Three breaches at Marriott and its Starwood subsidiary between 2014 and 2020 affected more than 344 million customers worldwide, according to the Federal Trade Commission, and the order the FTC issued on 20 December 2024 now requires the company to run internal and external penetration testing, segmentation testing and web application penetration testing at least once a year. One of those intrusions sat inside a Starwood guest reservation database from about July 2014 until September 2018. Hotels hold payment cards, passport numbers, loyalty balances and stay histories, spread across properties, franchisees, management companies and vendors, and the orders that followed the industry's largest breaches now require Marriott and Wyndham to prove that the networks between them are separated and tested.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Every human-led engagement is staffed by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, backed by 18 published CVEs and bug bounty Hall of Fame listings at PaySafe, the US Federal Reserve, Apple, Google and the US Department of Defense. For a hotel group that means PCI DSS 11.4 internal and external tests of the cardholder data environment, segmentation tests that start from guest Wi-Fi, conference and back-of-house networks, the booking engine and loyalty platform tested authenticated across guest, member, front desk and franchise roles, Active Directory and vendor access paths, and vishing aimed at the help desk and front desk. It is delivered as a one-time annual engagement or a continuous program through the PTaaS portal, with retesting and an attestation letter included on human-led and hybrid engagements. Published pricing is US$3,000 (Autonomous) and US$6,800 (Hybrid) per one-time assessment of one web application and its APIs, or US$650 and US$1,275 a month on 12-month continuous plans (pricing); property and portfolio scopes are quoted.
This guide is written for hotel owners, management companies, franchisors, resort operators and the hospitality technology vendors that serve them in the United States and Canada. Every rule is quoted from its own text or its regulator's announcement, and every vendor entry links to a page on the vendor's own site, all checked on 1 October 2026. Casino floors, cages and gaming systems are covered separately in our iGaming and casino ranking.
Quick answer: who are the best penetration testing companies for hotels and hospitality in 2026?
The best penetration testing companies for hotels and hospitality in 2026 are Stingrai, Coalfire, NetSPI, LevelBlue, DirectDefense, ioSENTRIX, VikingCloud, SecurityMetrics, GuidePoint Security, Kroll, Rapid7 and Withum. Stingrai ranks first for named, certified penetration testers across the cardholder data environment, guest Wi-Fi segmentation, booking and loyalty platforms and the help desk, with retesting and an attestation letter included, one-time or continuous. Coalfire, NetSPI and LevelBlue follow for a published resort red team that reached the reservation and loyalty systems, network and application testing for Carlson Companies, whose brands included Radisson Hotels, and a hospitality practice backed by its own threat research.

What hotels are actually required to test
PCI DSS is the one rule in this section that applies to every hotel that takes cards, and it names penetration testing outright. The orders against Marriott, Wyndham and Hilton bind those companies only, but they show what regulators required after hotel breaches. Canadian privacy law names no test at all.
PCI DSS v4.0.1 requirement 11.4
Requirement 11.4 of PCI DSS v4.0.1, the version the PCI Security Standards Council published in June 2024, reads: "External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected." Its sub-requirements set the scope and the cadence:
11.4.1, methodology. "Coverage for the entire CDE perimeter and critical systems," testing from inside and outside the network, "Testing to validate any segmentation and scope-reduction controls," application-layer testing for at least the vulnerabilities in requirement 6.2.4, network-layer testing, a review of threats and vulnerabilities experienced in the last 12 months, and retention of results for at least 12 months.
11.4.2 and 11.4.3, internal and external tests. "At least once every 12 months" and "After any significant infrastructure or application upgrade or change," by a qualified internal resource or qualified external third party, with "Organizational independence of the tester" (the tester is not required to be a QSA or ASV).
11.4.4, remediation. Exploitable vulnerabilities are corrected according to the entity's risk ranking under 6.3.1, and "Penetration testing is repeated to verify the corrections."
11.4.5, segmentation. Where segmentation isolates the cardholder data environment (CDE), tests run "At least once every 12 months and after any changes to segmentation controls/methods," "Covering all segmentation controls/methods in use," and confirm the controls "isolate the CDE from all out-of-scope systems."
11.4.6, service providers. The same segmentation tests "At least once every six months."
11.4.7, multi-tenant service providers. Shared hosting and cloud providers must support their customers' external penetration testing.
How much of 11.4 a hotel validates depends on how it reports. A Report on Compliance and SAQ D cover the whole requirement; in the PCI SSC's v4.0.1 self-assessment questionnaires, SAQ B-IP and SAQ C include only the 11.4.5 segmentation test, SAQ A, SAQ B and SAQ P2PE include none of 11.4, and SAQ A-EP includes the external test (11.4.3) and the segmentation test (11.4.5) but not the internal test (11.4.2).
The standard defines internal testing as testing "from both inside the CDE and into the CDE from trusted and untrusted internal networks." In a hotel the untrusted internal networks are the guest Wi-Fi, the conference and event networks, and the segments that carry locks, thermostats and televisions. Requirement 1.3.3 puts network security controls "between all wireless networks and the CDE, regardless of whether the wireless network is a CDE," with wireless traffic into the CDE denied by default, and 11.2.1 requires a search for authorized and unauthorized wireless access points at least once every three months. The guidance under 11.4.1 is blunt: "Scanning for vulnerabilities alone is not a penetration test." Booking engines that serve a payment page also answer to 6.4.3, which requires an inventory and integrity check of every payment page script, and 11.6.1, which requires change- and tamper-detection on payment pages. Our PCI DSS penetration testing guide walks through the whole requirement.
