Hoist Group
Sweden · www.hoistgroup.com · 29 vendors
Hoist Group develops and delivers technology solutions and services for the hospitality industry, including high-speed internet, TV and entertainment systems, and property management software. The company aims to enhance guest experiences and streamline hotel operations for hotels, healthcare institutions, and public venues.
Resilience scores
- Digital Sovereignty: 24
- Digital Resilience: 7
- Financial Resilience: 5
Disruption prediction
Hoist Group has an estimated 11% probability of disruption in the next 6 months.
14 of Hoist Group's 29 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Netlify, Inc. — Technology — United States
- and 27 more
Services catalogue
12 services in catalogue across 4 categories; runs on 29 sub-vendors.
- Internet Services
- Point-of-Sale
- Hoist Cloud Wi-Fi
Insights
Last updated 2026-08-15 · revision 1
29 direct vendors, 303 subvendors
Direct vendors by controlling owner country (sample)
- France: 2
- United Kingdom: 2
- Denmark: 1
Subvendors by controlling owner country (sample)
- India: 2
- Netherlands: 4
- United States: 204
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Hoist Group exhibits a moderate level of migration readiness, scoring 60. The company's tech stack includes several modern components that facilitate migration, such as cloud-managed Wi-Fi solutions and the use of RESTful APIs for integrations with third-party systems like Property Management Systems (PMS). The adoption of a cloud-based hypervisor/virtualization (Guestcore HaaS) also points towards a familiarity with virtualized and potentially cloud-native environments. The absence of specified data residency requirements is a positive factor, as it removes a common and complex barrier to cloud migration. However, significant challenges and unknowns temper the migration readiness score. While Guestcore HaaS uses a cloud-based hypervisor, it is explicitly described as an 'On-premise virtualization platform,' indicating a substantial on-premise footprint that would require considerable effort to migrate to a fully cloud-native environment. The assessment is also hampered by missing data regarding the regulatory environment and the company's financial stability, which are crucial for understanding the feasibility and funding of a large-scale migration. Furthermore, the 'Vendor Lock-in Risk' is 'Unknown', and while there is geographic diversity among vendor HQs for 33 services, the actual number of unique vendors and the complexity of existing contracts are not provided. This lack of clarity on vendor dependencies could pose unforeseen challenges during a migration initiative.
Compliance
8 in-scope frameworks identified; showing 3.
PCI DSS (source) — Assessment Required
Hoist Group's parent company Planet is a major payment technology provider processing card payments for hotels and retail. The Hoist division's managed network infrastructure (Wi-Fi, back-of-house connectivity, PMS/POS integrations) is directly integrated with payment processing environments at hotel properties. PCI DSS applies to any entity that stores, processes, or transmits cardholder data, or whose systems could impact the security of the cardholder data environment (CDE). Risk is rated High because: (1) the Hoist managed network infrastructure connects to hotel POS and PMS systems that process payment card data; (2) network segmentation failures in Hoist-managed networks could expose cardholder data environments; (3) Planet (parent) is a payment processor subject to PCI DSS Level 1 compliance; (4) PCI DSS v4.0 (effective March 2024) has strengthened requirements for service providers and network segmentation; (5) non-compliance can result in card scheme fines, loss of ability to process payments, and reputational damage.
Evidence: https://www.weareplanet.com/hotel-networking, https://www.pcisecuritystandards.org/, https://www.pcisecuritystandards.org/assessors_and_solutions/service_providers
ePrivacy Directive — Assessment Required
The ePrivacy Directive (implemented in Sweden as the Electronic Communications Act, LEK) is directly relevant to Hoist Group's core business. The company's hotel Wi-Fi captive portal services capture guest data (email, device identifiers) and the platform explicitly advertises 'guest data capture for marketing and loyalty (with consent).' This involves: (1) processing of traffic and location data from Wi-Fi users; (2) use of cookies and tracking technologies on captive portal login pages; (3) marketing communications to guests who provide consent. Risk is rated Medium because: (1) violations can result in fines from the Swedish Post and Telecom Authority (PTS) and IMY; (2) the company's business model depends on lawful data capture from Wi-Fi users; (3) the upcoming ePrivacy Regulation (still in negotiation) may impose stricter requirements.
Evidence: https://www.weareplanet.com/hotel-networking, https://www.pts.se/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2022482-om-elektronisk-kommunikation_sfs-2022-482/
ISO 27001 (source) — Assessment Required
ISO 27001 certification is highly relevant for Hoist Group given its role as a managed ICT service provider handling sensitive hotel guest data and critical network infrastructure. The company's services (cloud Wi-Fi, managed networks, hypervisor services, 24/7 monitoring) involve significant information security responsibilities. Risk is rated Medium because: (1) ISO 27001 is not legally mandated but is a strong market expectation and often required by enterprise hotel chain procurement; (2) NIS2 compliance (which is legally mandated) can be partially demonstrated through ISO 27001 certification, making it strategically important; (3) no public evidence of ISO 27001 certification was found; (4) the hospitality sector has experienced significant data breaches, increasing the importance of demonstrable security controls. Risk is not High because ISO 27001 non-certification does not carry direct regulatory penalties, though it may affect NIS2 compliance posture.
Evidence: https://www.weareplanet.com/hotel-networking, https://www.iso.org/isoiec-27001-information-security.html, https://www.swedac.se/en/, https://www.iaf.nu/articles/Certified_Organizations/159
Financials
Financial Resilience Score: 5/10
Hoist Group's financial resilience is difficult to assess on a standalone basis following its acquisition by Planet (backed by Advent International and Eurazeo). Pre-acquisition, the company generated approximately SEK 1.2-1.4 billion in annual revenue with a recurring revenue base from multi-year hospitality contracts, providing reasonable revenue visibility. The sticky customer base across thousands of hotels in EMEA, combined with high switching costs, supported operational stability. However, significant risks temper this assessment. The company's heavy concentration in the hospitality sector made it particularly vulnerable to the COVID-19 pandemic, which likely materially impacted 2020-2021 revenue and cash flow. The capital-intensive delivery model involving on-premise hardware creates working capital risk relative to pure-SaaS peers. Historical private equity ownership (Segulah, Marlin Equity Partners, now Planet/Advent/Eurazeo) implies meaningful acquisition debt on the balance sheet. Post-acquisition, Hoist is now consolidated into Planet's private accounts with no separately published group financials. The strong strategic backing from large, well-capitalised PE sponsors materially strengthens the balance sheet and funding for R&D, but standalone financial resilience is no longer a fully meaningful concept. Competitive pressure from cloud-native PMS providers (Mews, Cloudbeds) and networking OEMs (Cisco Meraki, Aruba) selling directly represents an ongoing threat.
Key strengths: Sticky, recurring hospitality customer base with multi-year contracts and high switching costs, Broad product suite enabling upsell (Wi-Fi, TV, PMS, managed hosting), Strong strategic backing from Advent International and Eurazeo via Planet acquisition, Geographic diversification across EMEA reduces single-country concentration, Historical revenue of approximately SEK 1.2-1.4 billion pre-acquisition
Risk factors: Heavy concentration in hospitality sector tied to hotel capex and occupancy, Severe COVID-19 impact on hotel IT spending in 2020-2021, Capital-intensive delivery model with hardware deployments creating working capital risk, Integration risk into Planet with brand consolidation into 'Hoist by Planet', Competitive pressure from cloud-native PMS vendors and networking OEMs, Historical PE ownership implies meaningful acquisition debt on balance sheet, No publicly disclosed consolidated financials post-acquisition
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.