Sony Pixel Power calrec Sony

Ted Harrington on Security in the Industry

20/06/2017

by Debra Kaufman

Security has become an area of great concern in the media and entertainment industry, since the Sony hack in 2014. This year, TheDarkOverlord hacked Larson Studio and released most of the fifth season of Orange Is the New Black, and later hacked ABC's Good Morning America Twitter accounts. How worried should you be? And what can you do to protect your company? HPA spoke with security expert Ted Harrington, executive partner at Independent Security Evaluators to find out.

Awareness about security is indeed increasing. It is important to note, however, that the threats to M&E aren't necessarily increasing, but rather awareness about those threats. These challenges have existed all along. The Sony breach was a catalyzing event that heightened the urgency for organizations to approach security proactively rather than reactively.

Security is a business problem, not just an IT problem, and executives are starting to recognize it as such. Every major attacker category is interested in stealing content assets, and all for different reasons, which makes it an immensely difficult position for defenders to handle. That was actually a primary motivator for Independent Security Evaluators when we committed to working here years ago, because we love solving complex problems.

One of the most crucial cybersecurity areas is surrounding applications. Adoption of applications is very rapid, and is fundamentally changing the business of content creation and distribution. Applications also entail a vast collection of attack surfaces for adversaries to pursue.

Ransomware has gotten a lot of attention. According to Forbes, cybersecurity firm SonicWall reported about 3.8 million ransomware attacks in 2015, which skyrocketed to 638 million attacks in 2016. The best way to protect against ransomware criminals is proper offsite backup, and it's critical to note that many organizations don't set up backups at all. Or if they do, they do so improperly, and so the primary data and the backup data often get compromised in the same event.

Although some people still fear the putting content in the cloud, this fear is irrational. We find that most people fall into one of three categories: irrationally confident in the cloud, irrationally afraid of the cloud, or somewhere in between. We advocate that everyone should be in that third category. A healthy dose of skeptical paranoia combined with a reasoned approach to risk-taking is how executives should consider pretty much any business decision, including whether to adopt cloud services.

Content assets are more at risk in a cloud environment than in physical media, because the attack requirements are lower. However, it is worth noting that the only unhackable system is one that is disconnected and buried in concrete - and how usable is that system? All aspects of any business make tradeoffs, and there are ways to utilize cloud services that are effective in minimizing risk.

The primary risks of utilizing cloud services are the same risks as not using cloud services: exploitable design flaws, exploitable implementation flaws, improper configuration, broken trust models, and so on. Fundamentally, the only difference between cloud and on-premise is that someone else owns the hardware. The manner in which an organization must consider adversaries, architect systems, and protect assets are essentially the same whether or not they own the hardware. Cloud actually even offers some security upgrades: while the primary tradeoff of utilizing cloud services is that an organization entrusts the data to someone else's hardware, the benefit return is that the cloud service providers are constantly investing in hardware upgrades, have extreme physical security measures in place, and have the latest and greatest of everything. A company that manages their own equipment on premise usually tends to not invest as heavily or as frequently in upgrades.

All studios require their technology vendors to undergo some sort of security testing prior to approval to access content, and most require the vendors to pay for it. In many cases, all organizations on both sides of that equation do not understand the assessment methodology that is required, and there is usually a drive towards cheap pricing rather than through assessment. But security is not overhead to be reduced, it is a business enabler to be invested in.

Bigger companies tend to be the more common targets, but smaller companies tend to be lesser able to defend themselves or afford adequate security measures. At the same time, smaller companies tend to be the engines of innovation, and the bigger companies (such as the studios) partner heavily with smaller companies (such as many of the technology vendors). Attackers know this. Malicious campaigns are often organized around what is known as a stepping stone attack, which is targeted at the smaller vendor companies that have lower defenses but the same access to the extreme valuable content assets. In the event of a compromise, both the small company and the big company thereby get hurt.