What counts as a significant change at a hotel
PCI DSS does not define a significant change for any one environment. It lists activities that "must be considered and evaluated to determine whether a change is a significant change," including new hardware, software or networking equipment added to the CDE, "Any replacement or major upgrades of hardware and/or software in the CDE," changes in the flow or storage of account data, changes to the CDE boundary, and "Any changes to third-party vendors/service providers (or services provided) that support the CDE." At a hotel those are ordinary projects: a property management system migration, a new point-of-sale platform in the restaurants and bars, a new payment gateway or tokenization provider, a rebuilt booking engine, or a new managed network vendor. Each should be evaluated against 11.4.2 and 11.4.3 before it goes live, and requirement 12.5.2 has the entity confirm its PCI DSS scope at least once every 12 months and upon significant change.
Brands, management companies and franchisees
Many hotels in North America fly a brand they do not own, which splits the card environment between parties. PCI DSS defines a service provider as a "Business entity that is not a payment brand, directly involved in the processing, storage, or transmission of cardholder data (CHD) and/or sensitive authentication data (SAD) on behalf of another entity," including companies "that provide services that control or could impact the security" of that data. A brand or management company that runs a central reservation or payment platform for other properties can meet that definition, and a service provider that relies on segmentation must test it at least every six months under 11.4.6 rather than every 12. Requirement 12.8.1 has every entity keep a list of the third-party service providers that could affect the security of its account data. Confirm the classification with your QSA.
The FTC's Marriott order
On 9 October 2024 the FTC announced a proposed settlement with Marriott International and Starwood Hotels & Resorts Worldwide over three breaches from 2014 to 2020, and on 20 December 2024 it issued the final Decision and Order, Docket No. C-4807. In the FTC's announcement, the complaint alleged the companies failed to "implement appropriate password controls, access controls, firewall controls, or network segmentation," to patch outdated software and systems, to adequately log and monitor their networks, and to deploy adequate multifactor authentication.
Provision II.H of the order is as specific about testing as any rule in this guide. Marriott must run "a risk-based testing program" that "shall include an appropriate schedule of risk-based tests including internal and external penetration testing, segmentation testing, and web application penetration testing," and "Such testing shall not be less than annual, and promptly (not to exceed 120 days) after a Covered Incident, and shall include retests where necessary to confirm appropriate remediation." The same provision requires internal and external network vulnerability scans "at least quarterly or after any significant change." Provision II.E.5 requires multi-factor authentication for remote access by employees and vendors and an MFA option for US consumer accounts, Provision II.K requires franchised hotels by contract to keep appropriate safeguards and Marriott to run "a risk-based audit program" to check them, Provision III requires initial and biennial assessments by an independent third-party assessor for 20 years, and Provision VII requires Marriott to review a consumer's loyalty account on request and restore points lost to unauthorized activity.
The order binds Marriott and Starwood, and its definition of Marriott excludes franchised hotels and subsidiaries incorporated and operating outside the United States. Nothing in it applies to another hotel company. It is still the clearest statement of what a US regulator expected a hotel company's testing program to contain after a breach.
The states' Marriott judgments
On 9 October 2024, the day the FTC announced its proposed settlement, Marriott agreed to pay US$52 million to the attorneys general of 49 states and the District of Columbia. The New York final judgment, effective 8 November 2024, repeats the testing program at paragraph 70(b): "internal and external penetration testing, segmentation testing, and web application penetration testing" that "shall not be less than annual and shall include retests where necessary to confirm appropriate remediation." Paragraph 92 requires Marriott to offer consumers multi-factor authentication or an equivalent enhanced measure for any Marriott account, including a loyalty account. Paragraph 52 requires franchised hotels to notify Marriott within 24 hours of a compromise of their systems that compromises Marriott's, and paragraph 26 describes the incidents Marriott announced in March and June 2020, in which "a person or persons used the login credentials of certain Marriott franchise property employees" to reach about 5.5 million guest records.
Earlier orders: Wyndham and Hilton
The FTC's stipulated order with Wyndham Hotels and Resorts, filed in federal court in New Jersey in December 2015 after three breaches that the FTC said exposed the payment card information of hundreds of thousands of consumers, requires an annual written assessment of compliance with PCI DSS for up to 20 years. The assessor must "certify individually, as to each Wyndham-branded Hotel, whether Hotels and Resorts treats as an untrusted network any Wyndham-branded Hotel's network that has a Cardholder Data Environment." The order never uses the words penetration test. It makes the boundary between the brand and every branded hotel a certified control. In October 2017 Hilton agreed to pay US$700,000 to New York and Vermont after two 2015 breaches exposed more than 350,000 credit card numbers, and the Attorney General's announcement says the settlement requires a security program with "regular testing or monitoring of the safeguards' effectiveness" and an annual written assessment of PCI DSS compliance.
