{"id":4504,"date":"2022-10-12T02:29:32","date_gmt":"2022-10-12T09:29:32","guid":{"rendered":"https:\/\/cardonet.com\/news\/?p=4504"},"modified":"2022-10-12T02:29:39","modified_gmt":"2022-10-12T09:29:39","slug":"hotel-pci-compliance","status":"publish","type":"post","link":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/","title":{"rendered":"Hotel PCI Compliance"},"content":{"rendered":"\n<p>When credit and debit cards began to replace cash as the default method of payments, hoteliers and guests shared a sigh of relief.\u00a0<\/p>\n\n\n\n<p><strong>Paying by card is great for both<\/strong>&nbsp;&#8211; customers don\u2019t have to worry about carrying cash around and hotel staff don\u2019t have to go through the hassle and worry of transporting that cash to the bank.<\/p>\n\n\n\n<p>However, while card payments eliminated one security risk, it added another.&nbsp;<strong>Guests\u2019 card information is valuable to cyber-criminals<\/strong>. It\u2019s your responsibility, as the hotel operator, to protect your customers\u2019 information from data breaches. If you don\u2019t,&nbsp;<strong>your guests could become the victims of payment fraud&nbsp;<\/strong>&#8211; that doesn\u2019t, usually, translate into 5-star TripAdvisor scores.<\/p>\n\n\n\n<p>That\u2019s why\u00a0<strong><a href=\"https:\/\/www.cardonet.com\/hotel-pci-compliance.php\">PCI compliance for hotels<\/a>\u00a0is so important<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What is PCI (Payment Card Industry) compliance for hotels?<\/strong><\/h2>\n\n\n\n<p>The PCI Data Security Standard is a set of rules that governs how hotels should handle and store their guests\u2019 card payment information.&nbsp;<strong>If your business accepts card payments, you are responsible for following these requirements<\/strong>.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What are my hotel\u2019s PCI compliance requirements?<\/strong><\/h2>\n\n\n\n<p>The exact requirements will depend on the volume of card payments your hotel processes. The most stringent rules apply to businesses that process more than 6m transactions a year. These businesses are considered \u2018Level 1\u2019.&nbsp;<\/p>\n\n\n\n<p>The levels run from 1 to 4. In level 4, you\u2019ll find businesses with under 1m transactions a year, and the simplest compliance process.<\/p>\n\n\n\n<p>We must note, however,&nbsp;<strong>that it is up to your card operator\u2019s discretion<\/strong>&nbsp;&#8211; if you, for example, have previously suffered a data breach, they are able to put you in \u2018Level 1\u2019, even if your yearly transactions total less than 6m.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The 12 requirements of PCI Compliance for a hotel<\/strong><\/h2>\n\n\n\n<p>Regardless of what level applies to your hotel, there are 12 general PCI requirements that apply to all businesses which accept card payment.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li><strong>Firewalls<\/strong>: You must install firewalls to protect your guests\u2019 card information.<\/li><li><strong>No default passwords<\/strong>: As tempting as it may be to use the password that came with the card machine, it is a huge security risk.<\/li><li><strong>Protect your guests\u2019 cardholder data<\/strong>: You shouldn\u2019t store cardholder data unless you need to, but if you do, it is your responsibility to make sure that that data is protected.<\/li><li><strong>If you&#8217;re transmitting data over public networks, you need to encrypt it<\/strong>: When you transmit data over public networks, you run the risk of having that information be intercepted by hackers. Encrypting that data means that only authorised parties can access it.&nbsp;<\/li><li><strong>Update your antivirus software<\/strong>: How many of us have clicked \u201cNot now\u201d when faced with a reminder that your antivirus software needs an update? It\u2019s one thing to do that with your private computer, but it\u2019s a completely different situation when your guests\u2019 card information is at stake. You must ensure that all the computers, or devices, that have access to cardholder information are using good, up-to-date anti-virus software.<\/li><li><strong>Maintain system security<\/strong>: Your hotel should ensure that it installs the latest security patches and responds to vulnerabilities effectively.<\/li><li><strong>Restrict access to the data<\/strong>: Access to your guests\u2019 cardholder data should be on a strict, need-to-know basis.<\/li><li><strong>Unique IDs for authorised users<\/strong>: Of course, you are going to have to have some staff that are authorised to access cardholder data &#8211; they should be assigned unique IDs so that their access can be monitored, tracked, and flagged for any irregularities.&nbsp;<\/li><li><strong>Restrict physical access to the data<\/strong>: Installations of card processors, for example, should be monitored.<\/li><li><strong>Track and monitor access to networks and cardholder data<\/strong>: Log and monitor who has access to your hotel\u2019s network resources and cardholder data.