Video Conferencing Security Best Practices: A 15-Point Checklist

Meeyra Team15 min read0September 21, 2026

Video conferencing security best practices come down to 15 controls in three phases: before the meeting (one approved platform, SSO and MFA, patched clients, secure defaults, unique links), during it (identity checks, locked rooms, limited screen sharing, announced recording) and after it (retention limits, log reviews, access cleanup, incident drills).

Most guides stop at host settings. Settings matter, but the expensive incidents of the last two years started somewhere else: an unverified face on a call, an unpatched client, a recording nobody remembered to delete. This checklist treats video conferencing security as a process with named owners. Every control has a phase, a role, and a way to confirm it happened.

If you only need the host-side settings that keep uninvited guests out, start with our guide on how to prevent Zoom bombing. This article is the wider frame around it.

Table of Contents

The 2026 Threat Picture for Online Meetings

Meetings are where money moves and decisions get made, so attackers go there. In a Gartner survey of 302 cybersecurity leaders, 62% of organizations reported a deepfake attack in the past 12 months. That figure includes impersonation during video or audio calls, as Infosecurity Magazine reported.

The best-known case is the engineering firm Arup. A finance employee in Hong Kong joined a video call with people who looked and sounded like the CFO and other colleagues. All of them were deepfakes. He sent HK$200 million, about $25.6 million, across 15 transfers, according to CNN.

Official data shows the same trend at scale:

  • FBI: The Internet Crime Complaint Center logged 1,008,597 complaints and $20.877 billion in losses for 2025, up 26% from 2024. It tracked AI-related complaints for the first time: 22,364 reports and $893 million in losses. Business email compromise added $3.05 billion (IC3 2025 report).
  • IBM: The 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million. One in four malicious breaches was AI-enabled, mostly deepfake impersonation and AI-enabled malware, and those averaged $6 million (IBM).
  • Verizon: In the 2026 DBIR, vulnerability exploitation opened 31% of breaches and passed stolen credentials for the first time in 19 years. A third party was involved in 48% of breaches, and employee use of unapproved "shadow AI" tripled to 45% (Verizon).
Each number maps to a meeting control. Deepfakes call for identity checks. Exploited vulnerabilities call for patched clients. Third-party breaches call for vendor review. Shadow AI shows up in meetings as the uninvited notetaker bot.

The 15-Point Checklist at a Glance

The table below is the whole framework on one page. The sections after it explain each control and how to verify it.

#ControlPhasePrimary owner
1Standardize on one approved platformBeforeIT
2Put host accounts behind SSO and MFABeforeIT
3Patch meeting clients on a scheduleBeforeIT
4Enforce secure defaults account-wideBeforeIT
5Use a unique link for every external meetingBeforeHost
6Match controls to meeting sensitivityBeforeHost
7Verify identities before sensitive decisionsDuringHost and participants
8Lock the room and watch the rosterDuringHost
9Share a window, not the whole desktopDuringAnyone presenting
10Announce recordings and remove unknown botsDuringHost
11Control the physical environmentDuringParticipants
12Set retention limits for recordings and transcriptsAfterHost and IT
13Review attendance reports and audit logsAfterIT
14Rotate recurring links and revoke accessAfterHost and IT
15Rehearse the incident planAfterIT and everyone

Before the Meeting: Six Controls That Do Most of the Work

Most video conferencing security is decided before anyone clicks "join": six of the 15 controls sit in this phase. Four of them belong to IT, which means a host never has to think about them if IT does its part.

1. Standardize on one approved platform

CISA's guidance for securing video conferencing is blunt: "Only use video conferencing tools approved by your organization for business use." Every extra tool adds another vendor contract, another set of defaults, and another update cycle.

Publish a short approved list and say what to do when a client insists on their own platform. A sensible rule is to join foreign platforms from the browser instead of installing one more desktop client. Review each approved vendor once a year, because Verizon now links 48% of breaches to a third party.

