Most IT security teams have a detailed patch management process for servers and laptops. Most of those same teams have no patch process at all for the IP-connected cameras, microphones, and displays in their meeting rooms. That gap isn’t theoretical — it is the reason networked AV devices appear with increasing frequency in post-breach forensic reports as the initial point of entry or the lateral movement path.
AVIXA named cybersecurity the number one AV industry trend for 2026. ISE 2026 launched its first-ever dedicated Cybersecurity Summit in February. The industry has officially acknowledged what security teams at government agencies, healthcare systems, and defense contractors have been discovering the hard way for the past several years: AV infrastructure is now a serious security domain, and treating it otherwise creates measurable organizational risk.
Why AV Became the New Attack Surface
Networked AV devices share a common set of characteristics that make them attractive targets. They run embedded operating systems that receive infrequent firmware updates. They often ship with default administrative credentials that never get changed after installation. They sit outside most organizations’ formal patch management processes because they were procured and managed by facilities or AV teams rather than IT. And they connect directly to corporate network infrastructure — sometimes to the same VLAN as sensitive data systems.
A compromised meeting room camera is an insider listening device. A networked DSP with default credentials and an open management port becomes a lateral movement point into the broader network. A commercial display with web browsing capability — increasingly common in modern collaboration systems — becomes a potential phishing delivery mechanism if someone with physical access reaches the browser interface.
These aren’t hypothetical scenarios constructed to generate alarm. They are documented attack patterns that security researchers demonstrated publicly in 2024 and 2025, and that enterprise security teams are now actively working to close.
The Compliance Dimension Is Already Real
For organizations in regulated industries, AV cybersecurity is not a best practice question — it is a compliance requirement that auditors are beginning to examine explicitly.
Government agencies operating under FedRAMP or FISMA must account for all networked endpoints, including AV systems, in their system security plans. HIPAA’s technical safeguard requirements apply to any networked device capable of capturing, transmitting, or displaying protected health information — which includes cameras in patient-facing spaces and displays in clinical settings. FERPA creates similar obligations for educational institutions with networked AV in spaces where student records might appear on screen.
Defense contractors face the most immediate pressure. CMMC 2.0 compliance requires that all endpoints on networks that touch Controlled Unclassified Information meet specific configuration and access control standards. A conference room system on a network segment that touches CUI is a CMMC endpoint, and treating it otherwise puts certification at risk.
What Compliance Requires in Practice
The compliance requirements across these frameworks converge on a consistent set of technical controls: network segmentation isolating AV traffic, authentication requirements for administrative access, encryption for data in transit, and documented processes for firmware updates and configuration management. Organizations that implement these controls for their AV infrastructure are largely addressing multiple compliance frameworks simultaneously.
Manufacturer Security Features Worth Activating
The AV manufacturers that serve regulated industries have invested in security certifications and features that most of their customers have never turned on. This represents a straightforward opportunity: security capability already purchased and already sitting in your infrastructure, waiting to be configured.
- Shure: AES-256 encryption on IntelliMix and MXA series audio endpoints, with network authentication options on the conferencing DSP line
- Samsung: Knox security platform on commercial displays, providing certificate-based authentication, encrypted storage, and MDM integration
- Crestron: NIAP-certified and FIPS 140-2 compliant products available for government deployments; DM NVX AVoIP encoders and decoders meet requirements for classified environment AV
- Extron: Products on the DoDIN Approved Products List (APL) and JITC-certified for defense network use, with hardened firmware configurations available
- Logitech: TAA-compliant and NDAA Section 889-compliant devices for government procurement, ensuring supply chain integrity requirements are met
Most organizations using these manufacturers have never had a conversation about which security features are available, let alone which ones are activated. A configuration audit frequently reveals significant security capability sitting unused.
Zero-Trust Principles Applied to AV Networks
Zero-trust security architecture applies to AV networks the same way it applies to any other networked infrastructure. The implementation details differ, but the principles are identical: never trust by default, verify explicitly, limit access to the minimum required.
