Sony Pixel Power calrec Sony

Ted Harrington on Security in the Industry

20/06/2017

by Debra Kaufman

Security has become an area of great concern in the media and entertainment industry, since the Sony hack in 2014. This year, TheDarkOverlord hacked Larson Studio and released most of the fifth season of Orange Is the New Black, and later hacked ABC's Good Morning America Twitter accounts. How worried should you be? And what can you do to protect your company? HPA spoke with security expert Ted Harrington, executive partner at Independent Security Evaluators to find out.

Awareness about security is indeed increasing. It is important to note, however, that the threats to M&E aren't necessarily increasing, but rather awareness about those threats. These challenges have existed all along. The Sony breach was a catalyzing event that heightened the urgency for organizations to approach security proactively rather than reactively.

Security is a business problem, not just an IT problem, and executives are starting to recognize it as such. Every major attacker category is interested in stealing content assets, and all for different reasons, which makes it an immensely difficult position for defenders to handle. That was actually a primary motivator for Independent Security Evaluators when we committed to working here years ago, because we love solving complex problems.

One of the most crucial cybersecurity areas is surrounding applications. Adoption of applications is very rapid, and is fundamentally changing the business of content creation and distribution. Applications also entail a vast collection of attack surfaces for adversaries to pursue.

Ransomware has gotten a lot of attention. According to Forbes, cybersecurity firm SonicWall reported about 3.8 million ransomware attacks in 2015, which skyrocketed to 638 million attacks in 2016. The best way to protect against ransomware criminals is proper offsite backup, and it's critical to note that many organizations don't set up backups at all. Or if they do, they do so improperly, and so the primary data and the backup data often get compromised in the same event.

Although some people still fear the putting content in the cloud, this fear is irrational. We find that most people fall into one of three categories: irrationally confident in the cloud, irrationally afraid of the cloud, or somewhere in between. We advocate that everyone should be in that third category. A healthy dose of skeptical paranoia combined with a reasoned approach to risk-taking is how executives should consider pretty much any business decision, including whether to adopt cloud services.

Content assets are more at risk in a cloud environment than in physical media, because the attack requirements are lower. However, it is worth noting that the only unhackable system is one that is disconnected and buried in concrete - and how usable is that system? All aspects of any business make tradeoffs, and there are ways to utilize cloud services that are effective in minimizing risk.

The primary risks of utilizing cloud services are the same risks as not using cloud services: exploitable design flaws, exploitable implementation flaws, improper configuration, broken trust models, and so on. Fundamentally, the only difference between cloud and on-premise is that someone else owns the hardware. The manner in which an organization must consider adversaries, architect systems, and protect assets are essentially the same whether or not they own the hardware. Cloud actually even offers some security upgrades: while the primary tradeoff of utilizing cloud services is that an organization entrusts the data to someone else's hardware, the benefit return is that the cloud service providers are constantly investing in hardware upgrades, have extreme physical security measures in place, and have the latest and greatest of everything. A company that manages their own equipment on premise usually tends to not invest as heavily or as frequently in upgrades.

All studios require their technology vendors to undergo some sort of security testing prior to approval to access content, and most require the vendors to pay for it. In many cases, all organizations on both sides of that equation do not understand the assessment methodology that is required, and there is usually a drive towards cheap pricing rather than through assessment. But security is not overhead to be reduced, it is a business enabler to be invested in.

Bigger companies tend to be the more common targets, but smaller companies tend to be lesser able to defend themselves or afford adequate security measures. At the same time, smaller companies tend to be the engines of innovation, and the bigger companies (such as the studios) partner heavily with smaller companies (such as many of the technology vendors). Attackers know this. Malicious campaigns are often organized around what is known as a stepping stone attack, which is targeted at the smaller vendor companies that have lower defenses but the same access to the extreme valuable content assets. In the event of a compromise, both the small company and the big company thereby get hurt.

Steps companies should take right now to protect themselves are to understand and adhere to principles of secure design. I recently wrote a whitepaper on this topic, which you can read here. My advice is to invest in a proper security assessment, and avoid more cursory approaches like black box penetration testing, automated scaring, or reliance on compliance. Investigate your systems for weaknesses from the perspective of the adversary. Because, whether you do or do not approach your security weaknesses thoroughly, make no doubt about this: the adversaries will.
LINK: http://www.hollywoodprofessionalassociation.com/?p=155336...
See more stories from hpa

Most recent headlines

18/12/2025

Montreal's Bell Centre elevates fan experience with Argo S

Canada's largest indoor arena has transformed its live production capabilities with a full ST 2110 infrastructure and Calrec's compact Argo S console. S...