2. Put host accounts behind SSO and MFA

A stolen host account is worse than a leaked link. The attacker can schedule meetings in your CFO's name, open past recordings, and read chat history. Single sign-on ties meeting access to your identity provider, so offboarding in HR also ends access to the meeting platform.

Require multi-factor authentication for every account that can host or open recordings. CISA notes that users who enable MFA are significantly less likely to get hacked, because a stolen password alone no longer opens the account.

3. Patch meeting clients on a schedule

CISA asks organizations to enable automatic updates "or else establish routine updates (e.g., once weekly)". The reason became concrete in August 2026. A widely used meeting client patched a zero-click flaw that let one participant run code on another participant's machine, SecurityWeek reported.

Track client versions the same way you track operating systems. Include conference-room hardware, which often runs firmware nobody owns. Browser-based meetings shrink this work, because the browser updates itself and no separate client sits on the device.

4. Enforce secure defaults account-wide

Video conferencing security should not depend on each host remembering seven toggles. Set the defaults once at the admin level:

  • Waiting room or lobby on for external guests
  • Passcode required, join-before-host off
  • Participant screen sharing off until the host grants it
  • File transfer limited to safe file types
  • Recording off by default, with a visible indicator when it runs
CISA recommends waiting rooms, locking the event, and limiting shareable file types. Our Zoom bombing prevention guide walks through the host-side settings one by one, so this checklist does not repeat them.

NIST's advice on virtual meetings puts it plainly: "Limit reuse of access codes; if you've used the same code for a while, you've probably shared it with more people than you can imagine or recall."

A permanent personal room is fine for internal one-to-ones. It is the wrong choice for clients, candidates, and vendors. Generate a fresh link per external meeting, send it through the calendar invite, and never post it on a public page or social feed.

6. Match controls to meeting sensitivity

Not every call deserves the same friction. Three tiers are enough for most companies:

TierExamplesMinimum controls
PublicWebinars, open town hallsRegistration, muted entry, host-only sharing, a moderator on the roster
InternalTeam syncs, project reviewsSigned-in users, lobby for guests, unique link
ConfidentialBoard, M&A, HR, legal, paymentsNamed invite list, identity check, locked room, no recording by default, no third-party bots

For sensitive topics, NIST suggests one-time PINs or meeting identifier codes and multi-factor authentication. Ask hosts to pick the tier when they schedule. The choice takes five seconds and removes guesswork later.

During the Meeting: Five Habits for Hosts and Participants

In the live phase, video conferencing security is a matter of habits, not settings. The habits work when hosts and participants apply them without being told each time.

7. Verify identities before sensitive decisions

The Arup employee doubted the first email. The video call removed his doubt, because the faces and voices matched people he knew. A face on a screen is no longer proof of identity.

Adopt one rule: any request involving money, credentials, or data gets confirmed over a second channel you already trust. Call back a number on file or message the person in your internal chat. Never approve a payment inside the meeting that asked for it.

Remote hiring needs the same care. The FBI warned in 2022 about deepfakes and stolen identities used to apply for remote jobs. Ask candidates for unscripted actions on camera and verify identity documents separately.

8. Lock the room and watch the roster

Lock the meeting once the expected attendees are in. NIST recommends using a dashboard to monitor attendees and to "identify all generic attendees". In practice, that means asking "iPhone", "Guest 2", and unknown dial-in numbers who they are, or removing them.

In larger meetings, give a co-host the roster. The presenter cannot watch slides, chat, and the participant list at once.

9. Share a window, not your desktop

CISA tells users to know the difference between sharing one application and sharing the full screen. A full desktop leaks notifications, open tabs, file names, and password-manager prompts. Share a single window, close mail and chat first, and switch on do-not-disturb.

Keep sharing limited to hosts by default and grant it per person. That one setting also blocks the most common form of meeting disruption.

10. Announce recordings and remove unknown bots

CISA's rule for recordings is simple: "make sure participants are aware". AI notetakers made this harder. A federal class action filed in August 2025 alleges that a popular AI notetaking service recorded meetings without asking every attendee for permission, NPR reported.

