Empowering Exceptional Hospitality Environments
CIOREVIEW >> Media & Entertainment >> NEWS

Vice President of Information Technology

Francis Nunziata

Empowering Exceptional Hospitality Environments

Francis Nunziata
Francis Nunziata, Vice President of Information Technology

In an interview with CIOReview, John Diaz, Francis Nunziata, Vice President of Information Technology at Oxford Collection Hotels, highlights the latest trends in the hospitality space and how innovations are supporting hotels in exploring tech-driven opportunities for boosting customer experiences and administrative processes. 

Could you talk to me about your key roles and responsibilities?

I'm the Vice President of Information Technology for Oxford Collection, a hospitality company managing 17 hotels spread out across California, Oregon, Washington, and Idaho. My primary responsibilities involve strategic planning, developing and implementing a comprehensive IT strategy aligned with our organization's goals and objectives, and providing strategic guidance on technology investments, emerging trends, and industry best practices within the hospitality sector. I am also responsible for overseeing our IT infrastructure, which includes the design, implementation, and maintenance of our network servers, storage systems, and cloud-based applications. Ensuring data security and privacy is another crucial aspect of my role, particularly regarding PCI compliance. I strive to maintain continuous compliance with PCI standards and prepare for the upcoming changes introduced by PCI 4.0. This involves implementing measures to safeguard and protect cardholder data, such as incorporating new requirements for multi-factor authentication, especially for hourly employees. Managing vendor relationships is another aspect of my role, which involves evaluating and maintaining partnerships with various vendors. This responsibility extends to financial management, budgeting, and resource allocation. I also oversee project management and stakeholder engagement, ensuring the successful execution of IT initiatives within the organization.

What according to you are some of the challenges in this space?

One of the primary concerns that constantly occupies my mind is the security and compliance aspect of our operations. Industries like retail, food and beverage, and hospitality are attractive targets for malicious actors seeking to compromise or breach sensitive information. The thought of receiving a late-night call informing me of a breach attack, or ransomware incident is my greatest fear. As a result, I prioritize staying ahead of these threats, always striving to be one step ahead of the bad actors. To address this concern, I focus on proactive measures such as employee training to ensure they possess the latest knowledge about organizational security practices. It is essential to mitigate potential threats that may enter our environment. Moreover, I actively seek opportunities to allocate additional resources and funds to enhance our cybersecurity posture as an organization, constantly looking for ways to strengthen our defenses and protect our sensitive data.

By staying proactive and vigilant, we strive to stay ahead of the game and identify potential threats to our organization before they can cause harm.

What are some of the strategies that you have implemented so far to mitigate the potential threats? 

As a hospitality company that places a strong emphasis on prioritizing our people, training our teams and staff is of utmost importance when it comes to cybersecurity. We recognize that the human element can be the weakest link, with potential vulnerabilities stemming from social engineering and other forms of attacks that exploit employees. To address this, we invest significant time and effort into providing frequent and comprehensive training beyond the minimum requirements recommended by PCI. To support our employees, we aim to offer on-demand tools that empower them to handle specific situations they may be uncertain about. Our help desk is readily available to provide quick assistance on technology or compliance-related queries. We maintain a knowledge base containing valuable articles that offer best practices for our employees. Our training and learning development department works diligently to ensure every employee receives the necessary training, tools, and guidance to identify and potentially mitigate threats, whether face-to-face or through their digital communications. We continuously explore and implement additional technologies to enhance our security measures. This includes the adoption of technologies such as single sign-on, multi-factor authentication, and advanced endpoint protection. By staying proactive and vigilant, we strive to stay ahead of the game and identify potential threats to our organization before they can cause harm.

Are there any recent initiatives that you have been working on lately? Please elaborate on the technology elements that you leverage to enable cybersecurity in your hotel, that would be great.

In addition to focusing on our people, we devote significant effort to maintaining up-to-date documentation for our teams and staff. We regularly review and update our business continuity plans, disaster recovery plans, incident response plans, and backup strategies. For example, our backup strategy follows the 3-2-1 rule, ensuring that we maintain at least three copies of our data, with two copies stored at separate locations and one copy stored offsite. To enhance our incident response capabilities, we conduct role-play sessions where we simulate potential compromises or attacks against our organization. During these exercises, we engage different individuals within the organization to determine the appropriate responses, including whom to contact and what actions to take to preserve data and maintain the chain of custody. We understand that attacks or breaches can happen to any organization, so we operate under the assumption that it's a matter of when not if. Having robust processes in place and providing training enables our team members to respond effectively and efficiently, treating these scenarios as almost second nature. This ensures that everyone understands their roles and responsibilities and responds in a manner that is best suited for the organization and the customers we serve.

What would be your piece of advice for your peers who are aspiring professionals within the space?

As organizations strive to achieve and surpass PCI 4.0 compliance, which will officially come into effect in March 2025, it is important to consider the various legal requirements that apply in different operating areas. For instance, in regions like California, where we have line-level employees who are paid hourly, there may be a need to provide a stipend for cell phone usage. This can result in significant costs. Therefore, it becomes essential to explore creative and alternative solutions that not only meet acceptable standards but also go beyond the minimum requirements of PCI. By doing so, businesses can effectively manage costs while identifying and implementing the most suitable tools that align with their specific needs and circumstances.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.