IP Security For Broadcasters 2026 – Operating Systems

As well as providing the core functionality of a computer, operating systems represent a massive opportunity for hackers – and for broadcasters, the risk is growing. Increasing convergence between broadcast and IT infrastructures demands a proactive, layered approach to security that IT professionals can no longer afford to ignore.


This article is part of our free eBook ‘IP Security For Broadcasters - 2026 Edition’ - download it here.

In an ideal world, all software would be free from bugs. However, the massive number and combinations of inputs, calculations, and outputs that occur in most programs makes it almost impossible to test the system completely and exhaustively. Recent advances in software testing methods have made code much more dependable, but it’s impossible to make any system 100% reliable and predictable.

Operating systems (OS) are at the heart of every computing system and interact at some point with any application program running on the computer. Consequently, the OS represents one of the most critical security components of any computing system because it ultimately controls access to hardware, networks, memory, storage, and user applications.

Historically, many broadcast systems operated within relatively isolated production networks, but increasing convergence between broadcast and IT infrastructure has significantly expanded the potential attack surface.

Access vs Security

If we were to lock our computers in a vault one-hundred feet below a concrete bunker, not tell anybody their whereabouts, and not connect them to the internet, then the chances are that we would make them 100% secure. However, they would be perfectly useless as virtually nobody would be able to use them. But by making computers accessible and useable through networks, we inadvertently make them vulnerable to attack from cyber criminals and hostile actors. So, in this respect, security is about risk assessment and being proactive.

Any part of the computer that allows a user to input data is a potential source of vulnerability. Whether it’s the keyboard and mouse, the USB port, or the ethernet/WiFi connection, any mechanism that allows data or user interaction to enter the computer represents a potential attack surface. This makes the system particularly vulnerable as a hacker doesn’t need to be in the vicinity of the computer to do damage – they could be located on the other side of the world.

Building OS Defense

Preventing cybercriminals from accessing any computer on the network is of paramount importance and always the first line of defense, but to be effective with our security, we must assume somebody will be able to breach the network defenses and gain access to the computers on the network. And this is where the OS provides the next level of defense.

Hackers can generally exploit two types of vulnerability on individual computers, whether they’re a user’s desktop, a video processing server, or a web interface: through a user application or the OS. Restricting access to either of these relies on sophisticated login credentials. However, this proves difficult as users are generally hostile to security credential policies that require passwords to be changed regularly or use complex passwords that involve obscure characters. But this really is a line of defense that cannot be compromised.

Luckily, systems such as two-factor authentication make user security easier to implement and much more secure, but centralized credential authentication systems must be employed to facilitate their effective use. Examples of these include AD (Active Directory) or RADIUS (Remote Authentication Dial-In User Service).

To help keep the effects of any security breach to a minimum, users must have the minimum amount of read, write, and execute privileges. This involves a great deal of effort and planning from the IT system administrators, but again, is essential.

As already mentioned, no software system is 100% secure and vulnerabilities still exist in the code itself. These are not limited to any vendor, and the good news is that each vendor has a small army of developers constantly testing and fixing vulnerabilities should they occur.

Defense In Depth

Modern enterprise security increasingly relies on a layered approach often referred to as “defense in depth”. The principle behind this strategy is that no individual security mechanism should ever be trusted completely on its own. Instead, multiple independent protection systems operate together so that if one layer fails, additional barriers still exist to slow or stop an attacker.

For broadcasters, this may include network segmentation, firewalls, multi-factor authentication, endpoint protection, strict user privilege management, continuous monitoring, and regular software patching. Critical systems such as playout, contribution encoding, production control, and asset management servers should ideally be isolated from general office networks and internet-facing services wherever possible. Even within production infrastructure, systems should only be permitted to communicate with other devices necessary for their operation.

This layered approach is especially important because modern cyber attacks often attempt to move laterally across networks after gaining initial access through a single compromised machine or user account. Restricting communication paths and user privileges can significantly reduce the ability of attackers to spread through the wider infrastructure. In this respect, modern OS security is no longer simply about protecting individual computers, but protecting the entire operational ecosystem.

