Row wavy Shape Decorative svg added to bottom

Your Winter Security Checklist: Small Steps That Make a Big Difference

Winter is a good time to take stock. The team gets a breather, and there's finally a moment to look after the things that often get pushed to the back of the queue. Security is usually one of those things.
Seekom Winter Checklist

It doesn't have to be complicated. A few simple habits go a long way towards keeping your property and your guests safe online. So here's a quick checklist. Run through it with your team and you'll be in good shape going into the busy season.

Clean up your user accounts:

This is the one most properties skip, and it's probably the most important. Had a staff member leave in the last six months? A seasonal worker who came and went? Log into your Seekom account and check who still has access. Old accounts that are no longer in use are an open door, and one that's easy to close.

While you're there, make sure every team member has their own individual login. Shared logins might feel convenient, but they make it impossible to know who did what, and they're much harder to secure.

Switch on Two-Factor Authentication:

If you haven't already enabled Two-Factor Authentication (2FA) on your Seekom account, winter is the perfect time to sort it out. 2FA means that even if someone gets hold of a team member's password, they still can't get in without a second verification step. It's one of the simplest and most effective things you can do to protect your account, and it takes about five minutes to set up.

Our support team is happy to walk you through it. Just give us a call or drop us a message during business hours.

Stop sharing passwords:

We know, we know. It's easier to just tell the new person the password. But shared passwords are one of the most common ways accounts get compromised.

The good news is there's no reason to share passwords in Seekom. Every account can have unlimited individual users, so everyone gets their own login with their own access level. Set it up once and you'll never need to share a password again.

Update your passwords, not just your staff list:

Removing old user accounts is step one. But if a former team member knew your passwords, changing the locks matters too. Go through your key systems - your PMS, email accounts, OTA extranets, social media, and update any passwords that might have been shared with someone who’s no longer with you.

While you're at it, make sure passwords aren't being reused across different platforms. If one account gets compromised and the password is the same everywhere, the damage spreads fast. A password manager can take the headache out of keeping track of them all.

Tighten up your email security:

Your email account is the key to the kingdom. If someone gets into it, they can reset passwords for pretty much everything else. Yet email is often the last thing people think to protect.

A few quick wins:

  • Enable two-factor authentication on your business email account, not just your PMS
  • Check who has access to shared inboxes like info@ or reservations@ and remove anyone who no longer needs it
  • Be careful about what you include in automated guest emails. Avoid putting full booking reference numbers or personal details in subject lines where they can be easily read
  • If you get an email that looks like it's from a supplier or OTA asking you to update payment details or click a link, call them directly to verify before doing anything

Watch out for phishing emails:

Phishing is when someone sends you an email pretending to be a trusted source, trying to get you to hand over your login details or click a dodgy link. It happens more than you'd think in the accommodation industry.

The recent Booking.com breach is a good example of how this plays out. Once scammers had real guest data, including booking details and contact information, they used it to send convincing messages that looked like they came from a legitimate source. Guests were contacted via WhatsApp and email and asked to verify their payment details.

A few things to remind your team:

  • Seekom will never ask for your password by email or phone
  • If an email asks you to click a link and log in, go directly to the website instead of clicking
  • When in doubt, call the company directly using a number you already know
  • If something feels off, it probably is. Trust your gut and check with us

Review what data you're collecting from guests:

Take a look at your booking form and ask yourself: do we actually need all of this? A lot of properties collect more than they need. Dates of birth, passport numbers, dietary requirements for a property that doesn't serve meals. The less guest data you hold, the less there is to lose if something goes wrong.

Strip your forms back to what you genuinely use. It's better for your guests, better for your liability, and it makes your life simpler too.

Make sure your payment setup is secure:

If you're taking online payments, it's worth checking that 3D Secure (3DS) authentication is active on your SeekomPay setup. It adds a bank-level verification step for cardholders, which reduces fraud and protects your revenue from chargebacks.

Not sure if you have it switched on? Drop our support team a message and they'll check for you.

Start with whatever feels most overdue for your property. Even ticking off one or two things from this list will put you in a stronger position than you were yesterday. And if you need a hand with any of it, our support team is here. Give us a call or flick us a message and we’ll help you get sorted.

undraw_wireframing_nxyi (2) (1)

Note: Something you may not know is that we also build websites. Many of our customers have Seekom-built, self managed websites with full control, backed by our expert setup and support. If you’re interested in finding out more, please get in touch.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)

Why two-factor authentication is essential for accommodation providers

A recent high-profile cyberattack on a major international hotel group serves as a stark warning about the vulnerabilities in our sector and the critical need for proactive security measures.

Having robust cybersecurity in place has become a necessity in today’s accommodation industry, largely due to the vast amount of guest data stored digitally on internet-connected devices and servers.

