Tech Talk

Recent posts

With the news cycle laser-focused on the looming threat of a COVID-19 second wave happening in nearly every territory, it is up to each and every hotel to ensure we are all fully compliant with virus safety guidelines in order to restore group booking confidence. And the only way to ensure compliance with these safety guidelines is through contactless and compliance technologies to give guests a strong guarantee of proper sanitization as well as peace of mind.

A great deal has been written over the years about the viability of moving a hotel’s property-management system (PMS) to the cloud to take advantage of the latest technologies, but hoteliers need to realize that it’s not the only viable option. All platforms have advantages, including self-hosted, private cloud and on-premise solutions that leverage the latest mobile, contact free and web-based technologies. Independent operators can still enhance the digital guest experience, support personalized and mobile check-in, deploy contact free technologies, and secure hotel/guest data even if their PMS does not reside in the cloud. It should not be a question of “Cloud or On Premise?” but rather “Does the PMS solve your business objectives in both technology and service?”

Much has been written in the mainstream hospitality press about the challenges COVID-19 has presented to the industry. Hotels are in more pain than at any time in our memories. Because of the extensive media coverage, I won’t dwell on this topic further in what is primarily a technology column. But it’s the background for this week’s column, and so merits acknowledgement.

Are You All In?
Posted: 07/27/2020

Imagine everyone in your organization engaged, aligned, and performing to their potential. Imagine everyone playing “All In.”

Great organizations have synergy. Their culture allows them to play to a rhythm at a different tempo than the average organization. How do you get that at your organization?

Many front-line hospitality workers rely on tips for a significant part of their paychecks. If not for tips, many hotel associates who serve as waitstaff, bartenders, housekeepers, bell staff, concierges and pool attendants would soon be looking for other jobs. This is a regional issue: in most of Asia and Europe, staff get higher base pay, and tips are either not expected at all, or are truly discretionary. But in the U.S., Canada, Britain and other countries, tips are an important reality, and one that’s not likely to change anytime soon.

want to read more articles like this?

want to read more articles like this?

Sign up to receive our twice-a-month Watercooler and Siegel Sez Newsletters and never miss another article or news story.


The Equifax Breach: Takeaways for Hospitality Companies

by Mary Guzman

No single company buys enough insurance limits to have such a major impact that the prices go up or capacity falls away immediately following an event. A systemic loss, like one that impacts the power grid or halts the financial sector from trading for a few days, would be an entirely different (and scary) story. But this breach is still stacking up to be different from other recent mega breaches, and should serve as a wakeup call to those organizations that still think this isn’t going to happen to them, or that this is an IT risk and therefore not an issue for us non-IT folks to worry about. McGriff recently published a white paper about the specifics of the insurance response and the importance of preparation, business continuity planning.
This could lead to a new path for plaintiffs to the directors and officers (D&O) insurance. More than 90 law suits were filed in the first two weeks (some of them for the stock drop, but most of them for privacy-related damages and expenses which would include negligence, breach of contract, etc.). Until now, there have been cases against companies and their directors and officers brought by shareholders following a breach (tag-along suits) but none of them has prevailed (as far as I’m aware) given that the business judgement rule has generally provided a solid defense. In this case, it may appear that the directors and officers did not do what prudent people in their position would do, given the kind of information they hold, and the fact that senior management was allowed to sell shares of company stock after the breach was discovered internally but before it was made public. Time will tell, but we could be looking at a limits loss on the E&O/information security insurance tower and on the D&O tower. D&O underwriters have already started to ask more and tougher questions of their buyers around their risk management and readiness to handle the backlash of a major breach. 
This loss, coupled with recent natural catastrophes affecting the overall reinsurance market (insurance behind the insurers) may force a move back toward more rigorous underwriting. In the past two years, the insurance markets that write the E&O/cyber for companies like Equifax have become increasingly lax regarding the security/underwriting requirements they place on these companies due to competitive market pressure brought on by increased capacity (more capacity/supply = lower cost and better coverage). For hoteliers this means underwriting beyond a questionnaire about IT security and business continuity plans (more than just –do you have one?) and looking past “compliance” around the acceptance of credit cards. Another thing that most certainly will change is how much scrutiny there is on third-party service providers that hold, process or aggregate data and/or provide critical services, such as cloud providers or other third parties that handle reservations on your behalf. What kind of coverage is in your policy now for a breach caused by such third parties (on the liability side and on the first party side), and what do your contracts with those vendors say? Absent the insurance, vendors should be accountable for your costs that result from a breach, but generally they do not fully accept that risk, which is a major issue (and one that could be the subject of an article on its own).
Something else to consider: does your company want to manage the customer message and control the response if there is a major issue, or do you want to lay that off to the at-fault third party? Hint: you may want to handle the response internally, hire the forensics, legal and PR help you need, and then worry about subrogation/expense recovery later because your vendors are never going to care as much about your brand as you do. Whatever you decide is right for your company, make sure both your vendor contracts and your insurance track with that decision. Do you have your breach response providers vetted, under contract (retainer maybe?) and approved by the insurance carriers already? The whole issue surrounding who handles what following a breach becomes more complicated when you own, but do not manage your properties (or the other way around). Even more complex, if you have a franchise model where the franchisees are intended to be kept at arms’ length, yet the franchisor chooses to direct or control franchisee information security in order to better protect their brand. Even though each franchisee may have its own MSA with the card brands, there may be a very blurred line around who takes on what risk and responsibility unless it is explicitly agreed upon up front.
The insurance markets have become more willing to give control of the breach response to the insured in recent months, and they have more heavily relied on compliance with various information security standards such as PCI DSS as a means of underwriting. However, my suspicion is that markets will start to swing back the other way. Having a broker and outside privacy counsel that are specialists in this market is paramount to getting the best results for your company in what is sure to be a volatile several months.
About The Author
Mary Guzman
Director, E&O and InfoSec Strategy and Sales
McGriff, Seibels & Williams
Financial Services Division

Mary Guzman is the director, E&O and InfoSec Strategy and Sales with McGriff, Seibels & Williams – Financial Services Division. She was also a speaker at the 2017 CIO Summit where she discussed cybersecurity considerations. Mary can be reached at

Blog post currently doesn't have any comments.
Leave comment

 Security code