Honestly, after seeing this article upvoted so high and then reading it, I was relieved to see these comments. At it's root, security for always-on networked systems is extremely difficult, even at tech-first companies with an ingrained "security culture", nevermind a hospitality company like Starwood where "IT" is another department. And this guy comes forth with clueless statement after clueless statement about "The system was already operating securely for five years" and the one about the primary encryption keys. This whole article is incredibly self serving.
Mmmmhmmmm. It's executive CYA, and a public article for a public clusterfuck.
5 years ago is when this stuff probably started going sideways and those failures manifest later as massive outages, breaches, etc. Could be that the author IS WHY a lot of these issues cropped up later, so take proactive steps to blame others.
Gotta keep that executive cachet high so that you can slide into a CTO role elsewhere.