TL;DR:

  • Hospitality businesses process card payments, hold guest data, and run public Wi-Fi, making them attractive targets even at small scale
  • POS security, guest Wi-Fi segmentation, and booking system hygiene are the three areas that matter most
  • GDPR applies fully to guest data, and the ICO has fined small hospitality businesses; free help is available via NCSC’s Cyber Aware programme

Running a pub, restaurant, or hotel means you’re dealing with a lot of moving parts at once: staff, stock, customer expectations, and the endless pressure of margins. Cybersecurity probably feels like something that happens to large chains, not independent businesses. Here’s the thing, though: attackers don’t particularly target large businesses because they’re interesting. They target businesses that are likely to be underprepared. And by that measure, a busy independent restaurant with a till full of contactless transactions and a folder of customer booking data is a perfectly attractive target.

This isn’t meant to be alarmist. It’s meant to be practical. The steps that genuinely protect a small hospitality business are not complicated or expensive, and the NCSC offers real resources to help. Let’s go through what actually matters.

Your POS System Is the Front Line

Your point-of-sale terminal is probably the most attacked system in any hospitality business. Card skimming, where criminals attach hardware to your physical terminal to capture card data, is still a live threat despite chip-and-PIN being near-universal in the UK. Check your terminals regularly for anything that looks out of place, particularly around the card slot and PIN pad. Staff who handle the tills should know what the terminals normally look like, because it takes seconds to spot something that wasn’t there yesterday.

Software-based attacks are less visible but potentially more damaging. RAM scraping malware installs itself on the computer running your POS system and captures card data as it passes through memory before encryption kicks in. This is exactly how some of the largest hospitality data breaches have worked, and it affects smaller businesses too. The mitigation is fairly straightforward: use a POS system that is explicitly PCI DSS compliant, keep the software updated, and don’t use the POS computer for anything else. Browsing the web or checking emails on the same machine that runs your card payments is a real risk, and it’s a common one.

Your payment provider or POS supplier should be able to tell you clearly whether their product is PCI DSS certified. If they can’t answer that question, that’s a red flag worth taking seriously.

Booking Systems and Guest Data

Hotels, restaurants, and even busy pubs increasingly use digital booking systems: property management software like Mews or Opera for hotels, ResDiary or OpenTable for restaurants, and a range of simpler online booking tools for everyone else. These systems hold names, email addresses, phone numbers, and in some cases payment card details. That makes them a genuine target.

The most common attack vector isn’t sophisticated: it’s credential theft. Someone gets hold of a username and password, either through phishing, password reuse from another breach, or because the login is just weak. From there, they can access your guest list, export it, or in the case of hotels, look up future bookings to conduct targeted fraud against your guests.

Use strong, unique passwords for every booking platform. Enable multi-factor authentication wherever it’s offered; most major platforms support it now and it should be turned on by default. Limit who has admin access, because a former member of staff with active credentials is a common source of problems. When someone leaves, deactivate their account that same day.

If you hold guest payment card details beyond what’s strictly necessary, stop. You don’t need to keep card numbers after a transaction is processed, and holding them creates both a security risk and a GDPR liability.

Public Wi-Fi: Separate Your Networks

Almost every hospitality venue offers guest Wi-Fi, and almost every venue runs its back-office systems on the same network. That’s a serious problem. A customer connected to your Wi-Fi, or someone sitting outside with a laptop, should have absolutely no route to the systems running your bookings, accounts, or POS.

Network segmentation sounds technical but is increasingly handled by consumer-grade routers: you create a guest network that is entirely isolated from your internal network, so guests can get online but cannot see or reach anything else on your infrastructure. Any competent IT professional or even a technically minded friend can set this up in an afternoon. If your router doesn’t support it, a cheap business-grade router from the likes of TP-Link or Ubiquiti will.

While you’re at it, change the default admin password on your router. A staggering number of small business routers are still running on factory default credentials, which are publicly listed and trivially searchable.

Delivery Platform Account Security

If you’re on Deliveroo, Just Eat, or Uber Eats, your merchant account holds your bank details, your menu, and your reputation. Account takeover attacks on delivery platform accounts are increasingly common: criminals gain access, redirect payments to a different bank account, or run up fraudulent orders. The disruption to a small restaurant can be severe, particularly during busy periods when you don’t notice something’s wrong until it’s too late.

Use a unique password for each platform, enable two-factor authentication, and treat any email asking you to update payment or login details with extreme suspicion. All three major platforms have had phishing campaigns impersonating their support teams. When in doubt, log in directly through the app rather than following any link in an email.

The General Data Protection Regulation applies fully to hospitality businesses in the UK under the UK GDPR framework. If you’re collecting names, email addresses, dietary preferences, or any other personal data from guests, you have legal obligations around how you store it, how long you keep it, and what you do if it’s compromised.

The ICO (Information Commissioner’s Office) has fined small businesses, including hospitality operators, for data breaches. The fines are tiered and proportionate, but even a relatively modest fine comes with reputational damage and the cost of notifying affected customers. You must report certain types of breach to the ICO within 72 hours of becoming aware of it.

In practice: keep only the data you actually need, delete guest records once they’re no longer required, store data on systems with proper access controls, and know how to recognise a breach so you can report it promptly.

A Cautionary Tale: MGM Resorts

In 2023, MGM Resorts International suffered a ransomware attack that took down hotel check-in systems, slot machines, and digital key cards across dozens of properties. The attack began with a social engineering call to the IT help desk. Attackers impersonated an employee, talked their way into account access, and escalated from there.

MGM is obviously a different scale from a 30-room hotel in the Cotswolds. But the attack method, pretending to be someone you’re not to get access credentials over the phone, works just as well on a small business with a single admin account and no verification process. Teach your staff that IT support, your POS provider, or your booking system vendor will never call and ask for passwords or login codes. If anyone does, hang up and call the company back on a number you find independently.

Where to Get Free Help

The National Cyber Security Centre’s Cyber Aware campaign (ncsc.gov.uk/cyberaware) is genuinely useful and free. It covers the basics: strong passwords, multi-factor authentication, software updates, backups, and phishing awareness. Their Small Business Guide is a quick read that covers most of what you need to know to get the foundations right.

The Cyber Essentials certification is a UK government-backed scheme that, if you go through the assessment, gives you a recognised standard of basic cyber hygiene. Some contracts and suppliers now ask for it, and the process of achieving it forces you to address the most common weaknesses. It’s not expensive for a small organisation and signals to customers and partners that you take this seriously.

You don’t need a dedicated IT team to protect your hospitality business from the most common threats. You need good passwords, multi-factor authentication, separated networks, and staff who know what a suspicious email looks like. Get those right and you’ll be better prepared than the majority of businesses in your sector.