By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published July 28, 2026

TL;DR: Travel and tourism in EMEA faces high-frequency cyber attacks, with transport accounting for 11% of attacks in Europe and breach costs averaging $4.03 million in hospitality and $3.98 million in transportation, according to KnowBe4. Reactive defence is no longer enough when digital dependencies, external providers, and human plus AI risk converge.


At a glance

What this is: This whitepaper maps cyber risk in travel and tourism across EMEA and finds that high-volume PII handling, interconnected infrastructure, and human-plus-AI exposure are pushing the sector toward more frequent and expensive attacks.

Why it matters: It matters to IAM, PAM, and security teams because travel and tourism environments depend on external access, shared systems, and identity-heavy workflows where privilege, authentication, and third-party governance directly shape resilience.

By the numbers:

👉 Read KnowBe4's whitepaper on cyber risk in travel and tourism across EMEA


Context

Travel and tourism is a high-value cyber target because it combines sensitive personal data, distributed suppliers, and operational dependence on always-on digital services. In EMEA, that means the risk is not limited to one system or one brand: identity, access, data handling, and third-party connectivity all create routes for compromise.

The primary governance gap is reliance on reactive security in an environment that requires continuous trust decisions. Where booking, transport, hospitality, and partner platforms intersect, IAM, PAM, and non-human identity controls become part of operational resilience rather than back-office administration.


Key questions

Q: How should travel and tourism organisations reduce cyber risk across partner ecosystems?

A: Start by inventorying every external connection that can touch customer, booking, payment, or operational data. Then reduce standing privilege, require offboarding for every supplier identity, and segment high-value services so one partner compromise cannot spread laterally across the environment.

Q: Why do travel and tourism environments need stronger identity governance than many other sectors?

A: Because the sector relies on frequent third-party access, customer-facing systems, and automation that all interact with sensitive personal data. That combination creates many more trust decisions than a simple perimeter model can handle, so IAM, PAM, and NHI controls become core resilience controls.

Q: What do organisations get wrong about AI-driven cyber risk?

A: They often assume the main change is autonomous attackers, when the immediate change is faster and more variable abuse of existing identity pathways. That mistake pushes attention toward speculative defenses instead of scoped access, strong telemetry, and response readiness. The operational risk is already here, even if full autonomy is not.

Q: Who is accountable when supplier access is abused in a breach?

A: Accountability sits with the organisation that granted the access and with the supplier governance process that failed to constrain it. If a third-party platform can be abused to expose customer data, then access scope, offboarding, and monitoring were not aligned to the relationship. IAM and third-party risk teams should review supplier access as a lifecycle control, not a one-time approval.


Technical breakdown

Why travel and tourism environments expand attack surface

Travel and tourism organisations operate through dense chains of booking engines, payment platforms, logistics providers, loyalty systems, and support services. Each integration adds identities, tokens, service accounts, and delegated access paths that widen the attack surface. PII concentration increases the value of compromise, while business continuity pressure often keeps legacy access in place longer than it should remain active. The result is an environment where one weak supplier, one over-privileged account, or one poorly scoped API connection can expose multiple downstream systems.

Practical implication: inventory every external connection and map which identities can reach PII, booking, and operational systems.

How agentic AI changes identity and access risk

Agentic AI can accelerate customer service, itinerary handling, fraud review, and internal operations, but it also introduces software entities that make access decisions in runtime. That creates a non-human identity governance problem: the system needs defined ownership, bounded permissions, auditability, and a way to distinguish approved automation from unmanaged shadow AI. If AI tools can call other tools, retrieve data, or trigger workflows, they can unintentionally expand privilege unless access is tightly scoped and monitored.

Practical implication: treat AI-enabled workflows as identities that need lifecycle governance, logging, and least privilege.

Why reactive controls fail in high-dependency sectors

Reactive security assumes teams can detect, investigate, and recover before business impact spreads. In travel and tourism, that assumption breaks quickly because customer-facing services, partner platforms, and operational systems are tightly coupled. A security failure can affect bookings, check-in, payments, customer support, and staff operations at the same time. Effective resilience therefore depends on segmentation, stronger authentication, service-to-service trust controls, and recovery plans that are designed for concurrency, not isolated incidents.

Practical implication: build resilience around containment, service isolation, and identity assurance rather than incident response alone.


NHI Mgmt Group analysis

Unified resilience is the correct frame for travel and tourism cyber governance. The sector cannot separate data protection, access control, and service continuity because the same identities often touch all three. When external providers, customer data, and operational workflows are tightly coupled, identity governance becomes a resilience control rather than an administrative one. Practitioners should assess whether their current programme can contain a compromise without halting core services.

