Domes Resorts & Reserves operates a portfolio of five-star properties across Greece and Portugal, structured around distinct brand tiers: Domes Reserves (landmark luxury escapes), Domes Originals (refined lifestyle resorts), Domes Noruz (adults-only, design-led), and Domes Finds (concept-driven stays). Founded in 2008, the group was named World's Leading Resort Brand for 2025 and has received multiple Michelin Keys for properties including Domes Zeen Chania and Domes White Coast Milos. It partners with major hospitality groups like Marriott and Hilton and is pursuing an ambitious expansion strategy.
The attack surface here is non-trivial. You're defending a network that spans multiple resort properties across two countries, each one a convergence point for guest PII, payment processing, booking integrations with major global platforms, physical access control systems, and operational technology tied to building management. The threat model includes credential stuffing against loyalty and reservation portals, supply-chain risk through partner API integrations (Marriott, Hilton), and data exfiltration vectors across a hospitality vertical that's been a persistent target for financially motivated actors.
Security operations in a hospitality environment like this demand fluency across PCI-DSS compliance for payment infrastructure, endpoint protection across hundreds of guest-facing and back-of-house systems, and network segmentation between corporate, guest, and IoT layers - smart locks, HVAC controllers, and property management systems don't need to talk to each other or to the internet. If you've architected defense-in-depth for a distributed physical footprint where the perimeter is a hotel lobby and the credentials are room keys, this is the scale of problem you're solving.






