• Jump to contents
  • Jump to main navigation
  • Jump to site map
  • News
  • Insight
  • Careers
  • Support
  • Free IT Cost Review
  • Contact Us Now
  • Free IT Cost Review
  • Contact Us Now
  • +44 207 837 2444
  • US and International: +1 323 984 8908
  • Change Region
  • +1 323 984 8908
  • Change Region

Cardonet IT Support for Business

Cardonet are a consultative business partner who will work closely with you to provide a transparent, vendor-neutral approach to your IT Services.

+44 203 034 2244
7 Stean Street, London, E8 4ED

+1 323 984 8908
750 N. San Vicente Blvd, Los Angeles, CA 90069

  • Home
  • IT Solutions
    • Industry Sector IT Solutions
      • Hospitality
        • Hotels
        • Hotel Management
        • Restaurants
        • Pub & Bars
      • Finance Associations
      • Manufacturing
      • Charity
      • Education
    • Business IT Challenges
      • IT Outsourcing
      • GDPR Compliance
      • PCI DSS Compliance
  • IT Services
    • IT Support
      • 24x7 Service Desk
      • 24x7 Network Monitoring
      • IT Service Delivery
      • Proactive IT Support
      • Remote IT Support
      • Onsite IT Support
      • Out of Hours IT Support
      • Dedicated Service Desk
      • Network Support
      • Microsoft Support
      • Apple Mac Support
      • Business IT Support
    • IT Consultancy
      • IT Strategy
      • IT Projects
      • IT Audits
      • Software Licensing
      • IT Infrastructure
      • IT Procurement
      • IT Supplier Management
      • IT Security
      • IT Networks and Cabling
      • Cloud Readiness
      • Virtualisation
      • Backup and Continuity
    • Managed IT
      • Managed Networks
      • Managed Hosting
      • Managed Backups
      • Business Continuity
    • Managed Cloud
      • Private Cloud
      • Hybrid Cloud
      • Public Cloud
    • Communication
      • Onsite Telephone System
      • Hybrid Telephone System
      • Cloud Telephone System
      • Contact Centre
      • Video Conferencing
      • SIP Trunking
      • Lines and Calls
    • Cyber Security
      • Cyber Security Audit
      • Cyber Essentials Support
      • GDPR Compliance
      • Penetration Testing
      • Managed Cyber Security
      • PCI Compliance Support
      • ISO 27001 Certification
  • About
    • About Cardonet
      • Why Cardonet?
      • News
      • Insight
      • Management Team
      • Case Studies
      • Customers
      • Technology Partners
      • Accreditations & Memberships
      • Approach and Culture
      • History
    • Careers with Cardonet
      • Why Cardonet for your Career?
      • Meet our Team
      • Job Entry Options
      • Current Job Vacancies
  • Contact

News

Hotel PCI Compliance

by Liam Wray / Wednesday, 12 October 2022 / Published in IT Consultancy
PCI Compliance for Hotels

When credit and debit cards began to replace cash as the default method of payments, hoteliers and guests shared a sigh of relief. 

Paying by card is great for both – customers don’t have to worry about carrying cash around and hotel staff don’t have to go through the hassle and worry of transporting that cash to the bank.

However, while card payments eliminated one security risk, it added another. Guests’ card information is valuable to cyber-criminals. It’s your responsibility, as the hotel operator, to protect your customers’ information from data breaches. If you don’t, your guests could become the victims of payment fraud – that doesn’t, usually, translate into 5-star TripAdvisor scores.

That’s why PCI compliance for hotels is so important.

What is PCI (Payment Card Industry) compliance for hotels?

The PCI Data Security Standard is a set of rules that governs how hotels should handle and store their guests’ card payment information. If your business accepts card payments, you are responsible for following these requirements. 

What are my hotel’s PCI compliance requirements?

The exact requirements will depend on the volume of card payments your hotel processes. The most stringent rules apply to businesses that process more than 6m transactions a year. These businesses are considered ‘Level 1’. 