Steps companies should take right now to protect themselves are to understand and adhere to principles of secure design. I recently wrote a whitepaper on this topic, which you can read here. My advice is to invest in a proper security assessment, and avoid more cursory approaches like black box penetration testing, automated scaring, or reliance on compliance. Investigate your systems for weaknesses from the perspective of the adversary. Because, whether you do or do not approach your security weaknesses thoroughly, make no doubt about this: the adversaries will.
LINK: http://www.hollywoodprofessionalassociation.com/?p=155336...
See more stories from hpa

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

21/10/2025

Grup Mediapro to Deliver Prime Video NBA Coverage to the Hispanic Market

As Amazon's Prime Video prepares to launch its coverage of NBA basketball under a major new deal, Grup Mediapro has announced that it is working with the st...

21/10/2025

ADTH to Upgrade NextGen TV Receivers With Gateway Capabilities

ATLANTA Good news for consumers using an Atlanta DTH receiver to watch ATSC 3.0: with a new software update, they will be able to blanket their homes with Wi-Fi...

21/10/2025

Study: 'More Critical Than Ever for Brands to Focus on Hispanics

While recent news has been heavily focused on Hispanic migration into the U.S., The 2025 Hispanic Market Report from Claritas highlights the fact that this gr...

21/10/2025

RWS Appoints Michael Wayne as Head of Media and Entertainment

MAIDENHEAD, UK RWS has hired Michael Wayne as its head of media and entertainment in Los Angeles where he will lead the company's media localization busines...

21/10/2025

Imagine Communications Acquires Pixel Power From Rohde an...

Imagine Communications and Rohde & Schwarz today announced a definitive agreement under which Imagine will acquire Pixel Power Limited, a wholly owned subsidiar...

21/10/2025

ADTH Announces New NEXTGEN TV Gateway Receiver Implementi...

Atlanta DTH (ADTH) today announced a major update that will expand the functionality of its NEXTGEN TV receiver by enabling gateway capabilities allowing viewer...

21/10/2025

Heartland Video Systems Partners with Zixi for Resilient...

Heartland Video Systems, Inc. (HVS), a premier video systems integration, consulting, and expert ATSC 3.0 implementation firm announces that it has partnered wi...

21/10/2025

QuickLink Appoints Austin Hinton as Solutions Enablement...

QuickLink, the leading provider of award-winning video production and remote guest integration solutions, today announced the appointment of Austin Hinton as it...

21/10/2025

Miri Technologies to Unveil New Resilient Internet Platfo...

nternet connectivity startup Miri Technologies Inc. will use this week's NAB Show New York as the launch pad for its latest ground-breaking innovation, the ...

20/10/2025

Inside TAMS: How Time-Addressable Media Stores Could Redefine Sports Workflows

Inside TAMS: How Time-Addressable Media Stores could redefine sports workflows By Paul Markham Friday, October 17, 2025 - 08:57 Print This Story A penalty...

20/10/2025

Transformational Production: Inside TVN's Remote Production Push for the DFL's Bundesliga 2

Transformational production: Inside TVN's remote production push for the DFL...

20/10/2025

How NBC Sports Transitioned Stamford Facility to One Format: 1080p HDR

How NBC Sports Transitioned Stamford Facility to One Format: 1080p HDRMulti-year plan harmonizes workflows, simplifies operationsBy Ken Kerschbaumer, Editorial ...

20/10/2025

NBA on NBC' Studio Production Team Is Ready for Tip-Off With Coast-to-Coast Tuesday'

NBA on NBC' Studio Production Team Is Ready for Tip-Off With Coast-to-Coast...

20/10/2025

Under Pressure: TVN CEO Markus Osthaus Considers the German Sports Broadcasting Market

Under pressure: TVN CEO Markus Osthaus considers the German sports broadcasting ...

