The role of employees as a key factor in hotel cybersecurity

Authors

DOI:

https://doi.org/10.18778/0867-5856.2026.16

Keywords:

cybersecurity, hospitality, security culture, employees, incident reporting

Abstract

This study examines behavioral, organizational and psychological factors influencing hotel employees’ reporting of cybersecurity incidents, focusing on trust relationships and technical knowledge. The aim was to determine how trust in internal IT staff versus external institutions is associated with reporting intentions and how employees’ skills shape responses to cyber threats. A quantitative survey of 143 hotel employees was conducted, followed by statistical analyses, including paired t-tests and association-based regression models, to examine differences in reporting likelihood across channels. Results show that employees place the highest trust in internal IT experts, viewing them as the primary contact, while willingness to report to external institutions remains low, likely due to limited awareness or perceived procedural complexity. A paradox emerged: technically skilled employees, despite recognizing more threats, are less inclined to report incidents externally, often due to overconfidence, whereas less skilled employees exhibit greater caution and higher reporting rates. Employees trust basic security measures more than advanced tools, which are seen as complex. Findings underscore the need for targeted training, simplified reporting protocols, and stronger collaboration with external security actors, framing cybersecurity as a strategic element of hotel risk management.

Downloads

Download data is not yet available.

References

Alonso-Almeida, M. del M., & Giglio, C. (2024). Cybersecurity in tourism and hospitality management research: Current issues, trends, and an agenda for future research. Cuadernos de Turismo, (53), 243–260. https://doi.org/10.6018/turismo.616471

Arcuri, M.C., Gai, L., Ielasi, F., & Ventisette, E. (2020). Cyber attacks on the hospitality sector: Stock market reaction. Journal of Hospitality and Tourism Technology, 11(2), 277–290. https://doi.org/10.1108/JHTT-05-2019-0080

Bishop, L.M., Asquith, P.M., & Morgan, P.L. (2025). The employee cybersecurity awareness framework. Human Behavior and Emerging Technologies, Article 1025045. https://doi.org/10.1155/hbe2/1025045

Casais, B., & Ferreira, L. (2023). Smart and sustainable hotels: Tourism Agenda 2030 perspective article. Tourism Review, 78(2), 344–351. https://doi.org/10.1108/TR-12-2022-0619

Chang, S.E., & Lin, C.-S. (2007). Exploring organizational culture for information security management. Industrial Management & Data Systems, 107(3), 438–458. https://doi.org/10.1108/02635570710734316

Chen, H.S., & Fiscus, J. (2018). The inhospitable vulnerability: A need for cybersecurity risk assessment in the hospitality industry. Journal of Hospitality and Tourism Technology, 9(2), 223–234. https://doi.org/10.1108/JHTT-07-2017-0044

Chen, H.S., & Jai, T.-M.(C.). (2019). Cyber alarm: Determining the impacts of hotel’s data breach messages. International Journal of Hospitality Management, 82, 326–334. https://doi.org/10.1016/j.ijhm.2018.10.002

de Bruin, M., & Mersinas, K. (2024). Individual and contextual variables of cyber security behaviour: An empirical analysis of national culture, industry, organisation, and individual variables of (in)secure human behaviour. [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2405.16215

European Parliament and Council of the European Union. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). Official Journal of the European Union. https://eur-lex.europa.eu/eli/dir/2022/2555

Florido-Benítez, L. (2024). The cybersecurity applied by online travel agencies and hotels to protect users’ private data in smart cities. Smart Cities, 7(1), 475–495. https://doi.org/10.3390/smartcities7010019

Florido-Benítez, L. (2025). The role of cybersecurity as a preventive measure in digital tourism and travel: A systematic literature review. Discover Computing, 28, Article 28. https://doi.org/10.1007/s10791-025-09523-3

Fragnière, E., & Yagci, K. (2021). Network & cybersecurity in hospitality and tourism. In C. Cobanoglu, S. Dogan, K. Berezina & G. Collins (Eds.), Hospitality & tourism information technology (pp. 1–21). USF M3 Publishing. https://digitalcommons.usf.edu/m3publishing/vol17/iss9781732127593/7/

