Hamburger Menu

Protecting customer data in your PMS

Best practices for hospitality businesses to keep guest and payment data safe.  
 

Key takeaway: The safest customer data is the data you do not store. Limit what your PMS holds, mask what you must keep, and keep PCI DSS and payment data out of free-text fields.


Your property management system (PMS) is the record of everything a guest tells you: names, contact details, stay preferences, and often payment information. That makes it a high-value target. Over the past year, hotel groups and booking platforms across Europe have seen a rise in phishing and hacking campaigns across the industry, designed to reach customer data held in PMS and reservation systems.

This guide sets out how you should handle customer data in your PMS, what to avoid, and the habits your team can adopt to reduce risk, whatever PMS you use.

Why this matters now

Several incidents across the industry from the past 18 months show why the basics matter more than ever.

 

  • Recent phishing campaigns have targeted hotel staff and customers by impersonating familiar booking platforms and asking them to complete fake verification steps. Once credentials or access are compromised, attackers can use booking information to contact guests directly and request fraudulent payments.
  • Other campaigns have targeted hotel administrators and booking-platform accounts, creating a direct route to guest records and communications.
  • In another industry incident, unauthorised access to a reservation system exposed guest names, contact details and reservation notes. Payment information was not exposed because it was not stored in the affected system.


That last point is the one worth sitting with. The organisations that came through these incidents best were the ones that simply were not storing sensitive data they did not need. That is the core idea behind everything below.

The core principle: do not store what you do not need

Before deciding how to securely store a piece of customer data, ask whether your PMS needs to hold it at all. If a booking reference or loyalty number does the job, you do not need the underlying payment card number sitting in a database, an export, or a member of staff's notes. Every field you do not populate is a field that cannot be breached; every field you do need should be securely stored.

Network and firewall security

  • Default-deny inbound traffic. Only allow inbound connections that are required for business operations. Any service exposed to the internet increases potential risk.
  • Review internet-facing services regularly. Work with your IT provider to identify which systems, ports and applications are accessible from the public internet, and remove any unnecessary exposure.
  • Restrict administrative access. Limit administrative access to authorised personnel and, where possible, make it accessible only through a VPN rather than directly from the internet.
  • Limit access by source IP. Where internet access is required, restrict connections to trusted IP addresses rather than allowing access from anywhere.
  • Review outbound traffic from critical servers. Critical systems should only communicate with approved destinations where practical, which helps reduce the impact of malware or unauthorised activity.
  • Monitor firewall logs. Review logs regularly for unusual connection attempts, repeated authentication failures or unexpected outbound connections.

Network segmentation

  • Separate guest Wi-Fi from hotel business systems. Guest networks should never have access to PMS, payment, finance or administrative systems.
  • Separate critical systems from one another. Isolate PMS, payment systems, administrative workstations, CCTV, servers and IoT devices wherever possible.
  • Follow the principle of least connectivity. Systems should only communicate with other systems where there is a legitimate operational requirement.

Access management

  • Restrict staff to role-based access. Staff should only be able to see the guest and payment data their role requires.
  • Enable multi-factor authentication (MFA). Require it for every login to your PMS and any system holding cardholder data, not only for administrator or remote access. MFA significantly reduces the risk of a compromised password leading to unauthorised access.
  • Use and enforce an up-to-date password policy. Your policy should define minimum length and complexity requirements, including numbers or special characters where appropriate, and should prohibit password sharing and reuse across users or systems.
  • Conduct regular access reviews. Remove unused accounts and confirm that employees only have the access required for their role.
  • Disable accounts immediately when staff leave. Former employees and contractors should not retain access to any operational systems.
  • Review access and export data. Keep a log of who accessed or exported guest and payment data, and review it regularly.

Software and patch management

  • Keep PMS software up to date. Security updates and supported software versions help protect against known vulnerabilities. Refer to the relevant software manufacturer's customer documentation and announcements to confirm current support and update requirements.
  • Patch operating systems and infrastructure. Update servers, workstations, firewalls, databases and remote access tools regularly.
  • Avoid unsupported software. End-of-life systems no longer receive security fixes and represent an increased risk. Refer to respective software manufacturer’s customer documentation and announcements to establish this.  

Card data: what your PMS must never store

Payment Card Industry Data Security Standard (PCI DSS) rules are explicit on this point, and they apply whether the card is entered online, over the phone, or at the front desk.

 

  • Only store cardholder data in approved payment systems. Payment information should only be processed and stored within systems specifically designed and secured for payment processing, not within the PMS itself.
  • Use tokenised payment methods where available. Tokenisation reduces the amount of sensitive card data stored within your PMS and hotel environment.


