Web Conferencing Must Be a Safe Space | Complete security
Everyone is Aware That Free Professional Software is Not Without Its Price. It Generally Translates Into One of These Objectives: Access Your Personal Data, Send You Advertising, or Capture Your Attention in Order to Sell You Premium Services Afterwards. Many of Us Have Already Experienced This, for Example in the World of Consumer Software and Social Networks. This is All Legitimate, but When It Comes to Web Conferencing Services, It Departments and Buyers Need to Be Particularly Vigilant About Security Risks.
Many players provide free or low-cost services that offer a low level of protection. It only takes one major security breach to realize that the protective measures to be put in place are not superfluous expenses.
What are the three key security aspects to consider when choosing a web conferencing solution?
- Authentication
Ensuring that only authorized participants log into meetings is a major challenge with free audio, video, and web conferencing. You can host an encrypted meeting, but anyone with the meeting credentials can join and listen to what is being said. Worse yet, by using a phone connection, it is possible to listen without revealing one's name or true identity.
Lack of authentication is a serious risk factor. Last October, a major aircraft manufacturer consulted us after detecting that two external participants, connected by audio only, had attended a global internal meeting organized by its CEO. Likewise, as we enter the 2020 municipal election campaign, a number of politically engaged organizations have approached us to ensure that their opponents, detractors and unauthorized journalists cannot infiltrate their web conferences. - as they have done in the past.
However, security breaches that endanger a company and its staff do not only target aircraft manufacturers and political parties. To protect themselves, companies must turn to conferencing services that integrate comprehensive security features with encryption and two-factor authentication (secure two-step login process). It is essential to ensure that the system chosen eliminates the common loophole of being able to forward meeting invitations.
- Private life
There are many cloud or online services that can be accessed that don't make it clear that they capture and sell all the data that is relevant to you. This is data that reveals not only who you are, but also who you meet, for how long, and even how often.
At a minimum, if your company uses a free service that involves the exploitation of this type of data, your employees should be informed. For most organizations, this is not an acceptable compromise. Again, it's best to consider premium services that explicitly commit not to sell your data to third parties. Paying for services gives you a lot more leverage in the event of a privacy breach.
- Monitoring
The riskiest services are those that provide a unique number or link that anyone uses to log in without having to enter a password or meeting ID. There are no longer any conferences where the session has exceeded the time slot initially reserved, thus allowing participants to the next meeting to interfere and listen discreetly. Monitoring functions prevent this from happening. They allow administrators to control who and how many people have joined a conference, and more importantly from where they are calling. So, for example, if one of your employees seems to be calling from Vietnam when you are sure they are based in New York, you can disconnect them from the conference.
Publish a clear BYO (Buy Your Own) policy
Well-meaning colleagues could also sign up for free calling services that go under the ISD's radar to save money or try something more attractive to their teams. The publication of a clear security policy is necessary to explain exactly why free and potentially insecure services are not allowed. In order for these rules to be respected, it is necessary to expose the risks that these systems present to personal data as well as to privacy and the company.
In conclusion, corporate meetings should be safe spaces where no personal data or private conversation can be compromised. While there is a growing awareness of the dangers of free software, it should not be forgotten that it only takes one security breach in an online conference to create a critical situation. Rigorously evaluating the Complete security characteristics of your remote conferencing services can easily avoid this.

Comments
Post a Comment