Tech Talk

Recent posts

We’re hardly out of the woods with COVID-19, and that means many properties will have to make do with a customer base mostly derived from local leisure, staycations and workcations from drive-to markets. With fewer overall guests, outside of cost savings efforts we must simultaneously look at maximizing the revenue per available guest (RevPAG), and there’s no better way to go about this than by sharpening your use of the PMS.

This is the last issue of Siegel Sez before this year’s CYBER HITEC event. HITEC is an event I have not missed in 30 years, and historically it has always been a great place to find innovation.

Toxicity Kills
Posted: 10/07/2020

It doesn’t matter if it is toxins in your physical environment or toxins in your mental environment. This stuff kills! 

It’s said that when someone’s mindset shifts, everything around them can change at the same time, and in our current setting, the importance of being in the right headspace, both personally and as an organization, can’t be discussed enough.

In my last installment, I introduced four areas of hospitality technology that I believe have been significantly changed by COVID-19. I covered contactless technologies in depth in that first article. This week I will turn to the other three areas: social distancing; health and sanitation; and communications.

want to read more articles like this?

want to read more articles like this?

Sign up to receive our twice-a-month Watercooler and Siegel Sez Newsletters and never miss another article or news story.


PCI-DSS Introduces QIR Requirements; Shadow Brokers, IHG and a Rise in Healthcare Breaches

by David Durko

In the latest version of the PCI-DSS the Council officially introduced the QIR (qualified integrators and resellers) requirements. Although they have been communicating the requirements and publishing the list of validated companies we haven’t read or heard much more about it… until now!

Many hotels have received communications in the last two months from the card brands (ironically from Discover) enforcing the use of qualified integration companies.

So what does this mean?

If you plan to upgrade or change any payment application you must use a vendor that is currently on The PCI Council’s list of validated Qualified Integrators and Resellers. These companies have gone through the Councils Certification process and have proven themselves to understand how to implement payment solutions in a complaint manner. The point is the card brands want to avoid the days of installing systems and leaving the default credentials in place (MICROS/MICROS or SA/SA, for example).

The upside for the merchant is that there is accountability, should something go awry with the install and leads to or facilitates a compromise. The downside is an increase in costs. QIR registration is not cheap and the integrators will most likely pass the added expense along to their clients.

QSAs will now be obligated to validate that payment applications were installed by a QIR. This requirement is in effect and will most likely impact your 2018 compliance activities.

This week we saw the effect of stolen hacking tools exposed by the Shadow Brokers, InterContinental Hotels Group (IHG) released the actual number of hotels breached from 2016; Healthcare breaches jumped in March 2017, compared to January/February 2017.

Shadow Brokers, a hacking group that have a record of publishing hacking tools believed to be used by the NSA, released a trove of vulnerabilities, new tools and exploits from The Equation Group. Exploit components included ETERNALBLUE and DOUBLEPULSAR which are already found to be used in the wild by script kiddies.

It is suspected that Microsoft had a heads up prior to this release and held back on February’s Patch Tuesday to address this latest trove of exploits released. However, unpatched systems remain a serious threat to organizations, as well as unsupported versions such as Windows XP and Server 2003 that continue to remain exploitable.

The domino effect and the severity of these tools going public, intensifies and makes it possible for script kiddies to pawn thousands of computers using one of the exposed exploitable vulnerabilities such as the SMB networking one.

IHG Breach Greater than Originally Reported

At the end of 2016, news broke that a credit card breach involving IHG hotels had occurred. In February, IHG acknowledged a breach occurred between August and December 2016 and initially thought the impact was limited to about a dozen hotels. In April 2017, the number of hotels affected by the breach was updated to nearly 1,200.

Attackers are targeting the hospitality industry due to lack of security measures, making it possible to infiltrate terminal's remote access software with multiple entry points such as front desk, gift shop, bar and restaurants.

Read the full story in Krebs on Security.

Healthcare Breaches

Healthcare breaches in March 2017, jumped 155 percent compared to healthcare breaches in January/February 2017.

The largest incident reported; 697,800 patient records affecting Commonwealth Health Corporation in Kentucky on March 1, 2017. Of the incidents reported, 28 percent were the result of hacking which affected 600,279 patient records.

Healthcare breaches will continue if budgets are cut, legislation is pushed, and there is an underestimated penalty for healthcare data breaches.

About The Author
David Durko
Security Validation

David Durko is the CEO of Security Validation a leading managed data security and privacy firm servicing the hospitality industry.

Blog post currently doesn't have any comments.
Leave comment

 Security code