Who Has the Password?

by John C. Morley, Video Producer and Engineer

Years ago, protecting a television station meant locking the doors, securing the equipment, and ensuring only authorized personnel had access to the control room. Today, another part of the station needs just as much protection: its digital assets.

Community television stations may have more online accounts than people realize. YouTube channels, social media accounts, websites, streaming platforms, cloud storage, email accounts, scheduling systems, remote access tools, and equipment management systems may all require usernames and passwords.

The question every station should be able to answer is simple: Who has the password?

When One Person Knows Everything

In smaller organizations, it is common for one employee, volunteer, contractor, or technically knowledgeable person to set up many of the station’s accounts. Over time, that person may become the only individual who knows how everything is accessed.

That arrangement may work perfectly for years. Then the person retires, leaves the organization, becomes unavailable, or forgets how an account was configured.

Suddenly, something as simple as updating a website, accessing a YouTube channel, or changing a streaming configuration can become a major problem.

Stations should know which accounts they have, who has authorized access to them, and how to recover access if necessary. Just as importantly, the station itself should maintain ownership of important accounts rather than relying entirely on an individual’s personal email address or phone number.

Stop Sharing Passwords

One password shared among several people may seem convenient, but it creates unnecessary risk.

Whenever possible, systems should provide individual accounts for each authorized user. This makes it easier to add or remove access without changing credentials for everyone.

It also provides accountability. If several people use the same username and password, determining who made a change can become difficult.

Passwords should also be unique. Using the same password across email, social media, streaming services, and other systems means that a compromised account could expose several others.

Turn On Multi-Factor Authentication

Multi-factor authentication, commonly called MFA, adds another layer of security beyond a password.

If someone obtains a password, MFA can help prevent them from accessing the account without an additional verification step.

However, stations should also think about who controls that verification method. If an account sends every verification code to one employee’s personal phone, what happens when that employee leaves?

Whenever possible, recovery information and authentication methods should remain under organizational control. Backup recovery methods should also be reviewed so the station does not accidentally lock itself out of an important account.

Do Not Forget the Equipment

Digital security does not end with websites and social media.

Modern broadcast equipment is increasingly connected to networks. PTZ cameras, video switchers, encoders, streaming systems, servers, network-attached storage, automation systems, and other devices may have their own administrative passwords.

Default passwords should be changed, and administrative access should be limited to people who actually need it.

Stations should also document important configuration information. If a device fails and has to be replaced, having the necessary information available can save considerable time.

What Happens When Someone Leaves?

This is where having a documented process becomes important.

When an employee, contractor, intern, or volunteer who had access to station systems leaves, their access should be reviewed promptly. Accounts may need to be disabled, passwords may need to be changed, and shared access should be examined.

Waiting until there is a problem is not a good security strategy.

The same principle applies when someone new joins the station. Give people access to what they need to perform their responsibilities rather than automatically providing access to everything.

Final Thoughts

Stations should also periodically review their accounts, even when nobody has left. An annual or semiannual review can uncover old accounts, outdated recovery information, unnecessary access, or services the station no longer uses.

Community television has changed tremendously, and station security has changed with it. Cameras, switchers, servers, streaming platforms, websites, social media, and cloud services have created incredible opportunities, but they have also created more digital assets that stations must manage responsibly.

Every station should periodically ask a few simple questions: What digital accounts do we have? Who can access them? Is multi-factor authentication enabled? Can we recover the accounts if someone leaves? Are important credentials and configurations properly documented?

These are relatively simple questions, but answering them before something goes wrong can save a station considerable time, frustration, and potentially money.

If the answer to “Who has the password?” is only one person’s name, it may be time to take a closer look. 

About the Author

John has worked with technology and media for over 30 years. If your community television station has questions about technology, security, networking, or production infrastructure, he welcomes the opportunity to connect and share ideas.