Share

cover art for Episode 39: Paul Konikowski on Investing in Cybersecurity & Culture

Integrating Technology

Episode 39: Paul Konikowski on Investing in Cybersecurity & Culture

Ep. 39
Highlights From This Episode…

Bring up security early in the process. IT is often treated as an afterthought in AV.

Assess the impact of each device being comprised. 

Consider access for each device. Who? How? Why? Least resource or least route?

Consider if network connectivity is really needed for each device.

Perform role-playing to get better perspective of what a malicious actor could do.

Assess if users can accidentally cause a security breach, such as plugging in unkown USB sticks.

VLAN headers can be spoofed and should not be considered a security mechanism.

Close unused ports on all devices.

Enable device logging and monitor the logs for suspicious activity.

Consider messaging direction per device and disable a device’s ability to send or receive messages if not needed.

Being able to demonstrate internal security practices may reduce liability should an incident arise. *This is not legal advice 🙂

Create a culture of security awareness in your organisation through policies, training and compliance testing.

Perform internal and possibly public code reviews. 

Track data check-in and check-outs.




Mentioned In This Episode…

Harvard Online Course: Cybersecurity: Managing Risk In The Information Age

Zoom 

More episodes

View all episodes

  • 50. Episode 50: Fred Loucks Part 2 Microservices & The End Of AV Control

    43:22
    Patrick Murray interviews Fred Loucks about...How management will replace control in AV integration...How hardware manufacturers can modernize their business by moving to a subscription model and why they should...How to make the software delivery process as simple as installing hardware.
  • 49. Episode 49 Fred Loucks On AV Monitoring & Programming Your Way Through Problems

    34:40
    Fred Loucks, CTO of Level 3 Audiovisual, takes us on his white-whale journey to answer one question: How do you get visibility of audiovisual systems at scale?We learn some cool new phrases like "Automated remediation" and "Signatures of common issues" while digging deep into...Program Management from designing, deploying and updating with a focus on administration.How programming let him rollout 3000 Zoom Rooms in two weekends with a one-man team.The real costs of downtime and disruptions including productivity loss, embarrassment and loss of confidence.How collecting data adds value by answering questions - it starts with monitoring.Why there is resistance to AV monitoring tools.Wrangling the chaos of API's and protocols to create a data model.Why to avoid devices that are not observable.A day in the life of a support NOC technician.Defining a service status for AV systems in order to present an SLA.Why monitoring is incomplete without remote access, documentation and domain knowledge.The challenges of creating an AV NOC including deep integration with customer networks and staffing. Thinking about management instead of control. 
  • 48. Episode 48: AJ Thompson On Cloud Driven Solutions, Scaling and Open Source Control

    32:40
    AJ Thompson is Vice President of Cloud Driven Solutions and provides a range of services including SaaS platforms, Consulting, and App DevelopmentInterview HighlightsAJ was previously on the podcast in Episode 35Cloud Driven Solutions offers a meeting and agenda management application that integrates with AV systemsScaling was the biggest challenge when going to marketExpects an open source AV control system is inevitableMentioned In This EpisodeAMX, Crestron, QSys, BrightSign
  • 47. Episode 47: Wes Hatchett on Implementing Software-Based Control Systems

    39:14
    Wes Hatchett is CEO of ControlEnvy. ControlEnvy is an open-source software based control system.Wes and the ControlEnvy team were one of the first podcast interviews in Epsiode 6. Interview HighlightsCan run on Android.Has a setup configuration interface that includes troubleshooting and debug tools.Chose to focus on Android because it continues to outpace even laptops in processing power.Sample application: Google Pixel 4a installed in a rack connected via WiFi.A Mac Mini can also be used when a hard-wired appliance is required.The system is driven by states stored in a local data store.Paths are used to access components in the data store through logic macros.Shifting from completely custom programming projects to a product based model allows for better update management. Old systems benefit from feature updates instead of standing still.Mentioned In This EpisodeLutron, Sonos, Biamp, Google Pixel 4a, Apple Mac Mini
  • 46. Episode 46: Stephen Von Takach on Integrating Workplace Experiences, Gamification, Data-Driven Features and Open Source Software

    32:42
    Stephen Von TakachCIO at PlaceOSplaceos.comPlaceOS ties together drivers into systems by running functions on a scalable cluster of computing resources. Similar to how AWS Lambda works.Constraints allow creativity to blossom.Drivers can exist in multiple systems. Logic is system specific.Built on Crystal-lang, similar to ruby, but type-checked. https://crystal-lang.orgPlaceOS started in AV integration but, because they can integrate with anything, it has evolved to focus on workplace experiences. Streamlining your day, from when a persons enters a building until they leave.User actions generate data that give insight into utilization and enable features like contact tracing and gamification."Once you are integrated into every system, the experiences are only limited by your imagination."Digital twin - modelling real world systems in the digital realm.Mitigating risk through partnering with IT.Most stake-holder resistance concerns network security, GDPR conformance and data ownership.Conference room automation is evolving to eliminate the need for a touchpanel control interface.Open source removes vendor dependency and helps educate. It also helps create a cooperative driver development ecosystem.Clients are looking for a wholistic solution. A single workplace app (as opposed to multiple apps with separate functionality) drives usage and discovery of what the workplace is capable of.Gamification can be used to drive a behaviour, like using spaces in off-peak hours, by offering an incentive, like free coffee and gift cards.Mentioned in this episode:AMX, Cisco, Microsoft Teams, Project Connected Home over IP, Google, Apple, Zigbee, 
  • 45. Episode 45: Joe Way On Simplifying Everything with Software & Customer-Centric Design

    35:21
    USC tasked Joe Way, Director of Learning Environments, to create the single best IT Department in all of academia. Joe tells about what it was like to achieve that vision.
  • 44. Episode 44: Anton Karsten On Choosing Web Technologies For AV/IT

    35:54
    Anton Karsten helps me understand:How web browsers workSome history of HTML and browsersThe problem with frameworksChoosing frameworksSingle Page Apps vs Server-Driven ArchitectureUsing Javascript for AV Control and AutomationAdvantages of TypescriptOrganizing Project TeamsDealing With Different DevicesHow Large Companies Set User Experience StandardsHTML, CSS, Javascript, Angular, Vue, React, PHP, Saas, Webpack
  • 43. Episode 43: Steve Greenblatt On How Tech Managers Are Creating Change

    30:22
    A conversation with Steve Greenblatt of Control Concepts about:Why I stopped podcastingFocusing on complex systemsThe effect of software tools on AV projectsWhat developers need to succeedHow tech managers are forcing change
  • 42. Episode 42: Chris Neto On Personal Branding & Being Mistaken For A Twitter Bot

    47:12
    Highlights From This Episode…A great way to learn AV is to start on the end user/technology owner side.High Speed Internet at home was the spark for growth in AV.Keep a portfolio of your work and recommendations to present at job interviews.Study personal branding to improve your social media effectiveness.Social media is about building relationships by sharing information. Mentioned In This Episode…AltcommNew York Giants William Paterson UniversityPicturetelPolycomRCM Technologies StaffingSchering Plough PharmaceuticalsMerckNovartisBarcoStarinTwitterJoel Colm Twitter bookAV Help DeskPaul Konikowski Contact ChrisTwitterInstagramRebels & Flux LinkedIn