For AV infrastructure specifically, zero-trust implementation requires:
- 802.1X port authentication: Network switches require AV devices to authenticate before receiving a network connection — eliminating the risk of unauthorized devices plugging into AV infrastructure ports
- VLAN segmentation: AV management traffic, AV media traffic, and corporate data traffic operate on separate VLANs with explicit firewall rules governing what can communicate across boundaries
- IGMP snooping: Multicast traffic from AVoIP systems — cameras, audio distribution, display management — is controlled and contained rather than flooding network segments
- MACsec encryption: Where AV device firmware supports it, Layer 2 encryption on the physical network connection prevents traffic interception on the local network segment
The segmentation piece is the most impactful single change most organizations can make. A properly segmented AV VLAN limits the blast radius of a compromised device to the AV segment — a meaningful improvement over an unsegmented network where a compromised camera has a path to corporate data systems.
The Integrator Competence Gap
Most organizations work with a pure AV integrator — a company that designs and installs audio, video, and control systems, but whose team stops at the AV equipment itself. When a security requirement involves the network switch that the AV system connects to, or the firewall rules that govern AV management traffic, a pure AV integrator cannot help. They hand the problem to IT, IT hands it back, and the configuration gap persists.
This is where VIcom’s cross-domain capability creates a specific, measurable difference. VIcom holds DCJS license #11-6695 and SWAM certification, and the team that designs your conference room AV system is the same organization that can configure the 802.1X authentication on the network switch it connects to, define the VLAN segmentation policy, and write the firewall rules governing AV management traffic. That closes the handoff gap where most AV security vulnerabilities live.
VIcom has deployed secured AV infrastructure for the Newport News Police Department, City of Norfolk, and other government clients where AV security requirements are explicit and audited — not aspirational.
Your 10-Point AV Security Audit Checklist
Use this checklist to assess your current AV security posture. Each item represents a specific configuration state that can be verified without specialized tools.
- Default credentials: Confirm that every AV device — cameras, DSPs, control systems, display management systems — has had factory-default administrative credentials changed to organization-managed credentials
- Firmware currency: Pull current firmware versions on all AV devices and compare against manufacturer-published current versions; identify devices more than two major releases behind
- VLAN placement: Verify that AV devices are on dedicated VLANs separated from corporate data systems, guest networks, and employee workstations
- Firewall rules for AV management traffic: Confirm that administrative interfaces for AV devices are accessible only from authorized management workstations or networks, not from the open corporate LAN
- Encryption status: Document which AV devices support encryption in transit and confirm it is enabled; flag devices with no encryption support for priority refresh planning
- Physical port security: Verify that unused network ports on AV-connected switches have port security enabled or are administratively disabled
- Remote access method: Confirm that any remote access to AV systems uses authenticated VPN or zero-trust network access — not direct internet-facing management ports
- Recording storage security: Audit where meeting recordings are stored, who has access, and whether storage systems meet the same security standards as other organizational data repositories
- Certificate management: Verify that AV devices using TLS certificates for web management interfaces have valid, non-expired certificates with documented renewal processes
- Incident response plan inclusion: Confirm that AV infrastructure is explicitly named in your organization’s incident response plan, with defined procedures for AV device compromise scenarios
Most organizations complete this audit and find three to five items that require immediate remediation and several more that need a scheduled plan. That is a normal finding, not a failure — the value is in having the data rather than operating on assumptions.
Starting the Conversation
AV cybersecurity in 2026 is not a project you can deprioritize until next year’s security planning cycle. The combination of increasing regulatory scrutiny, documented attack patterns targeting AV infrastructure, and the ISE Cybersecurity Summit formalizing the industry’s acknowledgment of the problem means the clock has already started.
The practical starting point for most organizations is a structured AV security assessment: a systematic review of what networked AV devices exist, what their current configuration state is, and what gap exists between that state and your organization’s security requirements.
VIcom offers a complimentary AV security assessment for qualified organizations in Virginia. Our assessment covers device inventory, configuration review, network architecture, and a prioritized remediation roadmap — delivered by a team that can implement the technical controls, not just document the gaps. Let’s get started today!
