Small Hotels, Big Consequences: Why Hospitality Cybersecurity Is a National Security Issue

New research examines how cyber risks in small hotels can extend beyond individual businesses to economic resilience, government operations, and national defense.

Cybersecurity discussions often focus on large corporations, critical infrastructure, government agencies, and major technology companies. Yet some of the most consequential vulnerabilities may exist in organizations that receive far less attention.

Small hotels are one example.

In our recently published article in the European Journal of Applied Sciences, Dr. Swati Sharma and I examine how cybersecurity weaknesses within small hotels can create consequences extending well beyond the hospitality industry.

Small hotels may have limited cybersecurity resources, but they operate increasingly complex digital environments. They collect and process guest information, payment data, reservation records, employee information, and other sensitive data. At the same time, many depend on interconnected property-management platforms, wireless networks, cloud services, third-party vendors, and increasingly automated building and operational technologies.

This creates an important cybersecurity paradox: an organization does not have to be large to create significant cyber risk.

The Small-Business Cybersecurity Problem

Large organizations generally have dedicated cybersecurity personnel, formal governance structures, monitoring capabilities, incident-response processes, and significant technology budgets.

Small hotels often operate differently.

Technology may be managed by a small internal staff, an outside provider, or employees whose primary responsibilities are not cybersecurity. Older systems may remain operational because replacing them is expensive. Vendor relationships can introduce additional dependencies, while cybersecurity training and formal risk-management practices may receive less attention than immediate operational requirements.

Yet attackers do not evaluate organizations according to the size of their cybersecurity departments. They look for opportunity.

An organization that combines valuable information, interconnected technology, continuous operations, and relatively limited defensive resources can present an attractive target.

The Consequences Extend Beyond the Hotel

A cyberattack against a hotel is easy to view as an isolated business problem: reservations are disrupted, payment systems stop working, customer information is compromised, and the hotel suffers financial and reputational damage.

But that perspective may be too narrow.

Hotels are part of larger economic and operational ecosystems. They support tourism, local businesses, conferences, emergency response activities, government travel, contractors, and regional employment.

Disruption therefore can propagate beyond the organization initially attacked.

That observation leads to one of the central arguments of our research: cybersecurity risk should sometimes be evaluated according to an organization's position within a larger system, rather than simply according to the organization's size.

The National Defense Connection

There is another dimension that deserves greater attention.

Hotels regularly accommodate military personnel, government employees, defense contractors, and others traveling in support of government missions. Information associated with those travelers—particularly when combined with other information—can potentially reveal patterns involving identities, locations, organizations, schedules, or activities.

The concern is therefore broader than protecting credit-card numbers or reservation systems.

Modern cybersecurity increasingly involves understanding relationships between seemingly ordinary commercial systems and larger governmental, economic, and national-security environments.

A small business can occupy a strategically important position without realizing it.

Cybersecurity Is an Ecosystem Problem

This is part of a larger transformation occurring in cybersecurity.

Organizations once concentrated heavily on protecting their own networks and systems. Today, cloud computing, software platforms, mobile devices, interconnected operational technology, digital identity, and third-party services have made organizational boundaries increasingly difficult to define.

Security consequently depends upon ecosystems.

A vulnerability in one organization can become an entry point, intelligence source, operational disruption, or risk multiplier somewhere else.

That principle applies well beyond hotels. Small healthcare providers, manufacturers, logistics companies, professional services firms, educational institutions, and government contractors can occupy similarly important positions within interconnected systems.

Looking Beyond the Immediate Target

One lesson from the research is straightforward:

Cybersecurity significance should not be measured solely by organizational size.

Small organizations can hold valuable information. They can operate important technologies. They can support critical customers. And they can participate in economic and governmental systems whose importance greatly exceeds the apparent significance of any individual organization.

Strengthening cybersecurity in these environments therefore requires more than purchasing another security product. It requires improved governance, employee awareness, vendor management, technology management, incident preparedness, and a better understanding of how individual organizations fit into broader digital ecosystems.

That is the longer view of cybersecurity risk.

The question is no longer simply, What happens if this organization is attacked?

Increasingly, leaders must also ask:

What else depends upon this organization—and what could happen next?

About the Research

This article draws upon research published by Dr. Swati Sharma and Dr. Timothy Godlove in the European Journal of Applied Sciences, Volume 14, Number 4 (2026).

Sharma, S., & Godlove, T. (2026). Small Hotels, Big Consequences: How Cyberattacks Undermine Economic and Defense Systems. European Journal of Applied Sciences, 14(4).

Read the full published article:

Based on peer-reviewed research.

Next
Next

The Long View Revisited: What My 2015 Research on Patient Matching Still Teaches Us Identity, Consent, and Trust in an Era of Interconnected Health Data