Hotel cybersecurity protects the systems that keep a property operating, including guest WiFi, property management systems (PMS), point-of-sale (POS) terminals, staff devices, surveillance systems, and backups. Each system handles a different type of traffic or data, so it should not be trusted or protected in the same way.
This checklist gives Malaysian hotel owners, operations managers, and IT teams a practical baseline for reviewing those systems. It applies to independent hotels, resorts, serviced residences, and hotel groups, although the exact controls should always reflect the property’s systems and risk profile.
What cybersecurity challenges do hotels face today?
Hotels face cybersecurity challenges because they combine public networks, guest information, payment systems, staff devices, and 24-hour operations. Guest WiFi introduces devices the hotel does not manage; while hotel operations depend on connections between PMS, booking platforms, POS terminals, accounting software, email, door-access systems, CCTV, and third-party providers. A weakness in any one of these areas can disrupt services or expose more valuable systems.
What external threats target hotel systems?
External threats include phishing, ransomware, stolen credentials, unpatched systems, network scanning, and attacks through poorly controlled remote access. Guest isolation, firewalls, web filtering, bandwidth policies, and access logging reduce exposure, although no control can prevent every misuse of a hotel’s internet connection.
Real-World Reference
The Marriott and Starwood breach shows why visibility matters. Attackers compromised Starwood systems in 2014 and remained undetected until 2018. Marriott estimated that approximately 339 million guest records were affected. The case showed how prolonged access, weak detection, and inherited technology risks can expose guest data. Read the ICO penalty notice here.

How do internal practices create cybersecurity risks?
Internal risks often result from routine work rather than malicious employees. Common weaknesses include shared front-desk accounts, unsecured USB devices, excessive permissions, delayed updates, phishing emails disguised as bookings or invoices, and former employees retaining access. Named accounts, multi-factor authentication (MFA), endpoint protection, access logging, and consistent onboarding and offboarding reduce these risks.
What should hotels secure first?
Hotels should address the systems that create the largest operational or data risk first. For most properties, this means isolating guest traffic, restricting POS and PMS access, removing shared accounts, and confirming that important data can be restored. An assessment may identify a more urgent weakness, such as exposed remote access or an unsupported server.

Hotels need a layered cybersecurity strategy that combines infrastructure-level controls, employee training, and endpoint protection. It’s not just about having antivirus software. Every part of your digital environment is secure, from guest WiFi to internal systems. In hospitality, the smallest vulnerability can impact operations, guest trust, and your brand reputation.
Chong YC
CallNet Solution Mangaing Director
hotel cybersecurity checklist
A hotel cybersecurity checklist should identify what the property operates, separate systems according to risk, restrict user and vendor access, protect endpoints, and verify that recovery and incident procedures work. The following controls form a practical starting point.
1. Have you mapped every hotel system and data flow?
Hotels should document each important system, its owner, the information it processes, and the systems it can reach. The map should include:
- Guest and staff WiFi networks
- PMS, booking engines, and channel integrations
- POS terminals and payment gateways
- Accounting, HR, procurement, and email systems
- CCTV, access control, door locks, smart TVs, and other connected devices
- Onsite and cloud backup destinations
- Administrator accounts and vendor remote-access connections
Record whether each system stores, processes, or transmits personal or payment data. This helps define its security, compliance, and recovery requirements.
2. Is guest WiFi isolated from hotel operations?
Guest WiFi should operate on a dedicated VLAN or security zone with client isolation and no direct route to business systems. Staff and operational wireless networks also need separation. A different WiFi password is not enough if both networks still lead to the same unrestricted infrastructure.
Review the guest WiFi configuration for these controls:
- A dedicated guest VLAN or equivalent security zone
- Wireless client isolation
- Default-deny rules between guest and internal networks
- Secure administration of access points and controllers
- Bandwidth and content policies appropriate to the property
- Regular testing that guest devices cannot reach internal IP addresses
- Minimal collection of personal data through the captive portal
Callnet Solution works with partners such as Cisco and Ruckus to design managed wireless networks, secure onboarding, and access policies for hospitality environments.
3. Are PMS and POS systems kept in controlled security zones?
Hotel PMS and POS systems should be separated from guest traffic and general staff browsing. They should not automatically share one operational network because they process different information. The POS environment should allow only the systems, destinations, and ports required for transactions. PMS access should be limited to approved employees and integrations.
Hotels should:
- Document payment and guest-data flows.
- Place POS and PMS systems in appropriately restricted zones.
- Apply least-privilege firewall rules between zones.
- Encrypt supported connections.
- Review remote access used by vendors and support teams.
- Patch supported operating systems and applications.
- Install endpoint protection where it is compatible with the system.
- Test that segmentation controls block unintended access.
Segmentation can reduce payment-security risk and the systems included in the cardholder data environment. However, the PCI Security Standards Council explains that segmentation is not, by itself, a universal PCI DSS requirement or a replacement for broader controls — the hotel remains responsible for determining its scope.
To learn more, read the PCI SSC segmentation guidance.
4. Are staff accounts and endpoints properly controlled?
Staff accounts should identify individual users and grant only the access required for their work. Hotels should enforce MFA for important systems, review access after role changes, and promptly disable accounts when employment or a contractor’s engagement ends. Administrator access should remain separate from normal employee accounts.
Endpoint protection should detect suspicious behavior and isolate infected devices. Email security should filter phishing messages and malicious attachments. Hotels should also patch supported software, lock unattended terminals, and control unauthorized software and USB devices, especially on front-desk and back-office computers.
5. Can the hotel restore its systems after an attack?
Hotels should maintain encrypted, offsite backups of important operational and business data. At least one copy should be immutable or offline so ransomware cannot alter it using the same administrator account that manages production systems.
Backups may include PMS data where the platform permits, POS configuration, accounting and HR records, shared files, and device configurations. The property should define how much data it can lose and how quickly each system needs to return.
A successful backup notification does not prove recovery. Hotels should test selected restores quarterly and conduct a broader exercise annually or after a major system change. Manual check-in, room assignment, communication, and payment procedures should be documented in case the PMS is unavailable.
6. Can the hotel detect and contain an incident?
Continuous monitoring should analyze relevant events from firewalls, endpoints, servers, wireless infrastructure, and key cloud services. It detects unusual behavior and alerts the responsible team.
Examples include a guest device repeatedly probing an internal network, an unfamiliar administrator login, a POS terminal connecting to an unexpected destination, or endpoint protection isolating a front-desk computer.
Every alert needs an owner and an after-hours escalation path. The incident plan should assign responsibility for isolation, investigation, communication, evidence preservation, recovery, and regulatory assessment. Hotels should test it through a tabletop exercise twice a year and use short awareness exercises to confirm that employees can report suspicious activity.
What should hotel operators review regularly?
The following frequencies are a working baseline rather than universal legal requirements. Hotels should adjust them according to risk, system changes, vendor requirements, and applicable standards.
| Area | Pass condition | Evidence to review | Suggested frequency |
|---|---|---|---|
| Guest WiFi | Guest devices cannot reach business systems | Firewall rules and connection test | Quarterly |
| PMS | Access is limited to approved users and services | User list, MFA status, and access logs | Monthly |
| POS | The payment environment is scoped and controlled | Data-flow map and firewall rules | Quarterly |
| Staff access | Employees use named, least-privilege accounts | User-access report | Monthly |
| Endpoints | Supported devices are protected and patched | Endpoint and patch dashboard | Monthly |
| Vendor access | Remote connections are approved and monitored | Vendor list and access logs | Quarterly |
| Backup | Encrypted backups can be restored | Restore-test report | Quarterly |
| Monitoring | Important alerts reach a responsible person | Alert and escalation records | Monthly |
| Incident response | Staff understand their roles | Tabletop exercise report | Twice yearly |
| Training | Relevant employees complete awareness activities | Training records | Onboarding and periodically |
How do PDPA & PCI DSS affect hotel cybersecurity?

