Cybersecurity for hotels and restaurants
Hotel Cybersecurity and PCI Testing for Hospitality Groups
Hotel cybersecurity is a card problem, a Wi-Fi problem, and a franchise problem at once: card data at the front desk and the bar, guests sharing the airwaves with the back office, and brand systems reaching into every property. Invadel tests hotels, restaurant groups, and hospitality technology vendors at a fixed price, with a free retest and evidence your PCI assessor can use.






The stakes
Why hotels and restaurants get tested differently
Attackers go after hospitality for card data, guest identity, and leverage. Cards pass through the front desk, restaurants, bars, and spa, often on terminals and servers a vendor supports remotely. Loyalty accounts hold points, stored payment details, and travel history. The property management system runs check-in, room keys, and charges, so ransomware that reaches it stops the hotel. Front desk and reservations staff open messages from strangers all day, which makes them the easiest first step in.
The pressure comes from the card brands, the hotel brand, and regulators. PCI DSS asks for penetration testing, segmentation testing, and quarterly checks for rogue wireless access points wherever the validation route includes them. The FTC sued Wyndham in 2012 after intruders used one branded hotel’s network to reach the corporate network and the property management servers of 41 hotels, and the 2015 settlement required annual security audits conforming to PCI DSS for 20 years. In 2024 the FTC ordered Marriott and Starwood to keep an information security program, independently assessed every two years, after three breaches affecting more than 344 million customers.
A hotel network is several networks sharing one building: guests, back office, point of sale, the property management system, door locks, building systems, the brand’s connection, and vendor remote access, sometimes on the same switches. A scan from the internet sees none of it. Testing has to happen on property, from the guest Wi-Fi, a meeting room jack, and a back-office desk, toward the card data. Restaurant groups add a twist: every location is a copy of the same network, so one flaw repeats everywhere.
What we test
The systems attackers go after first
Point of sale and payment terminals
Front desk, restaurant, bar, and spa terminals and the POS servers behind them, tested for segmentation, vendor remote support access, and exposure to tampering.
Property management system and interfaces
The cloud or on-premises PMS and its links to POS, door locks, phones, and channel managers, tested for staff and vendor paths to guest and card data.
Guest and staff Wi-Fi
Guest isolation, captive portal bypass, rogue and evil twin access points, and whether a guest device can reach the back office, POS, or PMS networks.
Booking engine, loyalty, and guest apps
Reservation and payment flows, loyalty sign-in and point redemption, and the APIs behind the app, tested for account takeover and one guest seeing another’s booking.
Keycards, locks, and building systems
Card encoders, the lock server, and building and in-room devices, tested for network reach, with guest and staff cards tested for copying during a physical engagement.
Brand and management company connections
Links to the brand’s network, shared services, and the management company’s remote access, tested for the trust one property could borrow to reach another.
Compliance
The frameworks that usually apply
- PCI DSS
Requirement 11.4 penetration and segmentation testing of the cardholder data environment, and 11.2.1 checks for rogue wireless access points at least once every three months.
- New York SHIELD Act
Reasonable safeguards, including regular testing of key controls, for any business holding New York residents’ private information, card numbers with security codes and loyalty logins included.
- SOC 2
For PMS, booking, and guest technology vendors: the report hotel groups ask for in procurement, with a penetration test in the evidence set.
- Cyber insurance
Renewal applications ask about remote access, MFA, backups, and recent testing. The attestation letter and retest results back up the answers.
Services
What hotels and restaurant groups usually buy
- From $6,000
Internal Network Penetration Testing
Testing from an assumed foothold inside your network: Active Directory attack paths, lateral movement, and segmentation, from $6,000.
- From $3,800
Wireless Penetration Testing
On-site testing of your corporate, guest, and IoT Wi-Fi: enterprise authentication, evil twin and rogue access points, and wireless-to-internal segmentation, with a free retest, from $3,800.
- From $4,200
External Network Penetration Testing
Testing of your internet-facing perimeter, from exposed services and VPN gateways to mail and cloud edges, with a free retest, from $4,200.
- From $3,600
Phishing Simulation & Social Engineering Testing
Phishing and social engineering campaigns that measure real-world human risk, with click and credential metrics by department, from $3,600.
- From $5,200
Web Application Penetration Testing
Manual testing of your web application across the OWASP Top 10, business logic, and all user roles, with a free retest included, from $5,200.
PCI DSS on property
Hotel cybersecurity under PCI DSS, requirement by requirement
Which requirements apply depends on your validation route, which follows from your PCI merchant level and how you take payments. Where they apply, this is what they mean in a hotel or restaurant and how an engagement covers them.
11.4.2 and 11.4.3: internal and external penetration testing
- What it means on property
- At least once every 12 months and after significant change, covering the POS and PMS servers, the property network, and internet-facing booking and payment systems.
- How we cover it
- An internal test on property, run from the networks guests and staff actually use, and an external test of everything the property exposes to the internet.
11.4.5 and 11.4.6: segmentation testing
- What it means on property
- Where guest Wi-Fi, the back office, and building systems are kept out of PCI scope by segmentation, proof every 12 months and after changes that they cannot reach card data. Service providers, such as hospitality software vendors, prove it every six months under 11.4.6.
- How we cover it
- Testing from each out-of-scope segment toward the card environment, part of the internal test, with evidence for your assessor. See network segmentation testing.
11.2.1: wireless access points
- What it means on property
- Testing for authorized and unauthorized wireless access points at least once every three months, even where Wi-Fi never touches card data.
- How we cover it
- A wireless penetration test includes a rogue access point sweep of the property and tests guest isolation.
