Sony Pixel Power calrec Sony

Ted Harrington on Security in the Industry

20/06/2017

by Debra Kaufman

Security has become an area of great concern in the media and entertainment industry, since the Sony hack in 2014. This year, TheDarkOverlord hacked Larson Studio and released most of the fifth season of Orange Is the New Black, and later hacked ABC's Good Morning America Twitter accounts. How worried should you be? And what can you do to protect your company? HPA spoke with security expert Ted Harrington, executive partner at Independent Security Evaluators to find out.

Awareness about security is indeed increasing. It is important to note, however, that the threats to M&E aren't necessarily increasing, but rather awareness about those threats. These challenges have existed all along. The Sony breach was a catalyzing event that heightened the urgency for organizations to approach security proactively rather than reactively.

Security is a business problem, not just an IT problem, and executives are starting to recognize it as such. Every major attacker category is interested in stealing content assets, and all for different reasons, which makes it an immensely difficult position for defenders to handle. That was actually a primary motivator for Independent Security Evaluators when we committed to working here years ago, because we love solving complex problems.

One of the most crucial cybersecurity areas is surrounding applications. Adoption of applications is very rapid, and is fundamentally changing the business of content creation and distribution. Applications also entail a vast collection of attack surfaces for adversaries to pursue.

Ransomware has gotten a lot of attention. According to Forbes, cybersecurity firm SonicWall reported about 3.8 million ransomware attacks in 2015, which skyrocketed to 638 million attacks in 2016. The best way to protect against ransomware criminals is proper offsite backup, and it's critical to note that many organizations don't set up backups at all. Or if they do, they do so improperly, and so the primary data and the backup data often get compromised in the same event.

Although some people still fear the putting content in the cloud, this fear is irrational. We find that most people fall into one of three categories: irrationally confident in the cloud, irrationally afraid of the cloud, or somewhere in between. We advocate that everyone should be in that third category. A healthy dose of skeptical paranoia combined with a reasoned approach to risk-taking is how executives should consider pretty much any business decision, including whether to adopt cloud services.

Content assets are more at risk in a cloud environment than in physical media, because the attack requirements are lower. However, it is worth noting that the only unhackable system is one that is disconnected and buried in concrete - and how usable is that system? All aspects of any business make tradeoffs, and there are ways to utilize cloud services that are effective in minimizing risk.

The primary risks of utilizing cloud services are the same risks as not using cloud services: exploitable design flaws, exploitable implementation flaws, improper configuration, broken trust models, and so on. Fundamentally, the only difference between cloud and on-premise is that someone else owns the hardware. The manner in which an organization must consider adversaries, architect systems, and protect assets are essentially the same whether or not they own the hardware. Cloud actually even offers some security upgrades: while the primary tradeoff of utilizing cloud services is that an organization entrusts the data to someone else's hardware, the benefit return is that the cloud service providers are constantly investing in hardware upgrades, have extreme physical security measures in place, and have the latest and greatest of everything. A company that manages their own equipment on premise usually tends to not invest as heavily or as frequently in upgrades.

All studios require their technology vendors to undergo some sort of security testing prior to approval to access content, and most require the vendors to pay for it. In many cases, all organizations on both sides of that equation do not understand the assessment methodology that is required, and there is usually a drive towards cheap pricing rather than through assessment. But security is not overhead to be reduced, it is a business enabler to be invested in.

Bigger companies tend to be the more common targets, but smaller companies tend to be lesser able to defend themselves or afford adequate security measures. At the same time, smaller companies tend to be the engines of innovation, and the bigger companies (such as the studios) partner heavily with smaller companies (such as many of the technology vendors). Attackers know this. Malicious campaigns are often organized around what is known as a stepping stone attack, which is targeted at the smaller vendor companies that have lower defenses but the same access to the extreme valuable content assets. In the event of a compromise, both the small company and the big company thereby get hurt.

Steps companies should take right now to protect themselves are to understand and adhere to principles of secure design. I recently wrote a whitepaper on this topic, which you can read here. My advice is to invest in a proper security assessment, and avoid more cursory approaches like black box penetration testing, automated scaring, or reliance on compliance. Investigate your systems for weaknesses from the perspective of the adversary. Because, whether you do or do not approach your security weaknesses thoroughly, make no doubt about this: the adversaries will.
LINK: http://www.hollywoodprofessionalassociation.com/?p=155336...
See more stories from hpa

Most recent headlines

06/10/2025

France Tlvisions Wins Prestigious 2025 EBU Technology & Innovation Award in Groundbreaking Collaboration with Dalet

France T l visions, France's leading broadcaster, has received the 2025 EBU ...

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

30/08/2025

FCC Slightly Raises Regulatory Fees for TV Stations

WASHINGTON The Federal Communications Commission has adopted its FY 2025 Regulatory Fees Order that establishes the regulatory fee rates for the broadcast stati...

29/08/2025

Australian Red Cross and SBS launch training to help workplaces in the fight against Modern Slavery

Australian Red Cross and SBS launch training to help workplaces in the fight aga...