Johnston, A.C., & Warkentin, M. (2010). Fear appeals and information security behaviors: An empirical study. MIS Quarterly, 34(3), 549–566. https://doi.org/10.2307/25750691

Kraemer, S., Carayon, P., & Clem, J. (2009). Human and organizational factors in computer and information security: Pathways to vulnerabilities. Computers & Security, 28(7), 509–520. https://doi.org/10.1016/j.cose.2009.04.006

Kruse, C.S., Frederick, B., Jacobson, T., & Monticone, D.K. (2017). Cybersecurity in healthcare: A systematic review of modern threats and trends. Technology and Health Care, 25(1), 1–10. https://doi.org/10.3233/THC-161263

Maddux, J.E., & Rogers, R.W. (1983). Protection motivation and self-efficacy: A revised theory of fear appeals and attitude change. Journal of Experimental Social Psychology, 19(5), 469–479. https://doi.org/10.1016/0022-1031(83)90023-9

Magliulo, A. (2016). Cyber security and tourism competitiveness. European Journal of Tourism, Hospitality and Recreation, 6(2), 128–134. https://doi.org/10.1515/ejthr-2016-0015

National CERT (CERT.hr). (2025, March 25). Godišnji izvještaj rada Nacionalnog CERT-a za 2024. godinu [Annual report on the work of the National CERT for 2024]. https://www.cert.hr/godisnji-izvjestaj-rada-nacionalnog-cert-a-za-2024-godinu/

Organisation for Economic Co-operation and Development. (2017). Enhancing the role of insurance in cyber risk management. OECD Publishing. https://doi.org/10.1787/9789264282148-en

Organisation for Economic Co-operation and Development. (2024, June). New perspectives on measuring cybersecurity (OECD Digital Economy Papers No. 366). OECD Publishing. https://doi.org/10.1787/b1e31997-en

Ozturk, A.B. (2026). Applying protection motivation theory to hotel employees’ compliance with information systems security policies: The moderating role of generational differences. Journal of Hospitality and Tourism Technology, Vol. ahead-of-print No. ahead-of-print. https://doi.org/10.1108/JHTT-01-2025-0035

Perwej, Y., Abbas, S.Q., Dixit, J.P., Akhtar, N., & Jaiswal, A.K. (2021). A systematic literature review on the cyber security. International Journal of Scientific Research and Management, 9(12), 669–710. https://doi.org/10.18535/ijsrm/v9i12.ec04

Pipyros, K., & Liasidou, S. (2025). A new cybersecurity risk assessment framework for the hospitality industry: Techniques and methods for enhanced data protection and threat mitigation. Worldwide Hospitality and Tourism Themes, 17(1), 48–61. https://doi.org/10.1108/WHATT-12-2024-0296

Rid, T., & Buchanan, B. (2015). Attributing cyber attacks. Journal of Strategic Studies, 38(1–2), 4–37. https://doi.org/10.1080/01402390.2014.977382

Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change1. The Journal of Psychology, 91(1), 93–114. https://doi.org/10.1080/00223980.1975.9915803

Srivastava, G., Jhaveri, R.H., Bhattacharya, S., Pandya, S., Rajeswari, R., Maddikunta, P.K.R., Yenduri, G., Hall, J.G., Alazab, M., & Gadekallu, T.R. (2022). XAI for cybersecurity: State of the art, challenges, open issues and future directions. ACM Computing Surveys, 1(1). https://doi.org/10.48550/arXiv.2206.03585

Yallop, A.C., Gică, O.A., Moisescu, O.I., Coroș, M.M., & Séraphin, H. (2023). The digital traveller: Implications for data ethics and data governance. Journal of Consumer Marketing, 40(2), 155–170. https://doi.org/10.1108/JCM-12-2020-4278

Downloads

Published

2026-09-17

Issue

Section

Articles

How to Cite

Markelj, Blaž, Ajda Šulc, and Janez Mekinc. 2026. “The Role of Employees As a Key Factor in Hotel Cybersecurity”. Turyzm/Tourism 36 (2): 7-18. https://doi.org/10.18778/0867-5856.2026.16.

Funding data