8.2.7 and 8.4.3: vendor remote access
- What it means on property
- Vendor remote support accounts enabled only when needed and monitored, and multi-factor authentication on all remote access into the card environment, vendors included.
- How we cover it
- Review of the remote support tools POS and PMS vendors use, tested from outside and inside for always-on access and shared logins.
9.5.1: card terminals
- What it means on property
- A list of terminals, periodic inspection for tampering or substitution, and staff trained to report it.
- How we cover it
- A physical penetration test checks whether someone posing as a technician can reach, open, or swap a terminal.
6.4.3 and 11.6.1: payment page scripts
- What it means on property
- Where the booking engine’s payment page is in your scope, an inventory of every script it loads and an alert when the page changes without authorization.
- How we cover it
- Booking engine testing, run as a web application test, checks the script controls against what the page actually loads.
Summaries of PCI DSS v4.0.1 as of September 2026. Your acquirer and assessor decide what is in scope. Invadel also delivers the Report on Compliance assessment and the quarterly ASV scans, so the assessment and the testing run on one calendar.
How it runs
Typical engagements
Illustrative scopes for this industry, written to show what a test covers and what you walk away with.
They are not client stories; our anonymized engagements are on the case studies page.
Typical engagement
Independent hotel before its PCI assessment
An independent Manhattan hotel is preparing for its annual PCI DSS validation and has never tested its segmentation. We test on property from the guest Wi-Fi, a meeting room jack, and a back-office desk toward the POS and PMS networks, and sweep the building for rogue access points. A POS vendor’s remote support tool turns out to be always on. The vendor account is limited to support windows, the retest confirms it, and the assessor receives segmentation evidence.
Typical engagement
Restaurant group standardizing its locations
A restaurant group with locations across the five boroughs runs the same POS and network build at every site. We test one representative location on site, from the guest Wi-Fi and the manager’s office toward the POS, and test the online ordering site and the external perimeter remotely. A phishing campaign uses supplier invoice and delivery pretexts aimed at managers. One change to the standard build closes a finding at every location, and the retest confirms it.
Typical engagement
Hospitality software vendor before a hotel group’s review
A company selling a guest messaging and mobile check-in platform needs a penetration test before a hotel group signs. We test the web console, the guest app, and the API across property, staff, and guest roles, and find that staff at one property can read guest messages from another. The vendor fixes it, we retest at no cost, and the report and attestation letter go into the hotel group’s security review and the vendor’s SOC 2 evidence.
FAQ
What hotel and restaurant operators ask
01Does PCI DSS require a penetration test for a hotel or restaurant?
It depends on how you validate. A Report on Compliance or SAQ D includes the Requirement 11.4 tests: internal and external penetration testing at least once every 12 months and after significant change, plus segmentation testing where segmentation shrinks your scope. SAQ B, SAQ C-VT, and SAQ P2PE carry no penetration testing requirement. Your acquirer confirms the route, and our guide to PCI DSS penetration testing requirements maps each questionnaire.
02Our terminals use point-to-point encryption. Do we still need testing?
A validated P2PE solution can shrink your PCI scope to SAQ P2PE, a short questionnaire with no penetration testing requirement. It protects card data from the terminal onward, not the property management system, the guest profiles, the loyalty accounts, or the network they share. Those can still hold private information under New York’s SHIELD Act, such as ID numbers captured at check-in and loyalty logins, and they are where ransomware stops a hotel. Our guide to PCI compliance levels and SAQ types shows which questionnaire fits each way of taking payments.
03We are a franchised hotel. Who is responsible for testing?
Usually both parties, for different systems. The franchise agreement and brand standards set what the brand runs and what the owner or management company runs, and PCI scope follows the same line. The FTC’s case against Wyndham turned on that boundary: intruders used one hotel’s network to reach the brand’s corporate systems and then dozens of other hotels, and the settlement required franchisee networks to be treated as untrusted. We test the systems you own and operate, and your side of the brand connection, with the brand’s authorization wherever its systems are involved.
04Can someone copy our room keys?
It depends on the lock system, and it has happened at scale. In March 2024, researchers disclosed flaws in a widely deployed hotel lock family, more than three million locks in 131 countries, that let a single pair of forged cards open every room in a property. The fix meant lock updates, reissued cards, and new front desk software and encoders. A physical penetration test checks whether guest and staff cards can be read or copied, and how far a copied card gets.
05How much does penetration testing cost for a hotel or restaurant group?
External network testing starts at $4,200, internal network testing on property at $6,000, and a phishing campaign at $3,600. Wireless penetration testing costs $3,800 for one New York metro site of up to three SSIDs, such as guest, staff, and IoT, and $5,500 for a larger or multi-floor property of up to eight SSIDs. Resorts and groups of three or more properties are quoted from the scope. Physical testing starts at $6,800. Each price is fixed in writing before work starts, and penetration tests include a free retest. Starting prices for every service are on our pricing page.
06Can you test without disturbing guests?
Yes. Rules of engagement are agreed with your general manager and IT lead before testing starts: windows, systems handled with care, and a contact who can stop work at any time. We never use denial-of-service techniques, and testing that touches the PMS or payment systems is scheduled around the night audit and busy check-in hours. Wireless and internal testing happen on property in the New York metro, and properties elsewhere are tested through a device we ship or on an agreed trip.
07Do you deliver the PCI assessment and ASV scans too?
Yes. Invadel delivers the PCI DSS Report on Compliance assessment and the quarterly ASV scans of Requirement 11.3.2 alongside the Requirement 11.4 penetration test, so scanning, testing, and the assessment run on one calendar. The penetration test is still scoped and reported on its own, at a fixed price with a free retest of remediated findings.
Get a fixed price for your property or group
Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.