Beyond that, your PMS, and anyone using it, should never retain:

 

  • The card verification code (the 3- or 4-digit CVV or CVC), after the transaction is authorised.
  • The full contents of the card's magnetic stripe or chip.
  • PIN or PIN block data, under any circumstances.


If your business has a genuine, documented reason to retain the primary account number, cardholder name, expiry date, or service code, those elements must be encrypted or tokenised at rest, and access must be restricted to staff who need it. When a card number needs to be displayed at all, for example on a receipt or a booking summary, show no more than the first six and last four digits and mask the rest.
 

  • Do not send payment card details by email. Email is not an appropriate way to transmit payment card information, whether to a guest, a colleague or another department.

Free-text fields are where card data leaks in 

Simple rule for teams: never put anything in a comments or notes field that you would not want seen publicly. 


Most PMS breaches involving card data do not come from the payment module. They come from a well-meaning staff member typing a guest's card number into a notes or comments field, for example to record a late payment, a chargeback query, or a special request. Free-text fields are not encrypted or access-controlled the way payment fields are, so anything typed there is stored in plain sight, and is exactly the kind of field that gets pulled whole in a breach or an export.

To keep unmasked information out of comment sections:

 

  • Set one rule and repeat it in onboarding and refresher training: if you would not want it seen publicly, it does not go in a comments or notes field. That covers card numbers, CVVs, full payment details, and anything else a guest would not expect a stranger to read.
  • Where staff need to reference a payment, use the masked reference your PMS or payment provider already generates, such as a transaction ID or the last four digits, rather than the card number itself.
  • Turn on automated scanning where your PMS supports it, so that any text resembling a card number, expiry date, or CVV entered into a comment field is flagged or blocked before it is saved.
  • Review existing notes and comment histories periodically for anything that should not be there, and redact or delete it.


The same discipline applies to any other identifying customer information, such as passport numbers, home addresses, or ID document images. If it is not needed for the stay, do not store it. If it is needed, store it in a structured, access-controlled field, not a comment thread.

Phishing and user awareness

  • Train staff to recognise phishing attempts. Many security incidents begin with stolen credentials obtained through phishing rather than a technical system vulnerability.


These campaigns often begin with messages that appear to come from a familiar platform and ask staff to complete urgent verification steps. Brief staff, especially anyone with PMS or booking platform access, to pause and verify unexpected requests through trusted channels before taking action.

 

  • Be cautious of unexpected emails. Always verify requests involving payments, password resets, urgent actions or unusual attachments before acting on them.
  • Verify changes to banking or payment details. Confirm any such request using an independent communication channel, never by replying to the message or calling a number it provides, before processing it.
  • Report suspicious activity immediately. Early reporting often prevents a minor issue becoming a major incident.
  • Repeat this training regularly. Hospitality has high staff turnover, so a single induction session will not keep pace with a changing threat.

Backups and recovery

  • Maintain daily backups. Back up critical business and PMS data regularly.
  • Store backups separately. Consider off-site, immutable or offline backup solutions to protect against ransomware.
  • Test recovery procedures. A backup is only valuable if it can be successfully restored, so test that it can be.

Security monitoring

  • Monitor for unusual activity. Investigate unexpected user accounts, unusual logins, large data exports or unexplained system changes promptly.
  • Run regular vulnerability scans and keep antivirus and endpoint protection current, rather than only ahead of an audit. External and internal security reviews can identify weaknesses before attackers do.
  • Monitor payment pages and booking widgets for unauthorised script changes, which can indicate an e-skimming attempt.
  • Maintain an incident response process. Make sure staff know who to contact and what to do if suspicious activity is detected, so a suspected breach does not stall on “who do we tell”.

Security mindset

  • Treat cyber security as an ongoing process. Effective protection comes from multiple layers of security rather than a single technology or control.
  • Reduce exposure wherever possible. Fewer exposed services, fewer privileged accounts and fewer unnecessary connections generally mean a smaller attack surface.
  • Review security regularly. Technology, threats and business requirements change over time, so security controls should evolve with them. 

 

If you are not sure whether your PMS setup meets these practices

Start with the free-text fields. They are the fastest thing to check, the easiest to fix, and, based on recent incidents, one of the most common ways customer data ends up somewhere it should not be. 

Summary

Guest trust depends on treating their data, and the network it sits on, as something to minimise and protect, not just collect. The businesses that segment their network, control access tightly, patch what they run, limit what they store, mask what they must keep, keep card data out of free-text fields, and train staff against current phishing tactics are consistently the ones that come through an attempted breach with the least to disclose.