The short answer
A ransomware outage typically takes down your interconnected systems at once: the property management system, key encoders, payment terminals and phones. You can still operate if you switch fast to paper — printed arrivals, a manual room-status ledger, physical and master keys, escorting guests, manual card imprinting or cash, and offline records of every transaction. The goal is continuity, not normal speed, and never reconnect infected systems before clean-up.
Key takeaways
- An attack hits the PMS, key systems, point-of-sale, reservations and communications together, so your continuity plan must be one offline 'crash kit', not separate fixes.
- In the first hour, isolate affected segments, keep an offline decision log and engage your insurer, incident-response team and national CERT — do not decide on paying a ransom under pressure.
- Check-in without the PMS relies on printed reports, a manual room-status ledger and a designated 'rack clerk'; keys rely on physical/master keys and escort procedures.
- Paper payments (imprinters, cash, carbon-copy folios) are viable but create card-data risk; confirm the scenario with your acquirer and applicable card-data rules before dictating numbers by hand.
- Recovery runs from verified offline backups and golden images; afterwards reconcile manual logs and honour breach-notification duties, which paying a ransom does not remove.
What the attack actually breaks at the front desk and beyond
Modern hotels wire their room-management systems, electronic locks, payment terminals, online bookings and phones into one network. Ransomware rarely encrypts a single server; it moves sideways, so overnight you can lose access to reservation data, new key creation, card charges and internal communication all at once.
Attacks are deliberately timed to peak dates to maximise pressure. Omni Hotels took systems offline across its network during Easter 2024: guests faced long check-in delays, keys failed, and staff fell back to paper processes and hand-recording card details. In December 2021, Nordic Choice Hotels (attributed to Conti) lost reservations, check-in, check-out and key creation, with staff escorting guests to rooms. Beyond encryption, 'double extortion' means attackers threaten to publish stolen data.
- Property management system (PMS): bookings, rates, folios, reports — the operational 'brain'.
- Lock and key system: encoders and software often share a network with the PMS.
- Point-of-sale and payment terminals, plus online payment gateways.
- Telephony, guest Wi-Fi and staff communication channels.
The first hour: contain, notify, decide about payment
The CISA #StopRansomware method walks responders through detection and analysis, containment, eradication and recovery in sequence. When systems are encrypting, do not simply reboot or reconnect them; capture logs and disk images first, isolate affected segments and take machines off the network before touching anything.
The UK's NCSC advises victims not to panic, to review alternatives including not paying, to keep an offline record of decisions, and to consult insurers, the national cyber centre and a cyber-incident-response firm. Payment does not guarantee restoration and does not remove regulatory duties; it can even be unlawful if the recipient is sanctioned. The victim ultimately decides, but only after weighing backups, partial-recovery options and free decryptors made available by law enforcement.
- Isolate affected segments and collect logs or disk images before restarting anything.
- Report the incident: CISA and the FBI in the US, NCSC and police or the ICO in the UK, or your national CERT elsewhere.
- Activate your insurer and agreed incident-response provider, which should have an out-of-hours line.
- Keep every decision in an offline journal for regulators and post-incident review.
Running check-in and room keys on paper
Working without the PMS depends on pre-printed reports and a prepared crash kit. Export arrivals, in-house and departures lists, room statuses and folio balances daily; during downtime use paper registration cards and carbonless duplicate forms. Appoint a 'rack clerk' — the pre-automation role — who owns the manual room-status ledger and keeps it in sync with housekeeping so the same room is not sold twice.
Keys are the most fragile point. If encoders are down, hold a physical and master-key set, decide who may use it, and establish a guest-escort procedure. A standalone encoder isolated from the infected network can be used sparingly, but do not reconnect it until the environment is clean. Record every manually assigned room in the ledger and hand the data to the PMS on recovery.
- Printed packet: arrivals, in-house, departures, room statuses, VIPs and special requests.
- Manual room-status ledger in two versions — one for the front desk, one for housekeeping.
- Physical and master keys, named holders and a mandatory escort procedure.
- A separate, isolated encoder used only off the infected network and after verification.
Payments and folios without the POS and PMS
When terminals are unreachable, hotels historically use mechanical imprinters, cash and carbon-copy folios with signatures. Cloudbeds' downtime guidance is to record guest information and check-ins manually, collect payment receipts so they can be posted when the system returns, and keep paper copies of transactions for later audit.
Hand-recording full card details is a data-handling risk and a sensitive area under card-scheme rules such as PCI DSS. Before staff dictate card numbers onto paper, confirm with your acquirer and counsel whether the scenario is permitted in your jurisdiction. The usual compromise: cash and a signed imprint within limits, all paper with card data kept under lock, and destruction once transactions are posted to the system.
- Cash is the most dependable offline option; keep a reserve and change float ready.
- An imprinter with the customer's signature and a carbon copy — only if your acquirer supports it.
- Log every manual transaction in a separate register and post it to the PMS after restoration.
- Keep paper with card data in a safe and destroy it after reconciliation.
Recovery: backups, reconciliation, notifications
CISA recommends maintaining offline encrypted backups of critical data and regularly testing them, plus 'golden images' of systems for fast redeployment. Rebuild from verified copies on clean machines rather than from compromised disks, and only bring systems back into the network after eradication. When the PMS returns, reconcile the manual ledger against the system: check-ins, check-outs, payments and any unclosed folios.