PIPEDA and the Privacy Commissioner's hotel findings
PIPEDA applies to personal information an organization "collects, uses or discloses in the course of commercial activities." Principle 4.7 requires "security safeguards appropriate to the sensitivity of the information," including technological measures, section 10.1 requires a report to the Privacy Commissioner of any breach of security safeguards that creates "a real risk of significant harm to an individual," and the Breach of Security Safeguards Regulations require a record of every breach for 24 months. None of it names penetration testing.
Two findings by the Office of the Privacy Commissioner show how the Act lands on hotel companies. In PIPEDA Findings #2022-005, published 15 July 2022, the OPC found Marriott's safeguards and accountability measures inadequate over the Starwood breach, which involved up to about 339 million records, "including up to 12.8 million records where the country-of-residence information was listed as Canada." It recorded that "penetration testing and vulnerability testing was regularly conducted on the Starwood network between 2014 and 2018," alongside PCI DSS Reports on Compliance from two independent assessors, and then named the gap: "these testing measures do not detect unauthorized activities being conducted by an attacker that has already penetrated the system or network." It added that PCI DSS compliance "is focused on cardholder data" and that organizations should "consider how they assess their compliance with handling personal information that is not cardholder data." In PIPEDA Findings #2022-004, the OPC found that MGM Resorts contravened PIPEDA's breach reporting provisions over a 2019 breach that MGM later confirmed affected 1,934,090 Canadians.
Resorts in British Columbia and Alberta also answer to provincial law. British Columbia's Personal Information Protection Act, section 34, requires "reasonable security arrangements," and Alberta's Personal Information Protection Act adds at section 34.1 a duty to notify its Commissioner "without unreasonable delay" of incidents where "a reasonable person would consider that there exists a real risk of significant harm to an individual."
Quebec Law 25
Quebec hotels answer to the Act respecting the protection of personal information in the private sector, as amended by Law 25. Section 10 requires security measures "reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Section 3.5 requires prompt notice to the Commission d'accès à l'information of a confidentiality incident that "presents a risk of serious injury," section 3.8 requires a register of confidentiality incidents, and section 3.3 requires a privacy impact assessment for "any project to acquire, develop or overhaul an information system or electronic service delivery system" that involves personal information, which covers a new PMS or booking engine. The Act does not mention penetration testing. Our Law 25 guide explains where testing fits.
Rule | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|
PCI DSS v4.0.1, 11.4.1 to 11.4.5 | Yes | At least every 12 months and after significant change; segmentation every 12 months and after changes | Internal and external tests, segmentation of every control in use, retests of fixes, an independent tester |
PCI DSS 11.4.6, service providers | Yes, segmentation | At least every six months and after changes | Segmentation tests for brands or companies assessed as service providers |
FTC Marriott order, Provision II.H | Yes | Not less than annual; within 120 days of a Covered Incident | Internal, external, segmentation and web application tests with retests (binds Marriott and Starwood) |
State Marriott judgments (New York, paragraph 70(b)) | Yes | Not less than annual | The same testing program and an MFA option for any consumer account, including loyalty (binds Marriott) |
FTC Wyndham order, Part II | No | Annual | PCI DSS assessment certifying, hotel by hotel, whether each branded hotel's card network is treated as untrusted (binds Wyndham) |
New York and Vermont Hilton settlement | No | Annual | PCI DSS assessment and regular testing or monitoring of safeguards (binds Hilton) |
PIPEDA and SOR/2018-64 | No | None | Safeguards proportionate to sensitivity; breach reports; 24 months of breach records |
BC and Alberta PIPA | No | None | Reasonable security arrangements; Alberta notice of a real risk of significant harm |
Quebec Law 25 | No | None | Reasonable measures, incident notice and register, a privacy impact assessment before a new system |
The hotel attack surface: what a good scope covers
Card data is one part of what a hotel holds. The Starwood database held passport numbers and stay preferences, and Canada's Privacy Commissioner noted that PCI DSS compliance is focused on cardholder data and told organizations to assess how they protect the personal information that is not.

Property management system. Oracle OPERA and its peers connect to point of sale, payments, keycard encoders, the channel manager and the brand's central systems. Test those interfaces and how far a property account reaches, and check patch levels: NVD lists CVE-2026-34311, published 28 May 2026 with a CVSS 3.1 base score of 9.8, which it describes as an "Easily exploitable vulnerability" that "allows unauthenticated attacker with network access via HTTP" to take over Oracle Hospitality OPERA 5 Property Services. A move to a cloud PMS is a change to evaluate under PCI DSS.
Point of sale and the cardholder data environment. Restaurant, bar, spa and retail outlets, payment interfaces and back-office servers, tested from inside the CDE and into it from every internal network under 11.4.1.
Booking engine, channel manager and partner APIs. Rate and reservation logic, object-level authorization on reservations and guest profiles, and payment page scripts under 6.4.3.
Loyalty accounts. Credential stuffing resistance, MFA enrollment and recovery, and the logic behind points transfers and redemptions. Both Marriott orders now require an MFA option for consumer accounts and a way to restore stolen points.
Guest Wi-Fi and segmentation. Every route from guest, conference and IoT networks toward the CDE, the PMS and corporate systems, tested against 1.3.3 and 11.4.5 at every distinct property build. The Wi-Fi testing guide covers the method.
