Why Finance Events Need More Security
Virtual events have genuinely made life easier for finance teams. Investors, clients, employees, and everyone can show up without booking a flight or clearing their calendar for an in-person meeting. People log in from wherever they are, which is a big reason these events are so popular.
But for finance teams, getting people into the room (or onto the call, really) is only the first step. There can be sensitive information involved, and the team needs to know who is attending, what is being shared, and where that information goes after the event.
There is also a growing audience for these events, with virtual and hybrid formats making it easier for organizations to reach more people beyond the limits of an in-person venue. Grand View Research expects the global virtual events market to reach $297.16 billion by 2030.
For finance teams, though, getting more people into an event is only part of the job. They also need to consider who can access the event, what information they collect, what they record, and where they send that information afterward.
Finance leaders are also using webinars to educate clients, answer questions, and build trust with their audience.
That makes it important to plan for security from the beginning, rather than treating it as something to check a few hours before going live.
Classify the event before selecting the controls
Not every virtual event carries the same level of risk.
A public webinar about general financial education is different from an investor meeting that discusses financial results. A client-only event is again different if attendees can ask questions about their accounts or investments.
Before setting up the event, ask a few basic questions:
- Who is attending?
- What information will be discussed?
- Will attendees be allowed to speak or ask questions?
- Will personal or financial information be collected?
- Will the event be recorded?
- Who needs access to the recording afterwards?
The answers will help the team decide how much security the event actually needs.
Virtual event data privacy for financial services
A virtual event can collect much more information than people realize.
There may be registration details, attendance records, chat messages, poll responses, questions, recordings, transcripts, and engagement data. Not all of this information is NPI under GLBA. This information becomes relevant to GLBA privacy requirements when it is covered by those requirements, such as certain information about a customer’s financial relationship with a financial institution. This can include account numbers, balances, transaction details or application information.
If the event connects to a CRM or another marketing system, some of this information may also move into another platform.
This stage is where data minimization matters. Finance teams should collect only the information they need and know why they are collecting it, where it is stored, and who can access it.
The FTC’s GLBA Safeguards Rule applies to financial institutions under the FTC’s jurisdiction and requires covered institutions to protect customer information and take steps to ensure that service providers handling it also safeguard that information.
Secure the Platform, Identities, and Integrations
Choosing a webinar platform is not just about the video quality or how many people it can accommodate. The security side is as important when it comes to financial information.
How a platform handles access, stores data, and manages recordings is worth checking. If you want a deeper checklist, selecting a secure webinar platform walks through some of the security checks worth running before you commit to one.
Vendor security questions for webinar platforms
Before you trust a platform with an important finance event, it’s worth having an honest conversation with the vendor. Asking a few simple questions to the vendor can be very helpful:
- Where is the event data actually stored?
- Who has access to it?
- How is the data protected while it’s moving around and while it’s sitting in storage?
- What happens to the recordings after the event ends?
- Can you delete the data once you’re done with it?
- If something does go wrong, what’s the plan? Who do you call, and how quickly do they respond?
- Are other service providers involved in managing the data?
- What security certifications or independent assessments can they provide?
These are basic vendor security questions for webinar platforms that finance teams should ask before handing event data to a third-party provider. The FTC’s Safeguards Rule also includes requirements around monitoring service providers for covered financial institutions.
Use SSO and MFA for authentication.
A password on its own may not be enough when people are joining an event that involves sensitive information.
Single sign-on keeps login access in check, while multifactor authentication adds another layer. That means a stolen password alone still won’t be enough to get someone in.
Hosts, admins, speakers, and moderators especially need this extra layer since they’re the ones who can access event settings or sensitive information.
Give people only the access they need.
Not everyone on your team needs the same level of access.
A moderator just needs to manage attendees and questions. A speaker just needs to present. There’s no real reason to give either of them full admin rights. That’s just a risk you don’t need to take on.
Give people access to what they actually need for their part, and nothing more. That’s the main point of role-based access control.
It can also make things less confusing during the event. If something needs changing, the person handling it can do so without giving the rest of the team access to unnecessary controls.
Review integrations and AI for data sharing.
A webinar platform may connect with a CRM, marketing platform, captioning tool, recording service, or AI feature. Every connection sends event data to another destination.
Before enabling an integration, check what information it receives, where that information goes, who can access it and how long it is stored. This is especially important when another company is handling event or customer information.
AI features need the same kind of checking. If an AI tool creates transcripts, summaries, or notes, the team should know whether those conversations or attendee questions are stored, reused, or sent to another service.