Travel and tourism has a clear non-human identity problem hiding inside its automation layers. Booking systems, APIs, support platforms, and AI-enabled assistants rely on service credentials that are often broader than their task scope. That is where NHI governance matters most: ownership, expiry, rotation, and monitoring determine whether automation stays bounded or becomes a route to wider compromise. Practitioners should classify every automated integration as an identity with a lifecycle.

High breach costs in this sector reflect governance debt, not just attacker sophistication. Large losses follow when organisations postpone segmentation, privilege review, and supplier offboarding until after a disruption occurs. In practice, that means the expensive failure is often cumulative: stale partner access, weak service-account discipline, and inconsistent authentication controls compound over time. Practitioners should treat access reduction as a financial risk control, not only a technical hardening step.

Agentic AI widens the policy gap between what systems can do and what they are allowed to do. Travel organisations increasingly want AI to optimise operations, but runtime delegation creates a new accountability problem if approvals, logging, and scope boundaries are unclear. This is where identity governance and AI governance overlap: autonomous workflows need explicit boundaries, not informal trust. Practitioners should require named ownership and policy-based restrictions before AI touches sensitive workflows.

Strategic resilience in EMEA travel now depends on governable trust, not just perimeter defence. The industry’s interdependence means that identity, supplier access, and automation controls must be measured as part of resilience planning. That aligns with NIST-CSF and, where personal data is processed, GDPR accountability expectations. Practitioners should expect regulators and boards to ask whether access can be proven, reduced, and recovered under stress.

What this signals

Travel and tourism leaders should expect identity governance to be assessed as part of business continuity, not just security hygiene. The sector’s dependence on suppliers, booking platforms, and automation means that least privilege, offboarding, and service-account discipline now influence whether disruption stays local or cascades across operations.

Supplier trust exhaustion: this is the point at which repeated third-party access and long-lived automation credentials create a governance load that is harder to review than to grant. The practical response is to reduce the number of active trust relationships and make the remaining ones observable, time-bounded, and recoverable.

Boards and GRC teams should also expect more scrutiny around AI-enabled workflows that process customer data or trigger operational actions. Where AI acts inside a business process, ownership and auditability matter as much as model performance, and that is where identity security and AI governance meet.


For practitioners

  • Map every third-party access path to sensitive travel data Catalogue booking, hospitality, transport, and support integrations, then identify which human and non-human identities can reach PII, payment, and operational records. Prioritise vendors and accounts with broad delegated access or weak offboarding controls.
  • Classify AI-enabled workflows as governed identities Assign an owner, purpose, permission scope, logging standard, and expiration policy to each AI-enabled workflow that can retrieve data or trigger actions. Unmanaged assistants and automation should be treated as shadow AI until they are registered and reviewed.
  • Reduce standing privilege across supplier and service accounts Replace persistent broad access with task-scoped privilege where possible, rotate secrets on a defined schedule, and revoke access immediately when a partner relationship ends. Focus on integrations that bridge customer, payment, and operational systems.
  • Test containment against multi-system disruption Run scenarios where one compromised provider or identity affects bookings, support, and operations at the same time. Measure whether segmentation, conditional access, and recovery procedures can isolate the failure without forcing a full-service shutdown.

Key takeaways

  • Travel and tourism cyber risk is driven by dense supplier connectivity, sensitive PII, and operational dependence on digital services.
  • The sector’s biggest weakness is governance drift across human access, service accounts, and AI-enabled workflows that are not being managed as identities.
  • Practitioners should focus on containment, privilege reduction, and lifecycle control because resilience in this sector depends on proving trust, not assuming it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Travel and tourism risk here is driven by access paths to sensitive data and services.
NIST SP 800-53 Rev 5AC-6Least privilege is central to controlling supplier, service, and AI workflow access.
NIST AI RMFGOVERNAgentic AI creates accountability and ownership issues that fall under governance.
ISO/IEC 27001:2022A.5.19Supplier relationships are a major source of risk in travel and tourism ecosystems.
GDPRArt.32The sector handles personal data at scale, making security of processing directly relevant.

Apply Art.32 by strengthening access control, confidentiality, and resilience for personal data processing.


Key terms

  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Vendor offboarding: Vendor offboarding is the controlled removal of a third party's access, data paths, and operational dependencies when the relationship ends or changes. It is a lifecycle control, not an administrative closeout, because any surviving credentials or integrations remain active security exposure.

What's in the full report

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Sector-specific breakdown of how AI is altering the threat landscape in travel and tourism
  • Regulatory requirements for EMEA travel and tourism organisations that need mapping to internal controls
  • Strategic response areas for human risk and AI risk across the digital workforce
  • Actionable resilience recommendations for protecting systems, securing data, and reducing downtime

👉 The full KnowBe4 whitepaper covers the sector-specific threat landscape, regulatory context, and resilience recommendations.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners build the control discipline needed to govern automation, access, and lifecycle risk.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org