Sony Pixel Power calrec Sony

Ted Harrington on Security in the Industry

20/06/2017

by Debra Kaufman

Security has become an area of great concern in the media and entertainment industry, since the Sony hack in 2014. This year, TheDarkOverlord hacked Larson Studio and released most of the fifth season of Orange Is the New Black, and later hacked ABC's Good Morning America Twitter accounts. How worried should you be? And what can you do to protect your company? HPA spoke with security expert Ted Harrington, executive partner at Independent Security Evaluators to find out.

Awareness about security is indeed increasing. It is important to note, however, that the threats to M&E aren't necessarily increasing, but rather awareness about those threats. These challenges have existed all along. The Sony breach was a catalyzing event that heightened the urgency for organizations to approach security proactively rather than reactively.

Security is a business problem, not just an IT problem, and executives are starting to recognize it as such. Every major attacker category is interested in stealing content assets, and all for different reasons, which makes it an immensely difficult position for defenders to handle. That was actually a primary motivator for Independent Security Evaluators when we committed to working here years ago, because we love solving complex problems.

One of the most crucial cybersecurity areas is surrounding applications. Adoption of applications is very rapid, and is fundamentally changing the business of content creation and distribution. Applications also entail a vast collection of attack surfaces for adversaries to pursue.

Ransomware has gotten a lot of attention. According to Forbes, cybersecurity firm SonicWall reported about 3.8 million ransomware attacks in 2015, which skyrocketed to 638 million attacks in 2016. The best way to protect against ransomware criminals is proper offsite backup, and it's critical to note that many organizations don't set up backups at all. Or if they do, they do so improperly, and so the primary data and the backup data often get compromised in the same event.

Although some people still fear the putting content in the cloud, this fear is irrational. We find that most people fall into one of three categories: irrationally confident in the cloud, irrationally afraid of the cloud, or somewhere in between. We advocate that everyone should be in that third category. A healthy dose of skeptical paranoia combined with a reasoned approach to risk-taking is how executives should consider pretty much any business decision, including whether to adopt cloud services.

Content assets are more at risk in a cloud environment than in physical media, because the attack requirements are lower. However, it is worth noting that the only unhackable system is one that is disconnected and buried in concrete - and how usable is that system? All aspects of any business make tradeoffs, and there are ways to utilize cloud services that are effective in minimizing risk.

The primary risks of utilizing cloud services are the same risks as not using cloud services: exploitable design flaws, exploitable implementation flaws, improper configuration, broken trust models, and so on. Fundamentally, the only difference between cloud and on-premise is that someone else owns the hardware. The manner in which an organization must consider adversaries, architect systems, and protect assets are essentially the same whether or not they own the hardware. Cloud actually even offers some security upgrades: while the primary tradeoff of utilizing cloud services is that an organization entrusts the data to someone else's hardware, the benefit return is that the cloud service providers are constantly investing in hardware upgrades, have extreme physical security measures in place, and have the latest and greatest of everything. A company that manages their own equipment on premise usually tends to not invest as heavily or as frequently in upgrades.

All studios require their technology vendors to undergo some sort of security testing prior to approval to access content, and most require the vendors to pay for it. In many cases, all organizations on both sides of that equation do not understand the assessment methodology that is required, and there is usually a drive towards cheap pricing rather than through assessment. But security is not overhead to be reduced, it is a business enabler to be invested in.

Bigger companies tend to be the more common targets, but smaller companies tend to be lesser able to defend themselves or afford adequate security measures. At the same time, smaller companies tend to be the engines of innovation, and the bigger companies (such as the studios) partner heavily with smaller companies (such as many of the technology vendors). Attackers know this. Malicious campaigns are often organized around what is known as a stepping stone attack, which is targeted at the smaller vendor companies that have lower defenses but the same access to the extreme valuable content assets. In the event of a compromise, both the small company and the big company thereby get hurt.

Steps companies should take right now to protect themselves are to understand and adhere to principles of secure design. I recently wrote a whitepaper on this topic, which you can read here. My advice is to invest in a proper security assessment, and avoid more cursory approaches like black box penetration testing, automated scaring, or reliance on compliance. Investigate your systems for weaknesses from the perspective of the adversary. Because, whether you do or do not approach your security weaknesses thoroughly, make no doubt about this: the adversaries will.
LINK: http://www.hollywoodprofessionalassociation.com/?p=155336...
See more stories from hpa

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

04/05/2026

just:play pro 2026 and just:live pro 2026 are available to download!

just:play pro 2026 and just:live pro 2026 are available to download! More Details:At NAB 2026, ToolsOnAir showcased just:play pro 2026 and just:live pro 2026, ...

