Secure360

NIS2 is live. Here is what it changes for your hotel.

NIS2 makes hotel leadership personally liable for security. What the directive demands, the four obligations, and how to make your hotel audit-ready.

service-6

Chapter 01

Not another GDPR. Something bigger.

NIS2 is the EU directive that raises the bar for the security of network and information systems. It builds on the original NIS directive with a wider scope and stricter requirements. Where GDPR asks how you protect personal data, NIS2 asks whether you can keep running when your systems are attacked.

For hotels, that shift matters. GDPR sits mostly with legal and marketing. NIS2 sits with operations, IT and the board. It moves security from a document exercise to an operating discipline. The questions change with it. Not whether the privacy statement is current, but who notices an attack at 2am, and whether the front desk can keep checking guests in while it is contained. Under NIS2 a hotel measures its security in operational terms, not in paperwork.

Think about what your hotel actually runs on. The PMS, the booking engine, the payment terminals, the door locks, the wifi, the phone system. Every one of them is a network and information system in the directive’s sense. GDPR asked what happens if guest data leaks. NIS2 asks what happens when those systems stop, and whether you can bring them back in a controlled way. For a business that checks people in at every hour of the day, that is an operational question before it is a legal one.

The two directives, side by side

GDPR

Focus on privacy and personal data. Applies to how you process guest information. Breach notification to the privacy regulator. Largely a legal and administrative discipline.

NIS2

Covers security, resilience and continuity. Applies to systems, networks and suppliers. Incident reporting within 24 and 72 hours. A board level duty with personal liability.

Two directives. Two very different conversations. If your board has only had the GDPR conversation, NIS2 is a bigger step than most hotels realise. The good news is that the conversation is concrete. The directive does not ask for abstract maturity. It asks for measures you can point at: who monitors, who responds, who reports, who is accountable. Boards can work with that.

Chapter 02

Must you comply? That is the wrong question.

NIS2 applies to essential and important entities in sectors such as energy, transport, banking, health, digital infrastructure, public administration, food and manufacturing, generally from 50 employees or €10 million in turnover. Hotels are usually not directly named. But the formal scope is only half the story. The honest starting point is not a legal analysis. It is a simpler question: would your hotel keep running through the kind of incident NIS2 is designed to prevent? For most properties the answer today is a guess, because it has never been tested.

Ransomware does not check whether you are in scope. The NIS2 measures are simply what good security looks like today.

Tested backups, monitored endpoints, controlled access, a rehearsed incident response. Meeting the standard voluntarily means shorter downtime, fewer surprises and lower breach cost. The alternative is discovering all of it during an actual incident, which is significantly more expensive. Timing is the other factor. An incident does not wait for a quiet Tuesday in low season. It tends to arrive on a sold-out event weekend, when the queue at the front desk is longest and every system is under load. The hotels that recover fastest decided how they would respond long before they had to.

There is also a practical benefit to acting before you are forced to. Hotels that build these measures on their own schedule can spread the work and the cost over a sensible roadmap. Hotels that wait until a client, an insurer or a regulator demands it end up doing the same work under deadline pressure, which is always the expensive version.

The supply chain angle

NIS2 makes organisations that do fall under the directive responsible for the security of their entire supply chain. Companies and governments are already assessing their suppliers on it, and that includes the hotels where they book rooms, meetings and events. A hotel hosting a corporate conference handles that client’s attendee lists, invoices and network traffic. That places the hotel inside the client’s NIS2 supply chain, whether the hotel itself is named in the directive or not. The pressure arrives through the sales funnel long before any regulator calls.

In scope or not, the question your next corporate client will ask is the same: can you demonstrate that your security is in order. Demonstrable security is becoming a condition for doing business, not a bonus. We already see it in tenders: the security questionnaire arrives before the rate discussion does. A hotel that can answer it well keeps the conversation about hospitality. A hotel that cannot spends the meeting on IT.

Chapter 03

Four NIS2 obligations every hotel board should know

NIS2 is concrete. The obligations are specific enough to plan around. These four touch every hotel operation of any scale. Each one comes with an owner, a deadline and a form of evidence attached. That makes them useful even before the question of scope is settled, because they describe what a hotel board should be asking of its IT operation anyway. Read them as a working agenda, not as legal text.

Demonstrable security measures

Documented and demonstrable security measures across your entire environment: endpoint protection, email security, backup, access control, encryption and continuity planning. Not a policy document in a drawer, but measures that work and can be shown to work. The word demonstrable is doing the real work in that sentence. An auditor, a client or a regulator will not ask whether you feel secure. They will ask for the evidence, and the evidence has to exist before the question arrives.