<\/li><li><strong>Regularly test security<\/strong>: The only way to be sure that your security is up to scratch is to regularly test it.<\/li><li><strong>Maintain a business-wide security policy<\/strong>: This should be updated yearly, and the information within the policy should be distributed to all of your employees.<\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How does your hotel become PCI compliant?<\/strong><\/h2>\n\n\n\n<p>In an area as regulatorily and technically complex as this, it\u2019s recommended that you hire a technology partner to help you become, and stay, PCI compliant.&nbsp;<\/p>\n\n\n\n<p>We at Cardonet are hospitality IT support specialists and have helped hotels with every step of the PCI compliance process.&nbsp;<\/p>\n\n\n\n<p>Here\u2019s a sense of the steps that we would take if we partnered with your hotel.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li><strong>Audit your current card payment security<\/strong>. This will help us get a sense of where you\u2019re already PCI compliant, and where your vulnerabilities are.<\/li><li><strong>Gap analysis<\/strong>. We\u2019ll investigate your current system and perform a thorough gap analysis &#8211; that\u2019s where we look at where you are now, where you need to be to achieve PCI compliance, and what you need to do to get there.<\/li><li><strong>Define and implement policies for improvement<\/strong>. Now that we have a sense of what your hotel needs to do, we\u2019ll create and implement the internal policies that ensure that your card payment processing systems are in accordance with the 12 requirements of PCI compliance.<\/li><li><strong>Making sure everything is up and running<\/strong>. There\u2019s no use in implementing new policies only to find that they are not working for your business. We\u2019ll scan, test, and monitor your new set-up to make sure that isn\u2019t the case.<\/li><li><strong>A final audit<\/strong>. This is where we\u2019ll make sure that your hotel is now comprehensively PCI compliant.<\/li><\/ol>\n\n\n\n<p>While this may seem like a large undertaking, there are some huge upsides to your hotel being PCI compliant &#8211; and that\u2019s not only avoiding fines!<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Protection<\/strong>: With PCI compliance, your guests\u2019 data is more secure and there is less payment fraud. That means both your customers\u2019 wallets, and your hotel\u2019s reputation, are protected.<\/li><li><strong>Trust<\/strong>: By following PCI requirements, guests know that they can trust your hotel with their card payments. If they are comfortable making payments at your hotel, that means more revenue.<\/li><li><strong>Reduce costs<\/strong>: When your hotel is PCI compliant, you don\u2019t need to pay surcharges. Additionally, PCI compliance means that you are less likely to be hit with a fine if something does go wrong.<\/li><li><strong>Peace of mind<\/strong>: Going through the process of PCI compliance means that you know you\u2019ve followed best-practice industry guidelines in card payment safety. You\u2019ll know that you\u2019re already protected from the biggest risks associated with card payments.<\/li><\/ul>\n\n\n\n<p><strong>We at Cardonet provide expert IT support to hospitality businesses and have two decades\u2019 experience doing so.&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>PCI compliance is enormously important for any hotel &#8211; if you\u2019d like to hear how we can help you, please don\u2019t hesitate to&nbsp;<\/strong><a href=\"https:\/\/www.cardonet.co.uk\/it-services-quotation-request.php\"><strong>request a quote<\/strong><\/a><strong>. Otherwise, you can reach out to us today on +44 203 034 2244 or +1 323 984 8908.&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>We provide 24\/7 coverage throughout the United States, United Kingdom and Europe.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When credit and debit cards began to replace cash as the default method of payments, hoteliers and guests shared a sigh of relief.\u00a0 Paying by card is great for both&nbsp;&#8211; customers don\u2019t have to worry about carrying cash around and hotel staff don\u2019t have to go through the hassle and worry of transporting that cash<\/p>\n","protected":false},"author":8,"featured_media":4505,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[519],"tags":[687,551,604,810,811],"class_list":["post-4504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-consultancy","tag-compliance","tag-hotel","tag-hotel-it-services","tag-pci","tag-pci-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hotel PCI Compliance<\/title>\n<meta name=\"description\" content=\"It\u2019s your responsibility as a hotel operator to protect your customers\u2019 information from data breaches and that comes by being PCI compliant.