The Pacific Grove threat picture
Hospitality is a frequent target because it combines payment-card data with seasonal, high-turnover staff: a mix that invites point-of-sale compromise and social engineering. Inns and B&Bs run booking and guest systems that hold personal and card data year-round, with exposure that spikes during summer season and event weekends when seasonal staff are onboarded quickly and access is granted without time for proper vetting. A single credential in the wrong hands can expose an entire season's worth of guest records.
Small professional offices along Lighthouse Avenue face a different version of the same problem. One person often handles email, billing, scheduling, and bookkeeping. A business email compromise attack does not need to defeat a complex network. It needs one inbox, one wire transfer, one invoice changed. That is a realistic attack against a very small PG practice, and it is entirely preventable.
The controls that stop both scenarios are a proven set: PCI-aware point-of-sale security, segmented guest Wi-Fi, phishing-resistant MFA, managed detection and response, and cloud backup. In a town this small, the other requirement is discretion. On-site visits are scheduled around your hours, and we do not discuss client details. That standard came from operating inside DoD networks; it travels with us.