What we covered on the Terrace
The travel industry's threat landscape is evolving faster than most businesses can keep pace. At this year's TTI Summer Forum, John Howell (CEO, HowTech) and Mark Thompson (CIO, Palatinate Group) explored what realistic, business-aligned cybersecurity actually looks like for the organisations that power UK travel – without unlimited budgets or a 20-person security team.
Here's a summary of the four threads we covered, and why each one matters for your business right now.
Protecting personally identifiable information
Passport data, payment details and itineraries are among the most sensitive records any business handles. We looked at where the real risks sit in a modern booking flow — and how to reduce blast radius when something goes wrong.
Securing the booking & payment ecosystem
Travel rarely runs on a single system. Tour operators, OTAs, GDS connections, payment gateways and channel managers all share data. We explored how to harden these integrations without strangling the business.
GDPR, PCI DSS and global privacy obligations
UK GDPR, PCI DSS and a growing patchwork of international privacy regimes all apply at once. What does 'good' look like for an SME-sized travel business that can't staff a compliance team? We gave a practical answer.
Threat intelligence & incident response
Travel is a heavily targeted sector. We covered sharing threat intelligence across the industry, building an incident response plan your team will actually use, and what zero-trust really means in a multi-supplier environment.
Travel runs on trust. A single breach can erase years of brand-building overnight. Good security isn't a tax on innovation – it's what makes innovation possible.
The Travel Cybersecurity Checklist 2026
A practical, no-jargon guide to protecting your booking platform, customer data and payment flows — built for travel businesses that need real-world answers, not theoretical frameworks.
What's inside
- A step-by-step checklist covering PII protection in live booking flows
- The five most common vulnerabilities in travel supplier integrations
- A one-page PCI DSS readiness checklist for SME travel businesses
- Red flags that tell you your incident response plan won't hold up
- A zero-trust primer: what it means in a GDS-connected environment
Enter your details to get your FREE checklist
Win a FREE Cyber Essentials assessment
Everyone who completes the checklist above is automatically entered into our prize draw.
The prize: A full Cyber Essentials certification assessment for your organisation, conducted by HowTech – including gap analysis, technical review and certification submission support.
Value: up to £1,500.
The draw: One winner will be selected at random and contacted by 1 September.
Terms & conditions apply. UK businesses only. One entry per organisation.
Built by people who've done it at scale

John Howell founded HowTech after a career building and running travel technology for some of the UK's biggest names. As CEO of Multicom Products, he led the team behind FindandBook (FAB) — the booking platform that processed over £1.5 billion in annual transactions and powered half the UK travel market, with customers including Thomas Cook, TUI and LoveHolidays.
That background shapes how HowTech approaches security. We've seen what happens when booking platforms fail, when payment integrations get compromised, and when incident response plans turn out to be theoretical. We build defences that hold up in the real world, for businesses that can't afford to learn through a breach.
Ready to talk?
If there's a specific challenge you'd like to think through – whether it's a security assessment, an architecture question or a supplier integration you're not sure about – book a FREE 20-minute call with one of the team
No pitch. No preparation needed on your part. Just a conversation.
Book a FREE 20-minute call with one of the team