Your source for news on private equity, M&A, and real estate

“Zoom Bombing” Is Why Your Webinar Must Be Part of Your Cybersecurity Strategy

By

Victor M. Font Jr.

  |   June 28, 2026

  |   Categories:

zoom bombing

When most business leaders think about cybersecurity, they picture ransomware, phishing emails, stolen passwords, or credit card breaches.

Very few think about webinars.

That changed recently for marketing executive Remso W. Martinez.

Just minutes into a live webinar, his presentation was hijacked by what cybersecurity professionals commonly call a “Zoom bombing.” An unauthorized participant took control of the meeting, displaying offensive material and forcing the event to end abruptly.

Reflecting on the experience, Martinez wrote:

“Most people think cybersecurity is about protecting credit cards, passwords, and customer data. Few think about protecting their webinars. I certainly didn’t.”

His experience highlights a blind spot that exists in organizations of every size.

This wasn’t simply a Zoom problem.

It was a governance problem.

Today’s attack surface has expanded

Organizations spend considerable time and money protecting email systems, endpoints, cloud infrastructure, and identities. Those investments are essential.

But today’s customer interactions increasingly occur somewhere else.

  • Webinars.
  • Virtual conferences.
  • Live training sessions.
  • Sales demonstrations.
  • Online networking events.
  • Town halls.
  • Customer communities.

These platforms have become extensions of the business itself.

When customers, prospects, investors, partners, or members of the public interact with your organization through a virtual event, they aren’t evaluating Zoom, Microsoft Teams, Google Meet, or another platform.

They’re evaluating you.

If the event is disrupted, your reputation—not the software vendor’s—absorbs the damage.

Security is about more than data

Many executives still associate cybersecurity with protecting confidential information.

In reality, cybersecurity exists to protect three things:

  • Confidentiality
  • Integrity
  • Availability

A webinar hijacking may never expose sensitive customer data.

It can still destroy the integrity of your presentation, interrupt its availability, damage your brand, and erode trust among everyone attending.

Those are business risks.

And business risks belong squarely within executive leadership and governance.

Every customer-facing platform needs to be part of your security posture

Martinez made another observation that deserves attention:

“If your business hosts online workshops, networking events, webinars, or virtual training sessions, your event platform is part of your security posture.”

That statement should resonate far beyond marketing teams.

Every platform used to communicate externally becomes part of an organization’s attack surface.

Whether it’s Zoom, Microsoft Teams, Google Meet, Slack Connect, Discord, customer portals, or webinar platforms integrated with Eventbrite and CRM systems, these services deserve the same governance attention as any other critical business application.

Unfortunately, many organizations treat them as convenience tools rather than business-critical assets.

Governance means asking better questions

Technical controls matter.

  • Waiting rooms.
  • Authenticated users.
  • Restricted screen sharing.
  • Moderator roles.
  • Participant permissions.
  • Meeting passwords.
  • Registration requirements.

These controls dramatically reduce the likelihood of a disruption.

But governance begins before those settings are ever configured.

Leadership should be asking questions such as:

  • Who owns our virtual event security standards?
  • Are webinar platforms included in our cybersecurity policies?
  • Do we have standardized meeting configurations?
  • Who has authority to admit participants?
  • What is our response plan if an event is disrupted?
  • Have employees been trained to recognize and respond to meeting hijacking?

Organizations routinely conduct tabletop exercises for ransomware.

Few conduct them for customer-facing virtual events.

Perhaps they should.

A lesson worth sharing

Most organizations experience security incidents they never discuss publicly.

Martinez chose a different approach.

Instead of quietly moving on, he shared what happened in hopes that others could avoid making the same mistake.

That kind of transparency benefits everyone.

Cybersecurity is no longer limited to servers, networks, and endpoints.

It extends to every digital interaction an organization has with customers, prospects, partners, and the public.

The companies that recognize this shift will be better prepared—not only to prevent incidents but to preserve the trust they’ve worked so hard to build.

Because in today’s digital economy, every customer-facing platform is part of your cybersecurity strategy.