<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.avnetwork.com/feeds/tag/cybersecurity" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from AV Network in Cybersecurity ]]></title>
                <link>https://www.avnetwork.com/tag/cybersecurity</link>
        <description><![CDATA[ All the latest cybersecurity content from the AV Network team ]]></description>
                                    <lastBuildDate>Thu, 23 Apr 2026 10:54:12 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NAB 2026: Show Floor Feedback ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/business/expert-opinions/nab-2026-show-floor-feedback</link>
                                                                            <description>
                            <![CDATA[ Manufacturers are really getting a handle on AI, and there’s a new buzzword impacting the industry. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">soDFu65KuCmZrXhkFvBXYh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ykSVoJxyokYgTZveQTb92G-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 10:54:12 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Apr 2026 15:25:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mark J. Pescatore ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zJXGCzPnTt63KECrcVbtEM.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ykSVoJxyokYgTZveQTb92G-1280-80.jpg">
                                                            <media:credit><![CDATA[Mark J. Pescatore]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NAB Show Sign in LVCC Central Hall 2026]]></media:description>                                                            <media:text><![CDATA[NAB Show Sign in LVCC Central Hall 2026]]></media:text>
                                <media:title type="plain"><![CDATA[NAB Show Sign in LVCC Central Hall 2026]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ykSVoJxyokYgTZveQTb92G-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Back home in the refreshed Central Hall of the Las Vegas Convention Center, with additional exhibits spread across the North Hall and West Hall, the 2026 NAB Show closed its show floor on April 23. According to show officials, there were more than 58,000 registered attendees, an increase from last year. Almost half were first-time attendees, and more than 20% of registered attendees were international, with 146 countries represented. Plus, there were 132 first-time exhibitors. Beyond the numbers, here were a few trends I observed.</p><p><a href="https://www.avnetwork.com/news/sphere-las-vegas-immersive" target="_blank"><em><strong>[We Saw Phish at The Sphere, and the Video Content Had Us Bouncing around the Room]</strong></em></a></p><h2 id="acknowledge-the-influencers">Acknowledge the influencers.</h2><p>Whether you call them creators or influencers, the important thing is that you <em>call</em> them. NAB 2026 put an emphasis on the creator community and with good reason: It's healthy and it's growing. I attended "How Fortune 500 Brands Are Betting on Creators," while <em>SCN</em>'s Wayne Cavadi covered “State of the Creator Economy” at the Creator Lab, an area devoted to the creator community that celebrated its third year at NAB.</p><p>During<a href="https://www.avnetwork.com/events/conferences-trade-shows/nab-show-2026-how-creators-drive-conversion-for-big-brands" target="_blank"> “State of the Creator Economy,"</a> Alessandro Bogliari, co-founder and CEO of The Influencer Marketing Factory, explained the appeal of online influences. “The creator economy is a people business,” he said. “It’s a friend I’ve never met, and I follow them because you can see part of myself in them. AI simply cannot replace that.” </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mEtxrBV4fbauiwWU8aBRdX" name="Creator Lab Session WEB" alt="Creator Lab Panel at NAB 2026" src="https://cdn.mos.cms.futurecdn.net/mEtxrBV4fbauiwWU8aBRdX.jpg" mos="" align="middle" fullscreen="" width="3200" height="1800" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">For the third consecutive year, NAB hosted an area devoted to the creator community. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Mark J. Pescatore)</span></figcaption></figure><p>Of course, AI was also part of the discussion. Natalie Jarvey, editor of Ankler Media’s "Like & Subscribe" newsletter, said creators who once saw GenAI as a threat have now embraced it as a tool for making creative content. That said, she acknowledged it still has a different look and lacks the human touch. “Brands are all-in on everything AI these days: the good, the bad and the ugly,” agreed fellow panelist Pierre-Loïc Assayag, co-founder and CEO of Traackr.  </p><p>Meanwhile, in <a href="https://www.avnetwork.com/events/conferences-trade-shows/nab-show-2026-how-creators-drive-conversion-for-big-brands" target="_blank">"How Fortune 500 Brands Are Betting on Creators," </a>Jennifer Cho, chief customer officer at CreatorIQ, said creator marketing now delivers more ROI than the traditional marketing funnel. That's why major businesses are using creators to drive social media campaigns. Brendan Ittelson, chief ecosystem officer at Zoom, said measurement and metrics are critical, and it's important to be able to define customer success and identify audiences.  </p><p>How creators will impact the Pro AV industry remains to be seen. But between them and younger viewers embracing 9:16 content for shorter content on their mobile devices, there is the potential for serious disruption in the production status quo. That means new tools, new techniques, and new workflows—and customers looking to integrators for answers. </p><h2 id="there-s-a-new-buzzword">There's a new buzzword. </h2><p>AI is still making the most noise in the industry, but another buzzword has quietly become part of an awful lot of conversations: security. Whether you call it network security, IP security, or cybersecurity, minimizing the risk of intrusion or cyberattacks via Pro AV hardware and software is now a point of emphasis. And just to bring this to a full buzzword circle, AI is a great tool for bad actors.  </p><p>"Every device on-prem is a potential liability," agreed Frank Zovko, VP of engineering at AI-Media. The company used NAB 2026 to introduce its new LEXI Voice Encoder and LEXI Text Encoder for use in the creation of written and spoken captions, transcripts, and translations. Zovko said the company did its due diligence for security, with updated systems, an overhauled web interface, SOC 2 compliance, and more. AI-Media has also committed to quarterly updates for added security protections. </p><p>Security was top of mind for BeckTV at NAB, where the company launched BeckFlow, its web-based, broadcast-centric schematic documentation platform that doesn't rely on traditional CAD workflows. Matt Weiss, VP business development for BeckTV, has noticed there is more security awareness in the industry; in fact, he mentioned that BeckFlow is SOC 2 compliant and has authentication features.  </p><p><a href="https://www.avnetwork.com/news/netgear-acquires-exium-heres-everything-you-need-to-know" target="_blank">NETGEAR is so serious about security that it acquired Exium</a>, a cybersecurity company, last year. There was less concern about security when connectivity was defined by an HDMI cable, but today's IP-based workflows has "raised the bar for the need for security," according to NETGEAR AV's John Henkel. He advised keeping AV separated from other IT assets on its own network.</p><h2 id="ai-is-getting-some-serious-training">AI is getting some serious training.</h2><p>"We've gotta use AI." </p><p>I wonder how many companies have declared mandates like this—and then promptly left their teams to their own devices to figure out how to do just that. Thankfully, I'm happy to report that there are Pro AV manufacturers that are avoiding vague "and it's got AI" declarations and really focusing their AI efforts into meaningful products and workflows. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6i6Ntgawka4yjXFpexbEa4" name="Shure Fireside Chat WEB" alt="Shure Fireside Chat at NAB 2026" src="https://cdn.mos.cms.futurecdn.net/6i6Ntgawka4yjXFpexbEa4.jpg" mos="" align="middle" fullscreen="" width="3200" height="1800" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Shure's fireside chat at NAB 2026 discussed the company's use of AI to isolate sounds during live productions. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Mark J. Pescatore)</span></figcaption></figure><p>For example, I learned about Shure's Action Isolator software during a Sunday afternoon session in the Broadcast Engineering and IT Conference. Shure's Chad Wiggins, associate VP of innovation, and Brent Shumard, senior staff acoustic engineer, had a fireside chat with John Clark, NAB's chief innovation officer and SVP of emerging technology about why audio has lagged behind with AI.  </p><p>Beyond a "if it ain't broke, don't fix it" mentality, Shumard said audio is often messy and chaotic. However, AI adoption for processing is starting. Action Isolator uses AI to remove unwanted sounds. So, if you're shooting a basketball game, you can have the sounds of the basketball hitting the rim, dribbling the ball down the court, and even the squeaking of the sneakers all on one fader, minimizing the sounds of the crowd, band, or PA announcer. </p><p>How does Action Isolator do it? The first part is the right hardware. Shure's DCA901 broadcast microphone array offers eight channels of audio with very steerable pickup zones that can identify and prioritize key sounds in real time. But the secret sauce is training. The company is currently training the software for basketball, baseball, and hockey. Shumard said the trick is getting clean audio data for training the AI. </p><figure class="van-image-figure pull-left inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:120.00%;"><img id="FxXJx6p2WnrdbwxyV29DJc" name="Vizrt AI Keyer WEB" alt="Vizrt AI Keyer Demo at NAB 2026" src="https://cdn.mos.cms.futurecdn.net/FxXJx6p2WnrdbwxyV29DJc.jpg" mos="" align="left" fullscreen="" width="1000" height="1200" attribution="" endorsement="" class="pull-leftinline"></p></div></div><figcaption itemprop="caption description" class="pull-left inline-layout"><span class="caption-text">AI Keyer </span><span class="credit" itemprop="copyrightHolder">(Image credit: Mark J. Pescaore)</span></figcaption></figure><p>On the video side, Vizrt introduced AI Keyer at the show. Vizrt's chief marketing officer, Chris Black, said the company wants its AI applications to be transformative and capable of simplifying human workflows through agentic AI. AI Keyer is certainly designed to simplify VR and XR workflows, because it enables a production to change backgrounds and insert graphics without a greenscreen or special lighting. Indoor, outdoor, on a set, on location—it doesn't matter. </p><p>Again, AI training is the key. Vizrt is training its AI to recognize human shapes, maintaining the key while allowing your talent to walk and chew gum (and handle objects) at the same time. Vizrt is also working on training the AI to recognize hats and hairstyles, too.  </p><p>Is it perfect? No. But like previous technological leaps in our industry, this first generation is the worst it's ever going to look. And it's already more than good enough for prime time. All I'm saying is that if you've been keeping extra stock of green paint for the cyc, you might as well use it now, because you probably won't need it in the near future. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Editorial: For Whom the Alarm Bell Tolls ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/business/expert-opinions/editorial-for-whom-the-alarm-bell-tolls</link>
                                                                            <description>
                            <![CDATA[ Not worried about cybersecurity? You should be. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">erdbMzNfabHfzEAJGui5s4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lrixifi7BraW2ttqdZKn6c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mark J. Pescatore ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zJXGCzPnTt63KECrcVbtEM.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lrixifi7BraW2ttqdZKn6c-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mark J. Pescatore, Content Director, Systems Contractor News]]></media:description>                                                            <media:text><![CDATA[Mark J. Pescatore, Content Director, Systems Contractor News]]></media:text>
                                <media:title type="plain"><![CDATA[Mark J. Pescatore, Content Director, Systems Contractor News]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lrixifi7BraW2ttqdZKn6c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nobody wants their home alarm triggered, especially at 4:30 a.m. And yet, there I was, awakened from a dead sleep from something a lot louder (and earlier) than my Apple Watch's happy little chirping to announce a new day. </p><p>In some homes, the alarm is an absolute call to action. You'll find someone instantly alert, shotgun in hand and bandolier magically slung over one shoulder. Next comes that <em>chuck/chuck </em>sound of a round being loaded in said shotgun, followed by a pithy comment worthy of Bruce Willis in his prime.  </p><p><a href="https://www.avnetwork.com/business/better-safe-than-sorry" target="_blank"><em><strong>[Better Safe than Sorry]</strong></em></a></p><p>In my home, the response was somewhat different. There was no shotgun. There was a man muttering about his glasses and wandering over to the control panel.  </p><p>Why so calm? When my alarm went off, it didn't include that high-pitch siren that informs me of a breach. It was just the alarm. Don't get me wrong, it was annoying, but I was reasonably sure I wouldn't have to channel my inner John McClane.  </p><p>Turns out I was right to be annoyed rather than panicked. The control panel declared there was a low battery. Not a battery on one of the sensors—that would trip a real alarm. Instead, it was the chunky battery that sits in the control box year after year until it can find an inopportune time to lose its charge. One bleary-eyed order placed with Amazon later, I was in bed trying to will myself back to sleep.  </p><p>Now, if you really wanted to sound an alarm, you should have joined me at the inaugural Cybersecurity Summit last month at ISE 2026. I sat in on the opening session, "Building Cyber Resilience: Why AV systems become part of critical infrastructure," and let's just say it didn't appease my trust issues.  </p><p>The speaker was Shaun Reardon from DNV Cyber, and his message focused on the importance of planning. Reardon, who is outrageously qualified to speak on matters of security and cybersecurity, didn't sugarcoat the situation. Cyberattacks are a given, and if you don't think about cybersecurity early, it's going to cost you a lot of money later.  </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jz8yqSNbqi3LjDxDpN78tH" name="ISE 2026 Cybersecurity Summit WEB" alt="Presentation at ISE Cybersecurity Summit" src="https://cdn.mos.cms.futurecdn.net/jz8yqSNbqi3LjDxDpN78tH.jpg" mos="" align="middle" fullscreen="" width="3200" height="1800" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">DNV Cyber’s Shaun Reardon didn’t sugarcoat the importance of cybersecurity into today’s Pro AV environments.  </span><span class="credit" itemprop="copyrightHolder">(Image credit: Mark J. Pescatore)</span></figcaption></figure><p>Pro AV has its own cybersecurity challenges, because our industry's supply chain includes a heaping pile of vendors and a surplus of high-risk entry points, from IP-based cameras to digital signage systems and more. Reardon warned that this is where integrators can encounter liability; in fact, cybersecurity negligence can lead to lawsuits, fines, even potential prison time.  </p><p>We've probably all heard about the case of the hackers who stole data from about 40 million credit cards from Target's IT network more than a decade ago. They broke in using stolen network credentials from a third-party HVAC vendor. In the case of Pro AV, you've got all sorts of gear with default passwords that need to be changed and/or firmware that needs to be patched (seriously, when was the last time you plugged in a new device and it didn't want to immediately update its software).  </p><p>Plus, there's the added wrinkle of managed services. Yes, we all love that it reduces truck rolls and provides a steady revenue stream, but it's yet another access point that can be breached by the cyber bad guys. And I haven't even talked about potential personnel-based cybersecurity threats.  </p><p>It's easy to be complacent with cybersecurity, treating it like you would a checklist for packing your suitcase for summer vacation. However, Reardon considers the cybersecurity standards in place for our industry and others as minimal effort—conformity is <em>not</em> security. Consider those the starting point for your cybersecurity journey.  </p><p>Yes, journey: Cybersecurity needs to be a continuous effort, not a one-time deal. Basically, Reardon suggested a holistic approach. That means having a comprehensive understanding of your Pro AV environment, an incident response plan in place for when the cyberattack comes, and an active security mindset. Yippee Ki-Yay.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ISE 2026 Launches Inaugural CyberSecurity Summit ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/ise-2026-launches-inaugural-cybersecurity-summit</link>
                                                                            <description>
                            <![CDATA[ The global gathering of AV professionals will focus on immediate action, innovative defense, and industry resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SKaN2MTgQH4tS9zf2xNGMY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZCe6cYhBKSw8CK2iRVXJum-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Oct 2025 10:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Conferences &amp; Trade Shows]]></category>
                                                    <category><![CDATA[Events]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ZCe6cYhBKSw8CK2iRVXJum-1280-80.png">
                                                            <media:credit><![CDATA[ISE]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The ISE CyberSecurity Summit logo. ]]></media:description>                                                            <media:text><![CDATA[The ISE CyberSecurity Summit logo. ]]></media:text>
