商务支持

技术支持

About Guangxun

关于光迅

Ministerial Order No.176 Strengthens Cybersecurity Primary Responsibilities of the Accommodation Industry; All-Optical Networks Build a Solid Compliance Foundation
2026-09-17 17:52:18 60

Ministerial Order No.176 Strengthens Cybersecurity Primary Responsibilities of the Accommodation Industry; All-Optical Networks Build a Solid Compliance Foundation

“Many enterprises believe they are only victims when their websites get hacked. In fact, failure to fulfill security protection obligations itself constitutes an illegal act.”

These remarks were made by a police officer from the Cybersecurity Brigade of Jingkai Branch of Deyang Public Security Bureau. In July 2026, an e-sports hotel in Deyang was given a warning, ordered to rectify within a time limit and fined 10,000 yuan for “lack of technical protection measures and failure to record cybersecurity incident logs as required”. During the same law enforcement round, an incubation center was illegally breached due to weak passwords in its backend system. The Deyang Public Security Bureau stated plainly in its notice: “Weak passwords, unencrypted transmission and missing logs all count as typical ‘unprotected network exposure’.”

The e-sports hotel in question was not completely unprepared — it had implemented real-name authentication. The flaw lay elsewhere: real-name verification was in place, yet logs could not be properly retained.

Effective October 1, 2026, Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs (Ministerial Order No.176) officially came into force, replacing Order No.151 concurrently. For the hotel industry, this marks the transition of cybersecurity management from “advisory compliance” to “mandatory compliance”.

I. Three Major Upgrades of Order No.176: Redefining Hotels’ Primary Responsibilities

Order No.176 is not a minor revision of Order No.151, but a comprehensive upgrade of regulatory logic.

Upgrade 1: Regulatory scope expanded from “internet security” to “cyberspace security”
Order No.151 was limited to internet security. Article 2 of Order No.176 clearly defines cyberspace security as network security + data security + information security. Legislation bases are expanded to include the
Data Security Law, Personal Information Protection Law, Regulations on the Security Protection of Critical Information Infrastructures, etc. Inspected subjects extend from internet service providers to network operators, data processors, personal information handlers and other diverse entities.

For hotels, this means compliance requirements apply not merely to Wi-Fi internet logs. The processing, storage and transmission of guests’ personal information stored in the PMS system, such as names, mobile numbers and ID numbers, all fall within inspection scope. The Hunan Provincial Cyberspace Affairs Office has already imposed administrative penalties on a hotel management company on these grounds: its WeChat mini-program collected personal information without consent, transmitted and stored data without encryption, and failed to retain network logs.

Upgrade 2: Inspection method upgraded from “periodic random checks” to “online patrol + remote detection + on-site verification”
Article 4 of Order No.176 grants public security authorities statutory authority for online patrol and remote technical detection, forming a combined model of “online pre-screening + offline verification”. Public security organs may conduct remote detection on network facilities via vulnerability scanning and penetration testing, with only three working days’ prior notice required.

Previously, hotels could adopt last-minute fixes by hurriedly filling logs and configuring policies before inspections. Now, through remote detection, authorities can preliminarily assess log retention duration, export availability, and whether authentication records correlate with logs online. Compliance is no longer something that only needs to be ready during inspections; it must be maintained properly on a daily basis.

Upgrade 3: Penalties substantially increased alongside new laws
Together with the newly revised
Cybersecurity Law of 2026, the maximum fine for enterprises has risen to 10 million yuan, removing the flexible clause of “warning for first-time violations”. Article 7 of Order No.176 lists 11 key inspection items, adding checks on data security, personal information protection and vulnerability rectification.

II. How All-Optical Networks Build a Solid Compliance Foundation

The core concept of AINOPOL converged all-optical solution: compliance capabilities are built into the architecture, not added as external accessories.

Homologous generation of authentication and logs — resolving data disconnection

The root cause of hotel penalties is often not the absence of real-name authentication, but the lack of correlation between authentication records and network logs. Dream Series security optical gateways adopt session binding technology, attaching guest identity information to every internet access record to form a complete evidence chain.