18/12/2025

The Gauge: Mexico November 2025

During November, streaming's share of TV viewing in Mexico settled at 24.2%, an increase of 0.5 share points from the previous month. Disclaimer: YUMI TV,...

18/12/2025

The Gauge: Poland | November 2025

November continued the upward trend in television viewership. The significantly colder weather and a rich programming lineup encouraged viewers to spend more ti...

18/12/2025

Gracenote helps TV platforms go beyond the game and deliver more connected, visually rich sports hub experiences

As viewers turn to sports highlights, recaps and documentary programming, expand...

18/12/2025

NAB Once Again Urges FCC to Eliminate Ownership Rules

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

Carr Stands Up for His Policies in Senate Hearing

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

The HELM and ARRI announce strategic partnership to redef...

The HELM, a global expert in cinematic live broadcast and high-end production workflows, has entered a strategic partnership with ARRI, the renowned designer an...

18/12/2025

Cadena Melodia Upgrades to DHD SX2 Audio Production Conso...

Cadena Melod a de Colombia (Cadena Melod a), a long-established Colombian radio network, has chosen DHD audio SX2 production consoles for integration into the m...

18/12/2025

Czech TV Elevates Video Streaming with Harmonic

Harmonic (NASDAQ: HLIT) today announced that Czech Television (Czech TV), the public broadcaster of the Czech Republic, has teamed up with Harmonic to modernize...

18/12/2025

Broadcast Solutions Group acquires PMT Professional Motio...

Broadcast Solutions Group, a leading system integrator and provider of innovative solutions for the broadcast and media industry, has announced the acquisition ...

18/12/2025

Keepit named a Leader in IDC MarketScape for Worldwide Sa...

Keepit, the SaaS data protection company, announced today that it has been named a Leader in the IDC MarketScape: Worldwide SaaS Data Protection 2025-2026 Vendo...

18/12/2025

Limecraft 2025 Version 8 adds User Controlled Notificatio...

Limecraft today announced the release of Limecraft 2025.8, the eighth and final major platform update of the year. This release strengthens daily workflows acro...

18/12/2025

creativespace Expands Footprint in the House of Worship M...

DigitalGlue is very grateful, especially at this time of the year, that its creative.space platform has expanded its footprint within the House of Worship marke...

18/12/2025

TAG Video Systems Celebrates Multiple APAC Award Wins for...

TAG Video Systems is proud to share that the company has recently received multiple industry recognitions across the Asia-Pacific region, reflecting its ongoing...

18/12/2025

NDI and Zoom team up to bring seamless connectivity to me...

NDI, the leading video connectivity standard for AV-over-IP, and Zoom, the AI-first collaboration platform, announce a strategic collaboration to integrate the ...

18/12/2025

YES and Synamedia extended deal backs Partner TV launch

Leading video software provider, Synamedia, today announced that it is extending its long-standing relationship with YES, the pay-TV subsidiary of the largest I...

18/12/2025

Riedel Builds Global Communication and Commentary Network...

Riedel Communications today announced it provided a fully integrated communications and commentary solution for the 15th National Games of China, supporting 56 ...

18/12/2025

Clear-Com Arcadia Central Station Links Toledo Walleye an...

When both the Toledo Walleye and Toledo Mud Hens play at home on the same night, communication between their respective production teams is essential. To stream...

18/12/2025

TMT Insights Focus Platform Recognized with TV Tech Best...

TMT Insights' new upstream media supply chain platform, Focus, was selected as a winner in the 2025 Media & Entertainment: Best in Market Awards in the TV T...

18/12/2025

Clear-Com Named Official Intercom Partner for NAMMs 125th...

Clear-Com is proud to announce its continued role as the official intercom supplier for the Yamaha Grand Plaza Stage at The 2026 NAMM Show, taking place Januar...

18/12/2025

CES: NBCU Unveils New Cross-Platform Ad Tech Solutions, Capabilities

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

2026 NAB Show Opens Registration, Unveils Major Program Enhancements

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

YouTube Wins Global Rights to Stream the Oscars

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

18/12/2025

PGA TOUR Studios Teams up with SES for Hybrid Content Distribution

Long-term agreement includes the SES SCORE platform and hybrid distribution worldwide to deliver more than 5,000 hours of golf tournaments annually featuring th...

