10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
    • CSR and Sustainability
    • Events
    • Hotel Openings
    • Hotel Operations
    • Human Resources
    • Innovation
    • Market Trends
    • Marketing
    • Mergers & Acquisitions
    • Regulatory and Legal Affairs
    • Revenue Management
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
    • 🇫🇷 French
    • 🇩🇪 German
    • 🇮🇹 Italian
    • 🇪🇸 Spain
  • 📰 Columns
  • About us

Holiday Travel Brings Joy — and Cyber Risks: Is Your Website Secure?

  • Automatic
  • 28 January 2025
  • 4 minute read
Total
0
Shares
0
0
0

This article was written by Hospitality Technology. Click here to read the original article

image

For many, the holiday season is a time for family, celebration and travel — and unfortunately, a coinciding surge in cyberattacks. Travel booking websites experience a spike in traffic and transactions during the holiday months, creating opportunities for threat actors to exploit overwhelmed systems and distracted travelers. 

To protect both travelers and their businesses, organizations must prioritize securing their systems with solutions like tokenization. This includes preparing to meet updated standards from the Payment Card Industry Security Standards Council — known as PCI DSS 4.0 — which are raising the bar for safeguarding payment data. 

The security flaws putting travel businesses at risk

Travel booking sites remain lucrative targets for cybercriminals since customers must input sensitive payment data and personally identifiable information (PII) when reserving hotels, flights and rental cars. 

To make matters worse, a recent analysis uncovered serious security flaws across the Top 10 travel and hospitality websites, including exposed internal systems and public-facing vulnerabilities. 

These security gaps provide cybercriminals a clear path to exploit security flaws, leading to a disruption in operations and potentially data theft which threat actors will likely sell on the black market fueling further fraudulent activity. 

The expenses of inaction are only growing, with the average cost of a hospitality data breach reaching $3.82 million in 2024 — up from $3.36 million in 2023. And while this alone is a devastating figure for most businesses, it doesn’t account for diminished customer trust and lost business opportunities. 

🧐 You're Probably Overestimating Your Chances Why being on your… | Julia Kinner | 79 comments
Trending
🧐 You're Probably Overestimating Your Chances Why being on your… | Julia Kinner | 79 comments

As the cost of breaches climbs, so does pressure to meet evolving regulatory standards. The deadline to comply with PCI DSS 4.0 is fast approaching. Key updates include enhanced protections for e-commerce websites, stricter authentication requirements for accessing sensitive environments, and stronger safeguards for protecting cardholder data.

It’s time to secure your website and systems before it’s too late.

5 steps to protect your site during the holiday travel rush and beyond

A proactive approach to security is critical for safeguarding customer data and maintaining compliance with evolving standards. Here are five ways to secure your systems, support compliance and reduce your risk of becoming the next holiday hack victim:

  1. Identify and patch vulnerabilities.

The first step in securing your website is to map out every touch point where sensitive data is collected, stored and processed, such as payment pages, data inputs and storage systems. From there, conduct an internal and external penetration test with a reputable third party to identify potential vulnerabilities. 

These evaluations help identify security vulnerabilities like unpatched software or misconfigured servers, giving you the opportunity to resolve them before attackers can exploit them. It’s just as important to maintain strong patch management and ongoing vulnerability scanning processes to ensure your environment is regularly evaluated and updated with the latest security patches. 

  1. Shore up fraud prevention measures.

Reduce the risk of account takeovers and unauthorized transactions by leveraging security like PCI-3DS. PCI 3-D Secure (3DS) services support compliance efforts and add an extra layer of protection by verifying consumers’ identities with their card issuer during online, card-not-present transactions. 

  1. Devalue your data.

No matter how strong your cybersecurity defenses are, determined attackers will always find their way in. That’s why you have to make the data they’re after worthless. Partner with a reputable payment security or tokenization provider to identify a solution that secures data both in storage and in transit.   

For example, tokenization replaces sensitive data with randomized tokens that have no meaningful value, while encryption transforms data into unreadable code that can only be deciphered with the proper decryption key. These solutions ensure that even if attackers breach your systems, they can’t make use of your data. By handling only encrypted and tokenized data, you limit which systems interact with sensitive data, reducing the scope — and complexity — of PCI DSS compliance. 

