A Disturbing Reminder of a Systemic Problem
A BBC News article today reported a shocking breach of trust at a hotel in Maidenhead. In December 2022, a lone female guest was sexually assaulted after hotel staff issued a room key to a complete stranger who claimed to be her boyfriend. The case has only just reached sentencing, more than three years later, and yet the hotel’s response was to assert that staff had “followed security protocols.”
This statement alone should alarm anyone concerned with guest safety. No security protocol, if designed and implemented correctly, should ever allow hotel staff to hand a spare key to an unverified individual, especially when a lone female traveller is the only registered occupant of that room. At a minimum, staff should have checked with the guest directly, either by calling her room or knocking on her door. That this did not happen shows a failure not only of execution, but of the underlying system itself.
A Pattern the Industry Has Failed to Learn From
Sadly, these incidents are not isolated.
In 2014, business traveller Cheri Marchionda was staying at a hotel in Des Moines, Iowa. After she rejected a man’s advances in the hotel bar, she later awoke to find him in her room. He then violently assaulted her over several hours.
Police later discovered that the man had requested and been given a key to her room without being asked for proof that he was a registered guest. When he struggled to enter due to the safety latch, he persuaded a maintenance worker to disable it. The worker let him in, unaccompanied.
Cheri openly shared her identity in the hope of driving change in hotel security. Yet more than a decade later, her advocacy appears to have gone unheeded. The latest case mirrors hers almost exactly.
Hotel Responses that Miss the Point
The hotel chain told the BBC that staff had followed the “correct security procedures” and that they continue to train staff accordingly. But nowhere in their statement is there any indication that those procedures have been reviewed or strengthened in the wake of the incident.
For any organisation concerned with risk, failing to learn from such an event is itself a serious risk.
Why Brand Standards Don’t Guarantee Real Security
All major hotel chains have security brand standards, tailored to their portfolio and the perceived risk of their locations. But here lies a fundamental flaw in how the industry operates:
Most chains do not actually own or run the hotels that carry their name.
Owners are responsible for installing and paying for security measures. Operators are responsible for day-to-day implementation. Both decisions are often commercially driven, not risk-driven.
In my eight years developing global security standards, designing hotel security master plans, and advising on travel risk management, I’ve seen both exceptional examples and shockingly poor ones. And I can say with confidence:
Good brand standards on paper do not guarantee good security in practice.
Too often, hotel security becomes a “smoke and mirrors” exercise, high-end branding creating the illusion of high-end security, while basic measures remain inconsistently applied.
5 Things that Need to Change
- The industry needs a cultural shift. We must stop viewing security as a cost centre and start seeing it as a value generator -protecting revenue, reputation, and guest trust. Reframing security as a commercial advantage, not a financial burden.
- Learning from incidents instead of repeating them. The current pace of social, economic and technological change means that security brand standards can become obsolete much more quickly, so it is vital that they are regularly reviewed. However, they should also be reviewed in the light of an incident that directly impacts them, building the learning from those incidents into revised policies and procedures.
- Bridging the gap between written policies and operational reality. Organisations that regularly test and exercise their security policies, procedures and processes generally have better operational outcomes when reality hits during a live incident. Hotels need to regularly conduct table-top exercises and at least one live exercise annually to test reactions, decision making, response and stakeholder relations.
- Greater influence from corporate travel teams. Corporate travel teams, who put their duty of care obligations above commercial considerations (in line with ISO 31030:2021 Travel Risk Management - Guidance for Organisations) need to push hotels to meet higher, independently verified security standards.
- Consistent implementation of minimum standards, regardless of ownership structure. As an industry, we need to develop minimum security standards for hotels, which are cost-effective and promote guest safety, no matter who owns or operates the hotel. Ensuring that hotel chains are able to consistently implement those minimum standards across their portfolios.
Conclusion: The Illusion of Safety Must End
Until hotels treat security as a core operational responsibility, not a branding exercise, guests will remain vulnerable. Security measures must be robust, consistently applied, and designed with the realities of human behaviour and risk in mind.
Brand standards alone are not enough; real protection comes from real-life accountability.
