Cybersecurity | AV Integration | Enterprise Technology
The Fish Tank That Hacked a Casino: And Why Your Conference Room Is Next
How AV equipment became the enterprise’s most overlooked cybersecurity blind spot, and what to do about it.
In 2017, hackers broke into a North American casino, not through a phishing email or a compromised server, but through the thermostat in a decorative fish tank in the lobby. The tank was connected to the internet to monitor temperature and automate feedings. The hackers exploited that connection, moved laterally through the casino’s network, found the high-roller database, and exfiltrated 10 gigabytes of data to a server in Finland, all before anyone noticed.
Security professionals still tell that story because it perfectly illustrates the IoT paradox: the more convenient a connected device is, the more dangerous it can be. And right now, enterprises everywhere are making the same mistake that casino did, just with a different device.
That device is your AV system.
The Invisible Network Inside Your Conference Room
Walk into most modern conference rooms and you’ll find a cluster of networked devices: a video conferencing codec, a display or projector, a wireless presentation system, a room scheduling panel, a DSP audio processor, a control system touch panel, and a camera. Each one runs firmware. Each one has a network interface. And in most organizations, not one of them is managed with the same rigor as a laptop.
According to industry research, approximately 60% of AV equipment sits on enterprise networks connected via unmanaged switches, with no active monitoring, no patch schedule, and default credentials still in place. IT departments don’t think of a Crestron control processor as a cybersecurity endpoint. But attackers do.
Why AV Equipment Is a Prime Target
AV systems are uniquely attractive to threat actors for several reasons:
- They’re always on. Unlike a laptop that locks after inactivity, AV systems run continuously and are rarely rebooted.
- They’re full of sensitive data. Video conferencing systems capture audio, video, and screen content, often including financial presentations, M&A discussions, and HR conversations.
- They bridge networks. Many AV devices are simultaneously connected to the corporate LAN, display networks, and cloud management platforms, making them natural pivot points for lateral movement.
- They’re forgotten. Firmware is rarely updated. Default passwords are rarely changed. Security audits rarely include them.
- They’re trusted. Once inside an AV device on the same network segment as a file server or ERP system, an attacker faces far fewer internal barriers.
This Isn’t Theoretical: It’s Already Happening
Security researchers publicly documented attack patterns targeting AV infrastructure in both 2024 and 2025. Enterprise security teams are actively working to close them now.
In one high-profile incident, a German military officer on an unencrypted hotel conference line gave Russian intelligence a detailed briefing on weapons delivery logistics to Ukraine, captured simply by intercepting an unencrypted AV transmission. No sophisticated hack required. The AV system was the vulnerability.
Closer to home for most businesses: Zoom bombing, where journalists joined classified government meetings during the pandemic because recurring meeting credentials were never rotated, is a textbook AV security failure. The meeting room technology was not the problem; the absence of security governance around it was.
The pattern is always the same: a connected device no one considered a security risk becomes the entry point. The fish tank. The conference phone. The room scheduling panel. The camera. The question isn’t whether AV systems are vulnerable: it’s whether yours are defended.
The Skills Gap Making It Worse for AV Cybersecurity
Part of what makes AV cybersecurity so difficult to address is organizational. IT teams know cybersecurity but don’t know AV systems. AV teams know the technology but aren’t trained in network security. The result is a gap that neither team owns, and that attackers exploit freely.
This gap manifests in predictable ways: AV devices are excluded from vulnerability scans, left off asset inventories, omitted from incident response plans, and not covered by patch management policies. The device that facilitates your board meeting is treated with less security rigor than the coffee maker in the break room. Put simply: we don’t want to see your AV equipment floundering on your network with no one minding the tank.
Compliance Is Catching Up Fast
Regulatory frameworks are beginning to explicitly address AV infrastructure. If your organization operates in any of these sectors, AV cybersecurity is no longer optional:
- HIPAA: Requires safeguards for any networked device capable of capturing or displaying protected health information. Cameras and displays in clinical settings qualify.
- FERPA: Creates obligations for educational institutions with networked AV in spaces where student records might appear on screen.
- FedRAMP / FISMA: Government agencies must account for all networked endpoints in system security plans, AV systems included.
- CMMC 2.0: Defense contractors must demonstrate comprehensive endpoint management that auditors now interpret to include AV and collaboration systems.
- Cyber Insurance: Carriers are increasingly asking about IoT and AV device security posture in renewal questionnaires. Gaps can affect coverage and premiums.
Introducing AV Safety: A Framework for Closing the Gap
AV Safety is a systematic approach to treating your audiovisual infrastructure with the same security discipline applied to the rest of your IT environment. It’s not a product: it’s a practice built around five core pillars:
- AV Asset Inventory: Every networked AV device identified, catalogued, and included in your security ecosystem.
- Credential Hygiene: Default passwords eliminated, access controls implemented, MFA applied where supported.
- Network Segmentation: AV devices placed on dedicated VLANs, isolated from sensitive systems while maintaining full operational functionality.
- Patch Management: Firmware and software updates applied on a defined schedule, with a named owner responsible for execution.
- Continuous Monitoring: AV endpoints included in network monitoring, with alerting configured for anomalous behavior.
The Casino Didn’t Think the Fish Tank Was a Risk Either
The fish tank story endures because of how obvious the lesson seems in hindsight. Of course connected device on your network can be entry points, and of course you should have changed the default credentials. Of course it needed to be on a segmented network.
The AV systems in your conference rooms, boardrooms, training spaces, and reception areas are today’s fish tank. When it comes to AV cybersecurity, it’s sink or swim, and VisionPoint is here to make sure you swim.
Is your AV infrastructure included in your security plan?
VisionPoint offers a complimentary AV Safety consultation for Connecticut organizations. We’ll tell you exactly where your gaps are, no obligation.
About VisionPoint LLC: VisionPoint is a Connecticut-based AV integration company specializing in conference room technology, video conferencing solutions, digital signage, and managed AV services. We help organizations across healthcare, education, government, and commercial sectors deploy and secure their audiovisual infrastructure.