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hotel PCI Compliance\" \/>\n<meta property=\"og:description\" content=\"It\u2019s your responsibility as a hotel operator to protect your customers\u2019 information from data breaches and that comes by being PCI compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"News\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-12T09:29:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-12T09:29:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"334\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Liam Wray\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Liam Wray\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hotel PCI Compliance","description":"It\u2019s your responsibility as a hotel operator to protect your customers\u2019 information from data breaches and that comes by being PCI compliant.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/","og_locale":"en_US","og_type":"article","og_title":"Hotel PCI Compliance","og_description":"It\u2019s your responsibility as a hotel operator to protect your customers\u2019 information from data breaches and that comes by being PCI compliant.","og_url":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/","og_site_name":"News","article_published_time":"2022-10-12T09:29:32+00:00","article_modified_time":"2022-10-12T09:29:39+00:00","og_image":[{"width":600,"height":334,"url":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png","type":"image\/png"}],"author":"Liam Wray","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Liam Wray","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#article","isPartOf":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/"},"author":{"name":"Liam Wray","@id":"https:\/\/cardonet.com\/news\/#\/schema\/person\/4793159d5cd8ce4688ade48ba77da149"},"headline":"Hotel PCI Compliance","datePublished":"2022-10-12T09:29:32+00:00","dateModified":"2022-10-12T09:29:39+00:00","mainEntityOfPage":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/"},"wordCount":1144,"commentCount":0,"publisher":{"@id":"https:\/\/cardonet.com\/news\/#organization"},"image":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png","keywords":["Compliance","Hotel","Hotel IT Services","PCI","PCI Compliance"],"articleSection":["IT Consultancy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/","url":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/","name":"Hotel PCI Compliance","isPartOf":{"@id":"https:\/\/cardonet.com\/news\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#primaryimage"},"image":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png","datePublished":"2022-10-12T09:29:32+00:00","dateModified":"2022-10-12T09:29:39+00:00","description":"It\u2019s your responsibility as a hotel operator to protect your customers\u2019 information from data breaches and that comes by being PCI compliant.","breadcrumb":{"@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cardonet.com\/news\/hotel-pci-compliance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#primaryimage","url":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png","contentUrl":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2022\/10\/hotel-pci-compliance-cardonet.png","width":600,"height":334,"caption":"PCI Compliance for Hotels"},{"@type":"BreadcrumbList","@id":"https:\/\/cardonet.com\/news\/hotel-pci-compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"News Home","item":"https:\/\/cardonet.com\/news\/"},{"@type":"ListItem","position":2,"name":"Hotel PCI Compliance"}]},{"@type":"WebSite","@id":"https:\/\/cardonet.com\/news\/#website","url":"https:\/\/cardonet.com\/news\/","name":"News","description":"IT Services from Cardonet","publisher":{"@id":"https:\/\/cardonet.com\/news\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cardonet.com\/news\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cardonet.com\/news\/#organization","name":"Cardonet","url":"https:\/\/cardonet.com\/news\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cardonet.com\/news\/#\/schema\/logo\/image\/","url":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2018\/06\/it-support-london-cardonet.png","contentUrl":"https:\/\/cardonet.com\/news\/wp-content\/uploads\/2018\/06\/it-support-london-cardonet.png","width":1920,"height":1080,"caption":"Cardonet"},"image":{"@id":"https:\/\/cardonet.com\/news\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/cardonet.com\/news\/#\/schema\/person\/4793159d5cd8ce4688ade48ba77da149","name":"Liam Wray","description":"Liam is a freelance writer with an interest in technology.","sameAs":["http:\/\/www.cardonet.com"]}]}},"_links":{"self":[{"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/posts\/4504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/comments?post=4504"}],"version-history":[{"count":0,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/posts\/4504\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/media\/4505"}],"wp:attachment":[{"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/media?parent=4504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/categories?post=4504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cardonet.com\/news\/wp-json\/wp\/v2\/tags?post=4504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}