29/08/2025

Call for entries is now open for the 19th Annual South African Film & Television Awards (SAFTAs19)

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

29/08/2025

L3Harris Launches Counter-Unmanned Systems Initiative

L3Harris Technologies has concentrated decades of expertise across the entire enterprise to develop affordable and reliable best-of-breed solutions to rapidly c...

29/08/2025

The CW Network Extends Pac-12 Deal Through 2030-31 Season

BURBANK, Calif. The CW Network and the Pac-12 Conference have announced a new media rights deal that will extend their broadcast partnership beginning with the ...

29/08/2025

Global FAST Channel Count Continues to Spike

NEW YORK Gracenote has released a new analysis of its global video dataset showing that the number of FAST channels grew nearly 14% from Q1 2025 and 76% since 2...

29/08/2025

Harmonic Unveils New Capabilities for Its Live Sports Streaming Solution

SAN JOSE, Calif. Harmonic has announced a series of improvements to its live sports streaming solution that the company said will improve fan engagement, protec...

29/08/2025

Youtube TV, Fox Settle Differences, Renew Carriage Agreement

NEW YORK and LOS ANGELES Fox Corp. and YouTube TV last night announced a renewal of the full portfolio of Fox networks, including Fox News Channel, Fox Business...

29/08/2025

Lightware MTR integration brings advanced flexibility and...

Budapest, Hungary, August 2025 - The integration of Microsoft Teams Rooms (MTR) with Lightware's Taurus universal matrix switchers delivers a new level of f...

29/08/2025

Frequency Launches Studio Live - a Unified Platform to Br...

Frequency, the engine behind many of the world's best-known streaming television channels, today announced it will launch Studio Live, a next-generation uni...

29/08/2025

Scality Day 2025 Celebrating 10 years of global innovatio...

In an era when AI and cyber resilience are essential, Scality will mark the 10th anniversary of Scality Day on October 16, 2025 in Paris. This flagship global e...

29/08/2025

Disguise Drives New Immersive Racing Experience - F1 Box

Disguise's In-House Creative and Technical Teams Pre-Visualised, Programmed and Delivered Content for the Experience, All Powered by EX 3+ Technology solu...

29/08/2025

Disguise Supports Fellow Entertainment Tech Leaders at IB...

Disguise will be demonstrating the latest workflows for TV, film and live events on a number of partner booths at the show Disguise, the industry-leading tech...

29/08/2025

Accedo to Highlight Compose AI-Agent Enhanced Orchestration Layer

STOCKHOLM, Sweden Accedo will showcase Accedo Compose, its AI agent-powered modular orchestration layer that assists streaming providers in transitioning client...

29/08/2025

Cineverse Launches Streaming Apps for In-Vehicle Video Streaming

LOS ANGELES Cineverse has announced that it is working with Xperi to bring four of its streaming channels to automobiles for the first time as part of the DTS A...

29/08/2025

Gray Media to Simulcast 17 Dallas Stars NHL Games

DALLAS & ATLANTA Gray Media has announced an agreement with the sports streaming service Victory+ to simulcast 17 Dallas Stars NHL games in 15 television market...

29/08/2025

Comcast NBCU and Amazon Ink New Distribution Agreements

NEW YORK AND CULVER CITY Comcast NBCUniversal and Amazon have announced new and extended distribution agreements that will expand the content available on their...

29/08/2025

RED Digital Cinema To Highlight Cine-Broadcast Module At IBC2025

FOOTHILL RANCH, Calif. RED Digital Cinema will feature its Cine-Broadcast Module supporting live broadcast workflows during IBC2025, Sept. 12-15, at the RAI Ams...

29/08/2025

Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and Highlighting Ukraine's Investment Case

29 Aug 2025 Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and ...

29/08/2025

Sky Sports to show more NFL games than ever as part of new rights agreement

More than half of all NFL games live on Sky for the first timeFriday 29 August 2025 Sky Sports has announced a new three-year deal with the NFL, extending its ...

29/08/2025

'RIV4LRIES': The Trailer of the New Series With Samuele Carrino Only on Netflix October 1

Back to All News RIV4LRIES: The Trailer of the New Series With Samuele Carrino ...

29/08/2025

Steps ahead: RT to air inspiring documentary on 12-year-old Irish dance star

Get ready for an inspiring and emotional insight into the world of competitive Irish dancing with My Story: Tomi Champion of the World airing on RT 2 this monda...

29/08/2025

TODAY WITH DAVID MCCULLAGH TO AIR ON RT RADIO 1 WEEKDAYS AT 10AM

RT has today announced that David McCullagh is to be the new presenter of RT Radio 1's flagship Today programme, which airs every weekday at 10am, replaci...

28/08/2025

Meet the 2025 Sundance Institute Documentary Edit Residency Artists

By Kristin Feeley, Director, Documentary Film & Artist Programs If you want to tell untold stories, if you want to give voice to the voiceless, you've got ...