Door locks, kiosks and room automation. In March 2024 researchers disclosed Unsaflok, flaws in dormakaba's Saflok RFID locks affecting "Over three million hotel locks in 131 countries" on more than 13,000 properties. As of March 2024 about 36 percent had been updated or replaced, and the fix requires reissued keycards, upgraded front desk software and card encoders, and sometimes upgrades to elevator, parking and payment integrations. Self check-in kiosks, keycard encoders and in-room tablets belong in scope.
Help desk, front desk and reservations staff. Vishing for password and MFA resets, and lures themed on guest complaints and bookings. In March 2025 Microsoft Threat Intelligence reported a campaign, tracked as Storm-1865 and first seen in December 2024, that impersonates Booking.com and "targets organizations in the hospitality industry," aimed at the staff "most likely to work with Booking.com." The social engineering testing guide covers the method.
Franchise, vendor and cloud access. Property accounts that reach brand systems, vendor remote support tools, Active Directory paths, and developer and cloud credentials. The OPC's MGM finding describes an attacker who logged into a third-party platform used by MGM's developers with an employee's credentials exposed in an unrelated breach, bypassed multi-factor authentication through a flaw in that platform, and then used an access token to reach guest data on an external cloud server.
What the Marriott, MGM, Caesars and Omni incidents show

The Starwood reservation breach ran for about four years, and the OPC's point about it is the one most hotel test plans miss: penetration and vulnerability tests look for gaps an attacker could use later, and they do not detect an attacker who is already inside. PCI DSS guidance under 11.4.1 says testing of security monitoring and detection methods "should also be considered," and an assumed-breach scenario or a purple team exercise is how a hotel group finds out whether its logging would have noticed.
The two resort-operator intrusions disclosed in September 2023 show both where these attacks start and what they cost. Caesars Entertainment told the SEC in a September 2023 Form 8-K that the intrusion resulted from "a social engineering attack on an outsourced IT support vendor," after which the attacker "acquired a copy of, among other data, our loyalty program database." MGM Resorts' Form 8-K of 5 October 2023 estimated a negative impact of "approximately $100 million" on its September Adjusted Property EBITDAR and said occupancy that month was 88 percent against 93 percent a year earlier, with bookings through its website and mobile applications affected. Omni Hotels & Resorts said on its incident page, as archived in April 2024, that it had been responding to a cyberattack since 29 March 2024, shut down its systems to contain it, restored them across its portfolio by 8 April, and that the data taken may include names, email and mailing addresses and Select Guest loyalty information. The iGaming and casino ranking covers the casino side of 2023 in detail.
How we ranked them
Twelve vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, every PCI role is quoted from the vendor's own site, and every vendor entry links to a page on the vendor's own site, read on 1 October 2026, or in the newest archived copy where a vendor site blocks automated reading.
Published hospitality work on the vendor's own site. A hotel or resort engagement scored highest, then a hospitality practice page, then a hospitality customer story.
Firm-level accreditation on the CREST Marketplace, plus the PCI SSC roles the vendor states, such as QSA company, ASV or PCI Forensic Investigator.
Coverage of the hotel attack surface described above.
PCI DSS 11.4 fluency: segmentation testing, retests after significant change and tester independence.
Social engineering and physical testing, because Caesars' 2023 intrusion began with a social engineering attack on an outsourced IT support vendor and hotels are open buildings.
Named testers, identified with their certifications before signing.
Retest policy stated in writing.
Delivery: a portal for findings, and both one-time and continuous options.
North American delivery, with a Canadian office counted for Canadian owners.
Independence from the hotel's managed network, Wi-Fi, IT and security providers.
The 12 companies at a glance
# | Company | HQ | Accreditations verified | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | CREST Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | Named testers from the CDE to the help desk |
2 | Coalfire | Chicago, IL (mailing address) | CREST Penetration Testing (Coalfire Systems, listed under the United Kingdom; confirm which Coalfire entity signs North American work); PCI QSA company | Consultant-led offensive security and red teaming beside a QSA practice | Not stated | Not stated | No | A full red team across a resort |
3 | NetSPI | Minneapolis, MN (Toronto, ON office) | CREST Penetration Testing, Threat Led Penetration Testing | PTaaS platform with consultant-led testing | Not stated | Remediation testing listed | No | Program reporting across many properties and applications |
4 | LevelBlue | Plano, TX | CREST Penetration Testing, Threat Led Penetration Testing and more (UK entity) | Testing inside a managed security provider | Not stated | Yes, no additional cost | No | Consolidating managed detection and testing |
5 | DirectDefense | Englewood, CO (Denver HQ) | Not on the CREST Marketplace | Consultant-led network, wireless and physical testing; subscription programs | Not stated | Yes | No | Physical and network testing at the property |
6 | ioSENTRIX | Herndon, VA | CREST Penetration Testing | Consultant-led testing plus flat-rate PTaaS | Not stated | Free retesting stated | No | Room automation, IoT and guest-facing apps |
7 | VikingCloud | Chicago, IL and Dublin, Ireland | Not on the CREST Marketplace; QSA company, ASV and PFI | Testing beside managed networks, MDR and PCI programs | Not stated | Not stated | No | PCI programs across many properties |
8 | SecurityMetrics | Orem, UT | Not on the CREST Marketplace; PCI audit, ASV and PFI services listed | PCI-led testing, scanning and forensics | Not stated | Not stated | No | Independent hotels and smaller groups led by PCI |
9 | GuidePoint Security | Reston, VA | CREST Penetration Testing | Consultant-led testing within a wider security services firm | Not stated | Not stated | No | Brands buying testing inside a broader security program |
10 | Kroll | New York, NY (Toronto, ON office) | CREST Penetration Testing, Incident Response, Security Operations Centre | Consultant-led testing beside MDR and incident response | Not stated | Not stated | No | Testing next to a response provider |
11 | Rapid7 | Boston, MA | Not on the CREST Marketplace | Testing services beside a security platform | Not stated | Not stated | No | Hotel companies already on the Rapid7 platform |
12 | Withum | Princeton, NJ | Not on the CREST Marketplace | Advisory and accounting firm with a cybersecurity practice | Not stated | Not stated | No | Owners already working with Withum |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a hotel group's security and procurement teams can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Stingrai is rated 5.0 out of 5 from 20 reviews on Clutch, with further reviews on G2. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin. It includes a founding member of Uber's offensive security team, a researcher with more than 400 Hall of Fame reports at Apple, Facebook, Google, Yahoo and the US Department of Defense, and a penetration tester in the Halls of Fame of the US Federal Reserve, PaySafe and Zynga. Two named penetration testers run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security.
