Cyber Essentials Plus Checklist for AV Deployments
Audiovisual (AV) systems are no longer standalone solutions. They form part of a converged networked infrastructure, making cyber security an essential consideration for AV deployments.
This article explains Electrosonic's measures to maximize networked AV security by complying with Cyber Essentials Plus and describes the scope and benefits of Remote Technology Support Services.
Cyber Essentials Plus Checklist for AV Deployments
Today’s audiovisual solutions are highly integrated with other networked systems. These include:
- IT systems
- Building management systems
- Environmental management systems
- Access control systems
- Security and surveillance systems
AV integrators, therefore, recognize the importance of network security when deploying or upgrading AV systems. Every deployment must be 'cyber ready' to protect the AV systems and the client's core network against cyber threats.
Ensuring network security reduces the risk of cyber breaches. These can damage clients' systems and result in the loss of confidential data. Cyber breaches can also impact a client's reputation or lead to legal or financial penalties.
Electrosonic is committed to minimizing cyber security risk and is committed to ensuring ongoing compliance with the recognized legislation, including:
- Cyber Essentials Plus in the UK
- NIST Guidelines - Cyber Security Framework 2.0 in the US
- Federal Information Processing Standards (FIPS) in the US
- Other regional or client-specific cyber security frameworks
Cyber Essentials Plus and Cyber Security Frameworks help organizations guard against the most common cyber threats. Certification also demonstrates a commitment to cyber security and provides a clear picture of an organizations cyber security level.
Cyber Essentials Plus checklist for AV deployments
Electrosonic's engineering and commissioning teams understand network security essentials. They have deep knowledge and experience of working in highly secure networked environments. The teams integrate new and existing AV hardware and software with centralized control systems.
Engineers integrate AV systems with other client systems on a single converged network infrastructure where possible. This ensures consistent security standards throughout the organization. Sometimes, they create bespoke software solutions to improve AV security management.
The teams engineer, install and program these complex AV systems in line with Cyber Essentials Plus requirements. They collaborate with clients' IT and security teams to assess threats and implement measures to reduce vulnerabilities. The teams advise clients on AV hardware risks and mitigations and recommend measures covering:
- Audio, video and control systems
- AV-related LANs or WANs
- Local connections and endpoints
- Connectivity for cloud access
Electrosonic recommends using strong passwords on all AV endpoints and encryption on all networked AV data. These measures are essential for secure collaboration in hybrid working environments.
Encryption protocols include:
- AES- 256 (Advanced Encryption Standard)
- 802.1X
- TLS (Transport Layer Security)
- SSH (Secure Shell Protocol)
- HTTPS (Hypertext Transfer Protocol Secure)
- MFA (Multi-Factor Authentication)
- Directory-based permissions
Applying these measures reduces vulnerabilities and helps clients ensure compliance with regulations. While strong security is essential at the deployment stage, it is equally important to maintain protection when AV systems are operational. Secure networked AV simplifies that by providing a safe remote support and management platform.
Global remote support from a central source
All AV systems require ongoing maintenance and support to maintain efficiency and availability. Converged networked AV solutions bring additional monitoring and updating requirements to maintain the highest levels of security.
Electrosonic's Remote Technology Support Services can help reduce workload and augment existing skills to support complex networked systems and maintain system performance and security. The service typically includes:
- Monitoring AV endpoints
- Monitoring network connections
- Automated issue discovery, ticketing and alerts
- Fault resolution
- Proactive maintenance
- Managing firmware updates
- Managing security updates
- Stringent SLAs
- Access to technical helpdesk team
- Access to monitoring and performance data
Electrosonic has developed the capability to monitor, manage and secure large and small-scale networked AV systems worldwide.
Remote support can provide many essential benefits, including:
- Reduced internal support burden
- Access to expert monitoring resources and skills
- Proactive system monitoring
- Reduced maintenance requirements
- Faster problem resolution
- Minimum downtime
- Automated issue discovery, ticketing and alerts
- Comprehensive management information
- Up-to-date information on system and equipment status and performance
- Improved facility planning
- Enhanced user experience
- Increased adoption and usage through enhanced user experience
- Improved business performance
A custom remote support solution
In a recent project, Electrosonic managed AV systems and security for a professional services organization with eight locations.
Utilizing a centralized control system, our service team can remotely access the client's networks and meeting room systems. The team can access Crestron virtual software in the client's data center. The Crestron software manages all the AV hardware across all sites. This solution provides the flexibility and ability to monitor and control all meeting room hardware from a single point.
Electrosonic developed custom software to simplify management, which is loaded into a processor. The software communicates with any display or AV device that needs to be monitored. It manages device telemetry, its IP address and associated passwords and exports it to its digital twin in the cloud.
In addition, the software is scalable, which improves consistency and reliability and results in less troubleshooting.
Scalability is important because it simplifies the task of adding and programming new devices. The software also enables consistent standards of monitoring across the client's entire estate. That could have been a problem because the client's installation included eight generations of AV hardware. Different devices would have required various levels of support.
The custom software simplifies updating and maintaining the various generations of existing hardware. It also provides a seamless maintenance solution with a consistent look and feel across the estate.
Maintaining compliance with Cyber Security Plus
Security is an integral element of this remote support solution. Electrosonic engineers ensure stringent password protection on every device. They lock down laptops so that client staff cannot install additional software. Electrosonic's engineers' laptops are also set up with data encryption and limited administrator privileges.
Additionally, our client service teams use a dedicated encrypted password management system to access the client's remote sites. The remote connection system, developed in collaboration with the client, supports single sign-on or multi-factor authentication incorporating unique passwords.
As the client has achieved Cyber Security Plus accreditation, maintaining the most robust security standards is critical to the remote support function. To maximize the security posture, the service team monitors hardware diagnostics and installs the latest firmware and security updates.
Electrosonic's Remote Technology Support Services solution can potentially manage all aspects of AV hardware security in the future. The service team would be able to establish procedures to identify security threats and take remedial action to mitigate their impact.
Future Cyber Safeguards
The demand for remote AV technical support is on the rise as more organizations embrace hybrid working models. The integration of AI-powered solutions promises to significantly enhance these capabilities by automating troubleshooting tasks, supporting predictive maintenance, and providing expert recommendations.
Furthermore, advancements in remote support security are crucial in mitigating the growing risk of cyber-attacks on converged networked AV systems. Enhanced multi-factor authentication, stronger encryption protocols, increased user awareness, and advanced threat detection solutions will play vital roles in safeguarding these systems.
Together, these technological and security advancements supported by Remote Technology Support Services will ensure a more secure infrastructure, reducing the risk of cyber threats such as hacking, malware, phishing and other forms of attacks.
Nerijus Linauskas
Nerijus Linauskas, Lead Developer at Electrosonic, has over 15 years of experience in the audiovisual industry. He excels in system design, lean optimization, and programming, and is dedicated to understanding client needs to tailor innovative audiovisual solutions. He also provides technical support for live projects and contributes to optimizing engineering processes and project designs at Electrosonic.