                                <media:title type="plain"><![CDATA[The ISE CyberSecurity Summit logo. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZCe6cYhBKSw8CK2iRVXJum-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Integrated Systems Europe is launching the CyberSecurity Summit, a new addition to the ISE 2026 content program. Scheduled for Thursday, Feb. 5, the Summit will tackle the escalating cybersecurity challenges confronting the Pro AV and systems integration industries, as digital threats increasingly impact critical infrastructure, smart buildings, venues, and public services. With cybercrime surging across Europe and globally, the timing of ISE’s new Summit couldn’t be more relevant.</p><p><a href="https://www.avnetwork.com/search?searchTerm=ise+2026" target="_blank"><em><strong>[AV Networks' ISE 2026 Coverage]</strong></em></a></p><p>The Summit is part of ISE 2026’s overarching theme, <a href="https://www.avnetwork.com/news/step-beyond-the-unexpected-new-initiatives-at-ise-2026" target="_blank">Push Beyond</a>, which challenges the global AV and systems integration community to redefine what’s possible. By introducing the CyberSecurity Summit, ISE is pushing beyond traditional boundaries to address one of the most urgent and complex issues facing the industry today.</p><p>“Cybersecurity is no longer a technical afterthought, it’s a business-critical factor,” said Mike Blackman, managing director of Integrated Systems Events. “For AV manufacturers, integrators, and technology users, it’s essential for accessing public tenders, ensuring regulatory compliance, and building long-term trust with clients.”</p><p>As AV systems become increasingly networked and embedded in enterprise, public sector, and venue environments, they are directly exposed to the same vulnerabilities as traditional IT infrastructure. From control rooms and conferencing platforms to digital signage, smart buildings, and event venues, AV solutions are now high-value targets for ransomware, data breaches, social engineering, and denial-of-service attacks. At ISE’s CyberSecurity Summit, AV professionals will learn about safeguarding critical systems, navigate evolving regulations like NIS2 and ISO 27001, and transform cybersecurity from a vulnerability into a strategic advantage, before it’s too late.</p><p>Summit chair Pere Ferrer i Sastre, former directorgeneral of the Catalan Police with extensive experience in public security, digital transformation, regulatory frameworks, and critical infrastructure management, will facilitate discussions addressing emerging digital threats to the AV and systems integration sectors. </p><p>“Cybersecurity is no longer optional; it lies at the heart of every AV innovation," he explained. "ISE’s CyberSecurity Summit brings together the brightest minds in our industry to confront today’s digital threats head-on and turn them into strategic advantages. By sharing actionable insights, proven strategies, and real-world experience, we will empower AV professionals to protect critical systems, lead with confidence, and build a safer, smarter future for the entire industry.”</p><p>The CyberSecurity Summit at ISE 2026 will unite AV and cybersecurity leaders to tackle the most pressing challenges facing connected AV systems in critical infrastructure, smart buildings, and corporate environments. Opening with Pere Ferrer, the Summit features keynotes from Shaun Reardon (DNV Cyber) on building cyber resilience, Timo Kosig and Andrew Dowsett (Barco Control Rooms) on secure operations, and Pedro Pablo Pérez (TRC) on protecting corporate communications. Roundtables with Laura Caballero (Cybersecurity Agency of Catalonia), Folly Farrel (TÜV SÜD), and Sergi Carmona (Veolia España) will explore compliance, governance, and best practices for securing critical AV environments. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blueprint for Success: Inside Job ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/blueprint-for-success-inside-job</link>
                                                                            <description>
                            <![CDATA[ Employee devices are generating cyber risks. How do you protect your organization? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S4254aok8fYeRscS63kcKH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jul 2025 10:02:00 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Jul 2025 11:12:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mathew Newfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/c5ypDctsjQc2m4x9jfLeDH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mathew Newfield, Diversified]]></media:description>                                                            <media:text><![CDATA[Mathew Newfield, Diversified]]></media:text>
                                <media:title type="plain"><![CDATA[Mathew Newfield, Diversified]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Business professionals have moved from corporate offices to their homes and other remote locations and back again, with many now splitting their time through new hybrid workplace models. Regardless of location, workers often use their personal devices to get the job done. </p><p><a href="https://www.avnetwork.com/news/diversified-companies-underinvesting-in-workforce-technologies" target="_blank"><em><strong>[Diversified: Companies Underinvesting in Workforce Technologies]</strong></em></a></p><p>You may be surprised to learn that an overwhelming 89% of associates employ their own devices or apps for work due to better ease of use compared to company-provided options, according to the Diversified Technology Maturity Survey of more than 1,600 U.S. employees. Given the widespread BYOD usage—and all that we have learned about remote and hybrid work—you might think that enterprises had BYOD security solved.  </p><p>The reality? That’s typically not the case. Many businesses still lack the controls needed to protect their organizations in a BYOD world. Here’s how BYOD creates business risk and what companies can do to address it.</p><h2 id="split-tunneling-concerns">Split Tunneling Concerns</h2><p>Several business and IT leaders have told me they trust their employees not to visit or download materials from inappropriate or illegal websites. Trusting your employees to behave ethically and responsibly is a good instinct. But what these company and department heads often fail to understand is that most cyber incidents result from mistakes, not malicious intent. </p><p>For example, if an employee incorrectly keys in a website address, or maybe their child uses their device to play videogames and downloads a plug-in, their machine can get infected. Even the most innocent actions by your employees can create cyber risk. </p><div><blockquote><p>The savings you gain by not buying equipment may be eroded with additional security costs.</p></blockquote></div><p>During the pandemic, a lot of companies enabled split tunneling to reduce their bandwidth costs. These split tunneling adopters instructed their employees to use VPN to connect to corporate networks, but encouraged associates to use their own connectivity when doing internet work using browsers such as Google Chrome, Internet Explorer, and Mozilla Firefox. </p><p>However, home networks are some of the most vulnerable networks on the planet. They often include home automation devices that have never been patched. Home routers may not be password protected, or a technician who installed the router may have seen the password on the back of the device and used it later to log in, so outsiders may already be lurking within the home network.  </p><p>If a laptop that’s using split tunneling is not correctly configured and monitored, an adversary could attack that machine and use it to jump into your corporate network. The best approach to split tunneling is to avoid using split tunneling.</p><h2 id="byod-corporate-standards">BYOD Corporate Standards</h2><p>Some companies bought and configured computers for people who had to work from home during the pandemic. But a lot of businesses didn’t have the resources to do that, so they advised their associates to buy laptops online or from a big box store. </p><p>Businesses taking this BYOD approach now must contend with a mixture of machines, many of which are not owned or managed by the company, and most of which are not enterprise-grade. Plus, now that people are on the move again and many companies have hybrid work environments, employees often use these devices to log in from corporate and home offices, as well as airports, coffee shops, hotels, and more. That creates risk; in these situations, companies lack the security controls they had when people worked on stationary desktop computers at the office.  </p><p>Gain control of your BYOD environment and secure your IT environment (and company) by limiting the use of devices to corporate-approved machines. Ask employees to sign a document explaining that you will allow them to use their own device, but during their employment with your company, it will adhere to your corporate standards. This includes the company’s ability to install a corporate “image” on the device, which should include all of the security and management software that is used on standard corporate systems.   </p><h2 id="security-over-convenience">Security over Convenience</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oWqCaRVvxQLStG9qJFBZwg" name="SCN379.bus.gettyimages_1388606448_no_mask_16x9" alt="Cybersecurity issues with personal computer" src="https://cdn.mos.cms.futurecdn.net/oWqCaRVvxQLStG9qJFBZwg.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>If you’re a CIO or CISO, you’ve likely heard employees say that they want to use a particular application, rather than what you have invested in and provided, because it’s better, faster, or easier. They might even go ahead and get the legacy or freeware version of their tool of choice and start using it for work.  </p><p>But in a corporation, free rein comes with significant risk. If employees use freemium or individual versions of software for business—with or without your knowledge or consent—your company may be in violation of the software supplier’s licensing rules. </p><p>Avoid legal and cybersecurity risks by removing administrator rights on BYOD devices to prevent employees from administering their own patches and installing their own apps and software.  While the removal of local administrator rights will raise the level at which an IT organization must operate, it removes a lot of risks on your end points. </p><p>To combat cyber risks, you have to involve IT, human resources, legal, the executive team, and your associates, as there are a lot of factors to consider. The best tools in the world will be useless if you do not ensure everyone is aligned with the risks and the compensating controls. Depending on where you operate, you may also need to address privacy rules like GDPR. </p><p>Take a cross-departmental approach as you work to address the BYOD security challenge and ensure that you take the right approach to securing devices and your business. Also, ensure you are doing a cost benefit analysis, as the savings you gain by not buying equipment may be eroded with additional security costs. Put the proper policies in place that are approved by the heads of your IT, human resources, legal, and other relevant functions, as they will go a long way in protecting your corporation. </p><p><a href="https://www.avnetwork.com/news/cloud-power-cybersecurity-and-pro-av-priorities" target="_blank"><em><strong>[Cloud Power: Cybersecurity and Pro AV Priorities]</strong></em></a></p><p>Proactively secure and protect your technology, data, and operations with cybersecurity solutions that are matched with strong and reliable industry experience, and always ensure you partner with a security organization that understands your industry. There are differences in what you need to protect and how you protect it, depending on your vertical.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blueprint for Success: Finding Balance in Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/blueprint-for-success-finding-balance-in-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ It's about the experience, not the technology. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">74apQbjAg6D4f5K2zXkqnU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Apr 2025 10:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mathew Newfield ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/c5ypDctsjQc2m4x9jfLeDH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mathew Newfield, Diversified]]></media:description>                                                            <media:text><![CDATA[Mathew Newfield, Diversified]]></media:text>
                                <media:title type="plain"><![CDATA[Mathew Newfield, Diversified]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x2rQHjoLA5AqW2GrjMLnck-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>People think that cyber risk and cybersecurity are all about technology. But during my more than two decades in the cybersecurity arena—first as a cyber engineer and later as the chief information security officer at a public company and in executive management—I have found that cyber risk and cybersecurity have more to do with people, personalities, and psychology. </p><p><a href="https://www.avnetwork.com/news/cybersecurity-and-pro-av" target="_blank"><em><strong>[Cybersecurity and Pro AV]</strong></em></a></p><p>Whether you are preparing for the Super Bowl or another live event and/or delivering your product online or via TV, it’s critical to take an end-to-end approach to security. That starts with understanding what experiences people want and need from the content you are offering. </p><p>Expectations will vary depending on what you are offering and how people are experiencing it. Some people may be entering your arena. Others may be streaming or watching your event on TV. Certain individuals may be betting on the sporting event for which you are responsible. </p><p>Step back and think through all those scenarios, because the people experiencing your product through each of those lenses will be different. The attack vectors in these situations will also vary, as will regulatory requirements and people’s privacy expectations.  </p><h2 id="enterprise-vs-stadium-security">Enterprise vs. Stadium Security</h2><p>It’s critical to understand that you can't take blanket cybersecurity rules and programs from the enterprise world and shift them to sports or broadcast. There are distinct differences between sports and enterprise environments. One of the biggest differences is on the people side. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:920px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="6N3ajPVmkzDb7nZHetvnGA" name="Desk and eye -GettyImages_2190439490_16x9" alt="Cybersecurity Eyeball" src="https://cdn.mos.cms.futurecdn.net/6N3ajPVmkzDb7nZHetvnGA.jpg" mos="" align="middle" fullscreen="" width="920" height="517" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In enterprise cybersecurity, you generally can control who enters and exits your environments. You can limit what devices from what locations can access your website and VPN. And for physical security, you can issue badges to help ensure only current employees can enter your facilities and/or leverage geofencing to create virtual boundaries, so you can monitor access to sensitive areas and receive alerts if unauthorized parties breach those physical perimeters.  </p><p>But you don’t have that level of control with stadium security if you want to open your league and arena experiences to the world. You will need to implement an elevated level of both physical security and cybersecurity beyond what you would need in an enterprise environment. </p><p>Enterprise users are also more tolerant of the impacts of cybersecurity solutions. If an employee on a corporate laptop inside an enterprise facility has to wait an extra three seconds for a website to render, they are not going to file a complaint with the company’s chief information officer, chief information security officer, or IT team. If they did, it would probably elicit laughter. Public users have a different expectation regarding website load times when they are at home compared to being at work, so it is critical that the controls you put in place do not degrade their experience. </p><p><a href="https://www.avnetwork.com/news/ndi-6-1-new-features-enhanced-tools-and-more" target="_blank"><em><strong>[NDI 6.1: New Features, Enhanced Tools, and More]</strong></em></a></p><p>However, in sports, if your online experience is even a fraction of a second slower than what appears on the air, you may face a legal problem if you run afoul of sports betting rules. Cybersecurity controls, if implemented incorrectly, can easily add latency and delays to an online experience. Because there is less tolerance in sports for the impacts that cybersecurity controls can create, it is critical to work with consultative partners who are not only cybersecurity experts, but also understand your business and take an end-to-end approach to secure you and your customers and deliver top-notch experiences.  </p><h2 id="be-transparent">Be Transparent</h2><p>Many organizations today believe that security by obscurity is a good thing. The thought that if you don’t talk about or expose capabilities within your environment that something bad cannot happen is simply a wild fallacy. </p><p>People tend to inherently distrust security, technology, and cameras. If you are not clear about what you’re doing and why, it just takes a few people to post something that puts you on your heels. </p><div><blockquote><p>By making cybersecurity an integral part of your operations from the very beginning, you can turn it into a competitive advantage.</p></blockquote></div><p>It’s best to be transparent about what you’re doing. I’m not suggesting that you give away all your secrets or share your security protocols. But be forthright about your efforts to protect their physical security, credit card transactions, and other aspects of their experience.  </p><p>Explain in your literature, website, and stadium signs what controls you have in place. For example, you may want to post signs about whether or not you offer free Wi-Fi and how people can connect. That lets people know what is available and discourages them from connecting to unauthorized access points, protecting them in the process. </p><p>If you use cameras to allow faster entry into your facility or a more secure environment, let people know that. Calm people’s fears by communicating your policies around their images or information. If you will never use their face for anything other than a particular use case, share those details.  </p><p>Some visitors may be unwilling to allow you to use their face or their fingerprint, so let people opt into the experience. But remember that many of those same people already use their biometrics to log into their phones. If you offer something that makes opting in worth their while—and put the right information in front of them to make them comfortable—more people will opt in, which will improve their overall experience with your services. </p><h2 id="baked-in-security">Baked-In Security </h2><p>My team and I have had the opportunity to work with incredible organizations and venues such as Madison Square Garden, the NFL, the San Francisco Giants, the University of Texas Moody Center, and many others. Given my role, I have visited most of the stadiums across the United States. </p><p>Nobody likes to talk about security, but many sports organizations want to use facial recognition or fingerprint identification or encourage fans to install an app on their phones. I believe fans are willing to do all that if you demonstrate that you take cybersecurity—and your role as the custodian of their personally identifiable information—seriously. </p><p>No organization is immune to threats, but by making cybersecurity an integral part of your operations from the very beginning, you can turn it into a competitive advantage. Start by assessing the full spectrum of your audience’s interactions—whether in the stadium, online, or at home—and design solutions that balance security with seamless user experiences. Engage with trusted partners that have the expertise to help you implement robust, transparent, and scalable security measures tailored to your unique environment and budget.  </p><p><a href="https://www.avnetwork.com/news/executive-q-and-a-time-for-transformation" target="_blank"><em><strong>[Executive Q&A: Time for Transformation]</strong></em></a></p><p>Cybersecurity isn’t just a checkbox, it’s a responsibility that impacts every touchpoint of your brand. When you prioritize it, you protect your business and enhance the trust and loyalty of your fans and customers.  </p><p>Don’t wait for a breach to rethink your approach. The time to act is now. Evaluate your risks, build a strategy, and lead with a commitment to security that sets your organization apart. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud Power: Cybersecurity and Pro AV Priorities ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/cloud-power-cybersecurity-and-pro-av-priorities</link>