How a hotel engagement is tested. Network testing covers the external perimeter including remote access, the internal network and lateral movement, and segmentation tests that start from guest, conference and IoT networks and try to reach the CDE and the PMS, the evidence PCI DSS 11.4.5 asks for. Wi-Fi security assessments run on site or remotely, and the Active Directory assessment follows ACL abuse and Kerberos and delegation paths from a property workstation toward domain admin. The booking engine, guest portal and loyalty platform get web application testing authenticated across guest, member, front desk, revenue manager and franchise roles, for broken authorization, IDOR and business logic in rate, reservation and points flows, and mobile testing covers loyalty and mobile key apps against OWASP MASVS and MASTG. Social engineering combines vishing of the help desk and front desk with booking-themed phishing, physical security assessments test back-of-house doors and network closets, and red team engagements run the full chain against your SOC.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Reports are redactable, which helps when a brand, owner or acquiring bank needs a version without internal detail. Retesting is included, and every human-led and hybrid report ships with an attestation letter and a verified badge. Stingrai's penetration testing supports your PCI DSS program with internal, external and segmentation test evidence under 11.4, and it runs both one-time annual engagements timed to the assessment cycle and continuous programs that test every release.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers the booking engine, guest portal and loyalty web platform. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Networks, Wi-Fi, PMS interfaces, Active Directory, social engineering and physical work are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per one-time assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. Every other scope is quoted through get a quote.
Strength: every claim a brand's or owner's security team will ask about has a public source, from the CREST listing to the CVE records and review profiles, and the same named testers cover the CDE, the guest networks, the loyalty platform and the help desk. Limitation: a deliberately small team, which the CREST listing reflects, so multi-property physical and on-site Wi-Fi programs need scheduling lead time, and no hotel case study is published. Best for: hotel groups, management companies and hospitality technology vendors in the US and Canada that need named, certified penetration testers and an attestation letter for PCI DSS and brand audits, one-time or continuous.
2. Coalfire
Coalfire lists a mailing address at 330 N Wabash Avenue in Chicago, with offices in Alpharetta, Bellevue and Manchester. Its offensive security practice covers work "From red teaming and social engineering to threat-informed penetration testing," and its PCI DSS page says Coalfire "is one of the largest PCI QSAC (Qualified Security Assessor Company) organizations globally." Its hospitality evidence is a casino case study dated 1 November 2016: a full red team across physical, social and logical vectors that began with spearphishing and the casino's VPN and ended with administrator access that "was used to access hotel guest information through the reservation systems," added points to reward cards that could be converted to cash, and reached vault and cashier cage computers. CREST lists Coalfire Systems for Penetration Testing with seven years of membership (listed under the United Kingdom); confirm which Coalfire entity signs North American work. Named testers, retest terms and pricing are not published.
Strength: a published resort engagement that went through the reservation and loyalty systems, from a firm that also knows PCI assessment from the inside. Limitation: the case study dates from 2016 and is anonymized; if Coalfire is also your QSA, agree in writing how the testing team is kept separate from the assessors. Best for: resort and hotel groups that want a full red team across people, premises and networks.
3. NetSPI
NetSPI lists its headquarters in Minneapolis, Minnesota, and an office in Toronto, Ontario. Its hospitality evidence is a customer story with Carlson Companies, described there as a group "providing travel, hotel, restaurant, cruise, and marketing services" whose brands included Radisson Hotels. The story says NetSPI served as Carlson's Qualified Security Assessor and "has also been helping Carlson with penetration testing, both at the network and application levels," and quotes Carlson's chief information security officer on independence: "NetSPI cannot change those vulnerabilities before the report gets to me." Its PTaaS platform lists remediation testing, and CREST lists NetSPI for Penetration Testing and Threat Led Penetration Testing with ten years of membership. Named testers and pricing are not published.
Strength: a named hotel group engagement covering both network and application testing, plus a Toronto office. Limitation: the customer story is undated and describes Carlson's portfolio at the time it was written, so ask for current hospitality references. Best for: hotel groups that want PTaaS program reporting across many properties and applications.