Paying a ransom does not cancel notification duties. Depending on the jurisdiction and data types (personal data, payment records), specific deadlines and regulators apply — for example, the ICO in the UK. Name an owner for notifications, run a lessons-learned review, and drill the 'PMS down' scenario with front-desk staff so the next outage is shorter.
- Offline backups and golden images with regularly tested restore procedures.
- Reconcile manual ledgers with the PMS and close open folios after restoration.
- Assess what data was exposed and meet guest and regulator notification obligations.
- Run a post-incident review and drill the paper scenario with operations staff.
Real incidents and the operational pattern they reveal
Omni (2024), Nordic Choice (2021) and the wider hospitality pattern show that even large chains run on paper for the first period: printed lists, escorted guests, hand-recorded details. Nordic Choice declined to pay and instead re-imaged hardware with a new operating system, cutting downtime across roughly two hundred properties.
The lesson is that a pre-made crash kit and a rehearsed role model keep check-in, keys and payments moving while technical recovery proceeds in the background. The question is not whether an incident will happen, but how quickly your team can switch to manual mode and how well they have practised it.
- Plan for outage types of different duration — four hours of maintenance and a lost server room are different problems.
- Operating departments (front office, housekeeping, accounting) own the plan; IT owns restoration, not the paper workflow.
Where general guidance ends and professional advice begins
This article is general operational guidance, not legal, insurance or technical advice. Requirements differ by country, acquirer and insurance contract: some jurisdictions restrict hand-recording card details, others mandate notification deadlines. Decisions on paying a ransom, how long to run on paper and when to reconnect systems should involve your incident-response firm, lawyers and insurer.
National resources — CISA and the FBI in the US, NCSC and police in the UK, and sector CERTs elsewhere — provide current contacts and tools. Their documents are updated periodically, so verify the latest versions on official sites before an incident and treat schedules as subject to change.
- Agree manual payment scenarios with your acquirer and card-data requirements in advance.
- Document regulator-notification routes for your jurisdiction.
- Check current CISA and NCSC guidance on official websites before you rely on it.
Put it into practice
The 24-hour manual-operations crash kit and priority matrix
Prepare this kit in advance and store it offline in operating areas (front desk, manager's office, housekeeping). Own it with the front office and housekeeping teams, not IT: they execute the paper workflow while IT restores systems.
- Printed grab-and-go report packet: arrivals, in-house, departures, room statuses, VIPs and folio balances.
- Paper registration cards and carbonless duplicate folios for manual check-in and check-out.
- Manual room-status ledger forms in two versions — front desk and housekeeping.
- A named 'rack clerk' plus printed room-assignment sheets.
- Physical/master key set with a list of holders and an escort procedure.
- A mechanical imprinter and slips (only if your acquirer supports it) or a cash reserve with change.
- A clean, quarantined laptop and printer preloaded with offline forms, never joined to the infected network.
- A single offline action-and-decision log for regulators and post-incident review.
- A contact sheet: insurer hotline, incident-response firm, national CERT, acquirer support and law enforcement.
- Named owners for guest communications and internal staff updates during the outage.
- A documented procedure for reconciling manual ledgers with the PMS and destroying card-data paper afterwards.
Questions people ask
Should the hotel pay the ransom?
Treat payment as a last resort. It does not guarantee restoration, does not remove notification obligations, and may be unlawful if the recipient is sanctioned. First assess offline backups, partial-recovery options and any free decryptors released by law enforcement. The decision belongs to the victim but should involve the insurer, an incident-response firm and legal counsel reviewing the full impact.
How do we issue room keys if encoders and the lock system are down?
Fall back to physical and master keys: assign a named holder, keep a usage log and escort each guest to their room. A standalone encoder isolated from the infected network can be used sparingly, but never reconnect it until the environment is verified clean. For electrified locks that still respond manually, define a staff-assisted open procedure agreed with the engineering team and logged.
Can we take cards by hand without a terminal without breaching card-data rules?
Manually recording full card details creates risk and is usually restricted under card-scheme rules such as PCI DSS. Confirm with your acquirer and legal counsel whether an imprinter-plus-signature or hand-recorded scenario is permitted in your jurisdiction. The safe minimum is cash and, within limits, a signed imprint, with all card-data paper kept under lock and destroyed once transactions are posted.
How long can a hotel realistically run on paper?
Typically one to three days before errors, lost revenue and staff strain become serious. The limit depends on occupancy, property size and how complete the crash kit is. If downtime stretches, decide whether to compile revenue reports by hand or let the restored PMS catch up from your manual records instead.
When must we notify guests and regulators about a data breach?
Notification timing and scope depend on the jurisdiction and data types involved (personal data, payment records). In the UK the ICO applies; in the US, state breach-notification laws and sector regulators. Paying a ransom does not lift these duties. Assign an owner, confirm current requirements before an incident, and during it work with legal counsel.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- #StopRansomware Guide | CISACybersecurity and Infrastructure Security Agency (CISA)
- Guidance for organisations considering payment in ransomware incidentsNational Cyber Security Centre (NCSC)
- Preparing for scheduled maintenance to your Cloudbeds PMSCloudbeds Help Center
- Nice Recovery! Part 2 of 3Hospitality Upgrade
- Omni Hotels blames cyberattack for widespread tech outagesSC Media
- Ransomware attack locks Nordic Choice Hotels' guests out of their roomsCybersecurity Help (cybersecurity-help.cz)
- Известный отель подвергся кибератаке: гости не могли попасть в номераInc. Russia