                                                                            <description>
                            <![CDATA[ Here's how to successfully navigate cloud migration challenges. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n8L3NZPaQAS7rtXqSEHpAR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KAmD5NgpK449Ps4fLbUAeU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Mar 2025 10:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Van Hoy ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/PEWcMZvVC3dqurb8E8hTDJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KAmD5NgpK449Ps4fLbUAeU-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dave Van Hoy, ASG]]></media:description>                                                            <media:text><![CDATA[Dave Van Hoy, ASG]]></media:text>
                                <media:title type="plain"><![CDATA[Dave Van Hoy, ASG]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KAmD5NgpK449Ps4fLbUAeU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anyone who’s dealt with migrating AV infrastructure to the cloud knows it’s not as simple as flipping a switch. It’s a massive shift, and while it offers game-changing flexibility and scalability, it also brings some serious cybersecurity challenges. Moving from a system that’s locked down on-prem and staff-controlled to the public cloud means your data and systems are suddenly in a much more open environment—and that’s enough to make any security professional’s hair stand on end. </p><p>When AV infrastructure transitioned to IP transport, that was the first time we had to think about security differently. Now, with the cloud, it’s a whole new ballgame. You’ve got confidential data and mission-critical systems operating in a potentially public space.  </p><p><a href="https://www.avnetwork.com/news/cloud-power-the-evolution-of-virtualized-production" target="_blank"><em><strong>[Cloud Power: The Evolution of Virtualized Production]</strong></em></a></p><p>CIOs and CFOs love the cloud because it offers cost efficiencies and the flexibility of OPEX-driven tools. But the security teams? They’re often not as enthusiastic. They’re focused on keeping data safe, and that doesn’t always align with the real-time demands of AV production. </p><h2 id="identifying-the-problem">Identifying the Problem</h2><p>This is also a problem in broadcast, but it's a much bigger problem in AV and internal production. In broadcast, there is always a risk benefit analysis. Broadcasters must produce content, and they have to be on the air. So, there is an absolute business case to find a sweet spot balance between having restrictive practices and being able to run its core business of actually making media.  </p><p>In what have traditionally been referred to as corporate environments, that need for compromise isn't looked at in the same way. If you are a large corporation, your need to produce content from an extreme business case point of view is not the same as somebody who is producing content as the actual product.  </p><div><blockquote><p>Security isn’t just a box to check at the end of a deployment—it must be baked in from the start.</p></blockquote></div><p>If I’m a broadcast call letter TV station, I can say with certainty that if we can't come to a reasonable perspective on how my cybersecurity practices are going to deploy, then we can't run that television station, which means It has no income whatsoever. At a big corporation, I don't have the same business case to take to the cybersecurity people and say, “Look, if we don't do this, our company can't achieve its primary goal.” And that can make it very difficult to come to a working solution.  </p><p>The result? Delays. Building out a real-time AV infrastructure across the public cloud might only take 90 days, but getting the green light from the security team can easily take another year. Security teams often don’t understand the unique needs of real-time AV systems, and that’s where a lot of the friction can occur. </p><p><a href="https://www.avnetwork.com/news/avoip-beyond-the-buzzword" target="_blank"><em><strong>[AVoIP: Beyond the Buzzword]</strong></em></a></p><p>You’ve also got the question of trust. AV teams need real-time access to systems that security teams might see as vulnerable. This is where early communication becomes critical. Without it, you risk running into barriers that delay or derail projects entirely. Security isn’t just a box to check at the end of a deployment—it must be baked in from the start. </p><h2 id="why-systems-integrators-matter">Why Systems Integrators Matter</h2><p>This is where <a href="https://www.avnetwork.com/news/scn-top-50-systems-integrators-2024" target="_blank">systems integrators</a> like us come in. We’re the ones who navigate the maze of corporate security requirements while still delivering a system that works for AV.  </p><p>The first step is always to sit down with the security team and figure out their rules. What are the governance standards? What’s allowed and what’s not? Without those answers upfront, you’re just setting yourself up for wasted time and frustration. </p><p>From a best practices point of view, you really want to look at it from the point of view of network performance requirements and security requirements. Work out the conflict between those two things before you start down the real system design process.  </p><p>One of the first questions we ask clients is: What exactly are you trying to do with the cloud? Is it the best option for this application? And what would the partnership with a cloud vendor look like? </p><p>Once you've determined the goals that the client has from an a functional point of view, and then looked at that from the client’s security governance point of view, it is incumbent that you advise the client on what will be involved, as well as the potential risks, so they don't invest money in a project with you that at the far end they can't realize, because it doesn't meet the requirements of the company. </p><h2 id="measure-twice-cut-once">Measure Twice, Cut Once</h2><p>A lot of the lesser-known issues around this are things like what transport protocols are allowed on the network and what kind of security methodologies are allowed for a VPN? You take that information, look at your design and determine if using those standards will meet the performance requirements for the system you've been tasked to build.  </p><p>Next step is to calculate the upfront costs of a cloud-based system. The good news is that once you’ve run that gauntlet with your client, you have a guidepost of what's allowed and can work creatively to find where that adoption can be most useful.  </p><p>Once you understand the client requirements, the first order of business is to understand the security concerns, then evaluate if the cloud is the right way to go. We need to determine if we’re talking about a private cloud inside the client’s data center or server room, or the public cloud in the form of Google, AWS, and Microsoft Azure. You can run the same technology using all. So, the question is, when we say the cloud, do we mean public cloud or software-defined workflows?  </p><p>Typically, the first thing the folks in charge of cybersecurity with a large corporation will want to know about is the transport of content, how is it protected as it’s distributed, and how are assets stored. Once we answer those questions, we can make location decisions and evaluate those environments so that we mitigate the challenges of moving these workflows into a software defined infrastructure, whether it be on-prem or in the cloud.  </p><p>The overall key is collaboration. Integrators have to bridge the gap between what the AV team needs and what the security team will allow. That often means a lot of back-and-forth discussions, tweaking designs, and even revisiting fundamental assumptions about the project. It’s not a quick process, but it’s essential to get right. </p><h2 id="balancing-security-with-performance">Balancing Security with Performance</h2><p>Here’s the thing about cybersecurity: It’s not free. It costs you in performance. You only have so much bandwidth, and every layer of security you add takes a bite out of your bandwidth and compute power.  </p><p><a href="https://www.avnetwork.com/news/cybersecurity-and-pro-av" target="_blank"><em><strong>[Cybersecurity and Pro AV]</strong></em></a></p><p>The more cybersecurity tools deployed, the slower the core application will run. In the AV world, where real-time performance is critical, that tradeoff cannot be ignored. </p><p>Take VPNs, for example. They’re great for creating a secure bubble, but they also add latency and are heavy on network resources. When you’re dealing with live production, those extra milliseconds can make a big difference. It’s all about finding the right balance, and that’s where upfront design work becomes so crucial. </p><p>This balancing act isn’t just about technology, it’s also about priorities. Security teams prioritize risk mitigation, while AV teams focus on performance. Finding common ground requires a clear understanding of each side’s goals and constraints. It’s not easy, but it’s possible with the right approach. </p><h2 id="the-price-of-failure">The Price of Failure</h2><p>Let’s be honest: Cost is always a factor. Cloud migration isn’t cheap, especially when you factor in the time and effort it takes to get through all the security hurdles. But here’s the good news: Those costs are usually one-time expenses. Once you’ve gone through the process, you’ve got a roadmap for future projects. That said, it’s still our job as integrators to help clients weigh the financial and operational pros and cons upfront. </p><p>Cost concerns also tie back to scalability. One of the cloud’s biggest advantages is its ability to scale up or down based on demand. But that scalability comes at a price. Clients need to understand not just the upfront costs, but also the ongoing expenses of running a cloud-based system. That includes everything from storage and bandwidth to licensing fees and support contracts. </p><p>We’ve seen what happens when this stuff goes wrong. Not long ago, a major failure involving a cloud storage platform made headlines. Bugs in the system weren’t addressed, and when a minor failure occurred, it cascaded into a major disaster. Massive amounts of content that was thought to be stored safely was lost. It was a wake-up call: Redundancy isn’t optional, and you can’t rely on a single point of failure, even in the cloud. </p><p>Another example comes from live production. Imagine a virtual production control room running entirely in the cloud. It’s an elegant solution—until the network goes down. Without a backup plan, the entire production grinds to a halt. These real-world failures underline the importance of planning for the worst-case scenario. Redundancy, failover systems, and robust testing aren’t just nice-to-have, they’re essential. </p><h2 id="looking-ahead">Looking Ahead</h2><p>The future of cloud-based AV workflows is exciting. We’re seeing advances in bandwidth and security tools that will make cloud deployments more flexible and secure. We’re going to see new methods of deploying software-defined workflows that will allow us to be more fluid when it comes to what lives on premise and what lives in the cloud.  </p><p><a href="https://www.avnetwork.com/news/same-sandbox-different-toys" target="_blank"><em><strong>[Tech Perspectives: Videoconferencing Industry in Same Sandbox but with Different Toys]</strong></em></a></p><p>One of the biggest innovations on the horizon is the ability to dynamically allocate workflows between on-prem and cloud environments. Right now, you have to choose: Do you run your production control room in the cloud or on the ground? Soon, we’ll have the tools to make that decision on the fly based on the specific needs of a production. </p><p>Another area of innovation is hybrid cloud models. These setups allow organizations to combine the best of both worlds: the control and security of on-prem systems with the scalability and flexibility of the cloud. As tools and technologies mature, hybrid models will become more seamless, enabling organizations to optimize their workflows like never before. </p><p>Moving AV infrastructure to the cloud isn’t just a technical challenge, it’s a balancing act. You’ve got to consider security, performance, cost, and practicality. And you’ve got to bring the right people—from security teams to integrators—into the process early. </p><p>The cloud isn’t a shiny new toy anymore. It’s a mature, deployable technology that can deliver real business value when done right. As we continue to see innovations in this space, I’m optimistic about the future. With the right planning and tools, we can create AV systems that are not only secure but also flexible and efficient. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TD SYNNEX Jessica McDowell on Security ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/features/td-synnex-jessica-mcdowell-on-security</link>
                                                                            <description>
                            <![CDATA[ Phishing remains a top threat, as cybercriminals use deceptive emails, messages, and calls to trick people into providing sensitive information or downloading malicious software. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sydrjsz4CQHK4JNBFXGMng</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SHboN4Sj7mG3qx9hTHjJiJ-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Oct 2023 13:55:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Resource Center]]></category>
                                                                                                                    <dc:creator><![CDATA[ SCN Staff ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SHboN4Sj7mG3qx9hTHjJiJ-1280-80.jpeg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security]]></media:description>                                                            <media:text><![CDATA[Security]]></media:text>
                                <media:title type="plain"><![CDATA[Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SHboN4Sj7mG3qx9hTHjJiJ-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In an interview with <em>Systems Contractor News</em> (<em>SCN</em>), Jessica McDowell, senior vice president of Business Development & Security Strategy at <a href="https://www.tdsynnex.com/na/us/" target="_blank">TD SYNNEX</a>, said phishing remains a top threat, as cybercriminals use deceptive emails, messages, and calls to trick people into providing sensitive information or downloading malicious software. She notes that artificial intelligence can be a double-sided coin, offering enhanced security on one side and the potential for mishandling data on the other. TD SYNNEX provides industry training via its Enablement Portal TDS University and the Security Practice Builder.</p><h2 id="it-seems-the-security-landscape-changes-daily-what-are-you-seeing-as-the-latest-threats">It seems the security landscape changes daily. What are you seeing as the latest threats?</h2><div  class="fancy-box"><div class="fancy_box-title">Jessica McDowell, senior vice president of Business Development & Security Strategy at TD SYNNEX</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="poYJVbvmyaxShEjmomygYg" name="Jessica McDowell cropped.jpeg" caption="" alt="Jessica McDowell, Senior Vice President, Business Development & Security Strategy" src="https://cdn.mos.cms.futurecdn.net/poYJVbvmyaxShEjmomygYg.jpeg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TD SYNNEX)</span></figcaption></figure></div></div><p>Phishing continues to remain the top threat, as cybercriminals use deceptive emails, messages, and calls to trick people into providing sensitive information or downloading malicious software.</p><p>Increasingly, we’re seeing these attacks involve extorting money from victims, most commonly through ransomware. Those attacks are continually evolving in sophistication as hackers find new ways around restrictions. They’re even using generative AI and machine learning to efficiently spin off new, more enhanced, and effective vectors of attack.</p><p>Long-term and highly sophisticated cyberattacks by nation-state threat actors remain a concern for government agencies and large corporations. And while finance and healthcare continue to be the top targeted industries, we’re now seeing the largest number of attacks on manufacturing as cybercriminals focus attention on Operational Technology (OT).</p><p>OT accounted for nearly 40 percent of cyber-attacks in 2022. While IT attacks steal data, OT attacks focus on industrial control systems. Criminals seek to make a physical impact as well as a monetary one.</p><p>From an integrator’s perspective, everything is now on the network, so everything must be protected. Networked audio and video also add potential threats through holes created in the network. So, it’s critically important to consider security in every application and in every vertical market.</p><h2 id="how-does-ai-factor-into-the-security-landscape-and-where-does-av-fit-in">How does AI factor into the security landscape? And where does AV fit in?</h2><p>AI is a two-sided coin.</p><p>On the one hand, we believe AI could potentially enhance security solutions through automation. AI can help identify and respond to threats in real time, potentially detecting and preventing attacks more effectively. AI can do this by learning to recognize normal usage and network interactions and behaviors by analyzing vast amounts of data very quickly and accurately. The resulting reduction in false positives and negatives in threat detection means better detection of abnormal activities—both from the inside and from skilled outside attackers.</p><p>And AI can help to automate some security tasks, which reduces the workload on security teams, allowing them to focus on more complex security issues. This is particularly important to resource-constrained organizations.</p><p>Conversely, AI also presents security risks. With AI comes the need for access to large amounts of data, which raises concerns about data privacy and the potential for mishandling personal information. In addition, AI-fueled attacks have the potential to be highly sophisticated, leading to challenges in defending against them.</p><p>We’re seeing a rapid expansion of AI within the audiovisual segment. For example, AI-powered video analytics can be used for security and surveillance by analyzing camera feeds for potential threats or incidents. AI algorithms can also detect and flag inappropriate AV content, which helps platforms maintain content standards and safety.</p><p>From a physical security standpoint, an increasing number of features are getting built into cameras that allow users to monitor and track a variety of details.</p><p>With growing concern about AV devices creating security risks on the network, it’s important for AV teams to coordinate with network administrators closely, explain the purpose of the hardware being put on the network, and work with them to configure the network in a secure but functional way.</p><p>A good first step for AV integrators is to change the default passwords on devices and not use the same one on multiple devices. Good password management is a great start to any security best practice.</p><h2 id="how-is-td-synnex-continuing-to-enable-av-partners-who-want-to-expand-their-security-practice">How is TD SYNNEX continuing to enable AV partners who want to expand their security practice?</h2><div><blockquote><p>Our  services team has been incredible at helping augment our partners' capabilities in terms of delivery and support."Sandi Stambaugh, senior vice president of product management at TD SYNNEX</p></blockquote></div><p>TD SYNNEX provides industry training via our Enablement Portal TDS University and through our Security Practice Builder. Our product business management teams serve as thought leaders throughout various technology segments by creating content and delivering information about the industry and specifically how our vendors and value-added services address industry trends.</p><p>Our Next UP team is focused on new and emerging vendors. In addition to enabling our partners to sell specific vendor offerings, they offer line card consultations to help our partners identify where they may have a gap in their offerings or where they may need to beef up their offerings in a particular segment.</p><p>In fact, our services team has been incredible at helping augment our partners&apos; capabilities in terms of delivery and support. We continue to offer complimentary Security Assessments, and more partners than ever are taking advantage of those. In addition, we recently launched a self-service portal with five assessments for partners to take with or on behalf of their customers, providing a guided plan based on the report findings.</p><p>In summary, our value to our partners is simplified into four key pillars: We help you learn, we solve for the technology ecosystem&apos;s complexity, we deliver technology solutions with versatility, and we help you evolve.</p><p>For more information, you can reach us at <a href="mailto:cybersolv@tdsynnex.com">cybersolv@tdsynnex.com</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A Video Wall Solution Helps Cybersecurity Provider Meet Monitoring Demands ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/a-video-wall-solution-helps-cybersecurity-provider-meet-monitoring-demands</link>