28/08/2025

Watch These 9 Sundance Institute-Supported Documentaries That Spotlight Workers' Rights

Directed by Steven Bognar and Julia Reichert, Sundance Institute-supported Amer...

28/08/2025

Motivational Corridos: The New Sound of Resilience in Msica Mexicana

Corridos have been a cornerstone of M sica Mexicana for generations, telling stories rooted in everyday life. Now, a new chapter is taking shape: motivational c...

28/08/2025

Corridos Motivadores: El Nuevo Sonido de la Resiliencia en Mxico

Los corridos han sido un pilar de la M sica Mexicana durante generaciones, contando historias enraizadas en la vida cotidiana. Ahora, un nuevo cap tulo est tom...

28/08/2025

Verano Forever Brings Myke Towers, Bele, Elena Rose, and More to Miami for an Unforgettable Latin Summer Celebration

Earlier this month, we promised our Verano Forever party would bring the heat, a...

28/08/2025

Poland Selects L3Harris Electronic Warfare System for F-16 Fleet

L3Harris will provide the Polish F-16V fleet with the Viper Shield electronic warfare system as part of an upgrade program....

28/08/2025

AgileTV consolidates its technological leadership with the development of Lowi TV in Spain

Bilbao, August 26, 2025 - AgileTV, an international television and video technol...

28/08/2025

Craft Interview: Ken Wilkinson, Audio Engineer

Ken Wilkinson is an Emmy Awards nominated New York audio engineer who specialises in production sound mixing for film, commercial, episodic and documentary work...

28/08/2025

Fubo to Launch Fubo Sports Skinny Bundle for $56 Per Month

NEW YORK FuboTV today announced that it will launch Fubo Sports, a skinny bundle that focuses on sports with a subscription price of $56 monthly....

28/08/2025

Telestream to Launch 'Global Ingest Workflow at IBC2025

NEVADA City, Calif. At IBC2025, Sept. 12-15 at the RAI Amsterdam, Telestream will debut its new Global Ingest strategy, introducing a next-generation ingest arc...

28/08/2025

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Education

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Educatio...

28/08/2025

TAG Strengthens Regional Presence with Appointment of Oli...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has named Oliver Gappa as Sales Di...

28/08/2025

DHD to Demonstrate AI-Based Voice Enhancement at IBC 2025

AI-based voice enhancement will be among a series of innovations making their IBC 2025 debut on the DHD stand B46 in Hall 8 at the RAI Amsterdam Convention Cent...

28/08/2025

Telefonica Servicios Audiovisuales Hit the Back of the Ne...

Telef nica Servicios Audiovisuales (TSA), the leading system integrator and service provider in the media sector in Spain, with the support of Appear, the globa...

28/08/2025

Optical Media Anchors LiveU IQ into its On site Productio...

To fully immerse sailing fans in the world's biggest offshore yacht race, production company, Optical Media turned to LiveU's On-site Production solutio...

28/08/2025

WNED Adopts Calrec Type R console to weather any storm an...

Working with Calrec on its most recent overhaul, radio and television broadcaster, WNED has migrated to a fully IP infrastructure with multiple Type R consoles,...

28/08/2025

Cleeng unveils first ever free D2C subscription platform...

Cleeng, the Subscriber Retention Management (SRM ) inventor, has unveiled Cleeng Pro, the first-ever direct-to-consumer (D2C) subscription management platform t...

28/08/2025

Zixi and OKAST Partner to Power Scalable Global FAST Chan...

Zixi, the industry leader in live broadcast-quality video over IP, today announced that French media distribution platform OKAST has selected Zixi to enable rel...

28/08/2025

Nixer to unveil CV1 AoIP monitoring tool to address evolv...

Solution offers a streamlined, speaker-free architecture to optimize integration with premium external loudspeakers and advanced loudness metering Nixer Pro Au...

28/08/2025

Cinegy Announces Strategic Partnership with One Touch Pro...

Cinegy, the premier provider of software-defined television technology, has announced a strategic partnership with Vision One Touch Film Production Services L.L...

28/08/2025

Telestream Global Ingest Workflow Powered by Vantage Open...

Telestream, a global leader in media workflow technologies, will debut its new Global Ingest strategy at IBC2025, introducing a next-generation ingest architect...

28/08/2025

Telenor partners with Broadpeak for multi-country content...

Tier 1 operator selects Broadpeak to power high-performance, unified CDN solution across Norway, Sweden and Finland Broadpeak, a leader in streaming and moneti...

28/08/2025

24 Frames Digital goes live with Synamedia Quortex Play f...

Leading video software provider, Synamedia, today announced that 24 Frames Digital, one of India's leading live event streaming service providers, has chose...

28/08/2025

VisualOn at IBC 2025 - Whats Next in AI Powered Video Str...

Meet VisualOn at IBC2025: See What's Next in AI-Powered Video Streaming Join VisualOn at IBC2025 and discover how our AI-driven Optimizer and advanced media...