06/18/2026
In 2013, attackers stole 40 million payment card numbers from Target. They didn't break in through a payment terminal: they got in through a refrigeration and HVAC contractor's stolen password.
The contractor had remote network access to manage the heating and cooling systems. Once attackers had that login, they walked sideways into Target's network and found their way to the cash registers.
The full story was first reported by Brian Krebs in 2014, and it's still the textbook example of how a single connected vendor becomes the whole risk.
Most private clubs are running smaller versions of that exact architecture. A typical mid-sized club has between 100 and 300 connected devices: POS terminals, kitchen displays, cooler sensors, cameras at the gate and locker rooms, smart locks on back offices, irrigation controllers, the BMS.
Each one was installed by a different vendor at a different time. Many of those vendors still hold active remote access years after the install, often with the same password they used for the original setup.
After 20+ years working only with private clubs in Canada and the US, the gaps we find at most properties are usually the same ones, and almost all of them are fixable in a quarter without a major capital project.
We wrote a practical guide for GMs, with a 30/60/90 day playbook.
https://clubsupportinc.com/blog/iot-security-for-private-clubs-risks-in-connected-devices/
If you'd rather just have us take a look at your own club, we run a complimentary IT and security assessment. DM us for a free audit.