Applied IAM

Identity Security for Hospitality

A ten-minute phone call to a help desk took a casino operator offline for ten days. Hospitality runs on a workforce that turns over faster than any other sector, a property management system that every department touches, and a payment environment that PCI-DSS expects you to keep separate from all of it. The attackers who get in do not exploit the PMS. They ask someone to reset a password.

PCI-DSSProperty management systems70% turnoverFranchise estates
Help desk · inbound callOn hold: verification
Password reset and a new MFA deviceCaller has enough real detail to sound like an employee
  1. Request logged
  2. Verify identityRequired
  3. Reset password
  4. Close ticket
Identity verification
Confirm the caller against the HR record
Confirm the request with their manager
Skip verificationStart verification

Skip is not available. Identity verification comes before any credential or MFA change.

A help desk that cannot be talked into a reset.

The four problems

Why hospitality access is hard to hold

  • Turnover around 70%. Front desk, housekeeping, food and beverage, seasonal — the workforce changes faster than any manual offboarding process can follow, and the accounts that survive are the ones an attacker uses.
  • The PMS touches everything. Reservations, payments, guest data, loyalty, room access. Standing privilege in the property management system is standing privilege over the whole property.
  • Franchise and multi-property estates. Brand standards set centrally, systems run locally, and a general manager who holds admin on everything in the building because there is nobody else.
  • The help desk is the attack surface. Social engineering of support staff — a caller with enough real detail to sound like an employee — is how the largest hospitality breaches have started. That is a people control as much as a technical one.
The framework

PCI-DSS and the payment environment

PCI-DSS Requirements 7 and 8 apply to every property handling cards: individual accounts, MFA into the cardholder data environment, access by need to know, and a review cycle. In hospitality the difficulty is that the cardholder environment and the operational one overlap at the front desk, the restaurant and the spa. Segmentation has to be real and tested, which is PCI penetration testing, and the accounts that reach the payment environment have to be individual and reviewed. The CIO or CISO owns it; finance signs the attestation.

The fix

What actually fixes it

Three things, and they are the same three across every property.

Offboarding that runs itself

Lifecycle automation from the HR or scheduling system, so a departure removes access the same day. At 70% turnover, that is the single highest-value control in the sector. IGA implementation.

Standing privilege removed

General manager and IT admin rights vaulted, brokered and recorded, with elevation for approved tasks rather than permanent admin. For most properties and franchise groups, KeeperPAM fits the footprint better than an enterprise platform; the engagement is PAM implementation either way.

A help desk that cannot be talked into a reset

Identity verification before any credential or MFA change, and support staff trained on exactly the manipulation that has worked elsewhere. Security awareness training built for the front line.

Every property
1The workforceTurnover around 70%
Front deskOn shiftHousekeepingDepartedAccess removed the same dayFood and beverageOn shiftSeasonalDepartedAccess removed the same day
Fixed byOffboarding that runs itselfFrom the HR or scheduling system
2The PMSTouches everything
ReservationsPaymentsGuest dataLoyaltyRoom access
General manager and IT admin rightsVaulted, brokered and recorded
Fixed byStanding privilege removedElevation for approved tasks
3The help deskThe attack surface
A caller with enough real detailIdentity verificationCredential or MFA change
Fixed byA help desk that cannot be talked into a resetVerification before any change
FAQs

What hospitality teams ask first

By automating the whole lifecycle from the system that already knows someone has left. Departure removes access without a ticket. It is the only approach that keeps pace.

Yes. Governance and privileged access run centrally; property systems stay local. The role model is simpler than most sectors, which helps.

A verification step that cannot be skipped, and support staff who have heard the exact script an attacker will use. Both together; neither alone.

See who still has a key to the property

A free audit is a 30-minute review of your privileged and orphaned accounts by a certified engineer, with the findings in writing. The Hospitality blind spot brief covers the casino shutdown and the access gap behind it.