One cyberattack could take your channel off air
For decades, broadcast resilience meant redundancy. Backup power, duplicate signal paths, disaster recovery facilities and failover systems were designed around one overriding objective: keep the content on air.
Today, resilience has another dimension.
A broadcaster can have redundant hardware and backup power and still be vulnerable if an attacker compromises the connected infrastructure on which production and distribution increasingly depend.
Cybersecurity has become an operational issue.
Connectivity changes the risk
The reason is partly the transformation of broadcast infrastructure itself. IP networks, cloud services, remote production and software-defined systems are making media operations more flexible and scalable, but they also connect environments that were once relatively isolated.
The European Broadcasting Union (EBU) now explicitly addresses cybersecurity alongside the transition to IP, cloud and software-defined production infrastructure. Its cybersecurity recommendations cover areas including ransomware, cloud security, DDoS attacks, vulnerability management and secure file ingest.
The attack surface has consequently become much broader. A modern media operation can encompass studios, remote contributors, cloud platforms, corporate IT, storage, playout and distribution infrastructure, as well as technology supplied and supported by external partners.
A vulnerability in one part of that ecosystem can potentially affect another.
For broadcasters, downtime is different
A cyberattack does not have to involve stolen audience data to become a broadcasting crisis.
An attacker might disrupt distribution, make production systems unavailable, compromise access to content or interfere with systems required to operate the business. Cisco, for example, identifies threats to media environments including theft or ransom of premium content, modification of content, attacks on rights-management systems and denial-of-service attacks capable of disrupting distribution.
The industry has already learnt how serious the consequences can be. In 2015, the French broadcaster TV5Monde was taken off air by a cyberattack. Yves Bigot, director-general, told the BBC: "It's the worst thing that can happen to you in television." He added: "We were a couple of hours from having the whole station gone for good."
The EBU cited this incident when establishing minimum cybersecurity requirements for broadcast systems, software and services.
That changes how cybersecurity should be viewed. Protecting a broadcaster is not simply about protecting information. It is about protecting the ability to produce and deliver media.
Technology alone cannot solve the problem
Cyber resilience also extends well beyond the security department.
Access management, software updates, staff awareness, incident response, suppliers and third-party access all influence the risk profile. Verizon's 2025 Data Breach Investigations Report found that third parties were involved in 30% of breaches in its global dataset, while human involvement remained significant, particularly through social engineering and credential abuse.
This matters particularly as broadcast ecosystems become more distributed. Remote teams and cloud services can introduce more identities, devices, suppliers and connection points into workflows that still have to operate continuously.
Security therefore has to be considered as part of the architecture rather than added once the architecture is complete. The EBU's work on broadcast cybersecurity increasingly reflects this security-by-design approach, including guidance for vendors supplying systems, software, SaaS products and services to media companies.
Resilience is becoming a design principle
This does not mean broadcasters should retreat from IP, cloud or remote production. Those technologies are becoming fundamental to the industry's future. It means resilience has to evolve with them.
At Integrated Systems Europe, that relationship is increasingly visible. ISE 2027 exhibitor Cisco, for example, combines IP media networking with endpoint access control, network automation, analytics and security capabilities. Lawo's software-defined approach reflects the industry's wider movement towards networked production environments, while Riedel Communications operates in the mission-critical communications and networking environments on which major live productions depend.
For broadcast leaders, the question is therefore no longer whether cybersecurity belongs in the technology strategy. It is how effectively security, continuity and innovation can be designed together.
A broadcaster can recover lost data. Recovering immediately from an attack that interrupts a live channel is much harder.
As broadcasting becomes more connected, cyber resilience is becoming part of broadcast resilience itself. That makes it a conversation not just for cybersecurity specialists, but for engineering, operations, technology leadership and ultimately the boardroom.
At Integrated Systems Europe, those worlds increasingly meet. As broadcast and professional AV converge around IP, cloud and software-defined infrastructure, protecting the connected systems behind modern media operations is becoming as important as the capabilities those systems enable.
Stay ahead – Stay informed.
As an AV specialist or industry leader, you recognise how crucial it is to keep up with evolving trends, new technologies, and notable happenings within the audiovisual world. That’s why we’re delighted to invite you to receive exclusive email updates about ISE – the world-renowned tech show for the systems integration and audiovisual industry.
When you subscribe, you’ll be kept up to speed with insightful commentary on the freshest developments in AV, get early looks at what’s planned for the ISE content schedule – including headline speakers – and benefit from in-depth reporting on the show’s standout attractions.
Sign up now to stay at the forefront of audiovisual innovation and expertise.
Further reading
Discover broadcast solutions at ISE.
Discover cybersecurity and other emerging technologies at ISE.
-
The next broadcast revolution may be invisible to viewers – Explore how software-defined infrastructure is changing the foundations on which modern broadcast operations are built.
-
Is SDI finally losing the fight? – Learn why the transition to IP brings greater flexibility to broadcasters – and a new set of operational and cybersecurity considerations.
-
Playout is moving to the cloud – faster than many broadcasters think – See how cloud-based playout is changing the balance between flexibility, resilience and operational risk.
-
Is outside broadcast heading for reinvention? – Explore how remote production, IP networking and distributed infrastructure are reshaping live broadcast operations.
-
Why cybersecurity is now an experience issue – Find out why cybersecurity is becoming fundamental to the reliability of connected AV environments.