Keeping Software Up To Date

Major OS vendors such as Microsoft and Apple have a clear commercial incentive to keep their systems clear of vulnerabilities, but this raises an interesting question for open-source software. Although an OS such as Linux may be “free”, the reality of the situation is that, to make it as secure as the other major vendors, one of the commercial open-source software suppliers such as Suse, Redhat or Ubuntu must be adopted as they are constantly testing the OS for vulnerabilities and providing patches.

Any broadcaster should be extremely careful about downloading an instance of Linux and expecting it to be secure enough for enterprise use. There are a plethora of security patches and configurations that broadcasters often lack the resource and knowledge to install effectively and safely. However, the good news is that one of the commercial open-source vendors will have done the security checking, configuration, and validation to make it safe for enterprise use. They will also provide regular updates and patches as needed.

Figure 1 - All processes within the user space interact with the operating system kernel at some point. Here, two “write()” library calls are shown writing to the network and disk drive, with “printf()” sending data to the display port.

Figure 1 - All processes within the user space interact with the operating system kernel at some point. Here, two “write()” library calls are shown writing to the network and disk drive, with “printf()” sending data to the display port.

With some operating systems, the line between the OS and the internet browser is becoming increasingly blurred, to the point where the browser must be considered a potential source of OS vulnerability as it is often provided as a patch during OS updates. A browser can be made secure, but this often requires an in-depth understanding of its configuration to stop problems with Trojan software or spyware. These are small programs that can be installed on a computer by a hostile actor and either track keyboard, mouse and website actions, or attack other computers.

Leaving a user to configure their own browser security is a disaster waiting to happen; expert IT professionals must configure the browser and then lock it so the user cannot override the settings. The challenge with this is that users are often restricted by the security policies of the broadcaster. For example, it may be that Java applets or frameworks like ActiveX are disabled, thus restricting the user experience or access to some websites. Again, security is all about risk assessment and IT professionals must work in tandem with users to provide secure systems – a task much easier said than done.

Closing Vulnerabilities

Although SSH (Secure Shell) is separate from the OS kernel itself, it is commonly installed alongside the operating system to provide remote management capabilities. SSH is an essential administrative tool, but if poorly configured it too can significantly increase the attack surface of a system. Consequently, unused remote-access services should be disabled wherever possible and direct “root” logins should normally be prohibited.

SSH is one example of a remote-access service, and systems that do not require remote administration should ideally disable or avoid installing such services altogether. Compromise of a privileged administrative account may also provide attackers with a platform from which they can move laterally through the wider network.

Once a malicious user has access to a computer or server then they can use it for a whole host of nefarious actions including DoS (Denial of Service) attacks, where systems are flooded with large volumes of traffic or connection requests in an attempt to exhaust CPU, memory, network bandwidth, or application resources.

Operating systems are at the heart of most computer systems used in broadcast enterprise environments and have the potential to be a source of security vulnerabilities. Consequently, IT professionals specializing in security should install, configure, and maintain them, along with associated software such as browsers, so they always have the latest patches to keep vulnerabilities to an absolute minimum.


This article is part of our free eBook ‘IP Security For Broadcasters - 2026 Edition’ - download it here.

Supported by

You might also like...

The Changing Face Of Live Sports: Part 1 - The Rise Of Nimble Production

Live sports broadcasting has always been the preserve of big leagues and big broadcasters with the infrastructure, the clout and the resources to match. But it is no longer the only game in town.

Standards: Audio - High Efficiency Audio Codecs (HE-AAC)

HE-AAC builds on the foundations of AAC to deliver near CD-quality audio at bitrates as low as 32 kbps, making it the codec of choice for mobile TV, digital radio and low-bandwidth streaming. This guide unpacks the key technologies behind its…

IP Security For Broadcasters 2026 – The Psychology Of Security

As engineers and technologists, it’s easy to become bogged down in the technical solutions that maintain high levels of computer security. But as the boundaries between traditional broadcast engineering and IT continue to dissolve, the first port of call i…

Standards: Audio - Advanced Audio Coding (AAC)

AAC succeeded MP3 by delivering better quality at lower bitrates. This guide examines how it works, compares the leading encoder implementations, and explains where it sits within the broader MPEG audio standards landscape.

Broadcast Standards - The Science Of AI: New Foundations

We begin this series with the foundational building blocks of AI. Basic principles, the technology stack and the types of AI based upon it, and how to apply them effectively in a broadcasting enterprise.