While there’s no silver bullet for cyber security, measures such as two factor authentication (2FA) - which requires people to use two different means of verifying themselves when logging into a secure system – can significantly reduce the risk that your business being compromised.

Seekom blog graphic _why 2FA is essential

A wake-up call for the industry

A major hotel group, which operates around 80 hotels across seven brands throughout New Zealand, Australia and Europe, experienced a significant cyberattack in March and is working through the recovery process – highlighting the complexity of restoring compromised systems.

The impact of the cyberattack has been far-reaching and severely disrupted the hotel group’s normal business operations.

  • Offline communication and booking systems: Core booking and communication platforms were forced offline, leaving staff unable to access guest information or process reservations normally.
  • Manual workarounds: With digital systems compromised, staff had to implement manual workarounds, creating a surge in customer service inquiries that put significant pressure on staff whose resources were already stretched thin.
  • Inability to process online payments: Online payment-processing systems were disabled, forcing staff to rely on manual payment methods – adding a layer of friction to the guest experience.
  • Compromised booking information: Questions around the integrity of guest data created challenges in service delivery.

The recovery process continues

The fact that the hotel group is still working to fully restore its systems emphasises the damage cyberattacks can cause and underscores that prevention is better than cure when facing sophisticated online threats.

How two-factor authentication can protect your business

Implementing two-factor authentication is a powerful way to boost cybersecurity and is one of the most effective steps accommodation providers can take to protect their data from malicious cyber threats.

  • Extra online armour: 2FA requires two forms of verification before access is granted, making it harder for unauthorised users to access your systems.
  • Safeguarding sensitive information: With the wealth of personal and financial data handled by accommodation providers, 2FA helps ensure this information remains protected from security breaches.
  • Minimising potential damage: With 2FA in place, it becomes considerably more difficult for bad actors online to cause substantial business disruption.

Staying ahead of industry standards

While many of our competitors may not yet have adopted 2FA, the increasing frequency and sophistication of cyberattacks make its implementation critical. Such measures will soon become standard practice. Waiting until after an incident occurs can lead to significant operational disruption, financial losses and reputational damage – not to mention upset guests.

A proactive approach to security

This industry cyberattack is an unfortunate example that reinforces the need for businesses to have robust cybersecurity measures in place to avoid the pitfalls of operating in today’s complex digital landscape. By implementing 2FA, accommodation providers can help safeguard their operations, protect guest data and maintain the trust that forms the foundation of the hospitality business.

At Seekom, we’re committed to providing the tools and support you need to operate securely online. This is why we will be rolling out a phased implementation of mandatory 2FA from 20 May, as an important step in our ongoing efforts to protect your business and your guests.

Rest assured, our support team is on hand to answer any questions you might have and help you implement 2FA smoothly.

When it comes to cybersecurity, being proactive isn’t just good practice – it’s good business.

Ready to get started?

We encourage you to opt in to 2FA as soon as possible rather than waiting until it becomes mandatory. Early adoption allows your team to become familiar with the new login process at a time that suits you.

Thank you for partnering with us in creating a more secure environment for your business and guests. Together, we're taking an important step forward in protecting what matters most.

If you have any questions about the 2FA implementation process, please read our 2FA user guide or contact our friendly support team.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)

Two-factor authentication now available for Seekom users

We're thrilled to announce that two-factor authentication (2FA) is now available for all Seekom users! This important security enhancement is a significant step forward in our commitment to protecting your business data and your guests' information.

Two-factor authentication now available for Seekom users

Opt-in available now

Starting today, you can enable 2FA for your Seekom account by simply filling out this form and submitting it to our support team. Once activated, 2FA will apply to all staff set up as users within your account, providing comprehensive protection across your entire team.

The opt-in period will run for just over one month and gives you the flexibility to implement 2FA at your convenience. You can choose when best to activate it based on your property's schedule and staff availability, ensuring a smooth transition.

2FA starts becoming mandatory from 20 May

While 2FA is currently optional, it will begin to become mandatory for all Seekom accounts from 20 May onwards to keep you, other clients and guests as secure as possible and futureproof online security. This rollout will happen in tranches, becoming mandatory for some accounts slightly earlier than others. The opt-in period currently underway gives you several weeks to prepare your team and implement the change when it works best for you.

Why 2FA is necessary

In today's digital landscape, 2FA has become standard practice to safeguard companies’ data across all types of industries and protect them from the reputational damage that data breaches can cause. Businesses worldwide are choosing to adopt this critical security measure to protect sensitive information and prevent it from falling into the wrong hands.