                                                                            <description>
                            <![CDATA[ VuWall's disruptive approach to video wall management in AVoIP environments helps seamlessly manage and control visual content. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m3RYqJVvT863vJDsCzxukG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7MrAbiSoMSChnueRHTwfWV-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Feb 2023 14:04:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Video Walls]]></category>
                                                    <category><![CDATA[Products &amp; Solutions]]></category>
                                                    <category><![CDATA[Visual]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/7MrAbiSoMSChnueRHTwfWV-1280-80.png">
                                                            <media:credit><![CDATA[VuWall]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[VuWall video wall solutions set up in a control room help monitor cybersecurity issues. ]]></media:description>                                                            <media:text><![CDATA[VuWall video wall solutions set up in a control room help monitor cybersecurity issues. ]]></media:text>
                                <media:title type="plain"><![CDATA[VuWall video wall solutions set up in a control room help monitor cybersecurity issues. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7MrAbiSoMSChnueRHTwfWV-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As a result of the changes in how organizations and people now work, the reliance on experienced, certified, and readily available technical and cybersecurity support is at an all-time high. It’s essential that all risks are continuously monitored to ensure network infrastructure is always available and secure at all times. Khipu Networks is a cybersecurity company developed in response to the need for constant support and managed services that let customers focus on project delivery, rather than be consumed by the daily tasks of monitoring and managing unforeseeable problems and cyber breaches. The company provides many services, which are overseen from the company’s 24x7x365 staffed Network Operations Centre (NOC). To that end, the company required a video wall management solution that would allow the flexibility to visualize the entirety of their data and informational feeds and replace their existing visualization solution, which couldn’t match their current and future needs. </p><p>VuWall&apos;s disruptive approach to video wall management in AV-over-IP environments, bridging AV, IT, and IP systems to seamlessly manage and control visual content throughout organizations, was exactly what Khipu needed.</p><p><a href="https://www.avnetwork.com/news/ces-2023-panel-explores-how-to-build-new-era-of-cybersecurity" target="_blank"><em><strong>[Experts Explores How to Build New Era of Cybersecurity]</strong></em></a></p><p>Khipu proactively monitors clients’ infrastructure and security postures to provide immediate identification of problems either before or as they occur—allowing quick alerting, action, and resolution. This means staff must have eyes on clients’ entire IT environments, which can include LAN, Wi-Fi, next-gen firewalls, RADIUS, WANs, UPS power supplies, IoT, servers, service/application, and more. Khipu’s existing solution was not flexible enough to give them the insight to allow for rapid response—with equipment failures and nagging intermittent issues becoming the norm. For example, the content could not be changed dynamically, and the user experience was clunky. The company replaced their exiting screens with six LG 55SVH7F 0.44mm bezel displays. To complete the solution, they needed a single technology solution that would allow their integrator to effortlessly build an IP-based video wall as well as provide Khipu staff with a centralized video management platform with customizable views that can be changed as needed.</p><p>To meet the demand for flexibility and modularity, the integrator on the project, Clear Visual Communications, proposed VuWall. VuWall delivers an innovative ecosystem of video wall controllers, encoders, and decoders—all managed by its interoperable TRx Centralized Management Platform (TRx). TRx eliminates the complexity of traditional video wall control and signal distribution over IP, with easy drag-and drop operations and without any programming. Easy to use, the TRx platform enables distribution of any source to any type of display in professional and mission-critical applications, which proved to be an ideal solution for Khipu’s NOC.</p><p>Yet another benefit, TRx simplifies the integration of third-party products. Already supporting a variety of AV-over-IP protocols (H.264, SDVoE, NDI) and compatible with multiple brands such as NETGEAR, Samsung, LG, IHSE, Adder, Genetec, and many others, TRx continues to grow its ecosystem, ensuring future-proof and scalable deployments.</p><p><a href="https://www.avnetwork.com/news/road-to-ise-vuwalls-shows-off-new-video-wall-collaboration-technology" target="_blank"><em><strong>[VuWall&apos;s Shows Off New Video Wall Collaboration Technology]</strong></em></a></p><p>Clear Visual Communications built the much-needed video wall for the NOC by stitching together two VuWall PAK 40 video wall nodes, increasing processing scalability and flexibility while adding a layer of redundancy. The compact PAK appliance is a networked, multi-decode node that can operate as a standalone device or be stitched with other nodes to build an IP-based video wall that is infinitely scalable. It simplifies video wall deployments by reducing the number of connections and eliminating a single point of failure, reducing project risk, and offering improved reliability.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1709px;"><p class="vanilla-image-block" style="padding-top:89.88%;"><img id="6NYdpv6MQBBvdPeKim6ChV" name="Khipu 2 - Edit.png" alt="VuWall video wall solutions set up in a control room help monitor cybersecurity issues." src="https://cdn.mos.cms.futurecdn.net/6NYdpv6MQBBvdPeKim6ChV.png" mos="" align="middle" fullscreen="" width="1709" height="1536" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: VuWall)</span></figcaption></figure><p>Whether the deployment is large or small, all that&apos;s required are PAK appliances, making it easy to build video walls. To increase the size of a video wall, the integrators can simply add a PAK. PAK features up to four HDp60 outputs or one 4Kp60 output and multiformat decoding up to 32 HD streams per device, including H.264, MPEG2, MPEG4, NDI, PNG, JPEG and VNC/remote desktops or virtualized browsers. PAK is designed for multiroom visualization, situational awareness, control rooms, and corporate workspaces. Its eco-friendly design boasts a compact form factor and low power consumption. PAK is small enough to be mounted behind monitors, saving rack space, and reducing extended video cable runs.</p><p>The installation also included a VuStream 150 encoder appliance and Application Server, which are also centrally configured and managed by TRx. The VuStream 150 provides single stream encoding of H.264 and H.265 sources in FHD and UHD. The VuWall Application Server is an appliance for streaming, sharing, controlling, and visualizing websites, dashboards, and applications across networks. The Application server simplifies video wall deployments by providing quick access to websites, dashboards, and applications from a centralized source—a must for the NOC. The NOC also benefited from VuWall’s ControlVu touch panel, which gives operators the freedom to change layouts and control devices with a simple touch.</p><p><a href="https://www.avnetwork.com/news/pro-av-2023-trends-to-watch" target="_blank"><u><em><strong>[Pro AV 2023: Trends to Watch]</strong></em></u></a></p><p>Clear Visual Communication’s deployment of VuWall delivered the exact flexibility and ease of use the NOC needed, aligning with the mission-critical requirement of the cyber security service provider. In addition, the company didn’t have to make addition investments for an external control solution such as Crestron or Extron.</p><p>“Our video wall is critical to our Cyber Security Operations Center," explained James Holland, UK technical manager at Khipu Cybersecurity. "We are extremely pleased with the performance and ease of use of VuWall’s PAK and TRx solution. Learning to operate and manage video wall content took minutes. The intuitive software and rich feature set will certainly improve response times and increase productivity in our control room. Knowing how easy it will be to increase the size of our video wall with PAK, as our demands change, is very reassuring. The fast and easy deployment was impressive, and we are confident that our integrator made the right choice with VuWall.”</p><p><a href="https://www.avnetwork.com/" target="_blank"><u><em><strong>[AV Network&apos;s top stories, product news, and expert insights]</strong></em></u></a> </p><p>“As one of the very first PAK customers, we are now confident that this technology is the future of video wall deployments," added Rebecca McCartney, operations manager at Clear Visual Communications. "We were extremely impressed with the quick and easy installation of the system and the ease of system configuration, yielding to a low-risk deployment. The feedback from the end user’s cybersecurity control room operators has been extremely positive, especially with respect to performance and ease of use. We clearly made the right choice and look forward to many more control room and video wall projects with VuWall.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts Explores How to Build New Era of Cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/ces-2023-panel-explores-how-to-build-new-era-of-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ Many agree the number of breaches—and the cost per breach—are on the rise. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sQvBLgsvBzC4tFCYaTgNW6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KtzBxdaykh63PLzoU9ktHg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Feb 2023 13:15:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Wayne Cavadi ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/EUEfWrUh2T2VUdGijJVv5V.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KtzBxdaykh63PLzoU9ktHg-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Rajeev Chand]]></media:description>                                                            <media:text><![CDATA[Rajeev Chand]]></media:text>
                                <media:title type="plain"><![CDATA[Rajeev Chand]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KtzBxdaykh63PLzoU9ktHg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In today’s era of artificial intelligence and a cyber-attacks, neither consumers nor businesses can face insecurities alone. Having protection leads to empowerment and hopefully a day of human security in all technology.</p><p>Rajeev Chand, partner and head of research at Wing Venture Capital, moderated the "Great Minds: How to Build a New Cybersecurity Era" panel at CES earlier this year in Las Vegas. The panel included Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency (CISA), and George Kurtz, CEO of CrowdStrike, and discussed cybersecurity today and where it is heading.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:360px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="YfgbLJAcVnLTGiKPxdQzMk" name="Jen Easterly.jpg" alt="Jen Easterly" src="https://cdn.mos.cms.futurecdn.net/YfgbLJAcVnLTGiKPxdQzMk.jpg" mos="" align="right" fullscreen="" width="360" height="360" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Jen Easterly </span><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Unfortunately, neither Kurtz nor Easterly could deny that the number of breaches and cost per breach are on the rise. “Cybercrime totaled $6 trillion last year, is projected to be $8 trillion this year, and over $10 trillion in 2024; that’s just not sustainable,” said Easterly. “We have to take a different approach to sustainable cybersecurity, which is about technology companies creating technology that is secure by design and secure by default.”</p><p><a href="https://www.avnetwork.com/features/cloud-power-what-you-need-to-know-about-security-in-the-cloud" target="_blank"><em><strong>[Cloud Power: What You Need to Know About Security in the Cloud]</strong></em></a></p><p>“Security parallels the slope of the technology innovation curve,” added Kurtz. “As the technology curve increases in its complexity, so does the security. And that’s where the gaps come in. Hopefully programs can help aid and make it better, but sadly we’re still dealing with poor passwords and backward compatibility.”</p><p>Both Kurtz and Easterly concurred it would be nice to have a general report card but isn’t that easy. Industries like finance that are highly regulated are more prepared, whereas the electronics industry may not be.</p><p>“We have this focus on how prepared a company is. That&apos;s important,” Easterly said. “But what we need to do is to figure out how the technology products that we use every day are going to be designed to be safe with security features built in and how they are built so the number of vulnerabilities is fewer than they are now.”</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:360px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="JnwQeF6EHsW5r5JPjMK2N" name="George Kurtz.jpg" alt="George Kurtz" src="https://cdn.mos.cms.futurecdn.net/JnwQeF6EHsW5r5JPjMK2N.jpg" mos="" align="right" fullscreen="" width="360" height="360" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">George Kurtz </span><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>“Consumers shouldn’t have to think about security,” Kurtz added. “If you’re putting the onus on the consumer, you’ve already lost. That’s built into the overall economics of what people are buying.”</p><p>Among the many other topics discussed was Russian cyberattacks and where they may have fallen short, and the double-edged sword of AI in cybersecurity.</p><p><a href="https://www.avnetwork.com/features/the-big-return-mitigating-network-security-risks-in-a-hybrid-workplace" target="_blank"><em><strong>[Mitigating Network Security Risks in the Hybrid Workplace]</strong></em></a></p><p>“AI in general is critical in the field of cybersecurity,” said Kurtz. “And we use it for good purposes but then there are the bad guys that use it for evil purposes.” Kurtz went on to discuss what he called community immunity and how AI equates to protection through training and monitoring.</p><p>Lastly, both Kurtz and Easterly agreed that companies should not be afraid to report cyberattacks or breaches. It is about protecting the consumer and being able to analyze attacks will only further that.</p><p>“It’s not about blaming or shaming a company,” said Easterly. “It’s about protecting a company so we can do something about it. But most importantly we can use that information to protect a sector. It’s about keeping the neighborhood safe.”</p><p>“The intent is to add value, not to add burden,” she concluded. “We need to come together so that companies have an incentive to come forward. It’s about safety of Americans, not self-preservation.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cobalt Iron Granted Patent for Cobalt Iron Compass Technology to Stop Cyberthreats in Their Tracks ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/cobalt-iron-granted-patent-for-cobalt-iron-compass-technology-to-stop-cyberthreats-in-their-tracks</link>
                                                                            <description>
                            <![CDATA[ Cobalt Iron Inc. has been granted a patent on its technology for dynamic IT infrastructure optimization in response to cyberthreats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jFqeKU4wACrzrvjVjjRQ5g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PDZAXevfhYTLVqfPaLbhXE-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Feb 2022 16:38:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Products &amp; Solutions]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PDZAXevfhYTLVqfPaLbhXE-1280-80.jpeg">
                                                            <media:credit><![CDATA[Cobalt Iron]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Cobalt Iron&#039;s newly patented techniques introduce unique ransomware analytics and automated optimizations for cloud security.]]></media:description>                                                            <media:text><![CDATA[Compass]]></media:text>
