In 2023, the nexus of technology, collaboration, and compliance has never been more critical. As organizations harness the power of UC and collaboration tools to connect globally — especially across hybrid and distributed workforces — the need to fortify security measures and maintain regulatory compliance intensifies.
New opportunities and challenges emerge on an almost daily basis in this space, from bad actors that range from malevolent individuals to malicious nation-states, to how AI can potentially revolutionise how businesses manage their security and compliance needs.
With our latest Round Table subject, “Security & Compliance", we spoke with experts and executives from Allendeveaux, Theta Lake, and Cisco about the major challenges threatening cybersecurity in 2023, how organisations can ensure security around data storage and transmission, how to enable seamless collaboration while maintaining compliance, and how will AI impact cybersecurity moving forward.
What are the major challenges and bad actors threatening the cybersecurity of organizations in 2023?
[caption id="attachment_60028" align="alignright" width="212"]
Javed Khan[/caption]
Javed Khan, Senior Vice President and General Manager at Cisco Collaboration
Khan said that as technologies like AI are integrated into UCC tools, the cybersecurity landscape evolves in response to how these technologies may surface new security threats, including advanced scams and convincing deep fakes.
"There is an enormous opportunity to leverage emerging technologies to enhance hybrid collaboration experiences," Khan elaborated. "Yet, at the same time, organizations must explore ways to safely and intelligently integrate these technologies to mitigate potential harm."
To introduce or preserve a healthy cybersecurity culture through continuous and rapid technological change, Khan suggested that organizations could begin by investing in essential foundations for effective security. Such examples include a hybrid cloud strategy, a zero-trust approach, and a modern network.
"Updating and maintaining network infrastructure is fundamental and should not be ignored," Khan added. "In addition, having honest conversations with employees across all levels is critical to providing education on navigating and identifying potential new concerns and hazards as technologies mature and become more integrated into UCC platforms."
Dr. Scott Allendevaux, Practice Lead of Law and Policy at Allendevaux
For Dr Allendevaux, the evolving threat landscape and sophisticated bad actors present multifarious cybersecurity challenges for organisations, including ransomware attacks. "Ransomware attacks remain predominant, with attackers targeting critical infrastructure and demanding hefty ransoms," Allendevaux explained.
Meanwhile, Allendevaux highlighted that craftier phishing schemes and social engineering tactics exploit human vulnerabilities, resulting in unauthorized access and data breaches. Attackers are also increasingly targeting supply chains, Allendevaux said, exploiting vulnerabilities to compromise interconnected systems. Lastly, Allendevaux underlined that malicious or negligent insiders pose significant risks, producing potential data leaks or system compromises.
Among the bad actors threatening cybersecurity are nation-state actors, who engage "in cyber-espionage or cyber-warfare, they aim to steal sensitive data or disrupt services", explained Allendevaux.
Other bad actors include hacktivist groups who are "driven by ideological motives," Allendevaux detailed. "These actors engage in attacks to promote their agendas, potentially causing organizational harm." Organised crime-based cybercriminals engage in illicit activities, including data theft and ransomware attacks, for financial gain.
Lastly, amateur hackers, often named "script kiddies," explore "vulnerabilities and launch attacks, often without a specific agenda but causing potential disruptions", Allendevaux said.
In the era of remote and cloud-based work, what measures should organizations take to ensure the security of their unified communications and collaboration tools, especially around data transmission and storage?
[caption id="attachment_60029" align="alignleft" width="203"]
Dr Scott Allendevaux[/caption]
Dr Scott Allendevaux, Practice Lead of Law and Policy at Allendevaux
For Dr Allendevaux, organizations should prioritize multi-faceted security strategies written into a data protection program to safeguard UCC tools, particularly focusing on data transmission and storage.
"Firstly, robust encryption should be enforced for data-in-transit and data-at-rest, ensuring confidential information remains secure from unauthorized access," Allendevaux said. "Leveraging advanced encryption standards such as AES-256 can substantially bolster data security."
Furthermore, Allendevaux added, organizations should comply with recognized cybersecurity frameworks, including NIST and international data protection standards such as ISO 27001, ISO 27017, ISO 27018 and ISO 27701. This stresses a systematic approach to managing sensitive company information, such as personal data, Allendevaux said.
"Implementing comprehensive access control mechanisms is equally vital, allowing only authorized personnel to access sensitive communication and collaboration tools, thereby minimizing weaknesses," Allendevaux continued.
"Regularly conducting risk assessments, vulnerability assessments, and penetration testing (VAPT) can help in identifying and mitigating potential risks proactively. Furthermore, adopting a zero-trust security model, which necessitates strict identity verification for every user and device accessing the UC&C tools, can significantly enhance organizational cybersecurity posture."
Allendevaux expanded by suggesting that by amalgamating these security practices into a data protection program, organizations can build resilient and layered defence mechanisms, "ensuring that their unified communications and collaboration tools remain secure, reliable, and resistant to evolving cybersecurity threats".
Garth Landers, Director of Global Product Marketing at Theta Lake
For Landers, it's crucial that user actions, both negligence and malfeasance, are addressed and accounted for.
"Policies and guidance about usage related to approved tools/platforms and security, such as the use of VPNs, should be outlined, updated and enforced in conjunction with awareness training," Landers expanded. "In conjunction, policy enforcement tools should be adopted for safeguarding, securing and recordkeeping of data."
Javed Khan, Senior Vice President and General Manager of Cisco Collaboration
Khan highlighted that, as the world continues to transition into the era of hybrid work, organizations need to equip themselves with advanced security protections that safeguard employees and assets. "Everything from databases, networks, and unified communications must be protected to ensure that security is not compromised to allow for flexibility," he said.
"'Zero trust' approaches are more important than ever to reduce the risk of breaches," Khan continued. "Attack surfaces have increased as more people work from home and outside the office, utilize managed and unmanaged devices, and collaborate across company lines. When embracing flexible hybrid work cultures, organizations can adopt a zero-trust approach that offers an additional layer of security to ensure the hybrid experience is secure at every endpoint."
Khan underlined that customers entrusted Webex with their mission-critical collaboration, meetings, messages, calling, and data for exactly this reason because Webex "provides extended security options, advanced privacy features, and built-in compliance options for industry and regional requirements so customers can meet and collaborate securely – regardless of where they choose to work".
How can organizations balance the need for seamless collaboration with the imperative to maintain compliance with various regulations and standards, such as GDPR or HIPAA?
[caption id="attachment_52528" align="alignright" width="206"]
Garth Landers[/caption]
Garth Landers, Director of Global Product Marketing at Theta Lake
Landers highlighted that AI in its version form of machine learning and natural language processing is a critical part of security and compliance platforms like Theta Lake.
"For example, we apply these technologies to identify potential risky behaviours and policy violations," Landers said. "This assists compliance personnel in filtering through the high volume of textual, video, voice and whiteboard communications that can seem overwhelming to compliance review teams."