18/12/2025

Teaser for Can This Love Be Translated' Previews a Heartwarming Romance To Open 2026

Back to All News Teaser for Can This Love Be Translated' Previews a Heartw...

18/12/2025

2025-11-18

Using the additive process of 3D printing, layer after layer gets printed until an object is as close to the final shape needed as possible. Historically, machi...

18/12/2025

RT Supporting the Arts 2025 Review | January 2026 Events

In 2025, RT proudly supported 185 arts and cultural events across the island of Ireland, reflecting significant growth since the scheme was re-launched in 2014...

18/12/2025

The RT Sport Young Sportsperson of the Year Nominees 2025 Revealed

RT Sports Awards 2025 live on RT One and RT Player at 8:05pm on Saturday 20 December On Saturday 20 December live on RT One and RT Player at the earlier t...

18/12/2025

RT lyric fm celebrates the Winter Solstice with a special Ambient Orbit live broadcast

RT lyric fm presents a very special Winter Solstice edition of Ambient Orbit, l...

18/12/2025

Now Generally Available, NVIDIA RTX PRO 5000 72GB Blackwell GPU Expands Memory Options for Desktop Agentic AI

Top-notch options for AI at the desktops of developers, engineers and designers ...

18/12/2025

Celebrating 100 Years of Public Broadcasting in Ireland in 2026

At 7.45pm on 1st January 1926, the precursor to RT , then 2RN, delivered the fledgling new Irish state's first public radio transmission. From those first c...

18/12/2025

Deck the Vaults: Fallout: New Vegas' Joins the Cloud This Holiday Season

Step out of the vault and into the future of gaming with Fallout: New Vegas streaming on GeForce NOW, just in time to celebrate the newest season of the hit Ama...

18/12/2025

The Movie Experience SLO Becomes First U.S. Exhibitor to Adopt Dolby Vision+Atmos Theatrical Solution

December 18 2025, 05:30 (PST) The Movie Experience SLO Becomes First U.S. Exhib...

17/12/2025

The EU Investigative Journalism Award 2025: bold reporting, regional impact, and rise in public-interest journalism

Investigative journalists across the Western Balkans and T rkiye continue to con...

17/12/2025

Sports Broadcasting Hall of Fame Inducts 10 Industry Icons During Unforgettable Night

Sports Broadcasting Hall of Fame Inducts 10 Industry Icons During Unforgettable ...

17/12/2025

ESPN to Debut MNF Playbook with Next Gen Stats, a New AI-Driven NFL Data-AltCast

ESPN to Debut MNF Playbook with Next Gen Stats, a New AI-Driven NFL Data-AltCastThe series, powered by Adrenaline TruPlay AI, launches Dec. 22 and runs through ...

17/12/2025

Inaugural Optum Golf Channel Games Debut Under the Lights' in Primetime on Golf Channel and USA Network

Inaugural Optum Golf Channel Games Debut Under the Lights' in Primetime on ...

17/12/2025

Ring In the New Year With New Playlists Mixed by Artists, and More Spotify Hacks

The right playlist is essential on New Year's Eve, building the energy as you get ready and keeping it high as you count down to midnight. This year, Spotif...

17/12/2025

Clear-Com's Arcadia Central Station Links Toledo Walleye and Mud Hens Venues with...

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...

17/12/2025

Broadcast and Streaming Serve Up a Historic Month of TV in Nielsen's The Gauge

Audiences Watched Over 103 Billion Minutes of TV on Thanksgiving Day NFL Games ...

17/12/2025

EdgeBeam Wireless Makes Initial Sale, Expands Executive Team

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Warner Bros. Discovery Tells Shareholders to Reject Paramount Bid

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

NDI, Zoom Collaborate on Seamless Connectivity

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Broadcasters Mark Momentous Year of Challenges Amid Viewing Fragmentation

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Tennessee Public Broadcaster to Trial AI Metadata

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Chyron Unveils New AXIS Maps

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Broadcast Solutions Group Acquires PMT Professional Motion Technology

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Study: U.S. Pay TV, Video Revenue to Total $190.7B in 2030

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

Texas Attorney General Takes Aim at 5 TV Manufacturers

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

17/12/2025

DirecTV Wins Appeal in Retransmission Price-Fixing Suit

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...