AV Security Surprises Lurking on Your Network

Why AV and IT Can No Longer Work in Silos
AV equipment used to live on its own island. That’s no longer true. “As more things become network-based via protocols and just transports of signals, this was always going to happen,” Marques says. “You’re gonna have this crashing of AV and IT and what the rules are and what you need to have happen.” AV over IP and emerging standards like ST 2110 and IPMX all depend on the network — which means AV now shares infrastructure with an organization’s most sensitive systems, whether that network is dedicated to AV alone or riding on the client’s existing infrastructure.
The uncomfortable truth is that neither side has traditionally been equipped for this overlap. “Historically, some AV teams don’t have a lot of IT background, but IT teams don’t have a lot of AV background,” Marques explains. “Now you really do need both of those things on your team.”
A Guest Network That Talked Back
One story makes the stakes concrete. While simply searching for an AV device on the network using a basic diagnostic command, Marques started getting responses back from six-figure scanning equipment, servers, and other sensitive devices — not from the AV network, but from the guest network. “There’s no way these things should be talking back to me,” he recalls thinking. So he tested again, deliberately, from the guest network. Same result.
The response was immediate. Marques flagged it to his contact, and within roughly 24 hours, about twenty people from IT, security, and other departments were on a call. “Imagine being in a hospital or a government building,” he says. “Imagine hospital MRI machines, scanners, echo, cardiograph machines, and all these things are just randomly accessible.” The entire incident traced back to a single network segmentation misconfiguration — not a sophisticated breach, just a gap nobody had caught.
One Misconfigured Box, One Dead Campus Network
A second story shows how small the trigger can be. During a university’s first AV over IP pilot, a previous AV team had connected a device to the network without realizing it was still configured to act as a DHCP server — meaning it was handing out IP addresses. The university’s network already had its own system doing that job. The conflict brought down an entire segment of the campus network. “It actually shut down an entire segment of campus,” Marques says, “because of a box being added to a network with the DHCP server activated.”
Both incidents shared the same root cause: a simple, avoidable misconfiguration that nobody tested for before it caused real damage.
Building Security Into the Process, Not Bolting It On After
The fix starts before any equipment gets installed. On the AV side, that means gathering the manufacturer’s white papers and security documentation for anything that touches the network, understanding it internally, and sharing it directly with the client’s IT team. “Everything you learn from the manufacturer, share that with the IT team,” Marques says. “That way everyone’s on the same page” — including on protocol requirements like multicast traffic, which some IT environments block outright and which can derail a deployment if nobody checked in advance.
On the IT side, publishing clear, shareable standards helps just as much — from network expectations to something as simple as color-coded cabling. “If you look up in the ceiling and all you see is a bundle of blue cabling, how do you know what’s what?” Marques asks. Setting a standard, and sharing it before the project starts, prevents costly rework later.
The common thread across both incidents is that nobody had actually verified segmentation — they’d assumed it. “Test and verify segmentation, never assume isolation,” is the standard Marques now holds every project to. That, paired with genuinely bringing AV and IT to the table early rather than treating IT as an afterthought, is what turns a potential vulnerability into a system that just works. As Marques puts it, “We’re no longer separate teams. We’re really joined at the hip.”
Podcast Chapters
Chapters
(00:00) Rising Cybersecurity Threats with AI
(01:36) Hype Versus Reality in Artificial Intelligence
(08:00) Overlap and Vulnerabilities in AV and IT
(12:56) Real-World Security Gaps and Misconfigurations
(22:25) Best Practices for Securing AV and IT Integration
(27:34) Practical Security Advice for Everyday Use
(28:54) The Importance of Partnership in Delivering Secure Systems
Related Questions
Why is AV and IT convergence increasing security risk?
As more AV equipment becomes network-based — running on protocols like AV over IP, ST 2110, and IPMX — it shares the same infrastructure as an organization’s most sensitive systems. That overlap expands the attack surface, and historically neither side has had deep expertise in the other’s world: AV teams often lack IT security background, and IT teams often lack AV protocol knowledge.
What happened when a misconfigured guest network exposed sensitive equipment?
While simply searching for an AV device using a basic network command, the team found six-figure scanning equipment and servers responding back — even from the guest network, which should never reach that gear. Within 24 hours, roughly twenty people across IT, security, and other departments were on a call to contain it. The root cause was a single network segmentation misconfiguration.
How did one misconfigured device cause a campus-wide network outage?
During a university’s first AV over IP pilot, a previous AV team left a device active as a DHCP server — meaning it was handing out IP addresses — without realizing it. Because the university’s network already had its own system issuing addresses, the conflict took down an entire segment of the campus network.
What should organizations ask AV manufacturers about security before deployment?
Ask for the manufacturer’s white papers and security documentation for any device that touches the network, and review them before installation — not after. That information should then be shared directly with the client’s IT team so everyone understands what protocols (like multicast) the equipment requires and whether the network’s existing policies actually allow them.
What are practical first steps for securing an AV and IT integration?
Bring AV and IT to the table early, before hardware arrives. Share technical documentation and standards up front, agree on conventions like color-coded cabling to keep segments identifiable, and test and verify network segmentation directly rather than assuming it’s correctly isolated. Treat the relationship as an ongoing partnership, not a one-time handoff.
Relevant IndustRIes:
Related Services:
Let’s build your dream AV project together.
Strategic, precise guidance to turn communication goals into systems that perform where it matters most.