This matters even more when the event includes information that should stay within the organization’s approved systems.
Build Compliance Into the Content
Security is not only about stopping someone from entering the event.
The content itself also needs to be checked.
For financial firms, a presentation, investor communication, or live discussion can contain information that needs to be accurate, approved, and properly recorded. These are regulated communications, so the same care should not stop just because the conversation is happening online.
FINRA Rule 2210 says communications from member firms must be fair and balanced and not misleading. The rule also includes approval and recordkeeping requirements for certain communications.
Get content approved before the event.
Do not wait until the presenter is about to go live to check the slides.
The team should review the presentation, speaker notes, disclosures, landing page, promotional material, polls, and anything else that will be shown during the event.
This content approval process should also make it clear who reviewed the material and when.
Keep a record of what was approved, who approved it and when.
For FINRA member firms, Rule 2210 includes recordkeeping requirements for certain communications.
Make sure speakers know what they can discuss.
Slides get approved, but conversations don’t always stick to the script.
Speakers should know what topics are acceptable and which are not & how to respond if someone asks for investment advice or mentions a customer’s account details. This matters even more during live Q&A, since one unexpected question can send things sideways fast.
FINRA Rule 3110 requires member firms to have supervisory systems and written procedures in place to help ensure that applicable securities laws and FINRA rules are followed.
How to Moderate Q&A During Finance Webinars
Q&A is one of the most useful parts of a finance webinar, but it can create problems if no one checks what comes through.
An attendee might accidentally share an account number, transaction detail, personal information, or something else that should not be made public.
This is why finance teams should have someone reviewing questions before they appear to the audience. A moderated Q&A gives the team a chance to check questions before they share them with everyone.
Questions can be combined, cleaned up, or left out if they include sensitive information. If someone asks about their personal account, the moderator can direct them to the right private channel instead.
It is also worth telling attendees at the beginning of the event not to share account numbers, passwords, transaction details, or other private information in the chat or Q&A.
Moderation is not about stopping people from asking questions. It is about making sure that the questions we answer are safe to share with everyone at the event.
Run a Security-First Event Day
Most teams test whether the camera works, the microphone works, and the presentation loads.
For a finance event, the testing needs to go a little further.
How to prevent unauthorized access to investor webinars
Before the event starts, test the things that could actually cause a security problem.
- What happens if someone forwards the event link?
- Could someone who never registered still gain unauthorized access?
- Does the registration process actually verify who’s signing up?
- Who can share their screen?
- Can attendees access files?
- Does recording start automatically?
- Who can access the recording afterwards?
- Do the Q&A and moderation controls actually work the way they’re supposed to?
- What happens if the main speaker gets disconnected?
NIST recommends measures such as limiting the reuse of access codes, using additional authentication for sensitive meetings, using waiting rooms, monitoring attendees, and turning off features that are not needed. It also recommends limiting who can share their screen and avoiding recording when it is not necessary.
A rehearsal should also include a few things that could go wrong. What happens if an unauthorized person gets in? What happens if confidential information is accidentally shown on screen? Who will stop the session if there is a serious problem?
It is better to answer these questions during a test run than during the actual event.
Have people responsible for different things
One person should not have to manage everything.
For an important event, it helps to have clear roles for the event lead, technical producer, content moderator, and security or compliance contact. Having a simple event runbook can also help everyone know what they are responsible for before the event begins.
Everyone should know who to call if something goes wrong.
Say an attendee starts sharing something they shouldn’t. The moderator can jump on that while the technical producer keeps everything else running smoothly.
Virtual Event Incident Response Plan for Finance Firms
Even with all that prep, something can still go wrong.
The important thing is knowing what to do when it happens.
A virtual event incident response plan for finance firms should answer a few basic questions:
- What happened?
- Who needs to know?
- What needs to be stopped immediately?
- Who can pause or end the event?
- When does the issue need to be passed to security, compliance, or legal teams?
For a small issue, the team may be able to fix it without interrupting the event. If an unauthorized person gets in, they may need to be removed immediately. If someone accidentally shows confidential information, the session may need to be paused.
For a serious security issue, you may need to stop the event and pass it to the security, compliance, or legal team.
The plan should also include the webinar provider’s security contact and escalation process. You do not want to start looking for those details in the middle of an incident.
It is also worth thinking about business continuity. If the main speaker loses their connection or the platform has a technical problem, the team should already know what the backup plan is.
Post-Event Security and Recordkeeping
The work does not stop when everyone leaves the virtual room.
