Walk into any modern meeting room and count the computers. Most people say one, maybe two if a laptop is plugged in. The real number is closer to six. The video bar is a computer running Android. The room booking panel on the wall is a computer. The wireless presentation box, the smart TV, the ceiling microphone array, the thermostat behind the glass: computers, all of them, with processors, storage, operating systems and network connections. We secure networks for a living, and the pattern we see is remarkably consistent: businesses that are careful about laptops and servers extend none of that care to the dozens of quiet computers they have screwed to walls and ceilings.
The blind spot has a shape
It happens for an understandable reason. A laptop arrives through IT, gets enrolled, patched and monitored. A conferencing system arrives through an AV installer or an office fit-out, gets plugged into whatever network port is live, works on the first try, and is never thought about again. Nobody owns it. It does not appear in the asset register. It has no endpoint agent, because you cannot install one. And it sits on the same network as your file shares and finance systems, because that was the port that was live.
The result is a class of devices with all the properties attackers like: always on, rarely watched, never patched, and trusted by the network around them.
What these devices actually run
A video conferencing bar is not an appliance in any meaningful sense. Popular room systems run full Android or Linux under the hood, with web servers for administration, open services for discovery and casting, and vendor accounts with documented default passwords. Smart TVs ship with browsers and app stores. IP cameras and door controllers run embedded Linux, and plenty of them have shipped with hard-coded credentials over the years. When one of these devices is compromised, the attacker is not inside a gadget. They are standing on a general-purpose computer inside your network, with a network card and no security software, free to look around.
The widely reported casino case from a few years back, where attackers reached a high-roller database through an internet-connected fish tank thermometer, gets laughed at in conference talks. The mechanics deserve more respect than laughter: the thermometer was never the target. It was the unlocked side door to everything else, and most offices have a dozen doors just like it.
Firmware is patching, whether it is treated that way or not
Every business we assess has a patching story for Windows. Almost none has one for firmware. Conferencing systems, cameras, printers and network hardware all receive security updates from their vendors, and those updates fix real vulnerabilities, some of them remotely exploitable. The updates simply never get applied, because no person and no process owns the job. Worse, these devices outlive their support windows quietly: the video bar bought five years ago may have had its final update years back, and nothing about it looks different on the day the vendor stops caring.
Firmware deserves a place in the same cycle as operating system patching: an inventory of what exists, a schedule for checking it, and a decision point for devices that no longer receive updates. A device that can no longer be patched can still be contained, but only if someone knows it exists and decides to contain it.
Segmentation is the control that forgives you
Here is the honest truth about IoT security: you will not win the patching race on every device, and some devices were never securable to begin with. Segmentation is the control that forgives those failures. A conferencing system on its own , with firewall rules that allow it to reach its vendor's cloud service and nothing else, is a contained problem even when it is compromised. The same device on the flat corporate network is a beachhead.
Good segmentation for this class of device is not exotic. A dedicated network segment for AV and IoT equipment. Rules written from the device's actual needs: this camera talks to this recorder, this room system talks to Teams and its management cloud, and none of them talk to the file server, ever. Deny by default, and alert on the attempts. When we run an internal penetration test, the flat network with smart devices on it is reliably where the interesting findings come from, because one forgotten device undoes a great deal of otherwise careful work.
Questions worth asking this week
- Do we have a list of every non-computer computer on the network: conferencing gear, TVs, cameras, door controllers, printers, sensors? If nobody can produce one, that is finding number one.
- What network can those devices reach? If the video bar can ping the finance share, segmentation is a project that should start soon.
- Who applies firmware updates, and when did they last do it? A specific name and a recent date are the only good answers.
- Have the default passwords been changed on every one of them, including the ones the AV installer set up?
- Which of these devices no longer receives vendor updates at all, and what is the plan for those?
None of this requires new products, and that is rather the point. The risk lives in unowned devices and flat networks, so the fix lives in ownership and structure: know what is there, wall it off, keep it updated, and retire what cannot be. We design and install camera and door access systems as well as securing networks, which gives us a view from both sides of this fence, and the businesses that get it right treat every powered device with a network cable as what it is: a computer, with everything that word implies.