The levels run from 1 to 4. In level 4, you’ll find businesses with under 1m transactions a year, and the simplest compliance process.

We must note, however, that it is up to your card operator’s discretion – if you, for example, have previously suffered a data breach, they are able to put you in ‘Level 1’, even if your yearly transactions total less than 6m.

The 12 requirements of PCI Compliance for a hotel

Regardless of what level applies to your hotel, there are 12 general PCI requirements that apply to all businesses which accept card payment.

  1. Firewalls: You must install firewalls to protect your guests’ card information.
  2. No default passwords: As tempting as it may be to use the password that came with the card machine, it is a huge security risk.
  3. Protect your guests’ cardholder data: You shouldn’t store cardholder data unless you need to, but if you do, it is your responsibility to make sure that that data is protected.
  4. If you’re transmitting data over public networks, you need to encrypt it: When you transmit data over public networks, you run the risk of having that information be intercepted by hackers. Encrypting that data means that only authorised parties can access it. 
  5. Update your antivirus software: How many of us have clicked “Not now” when faced with a reminder that your antivirus software needs an update? It’s one thing to do that with your private computer, but it’s a completely different situation when your guests’ card information is at stake. You must ensure that all the computers, or devices, that have access to cardholder information are using good, up-to-date anti-virus software.
  6. Maintain system security: Your hotel should ensure that it installs the latest security patches and responds to vulnerabilities effectively.
  7. Restrict access to the data: Access to your guests’ cardholder data should be on a strict, need-to-know basis.
  8. Unique IDs for authorised users: Of course, you are going to have to have some staff that are authorised to access cardholder data – they should be assigned unique IDs so that their access can be monitored, tracked, and flagged for any irregularities. 
  9. Restrict physical access to the data: Installations of card processors, for example, should be monitored.
  10. Track and monitor access to networks and cardholder data: Log and monitor who has access to your hotel’s network resources and cardholder data.
  11. Regularly test security: The only way to be sure that your security is up to scratch is to regularly test it.
  12. Maintain a business-wide security policy: This should be updated yearly, and the information within the policy should be distributed to all of your employees.

How does your hotel become PCI compliant?

In an area as regulatorily and technically complex as this, it’s recommended that you hire a technology partner to help you become, and stay, PCI compliant. 

We at Cardonet are hospitality IT support specialists and have helped hotels with every step of the PCI compliance process. 

Here’s a sense of the steps that we would take if we partnered with your hotel.

  1. Audit your current card payment security. This will help us get a sense of where you’re already PCI compliant, and where your vulnerabilities are.
  2. Gap analysis. We’ll investigate your current system and perform a thorough gap analysis – that’s where we look at where you are now, where you need to be to achieve PCI compliance, and what you need to do to get there.
  3. Define and implement policies for improvement. Now that we have a sense of what your hotel needs to do, we’ll create and implement the internal policies that ensure that your card payment processing systems are in accordance with the 12 requirements of PCI compliance.
  4. Making sure everything is up and running. There’s no use in implementing new policies only to find that they are not working for your business. We’ll scan, test, and monitor your new set-up to make sure that isn’t the case.
  5. A final audit. This is where we’ll make sure that your hotel is now comprehensively PCI compliant.

While this may seem like a large undertaking, there are some huge upsides to your hotel being PCI compliant – and that’s not only avoiding fines!

  • Protection: With PCI compliance, your guests’ data is more secure and there is less payment fraud. That means both your customers’ wallets, and your hotel’s reputation, are protected.
  • Trust: By following PCI requirements, guests know that they can trust your hotel with their card payments. If they are comfortable making payments at your hotel, that means more revenue.
  • Reduce costs: When your hotel is PCI compliant, you don’t need to pay surcharges. Additionally, PCI compliance means that you are less likely to be hit with a fine if something does go wrong.
  • Peace of mind: Going through the process of PCI compliance means that you know you’ve followed best-practice industry guidelines in card payment safety. You’ll know that you’re already protected from the biggest risks associated with card payments.