4. LevelBlue
LevelBlue lists its global headquarters at 6010 West Spring Creek Parkway in Plano, Texas. Its retail and hospitality page says "LevelBlue helps hotels, travel agencies, retail franchises and more," names LevelBlue as a sponsor and contributor for the Retail & Hospitality ISAC, and links a SpiderLabs research report on emerging cyber threats in hospitality. Its penetration testing page offers retesting "at no additional cost" and says SpiderLabs is CREST-certified for Penetration Testing and Simulated Targeted Attack & Response. The CREST Marketplace lists LevelBlue Cyber Solutions Ltd with Penetration Testing, Threat Led Penetration Testing, Application Security Testing and Mobile Application Security Testing, and 15 years of membership. Named testers and pricing are not published.
Strength: a hospitality practice with its own threat research, and retesting at no extra cost. Limitation: managed security is the center of gravity and the CREST listing belongs to a UK entity, so confirm which entity delivers North American testing and keep testing independent of any network LevelBlue manages for you. Best for: hotel groups consolidating managed detection, incident response and testing with one provider.
5. DirectDefense
DirectDefense was formed in 2012 and lists its Denver headquarters at 116 Inverness Drive East in Englewood, Colorado, on its locations page. Its retail and hospitality page says it can "assist any hospitality business from hotels to motels in securing data and mitigating the security risk to your guests" and links a hospitality PCI compliance case study. A July 2020 field report describes a physical penetration test for a hotel client in which the consultant, staying as a paying guest, found network switch equipment in an unlocked cabinet inside an unlocked linen closet and, "Given the lack of proper segmentation on the network," had logical access to the hotel's entire internal network; it closes with four findings, from physical security to network access controls. Its testing service covers external, internal and wireless networks, and DirectDefense says it will "retest to confirm the risk is reduced," with subscription programs. DirectDefense is not on the CREST Marketplace; named testers and pricing are not published.
Strength: a published hotel physical test that ended in a segmentation finding, which is the path PCI DSS 11.4.5 is meant to close. Limitation: no firm-level CREST accreditation, and the hotel report dates from 2020. Best for: properties that want physical, wireless and network testing on site.
6. ioSENTRIX
ioSENTRIX lists its address at 13800 Coppermine Road in Herndon, Virginia. Its hospitality case study describes a penetration test for "A prominent hotel chain in the U.S." of a newly deployed room automation system, controlled through an Android tablet, which found weaknesses in network segmentation and password policies that "allowed guests to potentially control devices in other rooms or access the hotel's management systems." Its penetration testing page states "Free re-testing," and it sells a flat-rate PTaaS subscription. CREST lists ioSENTRIX for Penetration Testing with three years of membership. Named testers and pricing are not published.
Strength: a hotel IoT engagement tested exactly where guest technology meets the management network. Limitation: a smaller consultancy, so confirm US or Canadian staffing for on-site work. Best for: hotels deploying room automation, in-room tablets or other connected guest technology.
7. VikingCloud
VikingCloud lists headquarters in Chicago and Dublin, Ireland. Its hotel and hospitality page says "Protecting distributed operations is our specialty" and that its "network, segmentation, and mobile & web app penetration testing identify weak spots before they can be exploited," alongside managed networks, guest Wi-Fi, firewalls and managed detection for hotel locations. Its PCI compliance page states that it is accredited as a Qualified Security Assessor Company, an Approved Scanning Vendor and a PCI Forensic Investigator, and the hospitality page says it has more than 100 QSAs. VikingCloud is not on the CREST Marketplace; named testers, retest terms and pricing are not published.
Strength: segmentation testing from a PCI specialist that already works across multi-location estates. Limitation: if VikingCloud also runs a property's firewall or guest Wi-Fi, PCI DSS 11.4.5 still requires organizational independence of the tester, so use a separate team or provider for the systems it manages. Best for: multi-property operators that want PCI assessment, scanning and segmentation testing coordinated across many sites.
8. SecurityMetrics
SecurityMetrics says it is "headquartered in Orem, Utah," and was founded in 2000. Its hospitality solutions page says "Hospitality organizations such as resorts, hotels, motels, rental cars, and other travel companies are often targeted by threat actors because of their high transaction volume, perceived ease of entry, and potential earnings," and offers them PCI audits, penetration testing, vulnerability scanning, forensics and workforce training; its service menu lists ASV scanning and PFI forensic investigation. SecurityMetrics is not on the CREST Marketplace; named testers, retest terms and pricing for penetration tests are not published.
Strength: PCI audit, testing, scanning and forensics from one provider that addresses hotels directly. Limitation: testing sits inside a compliance-led business, so ask for a sample report that shows manual exploitation rather than scanner output. Best for: independent hotels and smaller groups whose testing is driven by PCI DSS.
9. GuidePoint Security
GuidePoint Security lists its headquarters at 1900 Reston Metro Plaza in Reston, Virginia. Its customer success story with Wyndham Hotels & Resorts, which it describes as "the largest hotel franchisor in the world," says GuidePoint has been a partner for over a decade, most recently on an endpoint detection and response rollout, data lake and SOC technology, and API security vendor selection. Its penetration testing services include cloud testing, IoT and wireless security assessments, social engineering, and red and purple team assessments. CREST lists GuidePoint Security for Penetration Testing with three years of membership. Named testers, retest terms and pricing are not published.