04/05/2026

just:in mac pro 2026 - The Next Level of Professional Recording on macOS

just:in mac pro 2026 - The Next Level of Professional Recording on macOS More Details:The headline innovation in just:in mac pro 2026 is the new Auto format si...

04/05/2026

SVG Sit-Down: NEP Americas Mike Werteen on How Great Tech, Better People Drive Success

Hardware is still an emphasis - Supershooter 11 is new, and REMI-based 65 is in ...

04/05/2026

Beyond 90 Minutes: How K League's Soccer Blueprint for Growth Has Lessons for Everyone

Head of International Business Development Min Joo Kim explores the league's...

04/05/2026

Audio-Technica ATND1061 and ATUC Discussion Systems Certified for Crestron Automate VX

Audio-Technica has announced that its ATND1061 ceiling array microphone and ATUC...

04/05/2026

Triple B Media Launches Bowling TV, a 24/7 FAST Channel Dedicated to Bowling

Triple B Media has launched Bowling TV, a free ad-supported television (FAST) channel dedicated to bowling. The channel is available on Prime Video, LG Channels...

04/05/2026

PlayMetrics Acquires SportsEngine from Versant

PlayMetrics, a provider of operations management software for youth sports organizations, has announced the completion of its acquisition of substantially all t...

04/05/2026

IHSE GmbH Appoints Dr. Thomas Niessen as CEO

IHSE GmbH has announced that Dr. Thomas Niessen has joined as CEO and Managing Director, effective May 1, 2026. He joins Frank Breitenfelder, who has served as ...

04/05/2026

PMY Group Deploys Optic Crowd Intelligence Platform at Australian Formula 1 Grand Prix

PMY Group deployed its AI-powered crowd intelligence platform, Optic, at the For...

04/05/2026

Behind The Mic: Stephen A. Smith and Skip Bayless to Reunite for First Take Episode; Donna Brothers Worked Final Kentucky Derby

Behind The Mic provides a roundup of recent news regarding on-air talent, includ...

04/05/2026

Spotify Brings Fashion and Podcasting Together With Mina Le and Mia Calabrese

Last week, guests gathered in New York City for On Air, In Style: An Evening with Spotify-a night of conversation, culture, and connection celebrating the inter...

04/05/2026

Avid introduce Pro Tools 2026.4

New music & post-production features added Avid's latest DAW update delivers an array of helpful features aimed at both music and post-production users,...

04/05/2026

SAG-AFTRA, Studios Reach Tentative Agreement

Share Copy link Facebook X Linkedin Bluesky Email...

04/05/2026

Study: Paramount-WBD Deal Signals New Era of Streaming Scale

Share Copy link Facebook X Linkedin Bluesky Email...

04/05/2026

Student Spotlight: Joshua Griffin

Student Spotlight: Joshua Griffin The New Orleans native, who was named the 2026 student commencement speaker for Boston Conservatory at Berklee, talks about ...

04/05/2026

It's Andrew! stomps onto screens this June

It's Andrew! stomps onto screens this June 4 May 2026 The ABC and Screen Australia are delighted to announce that brand new preschool series, It's Andr...

03/05/2026

Melbourne Instruments' Nina gains Braids engine

Polysynth now features Mutable Instruments' macro oscillators Melbourne Instruments have just released a free firmware update that brings the engine beh...

03/05/2026

Introducing the new Mistika Workflows Suite: transformative and cost-effective for every user

Introducing the new Mistika Workflows Suite: transformative and cost-effective f...

03/05/2026

Introducing the new Mistake Workflows Suite: transformative and cost-effective for every user

Introducing the new Mistake Workflows Suite: transformative and cost-effective f...

03/05/2026

Filming begins on the third and final season of Breathless

Back to All News Filming begins on the third and final season of Breathless Entertainment 03 May 2026 GlobalSpain Link copied to clipboard Discover the vi...

02/05/2026

Release Rundown: What to Watch in May, From Saccharine to Tuner

(L-R) Dustin Hoffman and Leo Woodall appear in Tuner by Daniel Roher, an official selection of the 2026 Sundance Film Festival. (Photo courtesy of Sundance In...

02/05/2026

Warm Audio launch the Reamper

Versatile re-amping tool announced Warm Audio are best known for their recreations of sought-after vintage studio gear, but their latest release brings a ne...

