Cyber security for high profile conferences
Managing the cyber security of high profile events in the real and virtual worlds.

Introduction
This guidance expands on existing NCSC Cyber security advice for Major Events, which should be read first, and covers fundamentals including governance, risk assessment, incident management, testing and exercising.
Here, we will focus on cyber risk analysis, the selection of suppliers and the assurance process. The advice is intended to cover both physical and virtual aspects of high-profile conferences, which are special because they can be an obvious target for potential attackers and any incidents can have a much bigger reputational impact.
Conferences are often held in public and their content is only occasionally of a sensitive nature. As a result, these events sometimes receive less attention from a cyber security point of view, than they should.
This potential for overlook is risky because, if a high profile event were compromised, the resulting disruption and reputational damage could be very serious.
If you have recognised the importance of cyber security for conferences, your next step is to understand cyber risks which your event faces. We look at how to do this in the next section.
Armed with a clear idea of the threats you face, you can consider how to manage those risks, bringing in security expertise where and when it's needed. Mitigations and their assessment will be the focus of subsequent sections.
Key risk considerations
Understand your cyber risks
The topics covered by a conference and the profile of the attendees will influence the level of threat which the event faces. This in turn will determine the kind of protection that's needed. So, an important first step should be to consider the circumstances of your specific conference and potential threat actors.
The NCSC website is one source of current threat information. There are also sector-specific guides, including those for small businesses, charities and board members.
Some key aspects of event security are considered next.
Disruption by uninvited or misbehaving guests
There have been many publicised examples of video conferences being disrupted. To address this risk, you will need effective identity checks.
Strong authentication (for example, requiring multi-factor authentication) is recommended, especially for presenters. Failing that, the meeting organiser should share passwords securely with participants only.
Organisers should also verify the identity of all participants ahead of time and check these credentials before allowing participants held in a virtual lobby, to join the conference.
Participants that are not successfully identified should be removed, if necessary. More advice is included in Video conferencing services: security guidance for organisations.
Moderation needs to be in place during the event. A time delay (‘profanity delay’) should be used for live streams, where appropriate.
Denial of service attacks
Follow NCSC Denial of Service guidance and ensure that services are designed to be resilient and scalable. You should ask your internet service providers to put upstream mitigations in place as well.
Where possible, avoid sharing network bandwidth and server capacity between obvious targets for denial of service attack. For example, don't mix websites with other essential functions, such as management networks. Provide further, reserved bandwidth, for essential services such as livestreaming of the event.
Remember to consider any separate but related functions such as those for registration.
Insider threat
The management of the event and of underlying IT infrastructure is key to security, so you should use trusted personnel and suppliers. Their actions should be logged, to ensure accountability. This is relevant to the staff that manage the conference, as well as suppliers that manage any underlying systems.
Compromised supplier or administrator account
It is equally important to gain assurance in the IT which your system, or conference, administrators used to carry out their role.
These should be corporate devices, managed from trusted environments. Ideally, they should also be configured using NCSC Mobile Device guidance.
Defacement of websites/portals
Websites are an obvious target for those looking to discredit or embarrass conference organisers. So, you should ensure that any websites are designed, developed and operated securely.
The OWASP foundation is one source of guidance on common vulnerabilities, secure web application development and testing. The steps described below under 'gaining assurance' should also be followed.
Sensitive data
This may be less of an issue for some events but if attendees (virtual or otherwise) provide personal information as part of the registration process, this can create a source of bulk data that is an attractive target to cyber criminals or other actors. This is particularly true where the data concentrates information relating to people from a particular role or sector.
If you cannot avoid collecting data, then NCSC guidance on protecting bulk data should be followed and any designs for new solutions should consider the NCSC secure design principles.
Some conferences can also include closed sessions or private chat. Even if these are not particularly sensitive, the reputational impact of compromise could be significant, so this aspect should be considered carefully when gaining assurance in the supplier.
On-site risks
The risk of disruption at a conference venue also needs to be considered.
Provision of Wi-Fi and internet access for attendees could be targeted, as could any network connected devices relating to building management and security (discussed further below).
The venue itself may also have a separate website, which could become a target.