Strength: a decade-long relationship with the world's largest hotel franchisor and a full testing catalog. Limitation: the Wyndham story is about security operations and vendor selection, not penetration testing. Best for: brands buying testing inside a broader security program.
10. Kroll
Kroll lists its headquarters at One World Trade Center in New York and a Toronto office at 333 Bay Street. Its hospitality case study describes a hospitality company with a "Large and distributed IT estate" and "Legacy infrastructure and point-of-sale systems" that chose Kroll Responder, Kroll's managed detection and response service, after a security audit. Its penetration testing service covers external and internal networks, cloud, APIs, mobile applications, AI and LLM systems, and IoT and hardware devices, alongside red teaming. CREST lists Kroll LLC for Penetration Testing, Incident Response and Security Operations Centre with eight years of membership. Named testers, retest terms and pricing are not published.
Strength: testing, incident response and MDR under one contract, with a Toronto office. Limitation: the hospitality case is managed detection rather than testing. Best for: hotel companies that want testing from a provider that can also run the response.
11. Rapid7
Rapid7 lists its global headquarters at 120 Causeway Street in Boston. Its Wyndham Hotels customer story, filed under the hospitality industry, says Wyndham "has been using Rapid7 for over a decade," with InsightAppSec, InsightIDR and InsightVM securing "3500 corporate users, 150 applications and more than 1 million loyalty members." Its penetration testing services cover external and internal networks, web applications, IoT devices, social engineering, wireless networks and red team attack simulation. Rapid7 is not on the CREST Marketplace; named testers, retest terms and pricing are not published.
Strength: testing that feeds straight into a vulnerability and detection platform many hotel groups already run. Limitation: the hospitality story concerns products rather than a testing engagement, and PCI DSS is clear that scanning alone is not a penetration test. Best for: hotel companies already standardized on the Rapid7 platform.
12. Withum
Withum's cybersecurity services page lists penetration testing among its services, names Princeton, New Jersey as its corporate headquarters, and says "Hotels, resorts and entertainment venues are high-value targets for cyber-criminals." Its May 2025 article on cybersecurity measures for hotels recommends penetration testing and describes Withum as committed to helping clients in the hospitality industry. Its hospitality industry page lists "Hotels ranging from small, boutique to large, international chains" among the clients it serves. Withum is not on the CREST Marketplace; named testers, retest terms and pricing are not published.
Strength: an advisory and accounting firm that already works with hospitality owners. Limitation: penetration testing is one line in a broad advisory catalog, and if Withum also audits or manages your systems, independence needs settling in writing. Best for: owners and management companies that already use Withum for accounting or advisory work.
Firms considered and not ranked
Some familiar names were left out because their sites show no hospitality practice and no security work for a hospitality client. Sikich's cybersecurity page lists hospitality among the sectors it serves without describing an engagement. MNP's PCI case study tested a payment service provider whose customers include resort operators, not a hotel. Gaming test labs and casino specialists are covered in the iGaming and casino ranking linked above. Whoever manages a hotel's network, Wi-Fi or firewall should not be the one testing it.
How much does hotel penetration testing cost in 2026?
Hotel scopes usually combine a PCI DSS internal and external test with segmentation checks, the booking engine and loyalty platform, and a social engineering campaign. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per one-time assessment of one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. Property networks, Wi-Fi, Active Directory, PMS interfaces, social engineering and red team work are quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Hotel scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Booking engine, guest portal or loyalty web application | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
Booking, channel and partner APIs | US$6,000 to US$30,000 | C$15,000 to C$25,000 |
Guest or loyalty mobile app (per platform) | US$7,000 to US$35,000 | C$18,000 to C$30,000 |
External perimeter and internal network, including segmentation | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 external; C$20,000 to C$35,000 internal |
PCI DSS-driven test of the cardholder data environment | US$12,000 to US$25,000 | Quoted per scope |
Active Directory | Within the network band | C$25,000 to C$35,000 |
Red team across the help desk, premises and network | Quoted per scope | C$45,000 to C$65,000 |
Annual program for an enterprise hotel group | US$50,000 to US$150,000 or more | C$60,000 to C$90,000 (PTaaS) |
Three things move a hotel quote most: the number of properties and distinct network builds in scope, whether social engineering includes vishing and on-site visits, and how many booking, loyalty and partner applications need authenticated testing across roles. The cost calculator gives a starting figure.
Buyer checklist: questions to put to every vendor
The RFP template turns these into procurement language.
Who exactly will test, and can we see their names and certifications before we sign?
Where is your firm-level accreditation listed, and which legal entity will sign our statement of work?
Will you test segmentation from every guest, conference and IoT network into the CDE and the PMS, covering every control in use as PCI DSS 11.4.5 requires?
How will you test the PMS and its interfaces to point of sale, payments, locks and the brand's central systems without disrupting check-in?
Will the booking engine and loyalty platform be tested authenticated across guest, member, front desk and franchise roles?
Do you run vishing against the help desk and front desk, and do you test the password and MFA reset process live?
Can you include an assumed-breach or detection scenario, given that regular testing on the Starwood network did not catch an intruder already inside?
