martechoutlookeurope

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our MarTech Outlook Advisory Board.

Elavon Merchant Services

Securing the Digital Customer Experience in Hospitality

Candice Pressinger

Hospitality Trust Advocate

We hear it time and again – the customer is king. The key to servicing these royal consumers is a first-class customer experience. These days, differentiating yourself from your competitors is crucial to success, and expected. In the hospitality industry, more and more business is done online. In the travel and tourism market in particular, 73% of total revenue is expected to be generated through online sales by 2026. Already, more than half (55%) of travellers worldwide use their computer to plan and book their travel. Customers expect booking travel online to be frictionless, simple, and integrated. They want to self-service and/or low contact with operators.

Mobile has emerged as the preferred channel for last-minute bookings and for millennials. In 2020, mobile bookings represented over 27% of total hotel bookings, rising to over 40% in 2021. Approximately 66% of millennials book their trips using a smartphone, while 74% use it to research.

With this in mind, mobile is key to delivering the experience customers expect and need. However, in offering many ways to interact with your brand, you need to ensure that experience is consistent across web, mobile, over the phone or in person. And that means:

• Making sure that the ‘payment moment’ doesn’t disrupt the guest experience.

• The capture, processing, transmission, and storage of more personal data.

• Increasing dependence on third parties to deliver and service that guest interaction and experience.

Current hospitality threat landscape

In terms of keeping that digital consumer interaction, and the payment moments that will be part of that, secure – what does the threat landscape look like?

Because hospitality businesses already hold a host of personal and financial information on their guests, they are being targeted by financially motivated criminals going after payment and personal data.  Studies have found that the hospitality industry has the second-highest number of cybersecurity breaches after retail. The most common initial attack vectors of data breaches as:

• Stolen or compromised credentials

• Phishing, such as obtaining credentials and critical information via disguised emails

• Cloud misconfiguration, such as overly permissive access, lack of control of inbound/outbound traffic, not securing ‘secrets’ (encryption keys, passwords etc.).

• Vulnerabilities in third party software.

• Hospitality businesses are already a target for cybercriminals.  With digital reinvention to deliver delightful customer experiences – and the expanded attack surface and more data – they are becoming even more attractive and vulnerable.

Mobile threat landscape

Despite the clear importance of mobile apps to business - look at Starbucks, McDonalds, Uber as examples - analysis has found that many merchant businesses fall dangerously short in mobile app security and privacy.

A recent analysis of more than 400 Android and iOS mobile apps by the NowSecure MobileRiskTracker found 99% have security risks and 61% have privacy risks.

Common security risks

  • Insecure network communication
  • Personal data leakage
  • Insecure data storage
  • Attackers able to take over the mobile app

 

 

Privacy risks

  • App exposes personal data
  • Insufficient protection of sensitive data
  • Personal data leakage over the network

 

Those security risks uncovered in the assessment should be of significant concern: personal data is being exposed or leaked and hence is ripe for misuse.  Examples of insecure mobile apps include:

• A brewery/pub chain’s mobile app that leaked personal data, including birthdates, addresses, purchases and number of shares owned, on 200,000 shareholders and customers for 18 months.

 A parking mobile app exposed personal data of 21 million customers, including phone numbers, car registration numbers, hashed passwords, and mailing addresses

With the consumer mobile device being key to the customer experience and hotel mobile apps evolving into “super apps” offering many services and functions including room key, navigation, payment methods, in-hotel event bookings, reservations and more, hackers are likely to see the digital reinvention and increasing reliance on mobile as an opportunity ripe for exploitation.

Implications of a breach

If the worst was to happen to your business – a breach of your customers’ data - what are the implications? According to the IBM Cost of a Data Breach report: in 2022, the average cost of a hospitality sector data breach was $2.9m. Those costs include notification; post-breach response; detection and escalation; lost business cost. Consider the lost revenue and lost opportunity costs too. According to a survey of more than 10,000 consumers worldwide conducted on behalf of Gemalto, 70% of consumers say they are unlikely to do business with a company if it experienced a data breach.

What does ‘secure and compliant’ mean?

In the context of this article it means:

• Payment card data security – PCI DSS compliance - minimising your attack surface, managing and reducing vulnerabilities, reducing the potential for exposure of card data and for breaches or misuse.

• Supporting EU regulatory compliance for Strong Customer Authentication (SCA) – for all face-to-face and online transactions (including those taken by an intermediary)

• Fulfilling your legal obligations to protect personal data under GDPR, UK Data Protection Act etc. - minimising risks to personal data through appropriate operational and technical safeguards.

Your business needs to fulfil your security and data protection obligations while focusing on the customer experience.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief