Home
published on 27 April 2020 | reading time approx. 4 minutesby Sabine Schmitt, Rödl & Partner Nuremberg, and Bastian Schönnenbeck
Due to current contact bans and exit restrictions, business meetings more and more take place online. In particular, the video conferencing platform “Zoom” has achieved great popularity in the past few weeks. However, over the same period Zoom has also been exposed for having security gaps and data protection problems.
This lack of security is leaving the meetings open to all sort of mischief. For example, unauthorized parties are joining Zoom meetings and overhearing them or sharing their screens to broadcast offensive content.
Considering that many of these business meetings contain personally identifiable information and classified information, companies should really ask themselves if it is worth the risk to use video conferencing tools.
Hereafter there are a few issues for companies to take into consideration from the perspective of the data protection. We also explain the challenges your IT security teams face with the new digital resources and how proactive risk management could look like.
At the selection stage companies should already take a closer look at the data protection regulations to comply. In particular, you should pay attention to the following points:
Video transmissions should use end-to-end encryption. Caution applies here for persons subject to professional secrecy: a video conferencing tool using a system that transmits data over the network in unencrypted form constitutes a failure to comply with the obligation of secrecy.
Use password protected meetings to keep unwanted participants out
Before using the selected video conferencing service for your company meetings, you should also considering the following points:
Within the IT infrastructure, security teams are aware of the need to evaluate critically the used tools, services and resources in terms of their intended use. In addition to the widely described data protection aspects, cybersecurity ratings are playing an important role in corporate risk management. The evaluation of third parties or their tools and applications is particularly important when situations and scenarios change almost daily and decisions have to be made under high pressure. Due to the current increase of employees working from home the threat level is rising. Studies show that home networks pose a significant cybersecurity risk (malware infections, phishing attacks, etc.).
Within the risk management of your company, a cybersecurity rating can be supplemented easily and practically. Such a rating takes a three-dimensional view of the environment of your company or a third party (e.g. a video conferencing tool that is planned to be introduced).
The main indicators, such as the use of certificates, patch and update levels, encryption technologies, spam distribution and the presence of compromised end devices and servers are checked. Therefore the rating provides valuable information about the resistance of the own security eco-system to various attack scenarios.
In view of the expected increase of employees in home offices and the general rise in the use of video conferencing tools, it is advisable to have a stable cybersecurity management system as part of your risk management. We contribute to the security of our clients too. For this reason, the instrument of cybersecurity rating is available at special conditions until the end of 2020.
Coronavirus: What you need to know
Sabine Schmitt
Manager
Send inquiry
Data protection