What can we hand a brand, an acquiring bank or a QSA? Ask for the attestation letter, an executive summary and a redacted report.
Is retesting included, and within what window?
Are you independent of our network, Wi-Fi, firewall and managed security providers?
Frequently Asked Questions
Who are the best penetration testing companies for hotels and hospitality in 2026?
The best penetration testing companies for hotels and hospitality in 2026 are Stingrai, Coalfire, NetSPI, LevelBlue, DirectDefense, ioSENTRIX, VikingCloud, SecurityMetrics, GuidePoint Security, Kroll, Rapid7 and Withum. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level with two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP on every human-led engagement, testing the cardholder data environment, guest Wi-Fi segmentation, booking and loyalty platforms and the help desk, with retesting and an attestation letter included on one-time or continuous terms. Coalfire, NetSPI and LevelBlue follow.
Does PCI DSS require hotels to do penetration testing?
Yes, for any hotel whose card environment is assessed against requirement 11.4, which covers every Report on Compliance and SAQ D. Requirements 11.4.2 and 11.4.3 of PCI DSS v4.0.1 require internal and external penetration tests at least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified tester with organizational independence. Requirement 11.4.4 requires retesting to verify corrections, and 11.4.5 requires segmentation tests at least every 12 months and after changes when segmentation isolates the cardholder data environment. Service providers test segmentation at least every six months under 11.4.6. Hotels that qualify for a shorter self-assessment questionnaire validate less: SAQ A, SAQ B and SAQ P2PE contain no 11.4 testing, SAQ B-IP and SAQ C contain only the 11.4.5 segmentation test, and SAQ A-EP includes the external test (11.4.3) and the segmentation test (11.4.5) but not the internal test (11.4.2), so confirm your SAQ type with your acquirer or QSA.
Does guest Wi-Fi have to be included in a hotel penetration test?
When the hotel relies on segmentation to keep guest Wi-Fi out of the cardholder data environment, yes. Requirement 11.4.5 requires penetration tests covering all segmentation controls in use and confirming they isolate the CDE from all out-of-scope systems, and requirement 1.3.3 requires network security controls between all wireless networks and the CDE, with wireless traffic into the CDE denied by default. A test that starts on the guest network and tries to reach the CDE and the PMS is the direct evidence.
What does the FTC's Marriott order require for penetration testing?
The final order the FTC issued on 20 December 2024 requires Marriott and Starwood to run a risk-based testing program that includes internal and external penetration testing, segmentation testing and web application penetration testing, not less than annual and within 120 days after a Covered Incident, with retests where necessary to confirm remediation. It also requires quarterly vulnerability scans, multi-factor authentication for remote access, contractual safeguards and a risk-based audit program for franchised hotels, and biennial third-party assessments for 20 years.
Do the FTC and state orders apply to every hotel?
No. The 2024 FTC order and the matching state judgments bind Marriott and Starwood, the 2015 FTC order binds Wyndham, and the 2017 New York and Vermont settlement binds Hilton. They show what regulators required after hotel breaches: annual penetration and segmentation testing, an MFA option for consumer accounts including loyalty accounts, and annual PCI DSS assessments, with Wyndham's assessor certifying, hotel by hotel, whether each branded hotel's card network is treated as untrusted. Other hotels answer to PCI DSS and to the consumer protection and privacy laws those orders enforced.
Does PIPEDA or Quebec Law 25 require a hotel to run a penetration test?
Neither statute names one. PIPEDA requires security safeguards appropriate to the sensitivity of the information, a report to the Privacy Commissioner of breaches creating a real risk of significant harm, and a record of every breach for 24 months. Quebec's private sector act, as amended by Law 25, requires reasonable security measures, prompt notice to the Commission d'accès à l'information of incidents presenting a risk of serious injury, an incident register, and a privacy impact assessment before a new information system such as a PMS. A penetration test is one of the clearest ways a hotel can show its measures were reasonable.
Is a PCI-scoped penetration test enough for a hotel?
It meets the card standard but not the whole risk. In its 2022 finding on the Starwood breach, Canada's Privacy Commissioner noted that penetration and vulnerability testing ran regularly on the Starwood network while an attacker went undetected, and that PCI DSS compliance is focused on cardholder data. Hotels also hold passport numbers, loyalty accounts and stay histories, so a good scope adds the loyalty and guest profile systems, the PMS, door locks and kiosks, the help desk, and a detection or assumed-breach scenario.
How much does hotel penetration testing cost in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per one-time assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; property networks, Wi-Fi, social engineering and red team scopes are quoted. Indicative bands from our cost guides put a US network test at US$5,000 to US$40,000 and a PCI DSS-driven test at US$12,000 to US$25,000.
Related reading
PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)
Best Penetration Testing Companies for iGaming, Sportsbooks and Casinos (2026)
Best Retail and E-commerce Penetration Testing Companies (2026)
WiFi Penetration Testing (2026): Wireless Security Assessment Scope, Cost and Methodology
Ready to scope a hotel penetration test?
The breach that ends in a regulator's order rarely starts at the payment terminal. It starts with a help desk that resets a password for a convincing caller, a franchise login that reaches brand systems, or a guest network that can see more than it should. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence PCI DSS, brand audits and Canadian privacy programs ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a property or portfolio scope, or see the published package prices on the pricing page.