                                <media:title type="plain"><![CDATA[Compass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PDZAXevfhYTLVqfPaLbhXE-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.cobaltiron.com/" target="_blank">Cobalt Iron Inc.</a>, a leading provider of SaaS-based enterprise data protection, has been granted a patent on its technology for dynamic IT infrastructure optimization in response to cyberthreats. Issued on Dec. 28, 2021, U.S. Patent 11212304 describes new capabilities for <a href="https://www.cobaltiron.com/?utm_term=cobalt%20iron%20compass&utm_campaign=Search&utm_source=adwords&utm_medium=ppc&hsa_acc=9505119050&hsa_cam=9220959776&hsa_grp=88750544530&hsa_ad=417705153578&hsa_src=g&hsa_tgt=kwd-872530754601&hsa_kw=cobalt%20iron%20compass&hsa_mt=e&hsa_net=adwords&hsa_ver=3&gclid=Cj0KCQiAuvOPBhDXARIsAKzLQ8G3RTce3wygHbJ6uB75loaVyxCfCVITg6hAMlwmEjmNH67j2aaF5aEaAgH8EALw_wcB" target="_blank">Cobalt Iron Compass</a>, an enterprise SaaS backup platform, whereby Compass will automatically reconfigure IT infrastructure when it detects cyberthreats, such as a ransomware attack. This capability keeps data safe and accessible.</p><p>Cybercriminal activities increasingly threaten the availability and integrity of critical business data. It is challenging enough to detect these activities in a timely manner, but once they are detected, businesses are often unsure of what steps to take to limit the impact of an attack and to remediate any damage. Particularly challenging is the fact that most IT infrastructures are statically configured and completely unresponsive to changing conditions and cyberthreats. </p><p><a href="https://www.prosoundnetwork.com/the-wire/cobalt-iron-named-top-10-cybersecurity-company-by-cio-bulletin" target="_blank">[Cobalt Iron Named Top 10 Cybersecurity Company by CIO Bulletin]</a></p><p>The newly patented techniques introduce unique ransomware analytics and automated optimizations that respond to cyberthreats. They will dynamically adjust access to backup infrastructure and data to reduce exposures to cyberattacks. They also can provide analytics-based insights into an attack and automatically perform various operations to further secure data.</p><p>The techniques disclosed in this patent:</p><p> •Continually monitor metrics, events, and conditions for indications of a cyberattack in the network.</p><p> •Analyze metrics, events, conditions, and configurations to identify infrastructure components and data that could be impacted by or be vulnerable to a cyberattack.</p><p> •Automatically restrict access to impacted or vulnerable infrastructure components and data.</p><p> •Automatically create an audit report of impacted infrastructure components and data.</p><p> •Automatically initiate remediation operations for impacted data. Remediation operations might include things such as:</p><p>  o Initiating data replication of a previous clean backup version of the data to an off-site location.</p><p>  o Initiating recovery and validation of affected data into a safe storage location.</p><p>For example, in the event of a cyberattack, Compass could detect the event, conduct impact analysis to determine which data and hardware components might be affected, restrict access to those data and components, perform other operations to remediate exposures, and generate an audit report associated with the event. </p><p><a href="https://www.helpnetsecurity.com/2021/12/16/cobalt-iron-compass-eos/" target="_blank">Cobalt Iron Compass EOS allows users to search the entire enterprise backup landscape</a></p><p>"The Cobalt Iron Compass solution delivers backup infrastructure and data with simplicity and security at scale," said Rob Marett, Cobalt Iron&apos;s chief technology officer. "This patent discloses additional ransomware analytics, combined with automated responses. These new Compass techniques further secure critical business data and make backup infrastructure more responsive to cyberthreats. This patent extends Cobalt Iron&apos;s technology leadership in the areas of ransomware analytics and automated IT infrastructure optimizations."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Solutionz Launches Solutionz Security  ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/solutionz-launches-solutionz-security</link>
                                                                            <description>
                            <![CDATA[ Solutionz Security, sister company of AV integrator Solutionz Inc., delivers enterprise cybersecurity protections to small and mid-sized businesses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iZi9ytNZhYZbTeP6TF5gsD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p29Cpa8rrW3y9mymR8zgxN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Aug 2021 07:01:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mergers &amp; Acquisitions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p29Cpa8rrW3y9mymR8zgxN-1280-80.jpg">
                                                            <media:credit><![CDATA[Solutionz Security]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity lock]]></media:description>                                                            <media:text><![CDATA[Cybersecurity lock]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity lock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p29Cpa8rrW3y9mymR8zgxN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Solutionz Inc. announced the launch of <a href="https://www.solutionzsecurity.com/">Solutionz Security</a>, a full-service firm offering cybersecurity protections for small and midsized businesses, the public sector, and enterprise organizations around the world.</p><p>Solutionz Security originated from a need to provide cybersecurity protection for the customers of AV integrator Solutionz Inc.</p><p>Executives at Solutionz saw that cybersecurity-related attacks were growing in both frequency and scope. The increase in ransomware demands, supply chain attacks, and threats to internet of things (IoT) devices places even small organizations at risk as hackers exploit backdoors in smart TV firmware or software, telecommunication equipment, and cameras.</p><p>“If you think about internet traffic that you have through communication, it is no different than data. The same mechanisms that monitor communication, monitor IoT traffic. There is an easy bridge that we are creating over that chasm,” said Solutionz CEO <a href="https://www.linkedin.com/in/wwarnick/">Bill Warnick</a> of the logical <a href="https://www.avnetwork.com/news/solutionz-launches-secureav-cybersecurity-managed-service">crossover from an AV-specific cybersecurity division</a> to the need for a sister company focused on full cybersecurity programs.</p><p><em>[ </em><a href="https://www.avnetwork.com/features/how-to-think-about-network-security-after-covid"><em>How to Think About Network Security After COVID</em></a><em> ]</em></p><p><a href="https://www.linkedin.com/in/cybersecurityshawn/">Shawn Fernandez</a>, Solutionz vice president of business development and leader of the initiative to develop Solutionz Security, said, “There are a lot of layers to cybersecurity. We created Solutionz Security to have 100 percent focus on cybersecurity. We took two years to develop our team of partners, experts who understand the complexities of cybersecurity both from the MSP and from the customer’s perspectives.”</p><p>Fernandez described Solutionz Security’s approach: “We are selling more than tools. We come into an organization and address their current defense posture.”</p><p>He continued, “The best money spent is the money already spent on your cybersecurity. We want to build on your success. We do not come in and say that we need to rip and replace your current solutions because our product is better. We look at what an organization has already done, the efforts already put in. We then assess the gaps that exist, and we formulate a plan, prioritizing the largest and most risky gaps, and then we solve for that.”</p><p>Warnick emphasized the importance of making cybersecurity simple for customers, “Cybersecurity does not have be hard. You don’t need a law degree to know when you need the police.” The quality of the assessment and managed services allow customers to feel confident that their digital landscapes are understood and protected without them needing in depth knowledge about cybersecurity. Solutionz Security’s cost-effective protections meet and document the various compliance requirements for payments, healthcare, corporate and government organizations.</p><p><em>[ </em><a href="https://www.avnetwork.com/news/comptia-ongoing-vigilance-and-improvements-characterize-the-state-of-cybersecurity-in-2020"><em>Ongoing Vigilance and Improvements Characterize the State of Cybersecurity in 2020</em></a><em> ]</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to Think About Network Security After COVID ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/features/how-to-think-about-network-security-after-covid</link>
                                                                            <description>
                            <![CDATA[ As networks grow more complex and devices more sophisticated, vigilance in the fundamentals of network security will be more important than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ooRBqA6wEk8eBpz77oBdXF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MTUDM8Jp2WbuFcGrNaY8j6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Aug 2021 20:00:31 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Aug 2021 16:12:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Control &amp; Automation]]></category>
                                                    <category><![CDATA[Products &amp; Solutions]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jim Beaugez ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MTUDM8Jp2WbuFcGrNaY8j6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/Teera Konakan]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network security graphic]]></media:description>                                                            <media:text><![CDATA[Network security graphic]]></media:text>
                                <media:title type="plain"><![CDATA[Network security graphic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MTUDM8Jp2WbuFcGrNaY8j6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Of the many cultural buzzwords coined during the COVID-19 pandemic, the term “Zoom bombing” may be the most memorable.</p><p>Early in 2020, celebrities like Kristen Bell and Conan O’Brien popularized the practice of surprising online videoconference attendees by joining their meetings unannounced. As charming as that may be, not all Zoom bombings are innocuous. Bad actors use these virtual break-ins to secretly snoop on corporations and organizations. They may also share inappropriate images and videos meant to disrupt the proceedings.</p><p>Like other computer and network hackers, Zoom bombers rely on human fallibility and poor judgment to gain access. The most common entrance is right through the front door, either because the host neglected to use safety protocols such as requiring a password, or because they failed to sequester attendees in a queue so they could be verified before being allowed into the meeting. Sophisticated hackers can mimic profiles of actual guests, making it harder for the host to kick them out of the call.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2974px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="FjRdwSFUBScAjAMdDQF264" name="Steve Greenblatt sq silo.jpg" alt="Steve Greenblatt" src="https://cdn.mos.cms.futurecdn.net/FjRdwSFUBScAjAMdDQF264.jpg" mos="" align="right" fullscreen="" width="2974" height="2974" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right inline-layout"><span class="caption-text">Steve Greenblatt </span><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>“The best way is to have at least one step of authorization, but two steps can ensure that there isn’t a breach or someone who is not authorized in the meeting,” said Steve Greenblatt, CTS, president and founder of Control Concepts. “A lot of these steps take time and effort, make conferences less convenient, or make more work for people, but they will result in a more secure outcome and allow hosts to avoid those types of embarrassments, as well as potential security breaches.”</p><p>Zoom bombing is just the tip of the proverbial iceberg of new network security threats. As workers return to office environments after a year or more of working at home, they may bring devices with them that have not been vetted by IT staff. Tim Albright, chief marketing officer at Conference Technologies Inc. (CTI) and CEO of AVNation, said that the potential for third-party peripherals to compromise an organization’s network is the single biggest security issue integrators are dealing with heading into late 2021 and 2022.</p><p><em>[ </em><a href="https://www.avnetwork.com/features/staying-secure-in-the-new-hybrid-work-world"><em>Staying Secure in the New Hybrid Work World</em></a><em> ] </em></p><p>“Up until a year and a half ago, the IT department was also the procurement department for everything that was on the network,” said Albright. “Now, a year and a half later, folks have gotten equipment on their own to make their work-from-home [situations] work. That stuff is going to start finding its way to the office and onto the office network.”</p><figure class="van-image-figure pull-left inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1095px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="mA7KgNkG6M8VU9RL8NsVC3" name="Tim Albright sq silo.jpg" alt="Tim Albright" src="https://cdn.mos.cms.futurecdn.net/mA7KgNkG6M8VU9RL8NsVC3.jpg" mos="" align="left" fullscreen="" width="1095" height="1095" attribution="" endorsement="" class="pull-left"></p></div></div><figcaption itemprop="caption description" class="pull-left inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Organizations have ways of locating unapproved peripherals, such as by deploying tools that continually scan the network for known and unknown MAC addresses and can alert IT or the AV integrator when an unauthorized device is connected. But those measures are purely reactive. Greenblatt says proactive maintenance can prevent security threats from infiltrating the network in the first place.</p><p><em>[ </em><a href="https://www.avnetwork.com/features/the-integration-guide-to-secure-av"><em>The Integration Guide to Secure AV</em></a><em> ] </em></p><p>“Vulnerabilities are happening all the time, and computers these days are getting updates and security patches to address new threats,” he said. “It’s very possible that becomes part of a maintenance agreement. In my business, for example, we have somebody who looks at our website every month to make sure we don’t have vulnerabilities, that we’re updating our software to make sure that somebody can’t come in and hack our website. If we apply that idea to an AV system, you look at the devices or the setup [and determine if] they need to be better secured. What was in place when the system was turned over may not be as effective now because of new vulnerabilities or issues that may have been identified since then.”</p><p>In addition to regular audits and multifactor authentication, integrators can set up a VLAN, or virtual local area network, to help protect against security threats. VLANs allow partitioning of a server so that different classes of connected devices can be grouped together. “The challenge with that, though, is that there are still some ports that need to be open” to allow certain local devices to be able to access the internet, Greenblatt said. “There are also AV over IP devices that need to be able to traverse the network to be effective, so while VLAN can be very powerful, there’s always going to be a need to open up access outside of it.”</p><p>Simple practices many people ignore, like changing devices’ default usernames and passwords, can also help prevent network hacks. It’s relatively easy for a hacker to match default IDs to Wi-Fi routers and other connected devices, and AV systems are particularly susceptible to distributed denial of service (DDoS) attacks in which vast numbers of devices across many networks are manipulated simultaneously.</p><p>These “zombie attacks” can be large in scale, and costly to fix. A well-known example in 2016 took down Netflix and many other networks along the East Coast. In the mix of devices exploited in the attack, Albright noticed something troubling to the AV business: zombie web cameras and network-compromised speakers. “When I saw that, it’s like, yes, the AV industry certainly has an issue with this,” he said. “We have an issue because our devices are getting put on the network more frequently, which means we need to make sure we’re doing the simple things, such as changing the login and password. You’ve got folks who can take control of these because they’re public-facing, on the network, on the internet.”</p><p>On the horizon, the increasing numbers of internet-connected smart devices create more network vulnerability. “You’re talking about yet another entry point that could be a vulnerability, and if it happens that an [Amazon] Echo or another type of voice interface is listening, then [hackers] can know what you’re talking about and be able to track what is happening,” added Greenblatt. “As we try to make systems intelligent, we have to be concerned about them having access to information that gives them more power than we know.”</p><p>As networks grow more complex and devices more sophisticated, vigilance in the fundamentals of network security will be more important than ever.</p><p>“The rule of thumb I think everybody goes with is that you’re only as strong as your weakest link,” concluded Greenblatt. “We do a good job of having technicians [pull wiring], and we have experts who know how to set up products and make sure an image looks good and the room sounds good, but we should also have an IT or cybersecurity specialist who can give our clients confidence because they know they’ve brought somebody in who’s going to protect them.”</p><p><a href="https://issuu.com/futurepublishing/docs/scn332.digital_august_2021"><em><strong>Click here to read more stories from the August 2021 issue of SCN.</strong></em></a></p><p><br></p><h2 id="focus-on-network-security">Focus on Network Security</h2><p><a href="https://www.avnetwork.com/features/playing-it-safe-the-state-of-networked-av-security"><strong>Improving AV Device Security on Converged IP Networks</strong></a> • How can system designers and integrators collaborate more effectively with tech managers to improve AV device security on converged IP networks?</p><p><a href="https://www.avnetwork.com/features/lock-and-key"><strong>Keeping Sensitive Information Secure on the Network</strong></a><strong> •</strong> As more networked devices join the AV space, many network administrators in all industries are expressing concerns about the efficiency of the network.</p><p><a href="https://www.avnetwork.com/features/staying-secure-in-the-new-hybrid-work-world"><strong>Staying Secure in the New Hybrid Work World</strong></a><strong> • </strong>As AV/IT managers adapt to the new hybrid workforce model, more personalized approaches to technology are needed, opening up new potential network security vulnerabilities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Increasing Threat of Ransomware in Higher Education (EDUCAUSE Review) ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/the-increasing-threat-of-ransomware-in-higher-education-educause-review</link>
                                                                            <description>
                            <![CDATA[ The Increasing Threat of Ransomware in Higher Education (EDUCAUSE Review) ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FRkYxwcsh7gShTwrV8DNdK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8XzQX3CwaieF2BxkneQcdX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Jul 2021 14:26:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ EDUCAUSE Review ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8XzQX3CwaieF2BxkneQcdX-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Measuring Learning Will Be Key to Improving It in 2018 (EdSurge)]]></media:description>                                                            <media:text><![CDATA[Measuring Learning Will Be Key to Improving It in 2018 (EdSurge)]]></media:text>