By requiring a second verification factor beyond just a password, 2FA creates a substantial barrier against unauthorised access. This is particularly important for accommodation providers, which handle guests' personal and financial information daily, including banking information such as credit card details.

Setup is simple

Implementing 2FA is easy and straightforward for users. After downloading either the Google Authenticator App or Microsoft Authenticator App on their smartphone, all they need to do is scan a QR code from your Seekom account and 2FA will be activated.

Once set up is complete, each user will need to use both their password and a time-sensitive code from their authenticator app to log in to your system. View our 2FA user guide for more information.

Preparing your team

If you haven't already done so, now is an ideal time to ensure all your staff have their own individual Seekom logins – to make this easy we include unlimited user accounts with all plans.

Setting up individual logins prepares you for 2FA implementation and also improves accountability by tracking which team member performs specific actions in your system. To find out how to set up staff logins check out our handy guide.

Ready to get started?

We encourage you to opt in to 2FA as soon as possible rather than waiting until it becomes mandatory. Early adoption allows your team to become familiar with the new login process at a time that suits you.

Thank you for partnering with us in creating a more secure environment for your business and guests. Together, we're taking an important step forward in protecting what matters most.

If you have any questions about the 2FA implementation process, please read our 2FA user guide or contact our friendly support team.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)

Enhancing your security: Two-factor authentication coming soon to Seekom

Get ready for a significant security upgrade! We're excited to announce that two-factor authentication (2FA) will be rolling out to all Seekom users in the next quarter. This enhancement will help protect both your business and your guests' information with minimal effect on your operations.

Seekom Ready for 2FA blog image

What is 2FA?

2FA is a security protocol that requires two forms of verification to be provided before access is granted to a user account or system – like requiring two keys to unlock a door rather than just one. This added layer of security ensures that only authorised users can gain access, even if someone else knows the password.

Why does it need to be done?

Enabling two-factor authentication (2FA) is important because it adds an extra layer of security to your account, making it much harder for unauthorised users to gain access:

  • Strengthens security: 2FA requires two forms of verification - typically something you know (your password) and something you have (like your smartphone or an authentication app). Even if someone steals your password, they can’t access your account without the second factor.
  • Protects against phishing: Phishing attacks can trick you into revealing your password, but with 2FA, even if your password is compromised, the phisher would still need the second factor to complete the login.
  • Prevents account takeovers: With the extra layer of security, 2FA greatly reduces the chances of hackers taking over your account, especially when passwords are shared or reused across different sites by different people.
  • Safeguards sensitive information: For accounts holding sensitive information – such as guests’ personal information, bank details and emails – 2FA helps prevent unauthorised access that could result in identity theft, financial loss, or privacy breaches.

2FA is a simple and effective way to significantly improve your online security and protect both your and your customers' personal information, as well as limit the chance of reputational damage to your business.

Setting up 2FA is quick, easy and typically takes less than five minutes per user. Each user on your Seekom account will just need to download either the Google Authenticator App or Microsoft Authenticator App on their smartphone, scan a QR code from your Seekom account, and they’ll be ready to go with an extra layer of security armour protecting your data.

We regard 2FA as such an essential part of our online security approach that all Seekom staff are required to use 2FA and cannot access our Seekom iBex system without it.

Rest assured we will try to make the upgrade to 2FA go as smoothly as possible for you.

trusted PMS

What to do to get ready for 2FA?

Make sure everyone is set up with their own individual logins. We offer unlimited user logins with all our plans to make this easy (unlike some of our competitors who charge for additional users). A user guide on how to set up staff logins can be viewed here.

Having all staff set up with their own login is best practice, as it allows you to see who has done what on the system, whether making a booking, upselling an item or actioning a rate change.

2FA works for both Google Authenticator app and Microsoft Authenticator App, with each user needing access to their own smartphone to activate their unique code.

When 2FA is first rolled out it will be a ‘soft launch’, which means you’ll be able to opt in and set up 2FA at a time that’s convenient for you and your accommodation property, rather than being made to do it immediately, including potentially during peak check-in times. The opt in option will be available for a few weeks, after which it will become compulsory and will be switched on for all accounts.

For the time being we just want to make you aware of the forthcoming 2FA roll out. No action is required on your part for now, although it’s an ideal time to make sure all your staff have their own individual logins.

We’ll confirm the start date of the soft launch roll out closer to the time and will look forward to taking the next step in our mission to keep your business and the data it holds safer and more secure than ever before.

Contact Us

4/234 Wakefield Street, Te Aro, Wellington 6011
Phone (NZ) : +64 4 974 9588
Phone (UK) : +44 20 3835 5939
Support: support@seekom.com
Websites: webhelp@seekom.com

Connect With Us

 Copyright 2025 © Seekom Limited (NZ owned)