Skip to content

In September 2023, MGM Resorts received a phone call.

The caller posed as an employee. Within minutes, a help desk agent reset credentials that gave attackers access to core systems across the company. The breach caused over $100 million in damages, disrupting payments, guest data, and room access across multiple properties. Mews No firewall was bypassed. No vulnerability was exploited. One person, under pressure, made a decision that seemed reasonable in the moment.

This is how hotel security actually fails — not at the perimeter, but in the space between policy and practice.

The industry’s exposure is structural, not incidental

82% of North American hotels experienced a successful cyberattack during the summer of 2024, with many hit multiple times. Blackswan-cybersecurity The average cost of a data breach in hospitality rose to $3.86 million in 2024. Help Net Security These are not numbers from an industry being ambushed by sophisticated actors. They reflect an industry whose operating conditions make consistent security behavior genuinely difficult to maintain.

The structure of hotel operations amplifies this in specific ways.

High staff turnover and frequent reliance on temporary workers add materially to the sector’s exposure — new employees are often more susceptible to phishing and social engineering attacks, as demonstrated by the MGM incident. Digital Watch Observatory Systems are accessed across roles, shifts, and shared devices. Technical proficiency varies widely across teams that were never hired for technical competency. An estimated 70% of hotel staff have access to sensitive systems without receiving consistent cybersecurity training. OysterLink

Under these conditions, the expectation that staff will consistently make the right security decision is not a strategy. It is an assumption — and a fragile one.

The gap between policy and behavior

Most hotels respond to human risk with training. Employees are told to use strong passwords, avoid suspicious links, follow access procedures. Periodic refreshers reinforce the message.

The assumption embedded in this approach — that awareness reliably produces compliance — does not hold under operational pressure.

A front desk agent managing a queue of waiting guests is not thinking about credential hygiene. A night shift employee troubleshooting a system failure is not reviewing security protocols. In these moments, behavior is shaped less by knowledge and more by context. And in hospitality, context consistently favors speed over caution.

Phishing and compromised or stolen credentials remain the top two initial attack vectors for breaches in the sector Venza — not because staff lack awareness, but because the conditions under which they work make sustained vigilance unreliable as a primary defense.

Training matters. But treating it as the main control is a design failure.

When the system depends on perfect behavior

Security strategies that rely on individuals consistently doing the right thing are fragile by design. The more a system depends on individual discipline, the more likely it is to be bypassed — deliberately or not.

This is not a criticism of staff. It is a systems observation.

According to the 2025 Verizon Data Breach Investigations Report, cybercriminals targeting the hospitality sector most often rely on system intrusions, social engineering, and basic web application attacks. Asimily Social engineering succeeds precisely because it exploits normal human behavior — trust, urgency, the instinct to resolve a problem quickly. These are not weaknesses to be trained away. They are features of how people function under pressure.

A security model that positions human behavior as the last line of defense will routinely find that line crossed — not because people fail, but because the model asks too much of them.

Designing for the mistakes that will happen

A more resilient approach begins with a different premise: people will make mistakes, and systems should be built to contain the consequences.

This shifts focus from behavior modification to system architecture. Access is scoped to what is actually necessary for each role, reducing the blast radius when credentials are compromised. Workflows are simplified so that the secure path is also the path of least resistance. Security controls are embedded in the process rather than positioned as additional steps that compete with operational urgency.

Shorter sessions with automatic logout are more reliable than manual sign-out under pressure. Single sign-on reduces password reuse without asking staff to remember more. Context-aware authentication can balance access and control without constant interruption. These are architectural decisions with more predictable outcomes than any awareness program.

The goal is not to eliminate human error. It is to prevent human error from becoming a security incident.

The friction problem nobody budgets for

One dynamic that receives less attention than it should: when security controls are perceived as obstacles, they get worked around.

Complex login procedures, frequent resets, multi-step verification — each adds cognitive load in an environment where staff are already managing guest interaction, operational pace, and system complexity simultaneously. The workaround is not defiance. It is adaptation. And it creates exposure that no policy document captures.

Designing security that works with how people actually operate — rather than how they are assumed to operate — is not a compromise of standards. It is a more accurate model of human behavior under workload.

A different definition of the problem

The framing of staff as “the weakest link” in hotel cybersecurity is only partially accurate — and the part that’s inaccurate matters.

Among hospitality businesses that have experienced a data breach, 89% experienced repeat breaches Coursera — a figure that suggests the root cause is rarely addressed after the first incident. If people were the fundamental problem, retraining would show results. The recurrence rate indicates something more structural is at work.

People are not the problem. Systems that place too much security weight on consistent human behavior are.

As long as hotel security strategy treats individual vigilance as a primary control, it will remain most exposed in exactly the conditions that matter most: high volume, high pressure, high staff turnover. Which is to say — normal operations.

The more durable path is to assume imperfect behavior and build accordingly.

Back To Top