Auditing Archives: The Case of the Overly Helpful Front Desk Clerk

Front desk clerks are friendly…sometimes to a fault, but friendly doesn’t necessarily equal secure.

Updated:  
December 7, 2022
Cybersecurity
Auditing Archives: The Case of the Overly Helpful Front Desk Clerk
Quick Answer:

Why is it risky for hotel front desk computers to handle both payments and general internet use?

Allowing guests to browse the internet or print boarding passes on the same computer used for payment processing creates risk because any malware or malicious link downloaded on that device can compromise future credit card transactions run on it.

- This is a widespread, common failure; the auditor notes seeing this issue "in virtually every hotel" audited.
- The underlying problem is a lack of network segmentation between POS/property management systems and general internet-connected devices.
- Segmenting payment-processing computers from general guest or staff internet use closes this exposure entirely.
- This is one of several recurring, low-tech failures SecurityMetrics auditors commonly find during PCI assessments.

Quick Answer: Why Shouldn't POS Systems Have General Internet Access


POS and property management systems should never allow general internet browsing, since malware from a shared computer can compromise every future card transaction it processes.

  • This SecurityMetrics case found hotel front desk clerks routinely using POS computers for guest tasks like printing boarding passes.
  • The core issue is lack of network segmentation between POS/property management systems and general internet-connected devices.
  • A single malware infection on a shared POS machine puts all future card transactions at risk.
  • Segmenting POS systems from other network activity is essential to reducing this exposure.

Just because you can get on the Internet, doesn’t mean you should.

The following post is a segment in the Auditing Archives series. Hopefully the security failures I’ve seen while auditing businesses will help inspire better practices to ensure your own business security.

Front desk clerks are friendly…sometimes to a fault, but friendly doesn’t necessarily equal secure. A front desk clerk that helps you print off your afternoon boarding pass on the same computer that was just used to run your credit card violates a serious security protocol. Unfortunately, the problem is pervasive. I’ve seen this issue in virtually every hotel I’ve ever stayed at.

Because point of sale (POS) and property management system components are not segmented from other systems with access to the Internet, any accidental malware download, malicious website, bad link, or virus downloaded to that front desk computer could result a compromise that will risk every future credit card transaction.

See also: SecurityMetrics PCI Guide

View the Slideshare below.

Auditing Archives: The Case of the Overly Helpful Front Desk Clerk from SecurityMetrics