TUI InfoTec GmbH is the technology arm behind TUI Group, the world's largest integrated tourism operator. The attack surface here is substantial: 125 aircraft, 18 cruise ships, over 460 hotels, and 1,600 travel agencies spread across 21 source markets and 180 destinations. That's a sprawling, high-value target environment spanning airlines, maritime operations, hospitality networks, and retail endpoints - each with distinct threat models from payment card fraud and credential stuffing to OT/ICS risks on ships and aircraft systems.
With nearly 67,000 employees worldwide, the organization operates across tourism, airline, cruise, and hospitality verticals. Security teams working in this context aren't just defending a corporate network; they're protecting reservation platforms, loyalty systems, crew and guest PII at scale, and operational technology that moves people across borders. The interconnected nature of the business - a booking made in one source market triggers logistics across airlines, hotels, and destination services - means lateral movement and third-party risk are persistent concerns.
TUI InfoTec is tasked with building and securing the technology stack that ties this complexity together. The company has committed to Science Based Targets for reducing its environmental footprint, and emphasizes values of being Trusted, Unique, and Inspiring. For security practitioners, the draw is the breadth of domains under one roof: cloud infrastructure, identity management, application security, and OT security across maritime and aviation contexts - each demanding different tooling, compliance regimes, and operational cadence.






