Ask the board of a hotel group how its hotels are performing and you will get an answer within minutes. Occupancy, rate, revenue per room and guest scores, all broken down by property and region. Now ask the same board about hotel security risk, site by site. In most cases, nobody can give an equivalent answer. That is the gap in risk insight for hotel leadership.
The information exists somewhere. It sits in audits, incident logs, training records and the heads of general managers. However, nobody brings it together in a form leadership can see and act on. This year has shown why that matters.
What 2026 has shown
In February, a court jailed a man for seven and a half years for sexually assaulting a woman in her room at a hotel in Maidenhead. He had talked his way into a key card at reception in the early hours by claiming to be her boyfriend. Afterwards, more than a hundred MPs signed a letter demanding a meeting with the chain’s chief executive.
Then, in August, a second woman spoke out. She described an attack at a London hotel in the same chain in October 2025. Her abuser told reception she was having a seizure, and staff gave him a key and directed him to her room. The company said staff had not followed its policy, which is never to confirm to a third party that a guest is staying.
In July, a guest at a hotel in Dundee entered another couple’s room while they slept. Once again, the company said staff had not followed its room access procedures correctly.
How the industry is responding
Since then, the chain has commissioned an independent review led by Paul Greaney KC. It now requires explicit guest permission before staff issue any additional key. It has also retrained 12,000 customer-facing colleagues, brought in independent audit and mystery shopping, and changed chief executive.
Meanwhile, UKHospitality is developing sector-wide Guest Security Principles and Good Practice guidance through a guest security working group.
I am not writing this to single out one company. Every large hotel group I have looked at faces the same underlying problem. This one has simply had it exposed in public.
One standard, hundreds of front desks
The detail that stays with me is this. In two of those three cases, the company says a policy existed but staff did not follow it. In the third, staff followed the procedure in place, and it still failed.
That is the portfolio problem in its simplest form. Head office writes the standard. Hundreds of front desks then apply it, often at three in the morning with one person on shift. Someone convincing is usually standing at the desk. As a result, leadership has very little sight of where the standard holds and where it does not. In most cases, it finds out after something has gone wrong.
Hotel security risk reaches beyond locks and cameras
These cases also show that hotel security risk, like all security risk, reaches well beyond physical protection. Talking a receptionist into handing over a key card is a deception aimed at a person, not an attack on a door. In fact, attackers used the same basic technique against the IT help desk at M&S in 2025. Locks and cameras matter, but they do little when someone hands over the key at the front desk.
When it goes wrong, the impact is plain to see. First, and most importantly, it falls on the guest, who had every reason to feel safe in their own room. After that, it falls on the brand. In this case, that meant national headlines, a letter from more than a hundred MPs, an independent review and a change of chief executive. For any hotel group, that is the real measure of security risk.
The wider threat picture for a hotel estate is broad. It includes room access and key control, violence against women and girls, and staff working alone at night. It also covers theft, large events and functions, guest data and booking systems, and at the far end, terrorism. None of it is new. What has changed is the level of scrutiny. Boards now need to show they have a grip on it.
Martyn’s Law adds a legal reason
From spring 2027, Martyn’s Law (the Terrorism (Protection of Premises) Act 2025) adds a compliance reason. Schedule 1 covers “Hotels etc”, and the Home Office guidance extends this to hostels and holiday parks.
The test is simple. Can you reasonably expect 200 or more people on site at the same time, at least occasionally? If so, you will need public protection procedures and must notify the regulator, the Security Industry Authority. At 800 or more, the heavier enhanced tier duties apply. Staff count towards both figures.
For a multi-site operator, the first challenge is knowing which sites are in scope. For example, a sixty-room country house hotel can sit well below the line on a weekday. On a wedding Saturday, however, it can clear it comfortably. Because the test looks at what you can expect occasionally, that hotel is in scope. Across an estate of hundreds of properties, many sites will sit close to the line.
The government intends that standard tier sites can comply without buying specialist services, and I think that is right. Even so, answering the scope question needs the same thing as answering the guest security question. You need a consistent, current picture of every property.
What a portfolio view of hotel security risk would look like
In practice, I think a useful portfolio view would do six things well:
- Ask every site the same questions. Cover room access and key issue, escalation, night staffing, CCTV and access control, training and event capacity. The people who run each property can answer them, without a specialist on site.
- Roll it up for leadership. Show one view across the estate, by brand, region and site, in language a board can act on.
- Highlight the exceptions. The value lies in surfacing the twenty sites that need attention, not confirming the four hundred that are fine. Specialist time can then go to those sites first.
- Look beyond the physical. Include procedures, people, guest data and systems as well as locks and cameras.
- Track it over time. Policies change, staff move on and sites change use, so a one-off audit soon goes stale.
- Answer the compliance questions too. Show which sites are in scope for Martyn’s Law, which tier, and on what evidence.
How HawkSight approaches it
We have built this kind of capability at HawkSight for other sectors. Our Gateway tool gathers structured site data from the people on the ground. Alongside it, HawkSight’s enhanced threat intelligence capability draws on more than 750 global news and intelligence sources. It assesses the adversarial threat at each individual site and maps it against the key assets the hotel depends on. It then sets out the controls needed to mitigate it.
Together, these give leadership both halves of the picture. First, what the threat is at each property. Second, whether the controls to meet it are actually in place.
Right now, I am exploring whether hotel operators want a version of this built for their estates. After all, guests trust a hotel with their safety, and shareholders trust leadership to protect the brand. Do you not owe both of them that picture?
I would like to hear from you
If you are responsible for security, safety or risk across a hotel portfolio, I would value your view. What would you want a single view of security risk across your properties to tell you? And what gets in the way of having one today?