Malaysian hotels process personal data and must protect it under the Personal Data Protection Act 2010 (PDPA). This may include guest names, contact details, identification information, booking history, CCTV footage, and data collected through a WiFi portal.
PDPA responsibilities extend beyond security software. Hotels should control access, protect data, manage service providers, set retention periods, dispose of data securely, and prepare for breaches.
Malaysia’s data breach notification obligations took effect on June 1, 2025. Data controllers must assess whether a breach may cause significant harm. The official form asks whether the Commissioner was notified within 72 hours after the organization became aware of it. Affected individuals may also require notification depending on the circumstances.
Hotels accepting payment cards must determine their PCI DSS responsibilities. PCI DSS is an industry standard, not a replacement for the PDPA. The hotel, acquiring bank, payment providers, and relevant assessors should confirm what is in scope.
What can a hotel improve within the next 30 days?
Hotels can make meaningful progress within 30 days by finding immediate exposure, closing high-risk gaps, and assigning owners to recurring security work.
Days 1–7: Find immediate exposure
- Map important systems and network segments.
- Test whether guest WiFi can reach internal addresses.
- List staff, administrator, and vendor accounts.
- Confirm when backups last completed successfully.
- Identify unsupported or seriously unpatched devices.
Days 8–14: Close high-risk gaps
- Block unnecessary routes between networks.
- Disable inactive and unknown accounts.
- Enable MFA for email, PMS, cloud services, and remote access.
- Patch exposed systems.
- Review vendor connections and endpoint protection coverage.
Days 15–30: Build repeatable controls
- Perform and record a restore test.
- Review firewall, endpoint, and access logs.
- Document incident contacts and escalation steps.
- Run a short phishing or breach-response exercise.
- Assign an owner and next review date to every checklist item.
How Callnet Solution helps Malaysian hotels strengthen their cybersecurity posture

Callnet helps Malaysian hotels assess exposure, design security zones, configure firewalls and managed WiFi, protect endpoints, implement backup and recovery, and monitor unusual activity. We work with partners including Cisco, Ruckus, Sangfor, WithSecure, Dell Technologies, Microsoft, Veeam, Druva, and PRTG, allowing us to recommend technologies based on each property’s requirements.
We can also help hotel groups establish a consistent baseline across properties while coordinating with existing PMS, payment, and support vendors.
What should hospitality operators do next?
If you are unsure whether guest WiFi, payment systems, and hotel operations are properly separated, Callnet can review the current environment and identify the gaps that create the greatest operational risk.
Book a free consultation with Callnet to review your hotel’s network segmentation, access controls, backup readiness, and monitoring coverage.




