PCI-3DS. PCI 3-D Secure (3DS) services support compliance efforts and add an extra layer of protection by verifying consumers’ identities with their card issuer during online, card-not-present transactions. 

  1. Devalue your data.

No matter how strong your cybersecurity defenses are, determined attackers will always find their way in. That’s why you have to make the data they’re after worthless. Partner with a reputable payment security or tokenization provider to identify a solution that secures data both in storage and in transit.   

For example, tokenization replaces sensitive data with randomized tokens that have no meaningful value, while encryption transforms data into unreadable code that can only be deciphered with the proper decryption key. These solutions ensure that even if attackers breach your systems, they can’t make use of your data. By handling only encrypted and tokenized data, you limit which systems interact with sensitive data, reducing the scope — and complexity — of PCI DSS compliance. 

  1. Avoid handling non-tokenized data.

Another way to reduce risk is to avoid handling sensitive payment data and PII altogether. By embedding an inline frame (i.e., iframe) into your website, users can securely input their information, which is then redirected to a trusted data security provider. This allows your payment processor to collect and process the sensitive data directly so it bypasses your servers entirely — reducing your exposure and shrinking your PCI DSS compliance scope.

  1. Enforce website content security.

Content security policies (CSPs) are a critical yet often-overlooked aspect of website security. A robust CSP ensures that only scripts and resources from trusted sources can load on your site, reducing the risk of threats like skimming attacks and malicious code injections.

This is particularly important in light of new PCI requirements for e-commerce transactions, such as 6.4.3 and 11.6.1, that aim to prevent attacks originating from compromised websites.  

‘Tis the season to safeguard your site

For those in the travel industry, the holiday rush is both a business boon and a security headache. While your site may be a prime target for cybercriminals, modern security solutions like tokenization ensure this data remains inaccessible to attackers.

These security measures require time and investment, but the consequences of inaction far outweigh these costs. By securing your systems now, you can protect customer data, comply with evolving standards and give travelers peace of mind that their data is safe from digital threats. 

Please click here to access the full original article.

Total
0
Shares
Share 0
Tweet 0
Pin it 0
You should like too
View Post
  • Innovation

Gen Z Frontline Workers Want Better Training — and They’re Willing to Stay for It

  • Automatic
  • 17 May 2025
View Post
  • Innovation

NRA Show 2025 NEWS: Sauce Unveils Full-Service Delivery Platform with AI Retention

  • Automatic
  • 16 May 2025
View Post
  • Innovation

Airbnb Moves Beyond Stays, Aiming to Redefine the Future of Travel

  • Automatic
  • 16 May 2025
View Post
  • Innovation

Why Contactless Hotel Experience Technology Is an Investment and Not a Digital Cost of Doing Business

  • Automatic
  • 16 May 2025
View Post
  • Innovation

The Guest and The Agent: How Artificial Intelligence Will Reshape Hospitality Behaviors

  • Automatic
  • 16 May 2025
View Post
  • Innovation

eviivo unveils advanced PayPal integration to help increase booking conversions

  • Automatic
  • 16 May 2025
View Post
  • Innovation

Winning the Direct Booking Game: Your Hotel’s Path to Profitability

  • Automatic
  • 16 May 2025
View Post
  • Innovation

CASE STUDY: HDG Legacy Slashes Utility Costs and Boosts Efficiency with Anacove’s AI-Driven Hotel Tech

  • Automatic
  • 16 May 2025
Sponsored Posts
  • The RFP Process for Hotel PMS

    View Post
  • Top hospitality tech trends from Mews Unfold 2024

    View Post
  • Getting Started with AI: A Step-by-Step Guide for Hoteliers

    View Post
Last Posts
  • The OTA Stockholm Syndrome in Hospitality
    • 17 May 2025
  • Gen Z Frontline Workers Want Better Training — and They’re Willing to Stay for It
    • 17 May 2025
  • NRA Show 2025 NEWS: Sauce Unveils Full-Service Delivery Platform with AI Retention
    • 16 May 2025
  • Airbnb Moves Beyond Stays, Aiming to Redefine the Future of Travel
    • 16 May 2025
  • Remington Hospitality Appoints Ben Perelmuter as Chief Executive Officer
    • 16 May 2025
Sponsors
  • The RFP Process for Hotel PMS
  • Top hospitality tech trends from Mews Unfold 2024
  • Getting Started with AI: A Step-by-Step Guide for Hoteliers
Contact informations

contact@10minutes.news

Advertise with us
Contact Marjolaine to learn more: marjolaine@wearepragmatik.com
Press release
pr@10minutes.news
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
  • 📰 Columns
  • About us
Discover the best of international hotel news. Categorized, and sign-up to the newsletter

Input your search keywords and press Enter.