By Jonathan Martin, EMEA Operations Director at Anomali
We as consumers use all sorts of criteria to decide what to eat, what to buy and where to go. Reputation and branding are some of the more conceptual factors by which we evaluate a purchase choice, but their powers are undoubtable. Hotel guests reasonably expect a safe experience, and the hospitality industry must do as much to secure their networks as they do making sure their facility feels welcoming.
Trusting your personal and financial data to a business is a big decision; consumers are beginning to be more discriminating about to whom they volunteer their information to. Studies report 60% of consumers lack confidence in the cyber-security of brick and mortar locations.
Working to gain an edge in garnering the public’s trust can be a huge competitive advantage. One security breach can be incredibly costly, making cyber-crime a huge burden for businesses. Large companies spend upwards of tens of thousands of pounds each day resolving the damage done by a data breach. Smaller companies which lack these resources regrettably go out of business within six months on average.
Unfortunately hackers have found ways to intercept credit card transactions in point of sale (POS) breaches. When such a POS hack affects a hotel chain, hackers can gather credit card information in hotel bars and restaurants then compromised accounts can be used to make fraudulent purchases and/or sold to other thieves or scam artists.
WiFi traffic is also vulnerable. Many people travel for work, taking sensitive data with them into their rooms. Laptops, mobiles, and smart devices can be hacked in a hotel. While malware and other threats can be inadvertently brought home like bed bugs.
As the reality of hacking begins to take hold in our public conscious, guests will hopefully begin taking more responsibility for securing their devices and adopt better practices for encrypting their data.
Still, hotels must do their best to assure security and privacy. Using a threat intelligence program allows businesses to detect suspicious behaviour ahead of time. It also integrates with numerous other applications thanks to the adaptation of universal standards for notating threat incidents.
One convention, TAXII, is used by threat intelligence platforms from many different developers. The TAXII server facilitates the collection, sharing, and analysis of cyber-threat intelligence. It can be an important component of a threat intelligence system. The Trusted Automated eXchange of Indicator Information language allows for notating the most important identifying details:
• Indicators
• Incidents
• Threat Actors
• Targets
• Course of action
Another good reason for using a threat intelligence platform that sends and receives threat intelligence using a STIX or TAXII server is for compliance with the law. Bills mandating threat intelligence platforms are gaining support, and government contractors must currently have satisfactory threat intelligence programs. If your business plans to keep government contracts as a source of business, compliance is an inevitability.
Don’t be left out in the rain when a POS hack or WiFi data breach hits. Start using a TAXII server before you’re left wondering what happened.

Hotel Business has an ABC certified circulation of 7,819 (audit period 1st July 2015 – 30th June 2016)