Hospitality Technology

AI Tops CISO Friction Points as Hospitality Security Budgets Inch Up

AI now tops CISO friction points at 71%, a 200+ leader benchmark shows, while security spend inches up to 0.75% of revenue and hotel operators fund AI via reallocation.

Artificial intelligence displaced ransomware and phishing as the No. 1 friction point for security leaders in 2026, cited by 71% of respondents in a benchmark survey of more than 200 CISOs across retail, hospitality, dining, and consumer-facing industries. The shift comes with only modest budget growth behind it: average security spend climbed from 0.57% to 0.75% of revenue in 2025, while average IT spend rose from 3.2% to 3.9%.

The report, drawn from the CISO Benchmark survey and examined through a hospitality lens by Hotel Business Review, describes an industry absorbing new AI-driven responsibilities without corresponding net-new funding.

AI as friction multiplier, not standalone threat

Ransomware fell 35 percentage points year over year to 34% as a cited friction point — not because the threat receded, but because CISOs increasingly treat it as an outcome of other vectors such as phishing, third-party compromise, and unpatched vulnerabilities. AI, by contrast, is a genuinely new category of uncertainty.

Three AI-related concerns dominate: data leakage through public AI tools (74%), insider misuse and shadow AI adoption (56%), and insufficient governance or usage policies (49%). In a hotel environment, those risks map directly onto guest experience platforms, revenue management tools, loyalty program integrations, and AI-assisted customer service chatbots — channels that move sensitive guest data in ways existing security controls were not designed to monitor.

The report frames AI as a friction multiplier that compounds already-existing threats, a dynamic amplified in hospitality by fragmented technology ecosystems spanning multiple properties, brands, and geographies.

Budgets grow, but AI is largely a reallocation exercise

Looking ahead, 54% of CISOs expect security budget increases in 2026, up from 44% the prior year. The primary drivers are company performance, routine annual adjustments, and digital transformation initiatives; incident-driven funding remains rare, a signal that security investment is becoming programmatic rather than reactive.

The AI budget picture carries a catch. Nearly 90% of CISOs expect AI-related security spending to rise over the next 12 to 18 months, with 43% anticipating significant increases. Yet 42% report AI investments won't meaningfully change their overall security budget, and 28% plan to fund AI priorities by reallocating existing dollars.

Some security leaders are managing the squeeze by pushing compliance-heavy budget items — routine PCI-DSS or privacy compliance assessments, for example — onto individual business unit or property budgets. That stretches security dollars without formally growing the core budget, though the report characterizes it as a workaround, not a permanent solution.

Role expansion and structural friction

AI governance is now formally in the CISO job description for 70% of respondents. Ownership is also extending into third-party risk management, business continuity, product security (up eight percentage points year over year), and enterprise risk management — while traditional IT duties such as network security, compliance, and infrastructure remain on the plate.

Structurally, 81% of CISOs still report through a technology function: 40% to the CIO, 27% to the CTO. The report flags one caveat — a CISO who is a peer to the CIO should share the same manager, or conflict escalation becomes unwieldy.

Execution barriers are organizational, not technical. Seventy percent of CISOs point to tensions between cyber and IT prioritization; 68% cite budget constraints. For hospitality operators, where property management systems, point-of-sale infrastructure, guest-facing technology, and building systems are deeply interwoven, that friction is especially acute.

Stable headcount, AI-driven productivity

Security staffing will hold largely steady in 2026. While 35% of CISOs plan to grow full-time staff, the dominant posture is stability. CISOs view AI as a way to extract productivity from existing teams, not shrink them. The highest-return applications: threat detection and analysis (63%), generative AI for reporting (53%), and incident response automation (44%).

Contractors face a different outlook. Twenty percent of CISOs project cuts to contractor staff in 2026, most pronounced at larger enterprises — a dynamic worth monitoring for hotel companies that historically lean on contract security labor.

The governance gap

With 81% of organizations at least partially implementing AI governance frameworks, adoption has moved quickly — but formal policies haven't eliminated the underlying risks. Data leakage and insider misuse concerns persist even where frameworks are fully implemented. Hotel companies deploying AI in guest services, revenue management, or workforce tools need governance designed for those specific use cases rather than generic enterprise policies.

The report's practical prescription: audit existing vendor contracts for underutilized AI capabilities, prioritize high-return applications like threat detection and automated compliance workflows, and use the benchmark's spending and staffing ratios in board conversations — sector-specific comparisons that hotel security leaders have historically lacked.

Success in 2026, the report concludes, will depend not on budget windfalls but on smart reallocation, cross-functional partnerships with operations, and property-level governance.

hotel-technologycybersecurityaidata-securityit-budget

More from Elena Vasquez

Elena Vasquez

Show full bio

News editor covering industry trends and analytics at The Pass Brief.

88 articles

Pairings

« Previous article