No company provides free business software out of the sheer goodness of their hearts. They do it for at least one of three reasons: to access your personal data; the opportunity to advertise to you; or to hook you in order to upsell you premium services at a later date. Many of us have learned this lesson the hard way in the world of consumer and social networking software.
None of this is inherently sinister, but when it comes to web conference services, IT and business buyers need to be particularly vigilant of the security risks. There are many players providing free and low-cost services that are very light on security. It only takes one major security breach to expose options in this space for the false economy that they represent.
Let’s take a take a closer look at the three key aspects of web conferencing security to evaluate when selecting providers:
1 - Authentication
[caption id="attachment_21396" align="alignright" width="250"]
Guillaume Vives[/caption]
Ensuring that only authorised participants join calls is a major challenge with free audio, video and web conferencing. You can host an encrypted meeting but anybody with the details of the call can join and listen in. Even worse, if people join using the audio-only options, they can listen in without revealing their names or identities.
Lack of authentication poses a serious risk factor. Last October a major aircraft manufacturer came to us after two external audio-only parties listened in on an all-hands meeting that their CEO hosted. Similarly, as we enter the 2020 election campaign, a number of politically engaged organisations have approached us to ensure that opponents, detractors and unauthorised journalists are not able to sneak onto their web conferences - as they have done in the past.
However you don’t have to work in aerospace or politics for security breaches like this to place your organisation and its people in jeopardy. To avoid them at your organisation, seek out premium conferencing services that include a full security suite with encryption AND two-factor authentication (two-stage secure login process). Crucially, make sure the system you choose eliminates the common loophole of being able to forward meeting invitations.
2 - Privacy
Lots of cloud or online services gives you free access without making it clear that they sell all the data they capture on you. This is not just data that reveals your identity, but also who you meet with, for how long, and even how frequently.
At minimum, if your company uses a free service that has granted permission to sell on this type of data, your employees must be made aware of this. For most organisations, this isn’t an acceptable trade-off. Again, look for premium services that explicitly state that they don’t sell your data on to any third parties. Paying for services gives you a lot more leverage in the event of any privacy breach.
3 - Monitoring
The riskiest services are those that provide a single number or call link that anyone use to join without so much having to enter as a password or meeting ID. I’ve heard countless stories about people being on conferences that finished late, where random people from the next meeting have joined and listened in. Monitoring capabilities prevent this from happening.