The event may have created a recording, chat messages, Q&A, attendance information, presentations, and other records.
Financial webinar recording and retention policy
Finance teams should decide before the event whether they need to record it and what will happen to the recording afterwards.
Not every event needs to be recorded just because the platform gives you the option.
If a recording is required, it should be moved to the organization’s approved storage or archive rather than being left in the webinar platform indefinitely.
How long it needs to be kept depends on the organization, the type of communication, and the rules that apply.
Firms that fall under FINRA requirements must retain certain communications in accordance with applicable recordkeeping rules. FINRA Rule 2210 requires members to maintain certain retail and institutional communications for the retention period required by SEC Rule 17a-4.
The SEC also has its own rules for how certain broker-dealers need to keep electronic records, including preserving them properly and keeping an audit trail when required.
In short, there is no single retention period for finance webinars. What applies to you depends on your legal, regulatory, and internal rules.
What virtual event records should a financial firm retain?
There is no one list that will apply to every financial firm, but records may include the final presentation, approved communications, recording, chat, Q&A, attendance information, approval details, and other event materials.
The team should decide what to keep before the event and ensure that they move those records to the right storage afterwards.
For firms subject to specific books and records requirements, the retention process should also take into account applicable regulatory requirements and any legal hold that may apply.
Key Security Considerations for Financial Services Webinars
A financial services webinar has to follow certain security and compliance requirements. Here are some things to consider before, during, and after the event.
Before the event
Security should be considered before the webinar starts. Start by classifying the event and identifying the attendees. Limit the information you require on registration forms to what you really need, and use the level of authentication appropriate to your audience and type of event.
Check user roles and permissions before the event. Check the integrations connected to the webinar platform, including AI tools. Ensure they are suitable for the event and access is restricted to only what is truly required. Presentation and promotional content should also be reviewed and approved prior to the webinar.
If the webinar will be recorded, consider whether that is necessary, where the recording will be stored, and how long it will be kept. Assign specific roles to the people running the event so it’s clear what they’re supposed to do. Perform a security rehearsal before going live to ensure access controls, permissions, sharing settings, and the response plan are functioning as expected.
At the event
Once the webinar starts, be sure to keep an eye on who’s joining and only let the right people in. Screen sharing should be limited to speakers, presenters, and those who truly need it. Someone else from the team should also monitor the chat and Q&A during the session.
Remind attendees not to provide account numbers, passwords, or other private information in the chat or Q&A. The team should also watch for anyone who shouldn’t be in the session and keep a private channel open to communicate during the event.
All participants should already know how to act if something goes wrong. The response plan must be defined before the webinar, not during an incident. If needed, the team should be ready to remove a person from the session, limit their access, or pause the webinar until the issue is resolved.
Post-event
When the webinar is finished, move the recording, and any other important records of the event to proper storage. See who still has access to the recording and review the event and access logs to see if anything needs attention.
Look through the chat and Q&A for any sensitive information that someone may have shared. It is also worth checking what information was collected during the event & where that information went. Remove information that is no longer required if your retention policy allows it, but check for any legal hold.
Lastly, if anything went wrong during the webinar, note it and discuss how to improve. Take those lessons and update your approach before the next event.
Final Thought
Virtual events make it easier for finance teams to reach investors, clients and other audiences, but they also require managing more information.
A secure event is not just about one setting on a webinar platform. It involves checking who gets access, reviewing what is being shared, monitoring the Q&A, knowing what to do if something goes wrong, and storing the right records afterwards.
Good finance webinar security starts before the event goes live. Following a secure virtual event checklist for finance teams, from planning through to closing out, is what actually reduces the chances of a small slip turning into a real problem.
FAQs
No. A webinar platform is not automatically FINRA compliant. Compliance depends on the platform’s capabilities, your firm’s configuration, how the platform is used and your firm’s applicable supervisory and recordkeeping requirements.
Record events only when there is a business or compliance need to retain them.
Avoid sharing personal or confidential account information in public Q&A.
Look for certifications such as SOC 2 and ISO 27001, depending on your firm’s requirements.
Keep relevant recordings, attendee details, communications, and other records required by your policies and regulations.
Related Reads
If you’re working out the content for a finance webinar, understanding audience needs in finance industry webinars is a good way to see what finance audiences actually expect and how to keep them engaged.
Are you trying to build more trust with clients through your webinars? building trust through finance webinars covers that topic.
And if you’re still weighing up platforms, selecting a secure webinar service walks through some of the security features worth checking.