Specifically, after guests connect to guest-room Wi-Fi, the authentication page automatically links to check-in data in the PMS system to complete person-room binding. Authenticated identity information persists throughout the whole internet session. A full log entry captures who accessed the network, at what time, from which room, using which device, and which websites were visited. Reports can be exported in one click for public security inspections without manual timestamp matching.

The solution supports multiple authentication methods including SMS verification, WeChat mini-program authentication, and room number plus the last six digits of ID documents, covering both domestic and overseas guests. The system directly connects to hotel PMS check-in records and room data, enabling automatic network real-name authentication upon guest check-in.

180-day log retention — tamper-proof and one-click export

Dream Series logs enforce complete fields: MAC address, IP address, authenticated account, session ID, protocol type, destination IP/port, accessed domain names, etc., with a 180-day rolling storage cycle. Logs are encrypted locally for tamper-proof and undeletable storage.

Dream Gateway paired with local hard disk storage suits hotels with strict data residency requirements. Data never leaves the hotel’s internal network, delivering dual capabilities of guest traceability and device security auditing.

Multi-dimensional queries by username, source IP, source MAC, domain name and more are supported, with one-click export of compliance reports formatted to meet public security requirements.

Security protection embedded in architecture — devices running continuously

Order No.176 requires hotels to deploy technical safeguards against computer viruses and cyberattacks. The AINOPOL solution integrates multi-layer security engines including firewall, IPS intrusion prevention, AV antivirus and WAF web application firewall, running continuously to satisfy regulatory requirements for “online devices, deployed measures and effective operation”.

Simplified architecture — less complex compliance deployment

Traditional hotel compliance requires separate procurement of multiple devices such as firewalls, log servers and authentication systems from different vendors, leading to complicated configuration and decentralized management. Dream Series security multi-service gateways integrate routing, switching, all-optical networking, security, AC, IPPBX and log auditing into one appliance, replacing multiple standalone devices. It supports diverse deployment modes including routing, bridge, bypass and hybrid. It can directly replace the original egress gateway or be deployed in bypass mode onto existing networks, finishing compliance networking for an entire hotel within half a day.

Authentication and logs are generated within the same system, transmitted over the same link and stored under the same architecture. The “last mile” of primary responsibility shifts from manual management to technical governance.

The biggest change Order No.176 brings to the accommodation industry is not the addition of more inspection items. It turns the “primary cybersecurity responsibility” from a slogan into technically measurable, traceable and punishable indicators.

The Deyang e-sports hotel was fined 10,000 yuan not because it suffered a hacker attack, but for failing to record logs as required. Another hotel in Yongding District had its penalty upheld in administrative reconsideration, due to missing Wi-Fi authentication portals and insufficient log retention period. These cases illustrate one fact: primary responsibility is not only investigated after incidents occur; penalties apply if obligations are not properly fulfilled.

AINOPOL converged all-optical solution integrates real-name authentication, log retention and security protection into one traceable, exportable system. It is not built merely to pass inspections; it eliminates non-compliance risks at the architectural level.

FAQ

Q: What exactly refers to hotels’ primary cybersecurity responsibility?
A: It includes legally recording and retaining user registration information and internet access logs, implementing cybersecurity grading protection, adopting technical measures to defend against computer viruses and cyberattacks, and protecting personal information and data security. Article 7 of Order No.176 lists the 11 key inspection items.

Q: How does the AINOPOL solution fix the disconnection between authentication and logs?
A: Dream Series security optical gateways adopt session binding technology, attaching guest identity information to every internet access record. Authentication and logs are generated within the same system, transmitted over the same link and stored under the same architecture, requiring no manual matching.

Q: What is the difference between all-optical networks and traditional networks for compliance deployment?
A: Traditional solutions require separate procurement of firewalls, log servers, authentication systems and other hardware, with complex configurations and prone to separation between authentication and logs. All-optical networks embed compliance capabilities in the architecture. One Dream Series device integrates all functions, and compliance networking can be completed within half a day.