                                <media:title type="plain"><![CDATA[Measuring Learning Will Be Key to Improving It in 2018 (EdSurge)]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8XzQX3CwaieF2BxkneQcdX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>"Even smaller universities and colleges, as well as those without an emphasis on research, are prime targets for this type of cyberattack. Regardless of whether an institution considers its data to be valuable, chances are that cybercriminals do."</p><p><a href="https://er.educause.edu/articles/2021/6/the-increasing-threat-of-ransomware-in-higher-education" target="_blank"><strong>Read More</strong></a></p><p><strong>WHY THIS MATTERS:</strong></p><p>Education is the most affected sector for malware attacks when compared to other industries like business and professional services, retail and consumer goods, and high tech. An analysis of ransomware campaigns within higher education found that ransomware attacks against colleges and universities have more than doubled since the onset of the coronavirus pandemic.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to Get an IT Security Certification ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/features/how-to-get-an-it-security-certification</link>
                                                                            <description>
                            <![CDATA[ In addition to keeping your systems locked down, a solid foundation in IT security concepts can help you gain access to higher-level business discussions, too. We explore what it takes to earn the gold standard of security certifications: the CISSP. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjCjdDCxPrNEk9SQN5Yyuc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/trpJkCuJiqu4PREfqVg9hn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Apr 2021 13:23:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Carolyn Heinze ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/trpJkCuJiqu4PREfqVg9hn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network security stock image]]></media:description>                                                            <media:text><![CDATA[Network security stock image]]></media:text>
                                <media:title type="plain"><![CDATA[Network security stock image]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/trpJkCuJiqu4PREfqVg9hn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Good AV/IT tech managers know that addressing security concerns makes for a stronger relationship between their organization and the security team—and for smoother deployments. But it doesn’t stop there: when you’re well-versed in IT security concepts, you’re well-positioned to gain access to higher-level business discussions. One route to developing security expertise is through certification, and <em>AV Technology</em> recently explored what’s involved in earning what’s widely considered the gold standard of security certs: the Certified Information Systems Security Professional, or CISSP. </p><p>Azeem Khan is senior consultant of application development (AV) at CIBC, a financial institution headquartered in Toronto. With a background in both security and AV, he is currently pursuing a CISSP—a logical step forward, he said. He believes that security knowledge is necessary in today’s networked environment, and holding a CISSP proves that one is capable of implementing and managing enterprise-level information security. “Nowadays at the enterprise level when we are putting all of these AV devices [on the network], it is our responsibility as AV specialists to be able to point out the security risks that we see when devices are communicating with each other,” he said. “As an AV specialist, you know how people interact with those devices, so you have more perspective on the security risk that comes from those devices versus people who are not from the AV domain.” </p><p><em>[</em><a href="https://www.avnetwork.com/features/staying-secure-in-the-new-hybrid-work-world" target="_blank"><em>Staying Secure in the New Hybrid Workforce Model</em></a><em>]</em></p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:400px;"><p class="vanilla-image-block" style="padding-top:137.75%;"><img id="hFwUz6bXrTfUgBz3AjznNn" name="05_F_Cert_Khan.jpg" alt="Azeem Khan, CIBC" src="https://cdn.mos.cms.futurecdn.net/hFwUz6bXrTfUgBz3AjznNn.jpg" mos="" align="right" fullscreen="" width="400" height="551" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Azeem Khan, CIBC </span></figcaption></figure><p>(ISC)2, headquartered in Clearwater, FL, is the professional organization that offers the CISSP. The CISSP comprises eight domains: security and risk management; asset security; security architecture and engineering; communication and network security; identity and access management (IAM); security assessment and testing; security operations; and software development security. (ISC)2 requires that candidates have five years of paid work experience in two of the eight domains (there are exceptions; visit the (ISC)2 website and download the CISSP Certification Exam Outline for more details).</p><p>“In IT and AV—and I consider AV part of IT—cybersecurity crosses many fields,” said Toni Hahn, content development manager at (ISC)2. “I feel everyone should know something about cybersecurity.” The CISSP, she explained, covers cybersecurity concepts, and the exam requires candidates to apply them. “AV could fit into almost every domain on the CISSP.”</p><p>The CISSP is not, however, for everyone. Damon Drake, content developer at (ISC)2, noted that sometimes organizations require job candidates to hold CISSPs for positions that don’t really require them. “We’ve seen [situations] where a company will have an entry-level position with entry-level pay requiring a CISSP certification,” he said. “It’s really a managerial-level cert. You’ve got to be able to look at risk management: how does that affect your physical security? How do you do access control—both physical and cyber?” There’s a lot to it, and as Drake puts it: “it’s not a beginner cert.”</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:400px;"><p class="vanilla-image-block" style="padding-top:139.25%;"><img id="cdLDymSnRfcCy9YnoiiSJn" name="05_F_Cert_Hahn.jpg" alt="Toni Hahn, (ISC)2" src="https://cdn.mos.cms.futurecdn.net/cdLDymSnRfcCy9YnoiiSJn.jpg" mos="" align="right" fullscreen="" width="400" height="557" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Toni Hahn, (ISC)2 </span></figcaption></figure><p>Drake and Hahn should know. Both are ex-military (he was in the Air Force, she’s former Navy). While in the military, both worked in AV and IT. Once out, both worked in security engineering and management in mission-critical environments. Both failed the CISSP twice.</p><p>Drake recounts that when he first decided to prepare for the CISSP, he took an online course featuring many videos. When he didn’t pass his first exam, he did a boot camp. That didn’t bring the desired results either. </p><p><em>[</em><a href="https://www.avnetwork.com/news/av-network-nation-panel-addresses-networked-audio-security"><em>AV Network Nation Panel Addresses Networked Audio Security</em></a><em>]</em></p><p>“A lot of it comes down to—and this is probably going to sound counter-intuitive—the more diverse your career is, the more you can get jaded by what companies do, as opposed to what the right thing to do is,” Drake said.</p><p>Because the questions on the CISSP exam are largely scenario-based, the “right thing to do” is the primary focus, Drake explained. But if you’ve been working in a company that has refused to invest in the application of security best practices, you may have developed a belief system that negates their necessity. This won’t be much help with the CISSP. “A lot of our questions are worded like, ‘What is the best? What is the most appropriate? What is the greatest?’ And although those are subjective terms, that is putting you in the best practice mindset. All of our questions are written that way to really focus on the best practice for whatever concept is being presented at the time. It’s really stepping back and almost being mentored by a manager and understanding the business functions, and then applying the cyber concepts to those.”</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:400px;"><p class="vanilla-image-block" style="padding-top:137.25%;"><img id="qbEfDeNFPkzhfdFRhNr38n" name="05_F_Cert_Drake.jpg" alt="Damon Drake, (ISC)2" src="https://cdn.mos.cms.futurecdn.net/qbEfDeNFPkzhfdFRhNr38n.jpg" mos="" align="right" fullscreen="" width="400" height="549" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Damon Drake, (ISC)2 </span></figcaption></figure><p>Like Drake, Hahn took a boot camp and failed her first exam. “Then I said, ‘well, I’m just going to study all these books and these practice questions,’” she recalled. “I thought I was really ready. They put the test in front of me and I actually asked the proctor—because this was back in the paper/pencil days—‘Are you sure you gave me the CISSP?’ He looks at the exam and he says, ‘Yup.’” After yet more studying—and another boot camp—the third time turned out to be the charm. </p><p><em>[</em><a href="https://www.avnetwork.com/features/byte-sized-lesson-security-and-tcp-handshakes"><em>Byte-Sized Lesson: Security and TCP Handshakes</em></a><em>]</em></p><p>Both Drake and Hahn agree that candidates should plan for a year’s worth of exam preparation. “One single boot camp, one class, one book, or one video series is probably not enough,” Hahn said. She advises people to cross-study and take the practice exams. Although they may not contain what is on the actual exam—sometimes practice exams focus on definitions, like “What is a disaster recovery plan?” rather than the scenario-based questions the CISSP exam tends to favor—she said that it helps people gain a deeper understanding of the concepts. “It all starts clicking. And so by the time you do sit for the exam, you know the concept—you’re not just memorizing [the definition of a disaster recovery plan]. You know the actual concept, and when you’re asked the [scenario-based] question, you can say, ‘You know what? This is what I would do.’”</p><p>Anishia Gopi, senior consultant of infrastructure engineering at CIBC, is also in the process of preparing for the CISSP exam. In addition to the official study guide and other materials, she has also participated in study groups. “Some people prefer to just sit with their book and go through it,” she said. While she said the book and online materials are definitely necessary, exchanging with other candidates helps to solidify the concepts. “If you have a group of people, you can share knowledge and tackle the scenario-based questions in a better way.” She also counsels candidates to examine the tasks they perform daily at work, and how they may relate to the exam preparation material. </p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:400px;"><p class="vanilla-image-block" style="padding-top:120.25%;"><img id="k9PdxwtkaCBcY4TgkPY5Cn" name="05_F_Cert_Gopi.jpg" alt="Anishia Gopi, CIBC" src="https://cdn.mos.cms.futurecdn.net/k9PdxwtkaCBcY4TgkPY5Cn.jpg" mos="" align="right" fullscreen="" width="400" height="481" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Anishia Gopi, CIBC </span></figcaption></figure><p>For Gopi, the CISSP provides the opportunity for meaningful professional development. “This is not just about adding a certification tag on your resume—it’s not just that,” she said. “You are taking a step toward being involved in making business decisions. It’s not easy—some of the modules are so difficult that you can easily give up. But I would say that if you are serious about that bigger goal, then it’s easier to pursue.”</p><p><strong>Additional CISSP Tips</strong></p><p>Hahn recalled that when she was working in AV, she was hands-on, ready to connect cables, configure systems, and perform the plethora of physical tasks associated with deploying a system. There is an element to the CISSP, she said, that more traditional AV professionals may be unfamiliar with. </p><p>“They have to touch on the paperwork side,” Hahn said. “How do you do a business continuity plan? What is a disaster recovery plan? Is there anything I need to know about configuration management? What is a risk assessment? It’s more the paperwork—the policies, the procedures—that an audiovisual professional may have to study a little more. And probably the cryptography—it’s not its own domain anymore, but it is on the exam.”</p><p><em><strong>Carolyn Heinze is a freelance writer/editor. </strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Americans Come 4th in the World in Terms of Cybersecurity, Study Finds ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/americans-come-4th-in-the-world-in-terms-of-cybersecurity-study-finds</link>
                                                                            <description>
                            <![CDATA[ NordVPN recently launched a National Privacy Test to gain insights into the global level of cybersecurity awareness and found that Americans are fourth in the world in terms of their cybersecurity skills and knowledge. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FbvU9V8w6CccYTK4DeLpL5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iADUKNNkMTCnHVCuNuQCGE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Apr 2021 16:47:12 +0000</pubDate>                                                                                                                                <updated>Tue, 27 Apr 2021 12:06:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iADUKNNkMTCnHVCuNuQCGE-1280-80.jpg">
                                                            <media:credit><![CDATA[Yuichiro Chino/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cybersecurity]]></media:description>                                                            <media:text><![CDATA[cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iADUKNNkMTCnHVCuNuQCGE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://nordvpn.com/ " target="_blank">NordVPN</a> recently launched a National Privacy Test to gain insights into the global level of cybersecurity awareness and found that Americans are fourth in the world in terms of their cybersecurity skills and knowledge.</p><p>The U.S. got 68.5 points out of 100 in the National Privacy Test and was outplayed by three European countries: Germany, the Netherlands, and Switzerland.</p><p><em>Watch the video below to learn more about the top five cybersecurity insights gained from the research.</em></p><iframe width="560" height="315" frameborder="0" data-lazy-priority="high" data-lazy-src="https://www.youtube.com/embed/jyWNy1qFSFI"></iframe><p>Americans have demonstrated a great knowledge of how to behave when facing direct threats online (87.3/100). For example, 92.9 percent of respondents understand that the bargains on streaming service accounts you can find on eBay are stolen credentials and should not be bought. </p><p>What Americans fell short of the most was habits. A third of respondents (30.6 percent) proceed without “wasting” their time on reading the privacy policy, while 31.0 percent postpone software updates indefinitely.</p><p>NordVPN says 48,000 people from 192 countries participated in the National Privacy Test, and analysis was performed only on countries where the number of respondents was higher than 400. </p><p><br></p><p>For more information or to view the full report, visit <a href="https://nordvpn.com/national-privacy-test/" target="_blank">https://nordvpn.com/national-privacy-test/</a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CompTIA: Ongoing Vigilance and Improvements Characterize the State of Cybersecurity in 2020 ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/comptia-ongoing-vigilance-and-improvements-characterize-the-state-of-cybersecurity-in-2020</link>
                                                                            <description>
                            <![CDATA[ According to CompTIA research, organizations are building confidence that their cybersecurity practices are headed in the right direction, aided by advanced technologies, more detailed processes, comprehensive education, and specialized skills. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UUxPoro3Uq3iePRKEPiNKQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xPEFf6uyYuZKVN5adcMkBo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Oct 2020 19:49:08 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Oct 2020 16:02:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Market Trends]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xPEFf6uyYuZKVN5adcMkBo-1280-80.jpg">
                                                            <media:credit><![CDATA[CompTIA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[State of Cybersecurity 2020 report from CompTIA]]></media:description>                                                            <media:text><![CDATA[State of Cybersecurity 2020 report from CompTIA]]></media:text>
                                <media:title type="plain"><![CDATA[State of Cybersecurity 2020 report from CompTIA]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xPEFf6uyYuZKVN5adcMkBo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are building confidence that their cybersecurity practices are headed in the right direction, aided by advanced technologies, more detailed processes, comprehensive education, and specialized skills, new research from CompTIA finds.</p><p>Eight in 10 organizations surveyed for <a href="https://www.comptia.org/content/research/cybersecurity-trends-research" target="_blank">CompTIA’s <em>State of Cybersecurity 2020</em> report </a>said their cybersecurity practices are improving.</p><p>At the same time, many companies acknowledge that there is still more to do to make their security posture even more robust. Growing concerns about the number, scale, and variety of cyberattacks, privacy considerations, a greater reliance on data, and regulatory compliance are among the issues that have the attention of business and IT leaders.</p><p>Two factors—one anticipated, the other unexpected—have contributed to the heightened awareness about the need for strong cybersecurity measures.</p><p><br></p><p>“The COVID-19 pandemic has been the primary trigger for revisiting security,” said Seth Robinson, senior director for technology analysis at CompTIA. “The massive shift to remote work exposed vulnerabilities in workforce knowledge and connectivity, while phishing emails preyed on new health concerns.”</p><p>[<a href="https://www.avnetwork.com/features/the-integration-guide-to-avoip-2020" target="_blank"><em>The Integration Guide to AVoIP</em></a>]</p><p>Robinson noted that the pandemic accelerated changes that were underway in many organizations that were undergoing the digital transformation of their business operations.</p><p>“This transformation elevated cybersecurity from an element within IT operations to an overarching business concern that demands executive-level attention,” he said. “It has become  a critical business function, on par with a company’s financial procedures.”</p><p>As a result, companies have a better understanding of what do about cybersecurity. Nine in 10 organizations said their cybersecurity processes have become more formal and more critical. Two examples are risk management, where companies assess their data and their systems to determine the level of security that each requires; and monitoring and measurement, where security efforts are continually tracked and new metrics are established to tie security activity to business objectives.</p><p>The report also highlights how the “cybersecurity chain” has expanded to include upper management, boards of directors, business units, and outside firms in addition to IT personnel in conversations and decisions.</p><p>Within IT teams, foundational skills such as network and endpoint security have been paired with new skills, including identity management and application security, that have become more important as cloud and mobility have taken hold. On the horizon, expect to see skills related to security monitoring and other proactive tactics gain a bigger foothold. Examples include data analysis, threat knowledge, and understanding the regulatory landscape.</p><p>[<a href="https://www.avnetwork.com/features/the-technology-managers-guide-to-the-state-of-av-over-ip" target="_blank"><em>The Technology Manager&apos;s Guide to the State of AV Over IP</em></a>]</p><p>Cybersecurity insurance is another emerging area. The report reveals that 45 percent of large companies, 41 percent of mid-sized firms, and 37 percent of small businesses currently have a cyber insurance policy. Common coverage areas include the cost of restoring data (56 percent of policy holders), the cost of finding the root cause of a breach (47 percent), coverage for third-party incidents (43 percent), and response to ransomware (42 percent).</p><p><em>State of Cybersecurity 2020</em> is based on a survey of workforce professionals at 425 U.S. companies conducted in August and September 2020. The complete report is available at <a href="https://www.comptia.org/content/research/cybersecurity-trends-research" target="_blank">comptia.org/content/research/cybersecurity-trends-research</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Solutionz Launches SecureAV Cybersecurity Managed Service ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/solutionz-launches-secureav-cybersecurity-managed-service</link>