  1. Avoid handling non-tokenized data.

Another way to reduce risk is to avoid handling sensitive payment data and PII altogether. By embedding an inline frame (i.e., iframe) into your website, users can securely input their information, which is then redirected to a trusted data security provider. This allows your payment processor to collect and process the sensitive data directly so it bypasses your servers entirely — reducing your exposure and shrinking your PCI DSS compliance scope.

  1. Enforce website content security.

Content security policies (CSPs) are a critical yet often-overlooked aspect of website security. A robust CSP ensures that only scripts and resources from trusted sources can load on your site, reducing the risk of threats like skimming attacks and malicious code injections.

This is particularly important in light of new PCI requirements for e-commerce transactions, such as 6.4.3 and 11.6.1, that aim to prevent attacks originating from compromised websites.  

‘Tis the season to safeguard your site

For those in the travel industry, the holiday rush is both a business boon and a security headache. While your site may be a prime target for cybercriminals, modern security solutions like tokenization ensure this data remains inaccessible to attackers.

These security measures require time and investment, but the consequences of inaction far outweigh these costs. By securing your systems now, you can protect customer data, comply with evolving standards and give travelers peace of mind that their data is safe from digital threats. 

Please click here to access the full original article.

Total
0
Shares
Share 0
Tweet 0
Pin it 0
You should like too
View Post
  • Innovation

Zucchetti North America Brings Lybra Assistant to Market

  • LODGING Staff
  • 19 June 2025
View Post
  • Innovation

LG Electronics Releases Pro:Centric+ Hotel TV Lineup

  • LODGING Staff
  • 19 June 2025
View Post
  • Innovation

E20X Pitch Competition Showcases Innovation in Hospitality at HITEC 2025

  • Colin Tessier
  • 19 June 2025
View Post
  • Innovation

How to elevate hotel loyalty—for your guests and your bottom line

  • Automatic
  • 19 June 2025
View Post
  • Innovation

Turning Technology into a Competitive Advantage for Hotels – Mark Fancourt [Greatest Hits]

  • Josiah Mackenzie
  • 19 June 2025
View Post
  • Innovation

Agilysys Launches Intelligent Guest Profiles at HITEC 2025 to Transform How Hoteliers Harness Guest Data to Expand Ancillary Revenue and Personalize Service

  • Automatic
  • 19 June 2025
View Post
  • Innovation

Amadeus Leverages AI to Enhance Its Portfolio of Hospitality Solutions

  • LODGING Staff
  • 18 June 2025
View Post
  • Innovation

PPDS Announces New Foldable Series at HITEC 2025

  • LODGING Staff
  • 18 June 2025
Sponsored Posts
  • Influence Society Publishes Q2 Edition of Societies Quarterly for Visionary Hoteliers

    View Post
  • Case Study: Refinery Hotel Redefines Revenue Management with LodgIQ

    View Post
  • Day & Night: The Bold Rebranding Powering Shiji’s Presence in Global Hospitality Tech

    View Post
Last Posts
  • Luggage Tags Made of Plant-Based Leather
    • 20 June 2025
  • NBA Finals 2025: How forward-looking search data reveals the winning playbook for hotels
    • 20 June 2025
  • Introducing Hyatt Centric Chicago O’Hare, A Reimagined Hotel Experience Where Curiosity of Travel Meets Exploration
    • 20 June 2025
  • Hilton to Triple its Presence in Africa to More Than 160 Hotels
    • 20 June 2025
  • Hotel Competitor Analysis: Reports, Comp Sets & Insights
    • 20 June 2025
Sponsors
  • Influence Society Publishes Q2 Edition of Societies Quarterly for Visionary Hoteliers
  • Case Study: Refinery Hotel Redefines Revenue Management with LodgIQ
  • Day & Night: The Bold Rebranding Powering Shiji’s Presence in Global Hospitality Tech
Contact informations

contact@10minutes.news

Advertise with us
Contact Marjolaine to learn more: marjolaine@wearepragmatik.com
Press release
pr@10minutes.news
10 Minutes News for Hoteliers 10 Minutes News for Hoteliers
  • Top News
  • Posts
  • 🎙️ Podcast
  • 👉 Sign-up
  • 🌎 Languages
  • 📰 Columns
  • About us
Discover the best of international hotel news. Categorized, and sign-up to the newsletter

Input your search keywords and press Enter.