Incident reporting within 24 and 72 hours

An early warning to the authorities within 24 hours of a significant incident, a full notification within 72 hours and a final report afterwards. That is only possible if you detect incidents fast and know exactly what happened. It requires monitoring, logging and an incident response plan that has been rehearsed rather than filed. For a hotel this is the hardest obligation to improvise. If the first hours of an incident are spent working out what is actually happening, the clock has already run.

Supply chain accountability

Your responsibility does not stop at your own firewall. PMS vendors, booking platforms, payment providers and IT partners are part of your risk. NIS2 expects you to assess and manage the security of your suppliers. The days of “our vendor handles that” have quietly ended. For a hotel the supplier list is long: the channel manager, the guest wifi provider, the door lock platform, the payment terminals. Each connection into your network is a possible route in. The directive expects you to know which supplier holds which access, and to review it on a schedule rather than on trust.

Board level responsibility

Management must approve the security measures, oversee their implementation and follow training to understand the risks. Non compliance can mean fines up to €10 million or 2% of worldwide turnover, and personal liability for directors. The board is now in the security architecture, whether it wants to be or not. In practice that means security reporting the board can actually read, and decisions the board can defend afterwards.

Chapter 04

Compliance is not a product. It is an operating model.

NIS2 cannot be bought off the shelf. It has to be built into how you run. Every Sbit service carries part of the load, so together they turn compliance into a byproduct of a well run operation. That matters, because the alternative is a shelf of point solutions that each cover a fragment of the directive and leave the gaps, and the accountability, to you.

Secure360

Our integrated security layer: endpoint protection, email security, backup, 24/7 SOC monitoring, awareness training, an annual penetration test and NIS2 ready compliance reporting. It covers the demonstrable measures NIS2 asks for, as one service. The evidence builds up as the service runs, so being audit-ready is a state your hotel maintains, not a scramble before a questionnaire.

Managed IT Support

Deadlines of 24 and 72 hours only work if someone is watching at 3am. Managed IT Support delivers continuous monitoring, incident response and the logging you need to report accurately and on time.

Managed Infrastructure

Network segmentation, hardened servers and cloud managed as one foundation. Managed Infrastructure limits the blast radius of an incident and keeps guest systems separated from back office and suppliers.

Managed Workplace

Most incidents start with a user. Managed Workplace manages identities, devices and access as one, so joiners, leavers and permissions never become the weak spot in your audit.

IT Strategy & Project Services

NIS2 makes the board responsible, so the board needs grip. IT Strategy translates the directive into a roadmap, supplier assessments and reporting your management can actually steer on.

Co-Managed IT

Running your own IT team? Co-Managed IT adds the security depth, tooling and 24/7 coverage NIS2 expects, without taking away control from your people.

The pattern across all six is the same. The measures NIS2 asks for are not extras bolted onto the operation. They are properties of a well run environment, delivered continuously, with the evidence produced as a side effect. That is the difference between buying compliance and running it.

Chapter 05

NIS2 compliance is the floor. Resilience is the goal.

Cyber resilience is not a one time project. It is a strategic alignment of technology, processes and people, reviewed and improved continuously. Hotels that treat NIS2 as a checkbox will keep chasing it. Hotels that build security into their operating model will not need to.

Start where the risk is. Get the basics demonstrably in order: backups that restore, endpoints that are watched, access that is controlled, an incident plan that has been walked through at least once. Then work up towards the fuller picture the directive describes, supplier by supplier and system by system. None of this has to happen in one quarter. All of it needs an owner and a date.

Hotels that build security into their operating model stop chasing compliance. Compliance starts following them.

And keep the goal in view. The point of the exercise was never the paperwork. It is a hotel that keeps checking guests in while others are handling an incident, and a board that knows exactly how it would respond if the incident were theirs.

The regulatory pressure is doing us a favour. It is forcing conversations that should have happened five years ago, and giving IT directors the mandate they have been asking for. The work is the same either way. Under NIS2, the timing is no longer optional.

NIS2 is not a compliance project. It is a personal liability.


Sandro Migliardi

CEO · Sbit Hospitality ICT Services

Let's talk

Ready to build NIS2 into your operation?

Book a conversation. We map your current environment against the four obligations, show you where the gaps are, and translate the directive into a roadmap your board can steer on.