Insights

Reassessing Systems Governance for Hospitality Portfolios

Written by Jason Pullo | Aug 11, 2026, 11:00:01 AM

Serious security incidents often start small. A property’s front-desk manager might click a link in an email that looks like it came from the corporate office. The link takes the manager to a webpage, where they enter their password. Nothing alarming happens—there’s no threatening ransom note and all systems continue to function as normal. But behind the scenes, someone has stolen that password.

Weeks later, guest credit cards start showing unexplained charges. By the time anyone connects the dots, the stolen password has already done its damage.

Some incidents begin with a single missed step in what should be a clearly documented process. For example, a property might complete a routine property management system (PMS) switch. But maybe the team fails to re-validate the cashier key-code controls after the conversion. That omission causes the property to lose visibility over who is providing physical access to rooms and other spaces—leaving the property vulnerable to fraud, theft, and other security issues.

These types of incidents happen more than anyone likes to admit. At the highest level, the problem is governance: Properties too often rely on individual knowledge and ad hoc workflows rather than documented processes. Of course, implementing governance is no easy feat in hospitality, especially given some of the challenges that are inherent to the industry.

Uncovering Inherent Challenges in Hospitality

The hospitality industry has some built-in challenges that make protecting critical systems particularly difficult.

Every property has its own IT environment. One hotel might run OPERA for its PMS; another uses Stayntouch. One might use Toast for its point-of-sale (POS) system while another uses MICROS. Add ProfitSword or Hotel Effectiveness for labor and reporting, Sertifi for e-signature and payment authorization, and a handful of other platforms for guest services and audit trails. Then multiply that diverse collection of software across a growing portfolio. No single person can hold the full picture in their head.

Turnover is constant—and so is knowledge. In the hospitality industry, employees rotate in and out faster than in almost any other field. When only the general manager knows exactly which vendor to call, or only the front-office director understands the quirks of reporting software, there’s a big problem. Because when those employees leave, their knowledge leaves with them.

Growth outpaces process. Acquisitions, brand transitions, and new property builds bring in teams with distinct ideas about how to operate. Informal governance of key systems might scale fine for three hotels. But it will almost certainly break down when an organization is responsible for fifteen properties.

The data is worth stealing. PMS and POS systems hold exactly what fraudsters want—guests’ personally identifiable information (PII) and payment data. That sensitive material is flowing through every booking, every folio, and every checkout. And it is protected only by whatever access controls happen to be in place—and not compromised—on any given day.

It might not be surprising that cyberattacks are prevalent in the hospitality industry. In fact, 82% of North American hotels experienced a successful cyberattack during the summer peak travel season of 2024—and more than half were hit five or more times in that single season.[1] Meanwhile, the average cost of a data breach in the hospitality industry climbed to $4.03 million in 2025, up from $3.82 million the year before.[2]

These attacks are not necessarily sophisticated: They might simply take advantage of admin accounts that haven’t been reviewed recently. But their devastating financial and reputational consequences demand a new model for managing systems and processes.

Establishing and Documenting Standards

Hotel management companies should no longer depend on individual employees to ensure the security and reliable operation of vital systems. They need to establish and document standards for essential processes.

At any given moment, a management company leader should be able to answer:

  • How many people can create a PMS login at each property?
  • What happens to system access, step by step, the day someone gives notice?
  • What is the control checklist that teams must use for validation after a PMS or point-of-sale (POS) conversion?
  • If an examiner, insurer, or auditor asked for evidence of these processes, would there be a document to hand them?

Creating well-documented processes will help prevent a single error or the departure of a single employee from ultimately leading to costly damage.

Defining a Working Model

What should those documented processes look like? Most hotel management companies will benefit from implementing multiple standards:

  • Place a hard ceiling on property-level admins. Limit the number of admins to no more than three per property. Admins usually include the general manager or assistant general manager, front-office director, and the director of finance. Document and recertify the list every quarter.
  • Create a standard offboarding checklist. Align termination timing with access removal across all systems—including PMS, POS, financial, email, and network systems. Make sure systems are disabled on the same day for involuntary exits. Any exceptions should be time-bound and documented.
  • Build a conversion control checklist. Make sure that checklist is in place for every PMS or POS migration. Cashier roles and key codes should be validated before the go-live date instead of discovered after a shortage.
  • Conduct quarterly access reviews. Turn policies into evidence. Document who has access, why, and whether that access has been approved. Create a document you can actually hand to an auditor, insurer, or ownership group.
  • Clearly define process ownership. The hotel management company should own the business decisions and the compliance outcome. A systems partner should support administration, validation, monitoring, and escalation. Teams should not have to guess about roles.

Designing Standards That Don’t Slow You Down

When something goes wrong, hotel management companies might reflexively move to lock everything down. But applying too many restrictions can impact business agility.

Establishing and documenting process standards can help reduce reliance on individuals for security and smooth operations—all without slowing down the business. These standards are not focused exclusively on restrictions. They improve visibility into processes and access, and they define responsibilities and workflows: Everyone knows what they should do and when. And when someone departs, the organization can keep moving forward without added risk.

FAQ

Why do hotel management companies need to re-evaluate systems and access governance?
Too many hotel management companies rely on individual knowledge or ad hoc workflows for managing critical PMS, POS, financial, email, and network systems. When an individual leaves or a single step is missed, those companies can be vulnerable to cyberattacks and other costly security incidents.

Why are hotel management companies particularly vulnerable to security problems?

Property-specific IT environments, frequent employee turnover, rapid business growth, and highly valuable data (including guests’ personal information and payment data) put hospitality companies at greater risk than organizations in other fields. These inherent challenges demand well-established, documented process standards.

What does a new model for systems and access governance look like?

Hotel management companies should: cap the number of property-level admins, create a standard offboarding checklist, build a system conversion control checklist, conduct quarterly access reviews, and clearly define process ownership—especially if the companies engage outside teams to help with governance.

Ready to get started?
Schedule a Systems Governance Assessment with ESP. There’s no cost or commitment. We map your current systems inventory, admin model, and access controls against a documented standard across PMS, POS, financial, and reporting systems. Then we hand you a prioritized 120-day roadmap, which you can use whether or not you engage us to run it.

Schedule a Systems Governance Assessment →

Sources

[1] VikingCloud, Peak Season, Peak Risk: The 2025 State of Hospitality Cyber Report, July 2025

[2] IBM, Cost of a Data Breach Report 2025, July 2025