Whatever the court decides, the operational lesson holds. A bot that joins for one participant records everyone. Write four lines into your policy:

  1. Only approved notetakers may join company meetings.
  2. The host announces any recording or transcription at the start.
  3. The host removes bots nobody can account for.
  4. Confidential-tier meetings run without third-party bots.
If you are choosing a recording tool, our comparison of meeting recording software covers storage limits and consent features.

11. Control your physical environment

Video conferencing security also depends on the room you sit in. CISA advises against public hotspots and asks home workers to use WPA2 or WPA3 on their Wi-Fi. Add a few habits of your own:

  • Wear headphones in shared spaces, including at home.
  • Check what the camera sees: whiteboards, screens, shipping labels.
  • Mute smart speakers during confidential calls.
  • Join confidential meetings from a company-managed device, as NIST recommends.
CISA's shortest rule is worth printing: "Do not discuss information that you would not discuss over regular telephone lines."

After the Meeting: Four Steps Most Teams Skip

The meeting ends, but its data stays. Most teams do nothing after the call, which is why this phase holds the easiest wins.

12. Set retention limits for recordings, transcripts, and chat

A recording is a copy of the meeting that outlives every live control you applied. NIST's advice is "Don't record the meeting unless it's necessary". For recordings you do keep, it recommends encryption, a passphrase, and deleting copies stored by the provider.

Pick a default retention period and let owners extend it only with a reason. Apply the same limit to transcripts, AI summaries, and chat exports, because they contain the same information in searchable form. Under the GDPR, storage limitation is a legal principle, not a preference.

13. Review attendance reports and audit logs

After a confidential meeting, compare the attendance report with the invite list. It takes two minutes and catches forwarded links.

IT should review the admin audit log every month. Look for new admin accounts, changed security defaults, recordings shared outside the company, and sign-ins from unusual locations. IBM's 2026 report found that organizations using AI and automation in security operations cut breach costs by almost $2 million on average, so automate these alerts where your platform allows it.

Recurring series collect attendees over time. The contractor who left in March still holds the link to Monday's leadership call. Regenerate links for recurring confidential meetings every quarter and whenever someone leaves the group.

Add meeting items to your offboarding list: host license, ownership of stored recordings, room-system PINs, and calendar delegation.

15. Rehearse the incident plan

Everyone should know three things: how to remove a participant, whom to tell, and what to preserve. Screenshots, the attendee list, and the exact time are usually enough for an investigation.

Deadlines make rehearsal worthwhile. GDPR Article 33 gives you 72 hours to notify the supervisory authority after you become aware of a personal data breach. An exposed meeting recording can qualify. Run a 15-minute tabletop once a year with two scenarios: a stranger joins the board call, and "the CFO" asks for an urgent transfer on video.

Who Owns What: Roles for Hosts, Participants, and IT

Video conferencing security fails when everyone assumes someone else handled it. This role matrix removes the ambiguity.

PhaseHostParticipantIT or security admin
BeforePick the sensitivity tier, create a unique link, invite named people onlyUpdate the browser or client, join from a managed device, check that the invite comes from a known senderApprove the platform, enforce SSO and MFA, set defaults, patch clients, review the vendor
DuringAdmit and verify attendees, lock the room, grant sharing, announce recordingUse headphones, share one window, challenge unusual requests, flag unknown attendeesMonitor alerts, keep an on-call contact for incidents
AfterStore or delete the recording per policy, share notes with invitees only, rotate recurring linksReport anything suspicious, never forward recordingsReview audit logs, enforce retention, run offboarding, lead the yearly tabletop

Participants are the largest group and get the least training. Give them a five-line card instead of a policy PDF: join from a managed device, wear headphones, share a window only, confirm money requests on a second channel, and report odd attendees.

