Collaboration platforms have played a vital role in keeping businesses connected and operational over the past 18 months but that’s not to say they’ve come without risk.
Workflows and business communication changed as people across the world were confined to their homes, creating challenges from a security and privacy perspective.
From sending inappropriate files over chat, to inviting too many people into meetings, businesses have been exposed to multiple new threats – according to RingCentral’s Chief Information Security Officer, Heather Hinton.
“It increased the risk posture in many companies from a host of different points of view,” she told UC Today. “People weren’t experienced in how to work from home.”
“They would let anyone in and say things on video or in chat that should have been limited to a much smaller group. or they’d let people into meetings that maybe shouldn’t have been, or they exhausted themselves by attending too many meetings.
“From a security point of view, this has greatly increased the potential for insider threat.”
This insider threat is, of course, not necessarily intentional. However, many employees are suffering from meeting fatigue because of how reliant businesses have become on virtual meeting platforms.
Video meetings at work have become, for many, one of the few chances they have to interact with other people beyond chat. This has in turn led to a culture of inviting too many people into meetings, Hinton said, because no-one wants to be left out.
But she added that many businesses have opened their eyes now the initial rush towards remote working has ended – nudged along, in part, by high-profile cybersecurity incidents such as the SolarWinds hack.
“Initially no one was paying attention to it; they just had to continue communicating,” Hinton added.
“But then there were a couple of high-profile incidents in the news that served as wake-up calls. People said, ‘hang on a second, this is something I need to pay attention to’, and now they absolutely are.”
One of the key aspects of security that businesses are turning to is encryption within communication and collaboration, Hinton said.
RingCentral recently launched end-to-end encryption for ad-hoc and scheduled meetings, with users given the option to turn the extra layer of security on or off. The programme is currently in open beta and is expected to hit general availability in October 2021, with dynamic (in-meeting, on-demand) end-to-end encryption expected by year end.
“We, as the vendors, have upped our game as well,” Hinton said.
“From my point of view, it lessens the burden on RingCentral because we don’t have access to the customer’s meetings and conversations.
“I can tell people how E2E encryption works and show them the protocol, and then the conversations about RingCentral’s access to customer content do become less important – because we never have access to that data.”
There are, however, some drawbacks to user experience that come with E2E encryption. Some features that are usually readily available, such as transcription, can no longer be used.
This has to be taken into account when deciding if E2E encryption is the most effective method of protection in all situations, although RingCentral is planning to lessen this impact over time.
“We don’t have access to the communication content when E2E encryption is turned on which means that customers don’t get the fully enriched experience,” Hinton said.




