Well, what is the answer then?

It can be as simple as changing the way you view things: cybersecurity shouldn't be seen as just the job of IT, it should be everyone's responsibility.

The first thing is awareness. Any internet-enabled device should be secured. Make it a habit to change default passwords, keep software up-to-date, and don't fall into the trap of thinking "out of the box" means secure. Be honest with yourself about what each device really does, what it stores, and more importantly, if it really needs to be connected.

When it comes to hotels, the need for higher standards is obvious as the danger is multiplied. It is a matter of duty of care rather than convenience.

Executive teams should manage digital aspects at the same level as physical safety. Where fire systems are regularly checked and tested, cybersecurity systems should also be subject to regular independent and thorough audits. There has to be a clean separation between guest and internal networks. Data access should be strictly controlled, continuously monitored, and fully documented. Besides technical training, the staff should be made aware operationally that a single slip can lead to a catastrophic situation and legal consequences.

Hotels should hold vendors and technology providers to the same level of scrutiny. No system can simply be integrated into a hotel environment without going through proper diligence, contractual safeguards and clear determination of responsibility in the event of failure or breach.

And above all, there is no good cybersecurity without a plan. It needs to be a live, exercised incident response plan rather than a piece of paper forgotten in some drawer. Because the real determinant of an event turning into a minor problem or full-blown negative publicity will be the speed and clarity of the response.

The UAE has a tough law and rightly so. But counting solely on the law is to be reactionary. Protection at the deepest level is obtained through forecasting, arranging, and unflagging execution.

After all, guests are unlikely to inquire about how sophisticated your systems are. Their only question will be: "Can I trust you?"


Mohamed Darwish Founder, Darwish Legal Consultants – UAE Hospitality Lawyer.

Founder of the Legal Lobby Podcast and the author of two books " The Art of Mediation: The Key to Resolving Disputes in the Hospitality Industry" and "AI for Lawyers: A Practical Guide," both are available on Amazon.com