02/05/2026

FCC Releases Tentative Agenda for May Open Meeting

Share Copy link Facebook X Linkedin Bluesky Email...

02/05/2026

Sinclair Remains Bullish on Station M&A

Share Copy link Facebook X Linkedin Bluesky Email...

02/05/2026

NABLF Announces 2026 Broadcast Leadership Training Award Winners

Share Copy link Facebook X Linkedin Bluesky Email...

02/05/2026

Gravity Media Taps Custom Consoles for Work on Production Center

Share Copy link Facebook X Linkedin Bluesky Email...

02/05/2026

May 01, 2026

Scripps Research immunologist Dennis Burton elected to American Academy of Arts and Sciences A leader in broadly neutralizing antibodies, Burton has helped driv...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

Ratings Roundup: NBA Playoffs Return to NBC Sports up 38%; NFL Draft Down 12% Overall From 2025

Ratings Roundup is a rundown of recent rating news and is derived from press rel...

01/05/2026

BKB Bare Knuckle Boxing Appoints Will Wright as Chief Operating Officer to Drive Global Growth and Operational Excellence

BKB Bare Knuckle Boxing ( BKB ), today announced the appointment of Will Wright ...

01/05/2026

NAB Rewind: Lawo's Andreas Hilmer on the Power of the Edge One AV Stagebox

Lawo has been at the center of the industry's transition to IP and other next-generation technologies. At NAB 2026, its story was the Edge One AV stagebox, ...

01/05/2026

Kentucky Derby 152 to Air Across 19 Networks in 170-Plus Territories

HBA Media, acting on behalf of NBC Sports and Churchill Downs Incorporated, has announced broadcast and streaming distribution for Kentucky Derby 152, taking pl...

01/05/2026

Give Me the Backstory: Get to Know Barbara Kopple, the Director of American Dream

By Bailey Pennick One of the most exciting things about the Sundance Film Festi...

01/05/2026

Find Out Which The Devil Wears Prada 2' Character You Are With Our New Playlist

Florals for spring? Groundbreaking. But a playlist that tells you which The Devi...

01/05/2026

Olivia Rodrigo Takes Over FC Barcelona Jersey for El Clsico Match at Spotify Camp Nou

One of the world's biggest popstars is headed to El Cl sico. Later this mont...

01/05/2026

Heritage Audio announce the Baby RAM Black Edition

Limited-edition model celebrates 15th anniversary Heritage Audio's range of monitor controllers has just gained a new member, the Baby RAM Black Edition...

01/05/2026

Universal Audio release UAD Enigmatic '82 Overdrive Special Amp

Dumble recreation now available as UAD plug-in Along with their renowned processing plug-ins, Universal Audio have been steadily introducing emulations of c...

01/05/2026

UPDATED: Republican AGs Join Nexstar-Tegna Antitrust Suit

Share Copy link Facebook X Linkedin Bluesky Email...

01/05/2026

Broadcaster Draper Media Names Bill Vernon President

Share Copy link Facebook X Linkedin Bluesky Email...

01/05/2026

Analysts: 'Hollywood's Vertical Video Strategy Is Dead Wrong'

Share Copy link Facebook X Linkedin Bluesky Email...

01/05/2026

Lightware UK celebrates new London showroom with launch e...

To celebrate the opening of its new showroom and office, Lightware UK hosted a dedicated launch event at the new London location. The event welcomed partners, c...

01/05/2026

Calrec Puts Broadcaster Choice Centre Stage at MPTS 2026

Choice without compromise The broadcast industrys transformation is accelerating, and traditional broadcasters are having to fundamentally reinvent how they o...

01/05/2026

Beam Dynamics Showcases its Asset Intelligence Platform a...

Beam Dynamics will return to MPTS 2026 with its asset intelligence platform, helping systems integrators, live production teams, media facilities and profession...

01/05/2026

Synamedia and FX Digital collaborate to bring GO Shorts a...

Best-in-class UX design and rapid, scalable delivery for next-generation viewing experiences Leading video software provider, Synamedia, today announced a coll...

01/05/2026

Compact new cforce MAX lens motor brings unrivaled speed and responsiveness to the Hi-5 ecosystem

Compact new cforce MAX lens motor brings unrivaled speed and responsiveness to t...

01/05/2026

Panavision welcomes Fritz Heinzle as Vice President of Sales

Panavision welcomes Fritz Heinzle as Vice President of Sales Brie Clayton May 1, 2026 0 Comments Heinzle will support Panavision's global growth s...