What the Target Data Security Breaches Mean for Hoteliers
January 15, 2014 6:15am
For the most recent update on this topic, click here
By Jim Butler and the Global Hospitality Group®
Hotel Lawyers | Authors of www.HotelLawBlog.com
15 January 2014
Hotel Lawyer: The growing problem of security breaches with sensitive customer information.
The recent headlines about the Target and Neiman Marcus security breach with customer credit cards highlights a growing crisis that concerns owners and operator of hotels as well as retailers. In this article, Bob Braun, one of the senior members of our Global Hospitality Group® who focuses on data security -- when he is not working on hotel management or franchise agreements -- gives us some thoughts on what to do about this problem.
The Target and Neiman Marcus breaches: What hoteliers need to know
by Robert E. Braun | Senior Member, Global Hospitality Group®
The Target and Neiman Marcus problem. The massive security breach of Target's customer data may affect more than 110 million Americans -- potentially about 1 in 3 persons living in the United States. Followed in quick succession by another 40 million customers of Neiman Marcus (and more disclosures expected soon from other retailers), it is time for us in the hotel industry to look at our own policies and procedures, and to think about how we should respond to these malicious attacks.
Hoteliers beware. Hotels are obvious targets for identity and financial theft for many reasons. Hotels transact business through credit cards, and those credit cards are kept on file and can be accessed multiple times during a guest's stay. The possibility that a credit card charge will be recorded occurs with each night's room charge, room service, bar or restaurant bill, spa charge, and so on. Every charge is another opportunity for an identity thief to access the information using sophisticated computer hacks and other malicious software, generally without the hotel's knowledge.
The need to respond to guest demands is another source of insecurity. The Identity Theft Resource Center noted, "The ability to connect to the Internet is an integral part of many individual's daily life. This has led to the increased demand for public WiFi." As a result, hotels find themselves compelled to offer wireless internet, and that service is almost always unsecured. But an unsecured wireless network is "just as dangerous as leaving files of your most important personal documents on a street curb for all to see. Hackers can easily get into an unsecured wireless network and get financial information, business records or sensitive e-mails." (PC World, "Got Wireless Security"). At the same time, hotels have little say in the matter. Guests demand wireless internet service.
Finally, hotels have employees -- lots of employees -- and many of them have access to the credit card and other personal information of guests. No matter how well trained and supervised, more personnel correlates to greater risk. The fact that low-level employees typically have access to key guest information, and that there is, historically, a high turnover in hotel employees, exacerbates the problem.
What happened to Target? While investigations are continuing, sources have reported that investigators believe the attackers used similar techniques and pieces of malicious software to steal data from retailers. One of the pieces of malware is a RAM scraper, or memory-parsing software, which allows cyber criminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text, the sources said. While the technology has been around for many years, its use has increased in recent years as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.
The lesson? Even as merchants become more vigilant and focus on the security of their systems, criminals have become more sophisticated and are investing more time and effort in crafting their own systems.
What should I do? The fact that Target, and others, have been victimized might not seem, at first, to impact other businesses. Securing guest and corporate information is a key task, and the steps necessary to implement a secure environment are unique to each organization. However, there are some general considerations that all firms should be aware of that are essential to securing information:
Most of all, hotel companies need to make a commitment to secure the sensitive information of their companies and their guests, and to seek out informed consultants and advisors. Information security is a relatively new and rapidly changing area, and requires specialized knowledge; the investment today can protect a hotel from being front page news -- for the wrong reasons -- later.
Developing a comprehensive information privacy and security program
The JMBM Global Hospitality Group® and the JMBM Data Security Group work with clients to establish and enforce data security policies, and assists clients when there are breaches. We have helped a variety of clients, including hospitality companies, in developing compliance programs, addressing data breach issues, and negotiating contracts with vendors and providers. Contact Bob Braun (RBraun@jmbm.com, 310.785.52331) for assistance. Bob Braun is a member of the International Association of Privacy Professionals and was the first and only "Super Lawyer" in Southern California in 2012 with a specialty in information technology.
If this article was of interest, you may also wish to read other articles on "Data Technology, Privacy & Security," which include the following articles:
Robert Braun is a senior member of the Global Hospitality Group® at JMBM. Mr. Braun advises hospitality clients with respect to hotel management agreements, franchise agreements and operating issues. He also advises on transactional matters, including entity formation, financing, and joint ventures, and works with companies on their data technology, privacy and security matters. These include software licensing, cloud computing, e-commerce, data processing and outsourcing agreements for the hospitality industry. He is a member of the International Association of Privacy Professionals. Contact him at 310.785.5331 or email@example.com.
This is Jim Butler, author of www.HotelLawBlog.com and hotel lawyer, signing off. We've done more than $68 billion of hotel transactions and have developed innovative solutions to unlock value from hotels. Who's your hotel lawyer?
Jim Butler is a founding partner of JMBM, and Chairman of its Global Hospitality Group® and Chinese Investment Group™. Jim is one of the top hospitality attorneys in the world. GOOGLE "hotel lawyer" and you will see why.
Jim and his team are more than "just" great hotel lawyers. They are also hospitality consultants and business advisors. They are deal makers. They can help find the right operator or capital provider. They know who to call and how to reach them.
Contact: Jim Butler
+1 (310) 201-3526
What Do Top Hotel Executives See on the Horizon for 2018?
GDPR: What You Need to Know About the EU's New Data Privacy Rules
Hotel Lawyer Jeffrey T. Myers Joins JMBM’s Global Hospitality Group®
Proposition 65 Defense Lawyer: Is Your Hotel Ready for the New Prop 65 Regulation Deadline? / Jim Butler
The 2018 LIIC Top Ten: The Annual Survey of Lodging Investments Trends and Challenges
Who Will You See at Meet the Money?
Important News for Hospitality Executives: How the New Tax Act Could Affect Your Estate Plan
California Labor & Employment Law Update: Key Changes in 2017 and What’s Slated for 2018
ADA Compliance & Defense Lawyer Update: 99 ADA Lawsuits Dismissed as Fraudulent and Malicious
Homeland Security Warns Against Threats to US Infrastructure
Resort Fee Litigation Advisory Group: How to Avoid Litigation on Resort Fees and Other Mandatory Hotel Charges
Hotel Lawyer: Tips on Negotiating Your Annual Hotel Budget
Resort Fee Litigation Advisory Group: How Resort Fees Became an Explosive $2.7 Billion Issue
Resort Fee Litigation Advisory Group: National Task Force of 47 Attorneys General Goes After Resort Fees
Resort Fee Litigation Advisory Group: The FTC Takes Aim at Hotel Resort Fees (Again) - The FTC 2017 Report
Resort Fee Litigation Advisory Group: Impending Eruption of Litigation over Resort Fees?
Hotel Lawyer: Tax Alert for Partnerships and LLCs
EB-5 Finance Lawyer: President Trump's Budget Deal Includes Extension of EB-5 Through 12-8-17
EB-5 Financing Lawyer: What JMBM Does to Help Developers With EB-5 Construction Financing
EB-5 Financing Lawyer: Why You Do NOT Want to Form Your Own Regional Center
Please login or register to post a comment.