As part of a settlement with the U.S. Federal Trade Commission (FTC), Marriott International and Starwood Hotels & Resorts have been ordered to implement information security programs. This follows the companies’ three major data breaches that affected millions of customers globally.
Required Security Procedures
The hospitality group is required by the FTC’s order to designate a program leader. Also, provide regular updates on the program’s success, and record its execution at predetermined intervals.
Employees must also receive frequent training in order to protect the private information kept on the company’s IT systems. The creation and upkeep of written incident response plans is one of the specific requirements for security and IT teams.
Specific requirements for IT and security teams include:
- Developing and maintaining documented incident response plans.
- Enforcing multi-factor authentication for remote access.
- Implementing robust logging and monitoring systems.
- Practicing strong security hygiene.
- Enhancing protections for customer data storage.
The order also emphasizes the importance of careful selection of vendors to ensure third-party compliance with the group’s security standards.
Allegations and Breaches
The FTC alleged that Marriott and Starwood misrepresented their data security measures. They failed to adequately protect customers’ personal information. The breaches compromised sensitive data such as passport details, payment card numbers, and loyalty account information, impacting approximately 344 million customers globally.
The FTC stated that security failures resulted in at least three separate data breaches, allowing malicious actors to access vast amounts of personal information.
This settlement serves as a reminder of the critical importance of rigorous data protection practices in safeguarding customer information.