20/10/2025

Carmen Emmi's Plainclothes Evokes the Rawness and Sensuality of New Queer Cinema

(L-R) Maria Dizzia, Carmen Emmi, and Russell Tovey attend the Plainclothes pre...

20/10/2025

Search and Follow Your Favorite Venues on Spotify

In March, we launched Concerts Near You to help listeners find concerts from their favorite artists. Since then, more than 3 million people have used it to disc...

20/10/2025

Arte Preta Brasileira Destaque No Dia AMPLIFIKA 2025

Em diversas cidades do Brasil, um movimento tem se fortalecido para celebrar o poder, a beleza e a profundidade da criatividade negra. O Dia AMPLIFIKA, agora em...

20/10/2025

Black Brazilian Artistry Takes Center Stage During AMPLIFIKA Day 2025

In cities across Brazil, a movement is growing that celebrates the power, beauty, and depth of Black creativity. AMPLIFIKA Day, now in its fifth edition, return...

20/10/2025

The Republic of Korea Selects L3Harris for Airborne Early Warning and Control Aircraft Program

Airborne Early Warning and Control aircraft rendering...

20/10/2025

Imagine Communications Acquires Pixel Power From Rohde & Schwarz

DENVER and MUNICH Imagine Communications today announced its plans to acquire Pixel Power Ltd., a wholly owned subsidiary of Rohde & Schwarz. Financial terms of...

20/10/2025

Globecast Appoints G Morgan as EVP of Sales, Globecast Americas

LOS ANGELES G Morgan has joined Globecast, a provider of broadcast, media and entertainment managed services, as executive vice president of sales, Globecast Am...

20/10/2025

Heartland Video Systems, Zixi Partner on IP Networking for Broadcasters

PLYMOUTH, Wisc. Heartland Video Systems and Zixi have partnered to enable broadcast-quality live video delivery over any IP network....

20/10/2025

A. R. Rahman on Facing Fear and Finding the Divine

A. R. Rahman on Facing Fear and Finding the Divine In an interview with Berklee President Jim Lucchese, the Oscar-winning composer reflects on how courage and...

20/10/2025

Sky unveils thrilling trailer of Original film Nuremberg, starring Russell Crowe, Rami Malek and Michael Shannon

Monday 20 October 2025 To view this content, please enable our use of cookies. ...

20/10/2025

Rohde & Schwarz transfers Pixel Power to Imagine Communications

Rohde & Schwarz transfers Pixel Power to Imagine Communications Companies work collaboratively to ensure continuity and ongoing support for existing customers...

20/10/2025

RT Prime Time to host final Presidential Debate

RT 's Prime Time is set to host the final Presidential Election Debate this Tuesday night, October 21, providing an opportunity to hear directly from Irelan...

20/10/2025

NVIDIA and Google Cloud Accelerate Enterprise AI and Industrial Digitalization

NVIDIA and Google Cloud are expanding access to accelerated computing to transform the full spectrum of enterprise workloads, from visual computing to agentic a...

19/10/2025

Sins of Kujo' Comes to Life in New Live-Action Series Set for Spring 2026

Back to All News Sins of Kujo' Comes to Life in New Live-Action Series Set for Spring 2026 Entertainment 19 October 2025 GlobalJapan Link copied to cl...

18/10/2025

NESN Taps Harmonic for Primary Live Sports Distribution

New England Sports Network (NESN) has chosen Harmonic, working with Astound Business Solutions, as its enterprise technology partner to transform primary distri...

18/10/2025

DirecTV Launches Gray's Gulf Coast Sports & Entertainment Network

NEW ORLEANS, La. In the run-up to the start of the NBA season, WVUE-TV and Gray Local Media have announced a deal with DirecTV that will greatly expand access t...

18/10/2025

Berklee Celebrates 40 Years of the Fall Together Concert

Berklee Celebrates 40 Years of the Fall Together Concert Faculty composers Bob Pilkington and Greg Hopkins are among the featured artists for this year's ...

