Risk Brief / Property & cyber security / Issue 02
Property & cyber security

A practical ransomware readiness check for hotel operators.

Five questions to ask before an incident tests the property, the team and the guest experience.

Hotels concentrate reservations, payments, guest data and connected operational systems. A ransomware event can quickly become a business-interruption event.

Readiness is less about perfect prevention than a coordinated first response: clear roles, tested backups, accessible vendor contacts and a plan for serving guests while systems recover.

Start with the systems that keep guests moving.

Map the property-management system, reservations, payments, door locks, phones, Wi-Fi and payroll. Identify which service must return first, who controls it and which outside vendor can respond after hours.

Questions to ask
  • What must be restored first?
  • Who can take systems offline?
  • Are backups isolated and tested?
  • Which vendors respond after hours?
  • How will the front desk operate manually?

Make response roles unambiguous.

Name the incident lead, technology contact, operations decision-maker, communications owner and insurance contact. Store the list somewhere the team can reach without the hotel network.

Practice the first hour.

Run a short tabletop exercise: a reservation system is unavailable at 4 p.m. on a sold-out Friday. Walk through the first calls, guest communications, manual workarounds and escalation decisions. Record the gaps while they are visible.

Manager checklist

A 30-minute ransomware readiness huddle.

  1. 01Confirm emergency technology and vendor contacts.
  2. 02Locate the cyber policy and incident-reporting numbers.
  3. 03Verify who owns backup testing and recovery decisions.
  4. 04Walk through a manual guest-service plan.
Keep the conversation going

Discuss cyber readiness with your UWIB advisor.