Cybersecurity: Why live events need to treat every connection as a risk
Live events depend on connected technology, but every new connection can create another potential route for a cyberattack. Ticketing, payments, Wi-Fi, digital signage, production systems, communications and third-party equipment increasingly share the same digital ecosystem, making cybersecurity an operational issue for venues and event organisers – not simply an IT problem.
A cyber incident doesn't need to bring down an entire stadium network to cause serious disruption. If it affects ticketing, payments, communications or production at the wrong moment, the consequences can quickly become visible to thousands of visitors.
The UK's National Cyber Security Centre (NCSC) specifically warns that major events are increasingly dependent on digital systems and that attacks affecting their availability, integrity or confidentiality can cause both financial and reputational damage.
Why are live events particularly exposed?
One challenge is the sheer number of organisations and systems involved.
A permanent venue may have its own corporate network, building systems, security infrastructure, Wi-Fi, displays and point-of-sale technology. On an event day, that environment can expand to include promoters, broadcasters, production companies, touring crews, caterers, sponsors and other contractors.
Some arrive with their own connected equipment. Others need access to venue infrastructure. And everything has to work within a tightly constrained timeframe.
The result is a technology environment whose boundaries can change from one event to the next. That makes knowing what is connected, who has access and how systems are separated particularly important.
The NCSC's guidance for high-profile events consequently recommends considering suppliers as part of the cyber-risk assessment, alongside areas including governance, incident management, testing and venue-related risks. (National Cyber Security Centre)
Audience data makes live events attractive targets
The live-events ecosystem also handles valuable data.
The scale of the potential exposure became particularly clear with the Ticketmaster incident in 2024. Live Nation told the US Securities and Exchange Commission that it had discovered unauthorised activity in a third-party cloud database environment containing primarily Ticketmaster data. Days later, a threat actor offered what it claimed was company user data for sale on the dark web.
The case illustrates an important point for venue operators: cybersecurity extends beyond technology physically installed inside the venue. Cloud services, ticketing platforms and other suppliers can all form part of the wider event ecosystem.
Segmentation can limit the impact
That doesn't mean every connected system presents the same risk.
One of the fundamental principles is avoiding unnecessary connectivity between systems. Guest Wi-Fi, payment infrastructure, production networks, corporate IT and operational systems may all have very different security requirements.
Network segmentation can help prevent a compromise in one area becoming a route into another.
This was among the practical strategies discussed at the ISE 2026 CyberSecurity Summit, where DNV Cyber's Shaun Reardon explored security-by-design for connected AV environments, including network segmentation, vulnerability management and incident response.
For live-events organisations, this means cybersecurity should increasingly be considered when networks and AV systems are designed – rather than added after deployment.
Don't forget the people
Technical protection is only part of the answer.
Temporary staff, freelancers and suppliers are fundamental to live events, which makes clear processes particularly important. Who is authorised to connect equipment? How are credentials issued and withdrawn? Who should a member of staff contact after receiving a suspicious message? What happens when a supplier needs urgent network access during a show?
Training should therefore concentrate on practical situations employees and contractors may actually encounter, including phishing, credential theft and suspicious requests for access.
Supplier relationships deserve similar scrutiny. A venue's own security can be undermined if trusted third parties have unnecessary access or poorly protected accounts.
Plan for the attack, not just its prevention
Perhaps the most important change in thinking is to accept that cybersecurity is also about resilience.
Major-event planning already anticipates physical disruption. Cyber incidents need the same treatment.
If digital ticketing becomes unavailable, can visitors still enter? If a payment system fails, can concessions continue operating? If a production network is compromised, can essential systems be isolated without stopping the event?
The NCSC recommends developing cyber incident-management plans and exercising them before major events.
This changes the question from "Can we stop every attack?" to the more useful one: "Can the event continue safely if something goes wrong?"
Cybersecurity is becoming part of AV design
As AV, IT and operational technologies converge, cybersecurity increasingly has to be considered across the entire system.
That shift was reflected in the inaugural CyberSecurity Summit at ISE 2026, which examined secure AV infrastructure, regulation, network resilience, critical environments and incident response. ISE also explored cybersecurity through its Megatrends programme, including a session examining the protection of connected digital infrastructure in public spaces. Both content streams will return at ISE 2027.
For venues, promoters and production teams, the implication is straightforward. Cybersecurity cannot belong solely to the IT department when so much of the event itself now depends on connected technology.
Every device does not need to become a cybersecurity project. But every connection should be understood.
Because when thousands of people are waiting for the doors to open and millions may be watching elsewhere, discovering a vulnerability is already too late.
Stay ahead – Stay informed.
As an AV specialist or industry leader, you recognise how crucial it is to keep up with evolving trends, new technologies, and notable happenings within the audiovisual world. That’s why we’re delighted to invite you to receive exclusive email updates about ISE – the world-renowned tech show for the systems integration and audiovisual industry.
When you subscribe, you’ll be kept up to speed with insightful commentary on the freshest developments in AV, get early looks at what’s planned for the ISE content schedule – including headline speakers – and benefit from in-depth reporting on the show’s standout attractions.
Sign up now to stay at the forefront of audiovisual innovation and expertise.
Further reading
Discover audio, lighting and staging at ISE
Discover cybersecurity and other emerging technologies at ISE
Related articles
- 5G is finally changing live events – but not in the way you think — Discover how 5G and private networks are enabling more flexible live production while creating new questions around security, resilience and integration.
- Why do so many venues fall behind before they're even finished? — Explore why flexible networks, interoperability and adaptable infrastructure are becoming essential to keeping increasingly connected venues secure and future-ready.
- The network is becoming the most important AV device — See why the shift towards IP-based AV is making network design fundamental to the performance, management and resilience of modern AV systems.
This article was first published on 2 September 2024; revised 3 September 2026.