17/10/2025

NEP Group Receives New Equity Investment From 26North Partners LP, Co-Investors

NEP Group Receives New Equity Investment From 26North Partners LP, Co-InvestorsCarlyle remains the largest shareholder as the company prepares for the futureBy ...

17/10/2025

Apple Lands Five-Year Deal for F1 Distribution in the U.S.

Apple Lands Five-Year Deal for F1 Distribution in the U.S.Besides airing on Apple TV, the sport will be amplified on other Apple servicesBy Ken Kerschbaumer, Ed...

17/10/2025

SVG Sit-Down: Marshall Electronics' Bernie Keach on the Future of PTZ Cameras

SVG Sit-Down: Marshall Electronics' Bernie Keach on the Future of PTZ Camera...

17/10/2025

L2 Productions' REMI Facility in Austin Can Produce Content From Anywhere

L2 Productions' REMI Facility in Austin Can Produce Content From AnywhereMusic festivals, sports events are produced via flypacks and remote control roomsBy...

17/10/2025

Give Me the Backstory: Get to Know Sarah Dowland, the Filmmaker Behind Sue Bird: In The Clutch

By Lucy Spicer One of the most exciting things about the Sundance Film Festival...

17/10/2025

Cooper Raiff Returns to the Sundance Film Festival With His Independent Series Hal & Harper

(L-R) Christopher Meyer, Addison Timlin, Cooper Raiff, Lili Reinhart, Alyah Chan...

17/10/2025

Ferramenta de arte da capa de playlists do Spotify chega ao Brasil com uma noite de autoexpresso

M sica e arte se uniram em uma noite especial na semana passada na ZIV Gallery, ...

17/10/2025

Spotify's Custom Playlist Cover Art Tool Arrives in Brazil With a Night of Self-Expression

Music and art came together for one special night last week at ZIV Gallery, an i...

17/10/2025

Spotify and FC Barcelona Extend Partnership Through 2030

Spotify and FC Barcelona are extending our partnership through 2030, continuing a collaboration that's redefining how fans, players, and artists connect. Th...

17/10/2025

Sports Fishing Championship Deploys DigitalGlue Storage Platform

MURRIETA, Calif. The Sports Fishing Championship (SFC) has deployed DigitalGlue's creative.space storage platform to streamline video production by centrali...

17/10/2025

TV Ad Impressions for Football Spiked in Q3

BELLEVUE, Wash. Football continued to cement its reputation as a bulwark of TV advertising in Q3 2025 with new data from iSpot that showed both the NFL and coll...

17/10/2025

Reeling in the Chaos Sports Fishing Championship Simplifi...

The Sports Fishing Championship (SFC), the premier competitive saltwater fishing series, has transformed its production workflow by adopting creative.space, the...

17/10/2025

QuickLink Unveils StudioPro Version 4 With Major Enhancem...

QuickLink, a leading provider of award-winning multi-camera video productions and remote contribution solutions, announces the release of StudioPro Version 4, ...

17/10/2025

Westcoast Pixel dazzles with dynamic 3D video projections

Although the annual Grammy Awards celebration is best known for recognizing achievements in the recording industry, the show often proves a visual spectacle as ...

17/10/2025

Alex Dunfey Promoted to CTO at OpenDrives

OpenDrives, Inc., a leading provider of software-defined data storage and data services, has promoted Alex Dunfey to Chief Technology Officer (CTO) from his for...

17/10/2025

University of Arizona Scales Up Broadcast Capabilities Wi...

The University of Arizona (UofA) has significantly upgraded its broadcast communication infrastructure with the integration of Riedel Communications' advanc...

17/10/2025

NESN Redefines Regional Sports Video Delivery with Harmon...

Harmonic (NASDAQ: HLIT) today announced that New England Sports Network (NESN), owned by Fenway Sports Group and Delaware North, has selected Harmonic as its en...