Gaining assurance
It's important to gain confidence that the security of your solution is appropriate for the risks you have identified. Your assessment of this should involve evidence provided by those delivering the service and/or evidence gathered independently.
The NCSC has guidance on choosing a video conferencing platform. Beyond simple video conferencing, larger conferences, may have additional requirements for registration, virtual meeting rooms and other special features.
Cloud security principles
For all of these cases, the NCSC Cloud security principles can be used as a guide to cover the fundamental security requirements. Potential suppliers should be encouraged to provide a description of how they address each of these, if they have not already done so.
The 14 principles cover security throughout the lifecycle of the service and include physical and personnel security (CPNI should be consulted for further advice on those aspects, if required). The risk scenarios described above can be used to help focus the assessment using the principles.
Independent assurance
Management environments and the end-user devices used by administrators should be considered as well as core infrastructure. Independent assurance (for example, through Cyber Essentials, ISO27001 and other standards) can give some level of confidence.
Independent suppliers
For smaller or specialist providers, it is reasonable to expect a greater level of detail to be made available, in terms of their internal architecture and processes. It is also important to understand how the provider is using any third parties and the security arrangements they have in place for them.
Secure design principles
Suppliers should be able to demonstrate that they are protecting exposed interfaces using an architecture with strength-in-depth and, for example, are using Web Application Firewalls to protect against common web-based vulnerabilities. Protective monitoring should be in place and security should be accounted for throughout the software development lifecycle (including the management of vulnerabilities in any software dependencies). Again, the NCSC Secure design principles should be consulted for more in-depth advice.
Penetration testing
Independent pen tests and audits should be carried out where possible. Specialised, web-application pen tests should be included where appropriate and the NCSC IT Health CHECK scheme is recommended.
For very high-profile events, it may be possible to arrange for NCSC Active Cyber Defence services to be provided before and during the conference, which could be useful in highlighting vulnerabilities or detecting threat activity against a supplier.

Venue-related issues
Where there is a physical venue for the conference, there are other aspects to consider. These include the provision of internet access for delegates and other visitors, as well as the protection of any smart or network-based functionality in the venue itself. A cyber attack against any of these could be disruptive and potentially cause a significant impact.
Internet access
Internet access is likely to be required for delegates and the press attending conference venues.
From a functional and reputational point of view, a network with a resilient architecture, using redundant routers and firewalls would be a good choice. The infrastructure should be upgraded/patched against any known vulnerabilities and the configuration audited and tested where possible.
Network monitoring and active management is recommended, to detect and counter any malicious activity or problems caused by misconfigured guest devices.
Network traffic from different sets of users (such as media, event staff and delegates) should be segmented. Delegates should treat the network as they would any other untrusted internet connection.
Upstream denial of service mitigation is recommended and an acceptable level of protection should be negotiated with the Internet Service Provider. Bandwidth for guest internet access should be reserved separately from that used for obvious denial of service targets, such as websites linked to the event.
You should have a back-up plan in case of problems with Wi-Fi. For example, wired connections should be made available on a priority basis, for appropriate users.
On-site networks
The venue should be assessed to determine whether there are any networked systems for building management, such as heating, ventilation, air-conditioning, lighting, fire or security alarms.
If these are present then the potential for them to be accessed remotely needs to be considered, as they could be misused to cause disruption. Steps to reduce this risk may need to be considered.
A combination of physical and personnel security around such devices is also recommended to ensure that they are not tampered with.
Third parties
The security and resilience of third-party services may also need to be considered by event organisers. For example, those relating to guest transport or security staff. These will need an appropriate level of security and back-up plans in place. Specialist advice should be sought, as necessary.
Event cyber security checklist
You should read the guidance first and understand it, but this list may be useful so you don’t forget anything.
-
Engage internal security teams as early as possible
For very high-profile events, contact the NCSC, who may be able to offer bespoke advice and support.
-
Consult Cyber Security for Major Events
It gives general guidance on governance, risk assessment, incident management planning and exercising.
-
For your event, identify any specific threats
Assess any resultant risks, including the scenarios outlined in this guidance.
-
Consider the top-level security requirements
covered in this guidance, before approaching potential suppliers.
-
Understand how and where services will be hosted
and the architecture of any solutions offered.
-
Assess suppliers against
the NCSC Cloud security principles and use VTC guidance and Denial of Service guidance as appropriate.
-
For smaller suppliers, or those providing specialised services
seek greater insight into their internal design and operation. Seek independent assurance, which should include a pre-event penetration test.
-
Determine whether any NCSC Active Cyber Defence or threat monitoring offerings might be available
to help protect the service and associated management environment(s).
-
Assess the risk to IT infrastructure at the venue itself
including any provision of guest internet access, and any networked building management and security. Ensure these systems are configured appropriately, patched and updated, tested and resilient to denial of service attacks.
-
Create an incident management plan and test it if possible
For major events, contact the NCSC beforehand, to set up points of contact.


