← Back to BlogMastering Engaging Web Conferences

Video conferencing security practices

Updated
12 min read
Video conferencing security practices

The pandemic shut us inside our homes. We all work remotely, and video conferencing has become an essential part of our lives.

Video conferencing security

Hackers break into webinars and get hold of the password. Imagine your webinar equipment, your information, and your company secrets ending up in public. An intrusion can disrupt e-learning too. Each of these does more damage to online meeting security than it first appears, and the FBI and other cybersecurity agencies have warned users about exactly this.

FBI warns of teleconferencing and online classroom hijacking

Source: fbi.gov

Cyber hacking has cost the US $57 billion to $109 billion. Therefore, the security of video conferencing shall be the utmost priority of the organizations. I am going to elaborate on simple steps. By using these steps, you will be able to secure your online meetings.

1. Create a meeting password

Your unique link and password are your webinar’s first line of defense. Have you heard of a Brute Force Attack? It is to hack your account by guessing the link and password. Every 1 in 5 attempts is successful.

You should not use a public link and password among the employees. Attendees must be given a link and password to curtail any potential chance of intrusion.

If you are using MyOwnConference, this part is straightforward. The platform offers two-factor authentication for tighter security.

Open your profile at the bottom of the sidebar, go to the "2FA" tab, and switch it on. It arrives switched off, as below.

The 2FA tab of the profile, with two-factor authentication still switched off

This feature is also available in other upgraded applications. So there is no need to worry about that. Though, you should be worried about the password you are setting. Always set a complicated password for authentication.

These passwords must be long and complex enough that nobody could guess them. Use a blended combination of letters, special characters, and numbers.

Trust me, using "1234" or the name of your organization is long past its day. Choose a distinctive name for your meeting.

A meeting form with a name field and a password field holding a long random password

2. Lock everyone

When you plan a meeting, you should have a list of all the employees attending the meeting. Set the maximum time limit for the employees to join.

After that time, you should lock your video conference. This feature will provide additional benefits in securing the conference. It will create more difficulty for the hacker to intrude and acquire valuable information.

You can make a list of the attendees and their current status at the conference.

The MyOwnConference attendees list with a search field, an add button and filters for status, group and attendance

The app provides an available option for employees. Also, you can add them before the start of the meeting. You should add only authentic people to the meeting. What I found attractive in this is the added-by option.

I know that a single person, especially a boss or a manager, cannot run the conference alone. There should be more than one host, or advanced webinar equipment. This feature will provide you with information about whoever has added a new person.

The way to limit the damage is to take precautions in advance. Be careful about how you share the link to the video conference.

I do not suggest you use public platforms for sharing video links. I mean, do not post on Facebook or Instagram or the office groups at WhatsApp.

A Facebook post composer with a public status announcing a live session and a link preview to it

That hands the details to people who should never have them. Write an invitation email to each individual instead. I know it is a chore, but prevention is better than cure.

An email meeting invitation with RSVP buttons and the topic, time and meeting ID below

After this, you have to provide your employees with a draft of rules that everyone must follow to ensure the video conference’s security. Make the rules short and specific, because a long formal document is the one nobody reads. These can include general rules:

  • You are not permitted to share the link and password with anyone without prior permission.
  • You are not permitted to post any video clip from the conference.
  • Posting the link of the conference on any social platform will be considered cybercrime and privacy invasion.

In MyOwnConference, if you only want the original invitees to be able to join the meeting, click the button so that the attendees can only join with their personal invitation link.

4. Create a waiting room

A waiting room for attendees is worth setting up. It serves the same purpose as a waiting room in an office.

Employees gather and wait in this virtual room until everyone has arrived.

That removes the awkward wait while people trickle in one by one.

An illustrated video call grid of four participants, one tile still loading and another offline

It also helps you control who enters and leaves. You are in charge of your online meeting.

It would be best to decide who will be in the meeting and who will not be. MyOwnConference lets you create a moderator list.

This works much like the waiting room, where you add attendees and wait until all of them are active.

Add a new moderator

5. Unknown phone numbers

I hope by now, you can conduct a secure video conference. Yes, your conference is indeed safe from any external threat. But what if the threat is from inside? Not intentionally, but unintentionally, employees can get involved in victimizing the conference.

Therefore, you must ensure that no one is dialing an unknown number during the conference.

It is your responsibility to keep an eye on every aspect of the meeting. Ask attendees right away if they dial an unknown number, and ask them for the details and the reason.

If the answer does not hold up, you can remove them from the conference. Joining from a cellphone is a genuine convenience, but for anything that involves screen sharing a desktop remains the safer choice.

6. File sharing limit

During the video conference, you should restrict the file sharing option on the message column. Left open, it lets outsiders reach private documents, or slip disguised material to any of the attendees.

The option for limiting file sharing differs from one application to another. You can either enable it entirely from the account or enable it for a specific group of people. From my perspective, limiting the type of file to share is the best option to include in the e-learning process.

A file transfer setting restricted to a short list of allowed file types

Source: zoom.us

It is the more convenient route. First, you have to click on the IM setting in the account management option.

Select the file transfer option and write the format of the file that you can use.

7. No recording

I mentioned Zoom bombing and unintentional employee behavior above. This step relates to both of them.

The screen sharing feature lets every attendee share and control the screen, which means any of them can record the whole conference.

Imagine an intruder sitting in your conference and recording everything without interruption, despite all your efforts. Would you be able to trace them? Probably not, because they never make a sound.

That makes this step obligatory. Limiting screen sharing limits recording along with it. Employees sometimes record simply to make a joke of it later, and it is still harmful to the organization.

This is why you should strictly enforce a no-screen-recording policy and limit screen sharing.

A screen sharing menu set so that only one participant can share at a time

Source: zoom.us

Do not worry about people being unable to show their work. You can add selected attendees to the sharing list once the conference has started.

But the initial sharing of the screen is not recommended.

8. Audio only

You can also try the audio-only option for the meeting. In this, you will reduce any possible chances of screen recording or leaking any valuable information.

You can ask your employees to switch off their webcams and take part in audio only. It also uses less bandwidth, which improves the quality of the conference.

I know a video conference without video sounds odd, but it is a reasonable trade for security. Do not worry about audio quality either, because several settings let you improve it.

I will use Zoom for the details, though the same controls exist on nearly every platform.

You can put your meeting on speakers, as long as you are not disturbing anyone around you.

The audio settings panel with the speaker device list open above the microphone and volume controls

If that is awkward where you are sitting, use the advanced microphone settings instead.

advanced microphone setting

There is one more control worth knowing. You can also suppress background noise if it bothers you or creates hurdles in understanding the audio.

9. Use a license

Video conferencing tools are now a necessity for an organization, not a luxury.

An organization should buy a licensed tool rather than rely on free features. The licensed tool will provide you with additional safety features for securing your video conference.

MyOwnConference costs from $25.80 per month, and it also has a free plan with no time limit.

The free-of-cost features are public and may expose your conference to more threats. Zoom sells a large-meeting add-on on top of a paid plan.

The Zoom pricing page with the Pro, Business and Zoom United Business plans and their yearly prices

Source: zoom.us

Cisco Webex publishes its entry tier on its own pricing page.

The Cisco Webex pricing page with the free tier and the Starter, Plus and Business plans

Image source: g2.com

10. Set up alerts

I know this all sounds like a lot for one executive to handle in a single video conference. I have a more convenient option for you.

You can use the alert options in the applications. The technology keeps improving, and there is a solution for most difficulties. You can customize the alert options so that you are notified whenever undesired activity occurs. Let me explain what counts as undesired activity.

Well, this is dependent upon your company’s security guidelines. Generally, it refers to forwarding invite emails to any unauthorized person, recording video or taking screenshots.

I will show the Cisco Webex features here, but something equivalent exists in every video-conferencing application to improve online meeting security.

A team messaging app with the list filter menu open on notification, mention and thread options

Source: webex.com

Zoom also provides these services. The services provided by Zoom are more convenient and advanced.

Zoom alert options

Source: screenstepslive.com

Final thoughts on video conferencing security practices

Hosts can practice several safety precautions during the meeting to eliminate the chances of intrusion. I am not claiming they will throw hackers out entirely, but they are effective to a real degree.

Experienced IT teams draft these precautions, and they make a meeting considerably harder to invade. A risk still remains.

Please let me know if you find any other precautions that seem more effective than mine, and I will add them to my next article about security.

FAQ

How can I make sure only invited participants join my meeting?

You should always set a meeting password and send personal invitation links instead of posting the link publicly. You also can lock the meeting once all expected participants have joined and use the waiting room feature to control who enters.

What should I do to prevent unwanted file sharing during the conference?

You limit file sharing by disabling it for everyone except trusted participants or by restricting the allowed file types in chat. This helps stop external or malicious files from being shared inside your meeting.

Why is recording during a meeting risky and what alternative do I have?

Recording risks leaking sensitive information, especially if an intruder is present. To avoid that risk you enforce a no-recording policy and you can run the meeting in audio-only mode so that video is turned off and the chance of misuse is lower.

Is it better to use a free conferencing tool or to buy a licensed version?

It is safer to use a licensed version because paid tools typically come with stronger security features. Free plans often miss advanced safeguards, which might leave your meeting more exposed to attacks.

How do alerts help me detect suspicious activity and when should I enable them?

Alerts notify you when someone does something like forwarding invites, recording, or taking screenshots without permission. You should enable them before the meeting so you are aware of any unwanted actions as soon as they happen.

Get started with MyOwnConference for free

Create a better experience for your attendees. You're just minutes away from building engaging online events.

Sign up for free
– No credit card required– No software to install
MC
Written byMelissa Calvert

Contributor

An external contributor to the MyOwnConference blog. The article stays published because readers still find it useful, and our editorial team is the one that stands behind it today.

Related articles