conferencing cybersecurity

Is Your Conferencing System a Cybersecurity Weak Link?

Video Conferencing Vulnerabilities

At home and in the office, the Internet of Things (IoT) has brought us new heights of connectivity and convenience. Yet recent years show that the connected devices that have opened up new doors for us have also exposed us to new vulnerabilities.

A cloud of insecurity seems to be looming over the new age of efficiency that connected devices have created. When not properly secured, connected devices can be a weak link when it comes to cybersecurity, leaving devices and the data on them at risk. We have seen the real-world risks associated with IoT devices in action last year, when the Mirai botnet hijacked more than a million devices to interrupt major websites. But that is not the only threat at hand. In the workplace, the security of these devices should be of utmost importance, especially considering what is at stake. In the hands of the wrong people, access to these devices can grant intruders the ability to spy on employees or steal corporate information.

Conferencing Systems

Conferencing systems — a camera, phone and codec — are among several devices that can help create a connected enterprise, increasing collaboration for the end users and improving ease of administration for the IT department. But the rise of remote working and global collaboration means that confidential corporate conversations are no longer protected by four walls; instead, they’re taking place across phone lines, network cables and video streams that span cities, countries and continents.

Protect Your Small Business

Intruders who manage to access a single conferencing system are suddenly granted an entry point to the entire network. They could monitor any communication coming in and going out of the device, and even snoop around other unprotected devices on the network. And unfortunately, these conversations can easily include a wealth of confidential and sensitive corporate information (just think about the content that is shared in an investors’ meeting).

The most common problem with these devices is access from the management console. You would be surprised to learn how many IT administrators leave the default passwords in place — a security gap that can allow someone access to your network and devices and the ability to modify or manipulate them. As a best practice, IoT devices should be treated like any other IT asset and secured accordingly. Authentication mechanisms that go beyond traditional password security should be mandatory.

Keep in mind that your conferencing devices are not the only security gaps. Cloud collaboration services — which are dominating the video collaboration space today and are frequently paired with conferencing devices — come with their own security concerns. Many service providers offer encryption of communication but do not do so by default. Instead, encryption is offered as a feature that customers would need to turn on — something that not everyone will realistically do.

Conferencing Security Challenges

These security challenges may seem daunting, but they do not have to halt your collaboration efforts.

Here are three best practices that can help prevent your conferencing system and service from becoming a cybersecurity weak link:

  1. Confirm and enforce encryption. Without encryption, your communication is subject to surveillance at any network level. Check with your service provider to ensure that encryption is turned on for all communications. Additionally, confirm if the provider is able to monitor your communications. Some vendors do this for support purposes, but it compromises your business’s privacy.
  2. Implement a strict password policy. Remember to use strong and complex passwords. When available, opt for multi-factor authentication. Take a look at the National Institute of Standards and Technology’s latest guidelines for effective password practices that do not put a heavy burden on users.
  3. Treat your conferencing devices as if they were servers. If you have to expose your devices to the public internet, take adequate precaution to limit damage if an intruder manages to gain access to the device. Quarantine non-compliant devices in a sandbox to protect the rest of your IT ecosystem, and be sure to keep all systems patched against known vulnerabilities.

Your network — and by extension, your business — is only as secure as the devices connected to it. Be proactive about vetting the security of your conferencing and collaboration devices and services to ensure that your business’s productivity boosts do not come at the cost of your privacy or security.

By Bobby Beckmann, CTO, Lifesize

Bobby Beckmann

As Lifesize CTO, Bobby leads a multinational team of engineers and developers to deliver continued innovation, scalability and reliability to the Lifesize cloud-based software service, HD camera and phone systems. With more than 20 years of experience, Beckmann helps Lifesize build on its reputation for innovations, recent momentum and usher in the next chapter of the company’s innovation.

Bobby joined Lifesize in 2015 and first served as vice president of service software where he played a pivotal role in developing the cloud-based software application and addressing the needs of the modern meeting environment. Prior to Lifesize, he served as CTO and vice president of engineering at Bloomfire, where he managed worldwide software engineering and product development efforts. Beckmann also previously held engineering leadership positions at OneID, Inc. and Optaros.

View Website
How Artificial Intelligence Is Revolutionising Enterprise Software In 2017

How Artificial Intelligence Is Revolutionising Enterprise Software In 2017

Artificial Intelligence Is Revolutionising Enterprise 81% of IT leaders are currently investing in or planning to invest in Artificial Intelligence (AI). Cowen predicts AI will drive user productivity to materially higher levels, with Microsoft at ...
Get Used To It – Artificial Intelligence For Real-time Gas Pricing

Get Used To It – Artificial Intelligence For Real-time Gas Pricing

Real-time Gas Pricing Get used to it – we will extract every dollar you can afford at your friendly …. ! I was reading in the Wall Street Journal about the implementation of Artificial Intelligence ...
Open APIs Alone Won’t Change Banking

Open APIs Alone Won’t Change Banking

Open Banking API's Most people think of banks as one monolithic entity, but they are actually made up of hundreds of independent, pseudo-integrated systems. When a bank wants to make any kind of change, it ...
ThreatMetrix Quarterly Fintech Cybercrime Report 2017

ThreatMetrix Quarterly Fintech Cybercrime Report 2017

Fintech Cybercrime Report 2017 ThreatMetrix has released its latest quarterly cybercrime report based on cybercrime attacks from October to December 2016, detailing trends across financial services and eCommerce, with a global study of traffic patterns ...
Adopting An Industry-Wide Red Line Movement

Adopting An Industry-Wide Red Line Movement

Red Line Movement Recently, I’ve been calling for an industry-wide adoption of the red line philosophy to help with the balance of features and quality in cloud application development. It seems that everyone has the ...

CLOUDBUZZ NEWS

Security in the Cloud—A Little Known Advantage, Actually

Security in the Cloud—A Little Known Advantage, Actually

Okay, I’ll go ahead and say it: Public cloud infrastructures are more secure, and the security is more cost-effective, than the majority of on-premises data centers. That should get the blood flowing. With the word ...
Cambridge Analytica files for bankruptcy in U.S. following Facebook debacle

Cambridge Analytica files for bankruptcy in U.S. following Facebook debacle

(Reuters) - Cambridge Analytica, the political consultancy at the center of Facebook Inc’s (FB.O) privacy scandal, filed for Chapter 7 bankruptcy in the United States late on Thursday. This past March allegations surfaced that Cambridge ...
Facebook Joins FIDO Alliance Board of Directors

Facebook Joins FIDO Alliance Board of Directors

Aligns with other leading global technology, financial services and e-commerce companies in effort to reduce world’s reliance on passwords MOUNTAIN VIEW, Calif., May 15, 2018 (GLOBE NEWSWIRE) -- The FIDO Alliance announced today that Facebook has been appointed ...
The Lighter Side Of The Cloud - Wearable Infection
The Lighter Side Of The Cloud - Easter Egg Hunt
The Lighter Side Of The Cloud - Snowball Effect
The Lighter Side Of The Cloud - iPatch
The Lighter Side Of The Cloud - The Apple Watch
The Lighter Of The Cloud - Virtual Lunch Break
The Lighter Side Of The Cloud - Car Troubles
The Lighter Side Of The Cloud - Once A Year
The Lighter Side Of The Cloud - Day 5