                                                                            <description>
                            <![CDATA[ AV integrator Solutionz, Inc. has launched SecureAV, a new cybersecurity service. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fn7suWZWqjHqdWWuAN6V4H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3Y79b96teKMJYqUXZrQrg3-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Apr 2020 12:43:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/3Y79b96teKMJYqUXZrQrg3-1280-80.png">
                                                            <media:credit><![CDATA[Solutionz Inc.]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AV integrator Solutionz, Inc. has launched SecureAV, a new cybersecurity service. ]]></media:description>                                                            <media:text><![CDATA[AV integrator Solutionz, Inc. has launched SecureAV, a new cybersecurity service. ]]></media:text>
                                <media:title type="plain"><![CDATA[AV integrator Solutionz, Inc. has launched SecureAV, a new cybersecurity service. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3Y79b96teKMJYqUXZrQrg3-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AV integrator Solutionz, Inc. has launched SecureAV, a new cybersecurity service. Enormous amounts of critical information are commonly exchanged via electronic meeting rooms, as well as unified communication environments every day. SecureAV protects organizations from inherent known vulnerabilities that exist in AV equipment. Through SecureAV, Solutionz proactively prevents, detects, responds, and reports on security concerns specific to an organization’s AV/UC environment.</p><p>[<a href="https://www.avnetwork.com/features/playing-it-safe-the-state-of-networked-av-security" target="_blank"><em>Playing IT Safe: The State of Networked AV Security</em></a>]</p><p>SecureAV is designed to address these specific security needs and protects that information on an ongoing basis, without utilizing scarce IT/security resources. SecureAV looks at every data packet coming into and out of the environment and uses machine learning to determine if the traffic is a threat. It then reacts according to personalized policies and protects the IoT environment against common attacks including eavesdropping, botnets, denial of service attacks, man in the middle attacks, LAN hopping, open relays, and other common security issues.</p><p>According to Shawn Fernandez, vice president of cybersecurity business development, “We have been watching and assessing the ever growing problem of malicious threats to the IoT environment for some time now, and are acutely aware that AV is now a part of every organization’s IoT landscape. We feel that it is imperative to respond with a service that will protect our customers from these growing threats.” Shawn will continue to expand the cybersecurity portfolio at Solutionz.</p><p>“I am excited about what this game-changing new managed service offers to our customers,” said Bill Warnick, chief executive officer of Solutionz. “We have partnered with some of the brightest minds in cybersecurity to provide the best possible protection for AV and UC environments. SecureAV gives our customers the confidence that Solutionz is on the job, vigilantly monitoring and taking action against any online threat.”</p><p>Solutionz’ SecureAV managed service offering is available to organizations regardless of where their AV/UC equipment was purchased. It offers remote support 24/7/365 and is fully customizable to meet budgetary needs.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Loose Lips Sink Ships ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/insights-and-blogs/understanding-your-nda</link>
                                                                            <description>
                            <![CDATA[ How to keep secret information secret. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6WMkXwtJLMUrrnQuFbf7bN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PmwgC2Rgn9j7Y5yiYTnbGT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Aug 2018 05:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 08 Feb 2021 21:16:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Expert Opinions]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bradford Benn, CTS ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PmwgC2Rgn9j7Y5yiYTnbGT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Loose Lips Sink Ships]]></media:description>                                                            <media:text><![CDATA[Loose Lips Sink Ships]]></media:text>
                                <media:title type="plain"><![CDATA[Loose Lips Sink Ships]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PmwgC2Rgn9j7Y5yiYTnbGT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Non-Disclosure Agreements (NDAs) are becoming very common in business—and not just pro AV, but all business. Not understanding all of the terms of an NDA and how to manage the information can cause damage to your company, your clients, and your reputation.</p><p>There are multiple items to consider when entering into an NDA. A few questions I ask are: Is it for the company overall, or just the person? Is it a single-sided NDA or is it mutual or bidirectional? Do you need to have subcontractors sign the NDA? These will typically be called out in the NDA itself. That is the first thing that most people neglect to do before signing: read the entire document. I have distributed and received many NDAs; I am always amazed by how many people don’t understand them…and sign them anyway. Some of the NDAs bind the company, some bind the individual. As a company principal, it is folly to have someone binding the company without a review first. Any questions and clarifications must be documented in the form before signing.</p><p>I prefer that NDAs be signed by all parties involved, even if it is companywide. The main reason is that I feel it helps all of the people understand the seriousness of the agreement. If everyone does not understand the requirements, how can the conditions be met? I also caution people that the NDA might have repercussions that are unexpected. When working with a publicly held company, the E.U., the U.S., and others have regulations to control financial information. This condition might seem far-fetched; however, think what would happen if someone knew where a company’s new headquarters was going to be built based on purchasing hundreds of conference room systems.</p><p>Now that a company has privileged information, managing it is imperative. Having been involved in projects that experienced information breaches, proactive information management is critical. The basic question I ask is: “Does this person need to know the project?” And about 95 percent of the time, they do not. After I have determined who needs to know, I then hand them a copy of the NDA to sign.</p><p>While managing information goes beyond the digital world, <a href="https://www.avnetwork.com/needtoknow/need-to-know-cybersecurity-and-av">securing the computer data</a> is one of the first steps to take. Not only should access be restricted, but I’d take it a step further and encrypt the data. Yes, information needs to be secure during transport and storage. The standard operating systems enable encryption of a hard disk; I do that on all my drives. I also consider encrypting the file with PGP or GPG <a href="https://www.avnetwork.com/features/keeping-clients-safe-with-encrypted-audio">encryption</a>, just in case. Multiple layers of security are key.</p><p>That seems easy enough, right? There is much more to be aware of when dealing with confidential information. If there are hard copies—such as drawings or plans—keeping those secure is essential. Sometimes it’s as simple as not leaving said hard copies unattended on a desk or at the printer. If hard copies are needed, store them in a locked filing cabinet or room. After using the documents, shredding the materials is a must. Don’t forget to apply this due diligence to erasing your whiteboard or digital collaboration system—you have to ensure your information is not just laying around the office.</p><p>Headed out on the road? Don’t forget your security processes while traveling. Do not have phone calls in public that reveal privileged information; the same approach goes for using a computer in public where people can shoulder surf. Don’t talk about the project when at lunch, even if it is just you and coworkers. While people are typically not malicious, the idea of gossip and sharing a secret is just human nature. People will share a secret they know to feel important.</p><p>Think I’m being a little overzealous about the security of data and keeping it secret? Think back to last year when <a href="https://www.nytimes.com/2017/09/07/business/equifax-cyberattack.html">Equifax let down its guard</a>—now think about how much it has sullied its own reputation. By following the rules of the NDA, I do not worry about my reputation. It is the only thing I can control. I don’t want someone else screwing it up by violating the NDA; that is why I am proactive.</p><p><strong>No Assumptions</strong></p><p>Do not assume that everyone working for the same company knows everything. This may seem very obvious, but when you think about the difference in responsibilities between the shipping department and the design department, you know those employees don’t know all of the same confidential information. Less apparent is that people within the same design department might not know about their coworkers’ projects.</p><p>Think of a significant integration firm with multiple locations. Why does the New York office need to know what the New Jersey office is doing? The same goes for end users or clients. Not everyone knows what is going on in every division. Just because it is the same company, do not share the information unless you know that you are allowed to share.</p><p>About to blab? Call the person you signed the NDA with and ask if you are allowed to share the information with another party. This will also help build your reputation—it will reinforce that you are cognizant of NDA requirements.</p><p>Don’t forget about subcontractors. If you are using them, ensure people critical to the NDA are aware subcontractors are now involved. And make the subcontractor has signed the same NDA, then file it with the originator.</p><p>Note: I am not an attorney; this column is not meant to provide any legal advice. Please consult your legal team for counsel. This piece is my opinion. I am not speaking for anyone else, including, but not limited to: my employer, <em>System Contractor News,</em> or Future plc.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSCA Announces 2018 Pivot to Profit Keynote Speakers ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/news/nsca-announces-keynote-2018-pivot-profit-conference</link>
                                                                            <description>
                            <![CDATA[ Former Pennsylvania Governor Tom Ridge to deliver keynote “Manage Cyber Risk Before It Manages You” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Z3bcTPkYALPkYeHaWAsN2D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9rvBxRsKfb4JfwoVfvfahi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Jul 2018 18:52:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Conferences &amp; Trade Shows]]></category>
                                                    <category><![CDATA[Events]]></category>
                                                                                                                    <dc:creator><![CDATA[ AVNetwork Staff ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9rvBxRsKfb4JfwoVfvfahi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSCA Announces 2018 Pivot to Profit Keynote Speakers]]></media:description>                                                            <media:text><![CDATA[NSCA Announces 2018 Pivot to Profit Keynote Speakers]]></media:text>
                                <media:title type="plain"><![CDATA[NSCA Announces 2018 Pivot to Profit Keynote Speakers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9rvBxRsKfb4JfwoVfvfahi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Former Pennsylvania Governor Tom Ridge will be the keynote speaker at NSCA's third annual Pivot to Profit event on Oct. 23-24 in Atlanta.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9rvBxRsKfb4JfwoVfvfahi" name="" alt="Tom Ridge" src="https://cdn.mos.cms.futurecdn.net/9rvBxRsKfb4JfwoVfvfahi.jpg" mos="https://cdn.mos.cms.futurecdn.net/9rvBxRsKfb4JfwoVfvfahi.jpg" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Tom Ridge </span></figcaption></figure><p>Ridge, alliantgroup chairman of cybersecurity and technology, first U.S. Secretary of Homeland Security, and 45th Governor of Pennsylvania, kicks off the event by sharing insights regarding how the industry’s businesses and clients can protect themselves while still implementing the technologies needed to compete on a global level.</p><p>His session—“Manage Cyber Risk Before It Manages You”—teaches integrators how to play offense vs. defense when it comes to data breaches. Pivot to Profit attendees will learn how to do as much as possible to equip and defend themselves against this new style of warfare.</p><p>During a long and distinguished career that has spanned the public and private sectors, Ridge has established himself as an authority in areas as diverse as intelligence analysis, national security, economic development, education, health, and the environment.</p><p>In response to the tragic events of Sept. 11, 2001, Ridge was appointed by then-President George W. Bush as the first director of the newly formed Office of Homeland Security. In January 2003, the Office of Homeland Security was designated by the Bush administration as an official cabinet-level department. Ridge was appointed as the nation’s first Secretary of Homeland Security.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JNPaATCBwHPNPpg8qzAEr" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/JNPaATCBwHPNPpg8qzAEr.jpg" mos="https://cdn.mos.cms.futurecdn.net/JNPaATCBwHPNPpg8qzAEr.jpg" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>At Pivot to Profit, integrators will also hear from technology experts about:</p><ul><li>Merging digital and physical workplaces</li><li>Ways to create immediate recurring monthly revenue streams</li><li>What’s moving to the cloud next</li><li>Smart buildings and their stress on network infrastructure</li><li>How managed services change marketing/client messaging</li><li>Healthcare, K-12, and higher-education technology solutions of the future</li><li>Building a managed services sales machine</li></ul><p>“For years, we’ve talked about how change is coming for systems integrators,” said Chuck Wilson, NSCA executive director. “That time of change is here, and it’s time for integrators to examine their technology, services, processes, and structure. Governor Tom Ridge will help them do that, and give them tips and strategies they can use to prepare for these changes.”</p><p>Registration for the two-day event is $295 through Aug. 31, 2018. After Aug. 31, pricing goes up to $495. For more information, contact NSCA at 800.446.6722 or visit <a href="http://www.nsca.org/p2p">www.nsca.org/p2p</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Need to Know: Cybersecurity and AV ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/needtoknow/need-to-know-cybersecurity-and-av</link>
                                                                            <description>
                            <![CDATA[ Installers, integrators, and end users must take extra care to ensure devices don’t create security vulnerabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5kqZFMTezjS8xJrNZQQ3jc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7fFziRwybrokDuwK4iUxY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jul 2018 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Megan A. Dutta ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/6rcY3aZLrW2oyE5Uy3cAEF.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7fFziRwybrokDuwK4iUxY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Need to Know: Cybersecurity and AV]]></media:description>                                                            <media:text><![CDATA[Need to Know: Cybersecurity and AV]]></media:text>
                                <media:title type="plain"><![CDATA[Need to Know: Cybersecurity and AV]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7fFziRwybrokDuwK4iUxY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe src="https://content.jwplatform.com/players/s41KgwEY.html" id="s41KgwEY" title="Need to Know: Cybersecurity" width="1920" height="1080" frameborder="0" scrolling="auto" allowfullscreen></iframe><p>Now that AV is consistently placed on the network, it is paramount that installers, integrators, and end users take extra care to ensure these devices don’t create vulnerabilities in enterprises’ security. With AV innovations and confidential information on the same network, how do we ensure the performance of the former doesn’t compromise the integrity of the latter?</p><p>Find out <a href="https://www.radioworld.com/needtoknow/cybersecurity">more about cybersecurity</a>.</p><p>First and foremost, AV professionals need to remember that network security is a large concern that should be considered at the earliest stages of system design. Private data—think employee social security numbers—is held on corporate servers, right alongside AV on the network. Not in an office? Those with technical skills and malicious intentions can create embarrassing situations for integrators and installers. Remember that time someone hacked a large touchscreen at Washington, DC’s Union Station and visitors were exposed to several minutes of adult videos in the middle of rush hour?</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mx7DuMoEZ4xruNVGP4Hh9d" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/mx7DuMoEZ4xruNVGP4Hh9d.jpg" mos="https://cdn.mos.cms.futurecdn.net/mx7DuMoEZ4xruNVGP4Hh9d.jpg" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>John Pescatore, director of emerging security trends at the SANS Institute, thinks AV pros should remember the basics: ensuring information AV systems are continuously updated and security controls are only accessible by authorized users. For sensitive systems, he cautioned, “authorized users should be required to use strong authentication, and not just reusable passwords.”</p><p>“Quite often, phishing attacks target system administrators and obtain their passwords—and the attackers are off to the races,” said Pescatore. “Strong authentication can be as simple as requiring receipt and entry of a text message in addition to a password, or require the use of a hardware token, like a USB key.”</p><p>A vital aspect of security is communication. All stakeholders should sit down together to discuss the goals of the AV systems, potential implications for security, and how the AV devices will be managed. Once devices are chosen, Pescatore says to “ensure manufacturers have a documented process for providing software updates, and make sure you have a process for rapidly installing the updates; generally, these should be installed in one week or less.”</p><p>Another workaround for AVoIP is to keep the products on an isolated network; Pescatore recommends using a firewall to provide only minimum access and to log all connections.</p><p>When it comes down to it, there’s no one-size-fits-all for network security. Integrators, IT professionals, and end users need to work together to determine what is the best solution for every single installation.</p><p>Find out <a href="https://www.radioworld.com/needtoknow/cybersecurity">more about cybersecurity</a>.</p><p><strong>Need to Know More?</strong></p><p><strong>Have a burning question about cybersecurity — or maybe request for a different topic you’d like to see us tackle? Email us at <a href="mailto:needtoknow@nbmedia.com">needtoknow@nbmedia.com</a> and we’ll put our top minds on it!</strong></p><p><strong>More from Future on cybersecurity:</strong></p><ul><li><a href="https://www.tvtechnology.com/needtoknow/need-to-know-protecting-the-broadcast-plant">Cybersecurity and Television [TV Technology]</a></li><li><a href="https://www.twice.com/needtoknow/cybersecurity-retail-how-to-stop-the-bleeding">Cybersecurity and Retail [TWICE]</a></li><li><a href="https://www.radioworld.com/needtoknow/cybersecurity-its-not-just-a-problem-for-it">Cybersecurity and Radio [Radio World]</a></li><li><a href="https://www.multichannel.com/needtoknow/need-to-know-iot-poses-new-cybersecurity-threats-cable">Cybersecurity and Cable [Multichannel]</a></li><li><a href="https://www.residentialsystems.com/needtoknow/cybersecurity/resi-need-to-know-cybersecurity">Cybersecurity and Residential Integration [Residential Systems]</a></li><li><a href="http://www.prosoundnetwork.com/needtoknow/need-to-know-cybersecurity-and-pro-audio">Cybersecurity and Pro Audio [Pro Sound News]</a></li><li><a href="https://www.techlearning.com/resources/five-cybersecurity-safeguards-for-school-districts">Cybersecurity and Education [Tech & Learning]</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keeping Your Converged IP Network Secure ]]></title>
                                                                                                                                                                                                <link>https://www.avnetwork.com/systems-contractor-news/keeping-your-network-secure-in-an-iot-world</link>
                                                                            <description>
                            <![CDATA[ With AV’s continued migration to IP infrastructure, the need to secure AV systems and networks from cyber threats is paramount. What are some key safeguards system designers should implement to promote network security? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uEBus2aoVXu7Vw3BpssVH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9jdFiP4d2LjrTGfKq3ypNF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 May 2017 17:30:12 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Feb 2021 18:30:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Products &amp; Solutions]]></category>
                                                    <category><![CDATA[Connectivity &amp; Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Lindsey M. Adler ]]></dc:creator>                                                                                    <dc:source><![CDATA[ http://cdn.mos.cms.futurecdn.net/2dx3P44JysvsFRrhmNehUk.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9jdFiP4d2LjrTGfKq3ypNF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Keeping Your Network Secure in an IoT World]]></media:description>                                                            <media:text><![CDATA[Keeping Your Network Secure in an IoT World]]></media:text>
                                <media:title type="plain"><![CDATA[Keeping Your Network Secure in an IoT World]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9jdFiP4d2LjrTGfKq3ypNF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Another day, another crippling global cybersecurity breach. Just as these words are being written, the world is reeling from the current cyberattack of the moment, the so-called WannaCry malware. An estimated 200,000 victims were cited across 150 countries by the European police agency Europol. The auto manufacturer Renault shut down, and hospital computers across the United Kingdom were frozen. As per usual, the pundits are calling it a teachable moment, but how many such learning experiences are really needed before the world at large takes serious action in defense of data and information security?</p><p>With AV’s continued migration to IP infrastructure (<a href="https://www.avnetwork.com/features/av-over-ip-what-you-need-to-know" target="_blank">AV over IP</a>), suffice it to say that the risk is clear and present, and the need to secure AV systems from malicious software is critical. Cybersecurity for audiovisual systems is new territory for the AV integration community, but you don’t need to be a security expert to implement key safeguards from the outset of your system designs.</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QiBrs6bAYE7yTu5sfJ7EAD" name="" alt="Theresa Payton, Fortalice" src="https://cdn.mos.cms.futurecdn.net/QiBrs6bAYE7yTu5sfJ7EAD.jpg" mos="https://cdn.mos.cms.futurecdn.net/QiBrs6bAYE7yTu5sfJ7EAD.jpg" align="right" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Theresa Payton, Fortalice </span></figcaption></figure><p>“AV security issues are mainly focused around network segmentation and management—if they are focused on security at all,” said Theresa Payton, CEO of Fortalice Solutions and former White House chief information officer. “The main priority is the network traffic for audiovisual data and ensuring delivery and quality. However, as my team has seen through experience, that lack of security makes them extremely easy to disrupt.”</p><p><a href="https://www.avnetwork.com/features/playing-it-safe-the-state-of-networked-av-security"><em>Improving AV device security on converged IP networks</em></a></p><p>Many of the basic steps to help protect AV systems data are simply a matter of taking the time and adding an extra step. Changing default passwords is a top recommendation—so basic, it’s often overlooked. “If you need remote access, make sure it is secure. Even small changes to the firewall could expose your customer to gaping security holes with a huge impact, so you need to understand them intricately,” advised Kirk Nesbit, vice president, design and support services, SYNNEX Corporation. “A best practice would be to have the firewall administrator give you SSL VPN access to the network, and then you administer your device instead of poking holes in the firewall for direct access.”</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pVdfZkLjNNLkW2DtcfZqiY" name="" alt="Kirk Nesbit, SYNNEX" src="https://cdn.mos.cms.futurecdn.net/pVdfZkLjNNLkW2DtcfZqiY.jpg" mos="https://cdn.mos.cms.futurecdn.net/pVdfZkLjNNLkW2DtcfZqiY.jpg" align="right" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Kirk Nesbit, SYNNEX </span></figcaption></figure><p>While IoT has dramatically changed the game for information security, it presents a host of challenges. “It is best to install only devices for which the manufacturers have provided a way for resellers to perform updates to underlying OS for security in addition to feature enhancements,” Nesbit added. “Then, have a plan to apply security patches on a regular basis. Many IoT devices released to the public can’t be updated, and could be running some three-year-old unpatched version of Linux—the lowest hanging fruit for hackers.”</p><figure class="van-image-figure pull-left" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="q57U2wuGjj9miwoNP5CJ4a" name="" alt="Scott Allard, AVNOC" src="https://cdn.mos.cms.futurecdn.net/q57U2wuGjj9miwoNP5CJ4a.jpg" mos="https://cdn.mos.cms.futurecdn.net/q57U2wuGjj9miwoNP5CJ4a.jpg" align="left" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-left"></p></div></div><figcaption itemprop="caption description" class="pull-left"><span class="caption-text">Scott Allard, AVNOC </span></figcaption></figure><p>A close examination of the customer’s network should be made in order to make recommendations that apply to their specific needs, noted Scott Allard, managing partner, AVNOC, a remote monitoring and service management software solution provider. Ingress and egress—or inbound and outbound network access either by an automated device or manually by a person—or accessing the customers network by using tunneling products should be avoided if not approved by the customer. “Those products allow access to a network basically undetected and information can travel without encryption,” he said. “Although it’s usually just to an AV system, it still can leave opportunity for undesirables. There are more secure solutions for remote access that give the end customer full control without providing VPN or allowing a remote desktop to exist in their network.”</p><p><a href="https://www.avnetwork.com/blogs/optimizing-av-over-ip-in-corporate-installs" target="_blank"><em>Optimizing AV over IP in corporate network installations</em></a></p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JDj6gP6b8YquLTSiEYzyk" name="" alt="Josh Srago, TEECOM" src="https://cdn.mos.cms.futurecdn.net/JDj6gP6b8YquLTSiEYzyk.jpg" mos="https://cdn.mos.cms.futurecdn.net/JDj6gP6b8YquLTSiEYzyk.jpg" align="right" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Josh Srago, TEECOM </span></figcaption></figure><p>Specifics of the use case are a key consideration for Josh Srago, audiovisual design consultant, TEECOM. “Understanding the needs of the client and the devices when it comes to which require access to a network that touches the outside world versus those that can remain self-contained is vital,” he said. “Is the device using Microsoft Exchange for access? And don’t forget, there’s still the physical element—how does the client handle physical loss of a device with access to networked systems?”</p><p>Beyond the usernames, passwords, and controlling access, paying attention to methods or remote access for control, service, and support are top priorities, according to Mike Maniscalco, vice president of product, Ihiji, a remote monitoring SaaS provider for AV integrators. “Additionally, integrators should be sure to disable insecure communication protocols like telnet, HTTP, and unencrypted VPN, and opt for more secure protocols such as SSH, HTTPS, and SSL.”</p><h2 id="educating-clients">Educating Clients</h2><p>Oftentimes end users can be their own worst enemies in the world of information security. Everyone wants the AV at work to function like the gadgets they know and love at home. The harsh reality is that this presents difficulties when a company’s intellectual property and means for conducting business could be held at ransom. Talking to clients about the risks their devices of choice present and the necessary precautions they need to take can be a delicate dance.</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KKknCXSkzn9hDJmoR2GEjC" name="" alt="Mike Maniscalco, ihiji" src="https://cdn.mos.cms.futurecdn.net/KKknCXSkzn9hDJmoR2GEjC.jpg" mos="https://cdn.mos.cms.futurecdn.net/KKknCXSkzn9hDJmoR2GEjC.jpg" align="right" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-right"></p></div></div><figcaption itemprop="caption description" class="pull-right"><span class="caption-text">Mike Maniscalco, ihiji </span></figcaption></figure><p>“Client education is key because ‘wetware,’ or the human-factor, is often the biggest risk to security,” Maniscalco said. “Limiting physical and remote access to devices is a best practice for securing any system. Be sure to educate clients on proper passwords and password management. Lastly, talk to your clients about the phishing schemes and the risk they pose to account security. These types of schemes can result in costly breaches and ransomware attacks.”</p><p><a href="https://www.avnetwork.com/blogs/how-to-transition-to-avoip" target="_blank"><em>IP network convergence requires that AV pros gain IT networking skills</em></a></p><p>Srago starts by talking to clients about how they want to use IoT in their workspace. “Once it’s established what systems they want to interact, it becomes an exercise in working with the IT department to determine how to mitigate as much risk as possible.”</p><figure class="van-image-figure pull-right" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sAbA3NS4dm5smRw6KA2UMJ" name="" alt="Network security" src="https://cdn.mos.cms.futurecdn.net/sAbA3NS4dm5smRw6KA2UMJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/sAbA3NS4dm5smRw6KA2UMJ.jpg" align="right" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pull-right"></p></div></div></figure><p>He explicitly calls out the fact that a 100 percent secure network does not exist. “If a device is connected, it is a potential vulnerability. This doesn’t mean that if you connect a smart device to the network, they will get your private data, but it doesn’t mean they won’t, either.”</p><p>Working with IT and not attempting to work around them is a crucial strategy for Srago when it comes to isolating systems through VPNs or VLANs or using their existing firewalls to your advantage, instead of seeking ways through it. “Knowing things like what ports are being used by the manufacturers and whether that’s going to be in conflict with other systems on the company network if the port number can be reassigned, is something simple that we can do to help make deployments easier and show that we are their partners with their best interests in mind.”</p><p>One simple add-on service integrators can provide or help facilitate is a vulnerability assessment or penetration test. “At Synnex, we have been running free vulnerability assessments for our resellers and their customers for up to five public IPs,” Nesbit said. “The results have been bittersweet: after running several hundred scans, we’ve found only two percent of the networks were secure and had no vulnerabilities. This has opened the eyes of many resellers, and they are now actively incorporating vulnerability assessments into their projects.”</p><p><a href="https://www.avnetwork.com/blogs/av-and-it-need-to-work-together-if-we-ever-want-av-over-ip-harmony" target="_blank"><em>AV and IT must collaborate for successful IP network convergence</em></a></p><p>The harsh reality is that no system can be considered beyond breach. This admission can be the first line of defense, followed by detailed action plans to have ready for not if, but when. Making false promises to clients about their systems’ security is a dangerous path down an inevitably precarious journey. A good dose of common sense, practical precautions, and informed processes will go a long way in the battle for cybersecurity.</p><h2 id="what-questions-do-you-need-to-ask-your-vendors">What Questions Do You Need to Ask Your Vendors?</h2><p>AV manufacturers have an important role in promoting network security. For many of them, it’s just as new and different a skill to employ as it is for integrators. Communication among all parties is necessary to ensure AV systems are capable of supporting clients’ information security needs. The process requires due diligence, and integrators and consultants need to hold their vendors accountable.</p><p>The experts interviewed for this article provided a wide range of questions for integrators and consultants with which to query their vendors.</p><ul><li>Does your product support secure communications?</li><li>Are logins encrypted?</li><li>Can the devices be updated?</li><li>Can the underlying OS and applications be updated?</li><li>Do firmware updates break any preexisting security setups?</li><li>What data is being tracked, polled, or accessed by your products? Is that information being stored somewhere? If so, is it on premises, or are you storing it on your own servers or cloud service? Who has access to that information at your company? How are you using that data?</li><li>Are you encrypting any data being transported?</li><li>Can credential names and passwords be changed on the devices?</li><li>If accessing via a web browser, are you masking the device’s IP address?</li><li>Are you using two-factor authentication for access to admin accounts?</li><li>How do you build security into your devices?</li><li>How long after a vulnerability is discovered in the underlying OS or applications will the vendor have a patch available?</li><li>If a security researcher discovers a vulnerability on your product, is there a way for them to report it to you? Is that process documented?</li><li>How do you disclose and communicate known security exploits with your devices?</li><li>Do you publish a security and privacy policy?</li></ul><h2 id="choose-wisely">Choose Wisely</h2><p>In many cases, there are a lot of manufacturers to choose products from, and that selection involves new requirements with network security considerations. “AV professionals should evaluate vendors for patching frequency, and understand the lead times and testing required before critical security patches can be deployed on AV networks. They’ll want to be sure that they are carefully managing applications that can be deployed on those networks that could cause network traffic and interference with time sensitive AV data.</p><p>With technology evolving at breakneck speed, integrators should always consider what’s next when selecting products. “Looking toward the future, which really is here now, the integration of home automation and voice-activated systems with AV systems means that there are increasingly major privacy issues with these systems, as they may capture personal information or conversations that need to be protected,” said Max Everett, managing director of Fortalice Solutions and former White House chief information officer. “So AV professionals need to be sure to ask vendors about the privacy implications of these systems. Who is protecting customer data? This is especially important as data is now more likely to be passed to cloud services.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>