Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Travel and tourism cyber risk in EMEA 2026: what should teams prioritise?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12754
Topic starter  

TL;DR: Travel and tourism in EMEA faces high-frequency cyber attacks, with transport accounting for 11% of attacks in Europe and breach costs averaging $4.03 million in hospitality and $3.98 million in transportation, according to KnowBe4. Reactive defence is no longer enough when digital dependencies, external providers, and human plus AI risk converge.

NHIMG editorial — based on content published by KnowBe4: Whitepaper Cyber Risk in Travel & Tourism EMEA 2026

By the numbers:

Questions worth separating out

Q: How should travel and tourism organisations reduce cyber risk across partner ecosystems?

A: Start by inventorying every external connection that can touch customer, booking, payment, or operational data.

Q: Why do travel and tourism environments need stronger identity governance than many other sectors?

A: Because the sector relies on frequent third-party access, customer-facing systems, and automation that all interact with sensitive personal data.

Q: What do organisations get wrong about AI-driven cyber risk?

A: They often assume the main change is autonomous attackers, when the immediate change is faster and more variable abuse of existing identity pathways.

Practitioner guidance

  • Map every third-party access path to sensitive travel data Catalogue booking, hospitality, transport, and support integrations, then identify which human and non-human identities can reach PII, payment, and operational records.
  • Classify AI-enabled workflows as governed identities Assign an owner, purpose, permission scope, logging standard, and expiration policy to each AI-enabled workflow that can retrieve data or trigger actions.
  • Reduce standing privilege across supplier and service accounts Replace persistent broad access with task-scoped privilege where possible, rotate secrets on a defined schedule, and revoke access immediately when a partner relationship ends.

What's in the full report

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Sector-specific breakdown of how AI is altering the threat landscape in travel and tourism
  • Regulatory requirements for EMEA travel and tourism organisations that need mapping to internal controls
  • Strategic response areas for human risk and AI risk across the digital workforce
  • Actionable resilience recommendations for protecting systems, securing data, and reducing downtime

👉 Read KnowBe4's whitepaper on cyber risk in travel and tourism across EMEA →

Travel and tourism cyber risk in EMEA 2026: what should teams prioritise?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12338
 

Unified resilience is the correct frame for travel and tourism cyber governance. The sector cannot separate data protection, access control, and service continuity because the same identities often touch all three. When external providers, customer data, and operational workflows are tightly coupled, identity governance becomes a resilience control rather than an administrative one. Practitioners should assess whether their current programme can contain a compromise without halting core services.

A question worth separating out:

Q: Who is accountable when supplier access is abused in a breach?

A: Accountability sits with the organisation that granted the access and with the supplier governance process that failed to constrain it. If a third-party platform can be abused to expose customer data, then access scope, offboarding, and monitoring were not aligned to the relationship. IAM and third-party risk teams should review supplier access as a lifecycle control, not a one-time approval.

👉 Read our full editorial: Travel and tourism cyber risk in EMEA demands unified resilience



   
ReplyQuote
Share: