Scoring Framework
We score hospitality networks across eight critical pillars, providing a clear 0–10 rating for each. Scores are evidence-based: 2/10 means measurable capacity crisis (338 devices per AP); 1/10 means exploitable security gap (no VLAN segmentation, default credentials active). The result: a one-page scorecard showing strengths, risks, and a prioritized improvement plan with costs and ROI projections.
1. RF Design & Capacity
Wireless architecture aligned to actual device density and usage patterns. We measure device-to-AP ratios (healthy: 50-100 clients/AP; critical: 300+), channel planning (2.4 GHz has only 3 non-overlapping channels; 5 GHz with DFS gives 23), AP placement strategy (high-density venues need many low-power APs close to clients, not few high-power APs for coverage), band steering effectiveness (push clients to 5 GHz to reduce 2.4 GHz congestion), and sustained throughput per client at peak occupancy (target: 3-6 Mbps sustained). Poor scores indicate capacity bottlenecks, interference from neighboring networks or on-premises equipment (microwave ovens on 2.4 GHz), or coverage gaps.
2. Segmentation & Least Privilege
Network isolation protecting critical systems from guest traffic and vendor access. We audit VLAN separation for Guest Wi-Fi, PMS/POS systems, IoT devices (smart TVs, thermostats, locks), vendor access networks, and back-office systems. Score 1/10 means flat network with no segmentation—guest devices can reach PMS systems directly. Score 8-10 means defense-in-depth: VLANs enforced at switch level, inter-VLAN routing restricted by firewall rules, vendor access limited to specific systems with session logging. We check for VLAN sprawl (too many VLANs = management burden) and verify that POS/PMS isolation is actually enforced, not just documented.
3. ISP/WAN Resilience
Internet connectivity architecture and failover capability. Single-ISP deployments score 4/10 at best—they're a single point of failure causing multi-hour outages when the ISP has issues (6-hour outage examples exist in resort deployments). Dual-ISP with manual failover scores 6-7/10 (requires human intervention). Dual-ISP with automatic SD-WAN failover scores 9-10/10 (sub-minute cutover, zero guest impact). We evaluate ISP diversity (are both ISPs using the same last-mile infrastructure?), bandwidth sizing for peak load, and DDoS posture. Coastal and remote properties face additional challenges—limited ISP options, weather exposure, and higher failure rates.
4. Monitoring & Alerting
Visibility into network health and performance with actionable alerts. We assess dashboard coverage (uptime %, peak concurrent clients, sustained throughput per device, failed authentication attempts, ISP failover events), SLO calibration (are targets realistic for property type?), alert tuning (actionable vs. noise), and incident response readiness. Score 2-3/10 means no monitoring—problems only discovered when guests complain. Score 8-10 means proactive detection: capacity trends predict exhaustion before it happens, failed auth spikes catch intrusion attempts early, and ISP degradation triggers failover before guests notice. Monthly reporting summarizes trends and capacity planning needs.
5. DNS & Name Services
DNS infrastructure for reliability, privacy, and basic security. We evaluate resolver choice (ISP default, public resolvers like Cloudflare/Quad9, or on-premises forwarding), malware/phishing domain blocking capability (DNS-layer filtering can block known-bad domains before guests reach them), DNSSEC validation (prevents DNS spoofing attacks), privacy considerations (who sees guest DNS queries?), and resilience (what happens when primary DNS fails?). Score 3-4/10 means relying on ISP defaults with no filtering or failover. Score 9-10 means privacy-respecting resolvers with malware blocking, DNSSEC validation, and redundant configuration. Balance security with guest privacy—don't over-log DNS queries.
6. Logging, Retention & Privacy
What data is collected, how long it's kept, and how it's protected. We audit authentication logs (failed/successful logins—useful for security but contain guest identifiers), DHCP lease logs (MAC-to-IP mapping—necessary for abuse response but privacy-sensitive), flow/session logs (bandwidth usage patterns), vendor access logs (who accessed what, when), and retention policies. Score 2-3/10 means either no logging (can't investigate incidents) or excessive logging with indefinite retention (privacy violation, GDPR risk). Score 9-10 means purposeful logging: collect what's needed for security and incident response, auto-purge on schedule (30-90 days typical), encrypt logs at rest, and restrict access to authorized personnel only.
7. Documentation & Vendor Access
Network documentation quality and vendor access governance. We review network diagrams (up-to-date? include VLANs and IP ranges?), equipment inventory (make/model, firmware versions, warranty status, support contacts), configuration backups (automated? tested restore process?), change logs (who changed what, when, why?), and vendor access controls. Score 2-3/10 means no documentation—network knowledge exists only in one person's head, and vendor credentials are shared/unchanged for years. Score 9-10 means living documentation updated with every change, vendor access is time-bound (not persistent), credential rotation happens quarterly, and all vendor sessions are logged. Prevents the situation where vendor makes undocumented change, then can't remember what they did when troubleshooting later.
8. Openness & Vendor Lock-in
Use of open standards, interoperable solutions, and vendor lock-in assessment. We evaluate reliance on proprietary protocols (can you switch vendors without forklift replacement?), configuration portability (are configs exportable in standard formats?), API access (can you automate monitoring/changes?), multi-vendor support (single-vendor monopoly vs. best-of-breed), and total cost of ownership including licensing. Score 3-4/10 means deep vendor lock-in: proprietary APs only work with proprietary controller, configs aren't portable, no API access, annual licensing costs escalate. Score 9-10 means open standards (802.1X, RADIUS, SNMP, syslog), configuration as code, vendor-neutral where practical, and exit strategy documented. Doesn't mean avoiding commercial products—means choosing solutions that don't trap you.
Assessment Deliverables
One-page color-coded scorecard: each pillar scored 0-10 with visual indicators (red <4, yellow 4-6, green 7-10). Executive summary translates technical findings to business risk: Security 1/10 = 'POS systems accessible from guest Wi-Fi', Capacity 2/10 = 'Network will fail at 60% occupancy', Reliability 4/10 = 'Single ISP means multi-hour outages inevitable'.
Key risks explained in plain language with real-world consequences: 'Unchanged vendor password for 8 years means any former vendor employee can access your PMS remotely', 'No ISP failover means lost revenue during 6-hour outage at peak season', 'Microwave interference drops guest Wi-Fi to unusable during breakfast service'.
Prioritized roadmap with three tiers: Quick wins (0-30 days, €0-500, high impact)—change Wi-Fi channel away from microwave, rotate vendor credentials. Critical fixes (30-90 days, €5k-20k)—add VLAN segmentation, deploy monitoring, add ISP failover. Strategic upgrades (90+ days, €20k-100k)—high-density Wi-Fi refresh, multi-property centralization, environmental hardening. Each item includes cost estimate, timeline, expected outcome metrics, and ROI justification.