Compliance Hooks: GDPR, HIPAA, and Breach Deadlines

A documented video conferencing security checklist is also how you show compliance. Three obligations come up most often:

  • GDPR Article 32 requires "appropriate technical and organisational measures". Encryption is the technical half. Roles, tiers, retention, and training are the organisational half (Article 32). Our guide to GDPR-compliant video conferencing covers vendor contracts and data location.
  • HIPAA requires a business associate contract before a vendor handles protected health information on your behalf (45 CFR 164.308(b)). Sign it before the first telehealth call.
  • Recording consent rules differ by country and by US state. CISA's guidance tells organizations to consult counsel on the laws that apply to recording video conferences.

Multilingual Meetings: The Gap Most Checklists Miss

When participants do not share a language, teams improvise. Someone runs a consumer translation app next to the call. Someone else invites an external caption bot. An ad-hoc interpreter joins through a forwarded link. Each workaround puts an unvetted third party inside a confidential conversation, which is the shadow AI pattern from Verizon's report.

The fix is to make translation part of the approved platform. Meeyra builds real-time AI translation for 42+ languages into the meeting itself, so no outside tool has to listen in. Media is encrypted in transit, audio is processed in real time for translation instead of being stored, and the meeting runs in the browser, so guests join by link without installing a client. Hosts set room rules for microphones, cameras, chat, translation, and screen sharing.

One trade-off deserves honesty. Server-side translation means the platform must process the audio, so strict end-to-end encryption and live translation cannot run in the same session. Our explainer on end-to-end encryption in video calls shows where that line sits. For mixed-language teams, see how meeting translation works in practice.

Rolling the Checklist Out in 30 Days

You do not need a project plan to start. A four-week rollout is realistic for most companies:

  1. Week 1: IT completes controls 1 to 4: approved platform, SSO and MFA, patch schedule, account-wide defaults.
  2. Week 2: Publish the tier table and a one-page host guide for controls 5, 6, and 8 to 10.
  3. Week 3: Send the participant card and introduce the second-channel rule for controls 7 and 11.
  4. Week 4: Switch on retention limits, schedule log reviews, update offboarding, and book the tabletop for controls 12 to 15.
Measure four things: the share of hosts behind SSO, client version compliance, recordings older than the retention limit, and the time it takes to remove an intruder in the drill. Numbers turn video conferencing security from a memo into a routine.

Good meeting security is rarely about one dramatic hack. It is about fifteen small, owned, repeatable steps. If you want a platform where encrypted transport, host room rules, and built-in translation come as standard, create a free Meeyra account or compare plans on the pricing page.

Frequently Asked Questions

What are the most important video conferencing security best practices?

The most important video conferencing security best practices are using one approved platform, protecting host accounts with MFA, keeping clients patched, generating unique links for external meetings, and verifying identities before sensitive decisions. Retention limits for recordings and a rehearsed incident plan complete the list.

Can a video conference be hacked?

Yes. Attackers exploit unpatched meeting clients, stolen host accounts, and leaked links. In August 2026, a widely used client patched a zero-click flaw that let one participant run code on another participant's machine. Regular updates and MFA close the most common paths.

How do you verify someone's identity on a video call?

Confirm the request over a second channel you already trust, such as a call-back to a number on file or a message in your internal chat. A familiar face and voice are no longer proof, because real-time deepfakes can imitate both.

Should every meeting be recorded?

No. NIST advises against recording a meeting unless it is necessary. Every recording creates a copy that needs encryption, access control, a retention limit, and in many jurisdictions the consent of the participants.

Who is responsible for meeting security: IT or the host?

Both. IT owns the platform, the accounts, the defaults, and the patches. The host owns the link, the invite list, the roster, and the recording. Participants own their device and their environment.

How often should video conferencing software be updated?

Enable automatic updates wherever possible. If that is not an option, CISA recommends a routine check for new versions, for example once a week. Browser-based meetings follow the browser's own update cycle.

Are AI notetaker bots a security risk?

They can be. A bot that joins for one participant records everyone in the meeting and sends the data to a third party. Allow only approved notetakers, announce them at the start, and keep them out of confidential meetings.