We at Cardonet provide expert IT support to hospitality businesses and have two decades’ experience doing so. 

PCI compliance is enormously important for any hotel – if you’d like to hear how we can help you, please don’t hesitate to request a quote. Otherwise, you can reach out to us today on +44 203 034 2244 or +1 323 984 8908. 

We provide 24/7 coverage throughout the United States, United Kingdom and Europe.

Share this on:

  • LinkedIn
  • Twitter
  • Facebook
Tagged under: Compliance, Hotel, Hotel IT Services, PCI, PCI Compliance

About Liam Wray

Liam is a freelance writer with an interest in technology.

What you can read next

rising costs and it
Rising Costs and Your IT: How You Can Save Money
Due Diligence Hotel Technology
Hotel Technology Due Diligence
11 Reasons Outsource Hotel IT Support
11 Reasons you should Outsource your Hotel IT Support

You must be logged in to post a comment.

Featured Posts

  • 247 Hotel IT Support Cardonet

    Why hotels need 24/7 IT Support

  • IT challenges operating hotels different geographies Cardonet

    Technology challenges operating hotels in different geographies

  • Google Workspace Microsoft 365 Migration

    Migrating from Google Workspace to Microsoft 365

  • Due Diligence Hotel Technology

    Hotel Technology Due Diligence

Archives

  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017

Categories

  • Bam's Blog
  • Customers
  • Cyber Security
  • Events
  • GDPR
  • Guidance
  • IT Consultancy
  • IT Support
  • Managed IT
  • Press Release
  • Recruitment
  • Team
  • Uncategorised
  • USA
  • What is

Tags

Business Business Continuity Christmas Christmas Party Cloud Computing Cloud Hosting Compliance coronavirus Covid 19 Cyber Awareness cyber crime Cyber Risk Cyber Security Cyber Threat Data Backups Disaster Recovery GDPR Halloween HOSPA Hospitality Hotel Hotel IT Services Hotel IT Solutions Hotel IT Support Hotels Hotel Technology IT documentation IT infrastructure IT Services IT Support Microsoft Microsoft365 Migration Network Security Outsourced IT Support Pancake Pancake Day Phishing Scams reduce IT costs Remote Working Security Software Team Team Event Teams

Cardonet Twitter

8 days agoOur thoughts are with them all on this day. https://t.co/KMjT8SBSmb
Follow @@cardonetit
TOP

We will help you overcome your technology challenges

Call us on +1 323 984 8908, email us at or fill out the following form to start the conversation.

",

For further information on how we process your data, please refer to our Privacy Policy.

IT Solutions

  • IT Solutions by Industry
  • Business IT Challenges

IT Services

  • IT Support
  • IT Consultancy
  • Managed IT
  • Managed Cloud
  • Communication
  • Cyber Security

About

  • Why Cardonet
  • Meet our Team
  • News
  • Insight
  • Case Studies
  • Careers

Contact

  • +44 207 837 2444
  • +1 323 984 8908
  • Change Region
Cardonet 22 years proudly supporting our customers
  •  
  •  
  • 750 N. San Vicente Blvd, Los Angeles, CA 90069
Cardonet IT Support and IT Services
Change Region
  • United Kingdom and Europe
  • United States and International

© 1999 - 2022 All rights reserved.

  • Sitemap
  • Terms and Conditions
  • Privacy Policy
  • GDPR
  • Accessibility Statement
  • Corporate Social Responsibility
  • Environmental Policy
Contact TOP
Cardonet
Cardonet Consultancy Limited 7 Stean Street London, Greater London E8 4ED
London Map +442030342244
Cardonet US Inc 750 N. San Vicente Blvd, West Hollywood Los Angeles, California 90069
Los Angeles Map +13239848908
Home Cardonet IT Support Logo