BWH Hotels, headquartered in Phoenix, Arizona, runs one of the world's largest hospitality networks - approximately 4,300 properties across more than 100 countries, operating under 18 brands including Best Western Hotels & Resorts, WorldHotels, and SureStay Hotels. Founded in 1946 and still privately held, the company uses a franchise model where each property is independently owned and operated, which means the attack surface isn't a centralized data center so much as a sprawling, heterogeneous federation of endpoint POS systems, reservation platforms, and guest Wi-Fi networks.
The threat model here is hospitality-classic: high-volume PII and payment card data flowing through systems that must stay PCI DSS compliant while serving millions of guests. The franchise structure means security architecture has to scale across independently operated properties while enforcing consistent standards - identity and access management, network segmentation, and incident response all need to work whether the target is a flagship resort or a roadside SureStay. There's no single corporate IT stack to defend; there's a governance problem layered on top of a technology problem.
For a security team, that translates into work spanning policy enforcement across a global franchise network, vendor risk management, compliance operations, and the practical challenge of hardening infrastructure that spans over a century of combined hospitality experience and nearly 80 years of organizational history. The company reports top-ranking employee engagement scores and emphasizes continuous innovation, but the real operational question is how you lock down a distributed footprint this wide without strangling the independently owned operators who depend on uptime and guest experience.






