Skip to content
Read our 2025 Mid-Year Update
  • About
  • Our Approach
  • Companies
  • Team
  • K1 Careers
  • Portfolio Careers
  • Media
  • Contact K1
Follow us on LinkedIn
Insights July 3, 2020

To Zoom or Not to Zoom: Addressing a Crucial Cybersecurity Question

Eight tips to help advisors balance between security and convenience with Zoom.
To Zoom or Not to Zoom: Addressing a Crucial Cybersecurity Question

This post was originally published by Sid Yenamandra at Smarsh.

Eight tips to help advisors balance between security and convenience with Zoom

Though shelter-in-place orders and working from home have become the new normal, the reality is that most businesses are not prepared to protect their employees and their devices from cyber criminals in a remote work environment. That’s especially true for the wealth management industry.

Let’s start with the fact that most employee-owned devices are not appropriately protected. Many broker-dealers, banks, insurance companies and RIA firms have stepped up their efforts to address some of the most glaring weaknesses. But for others, cybersecurity issues are only becoming more challenging as a surge of professionals flock to Zoom and other video conferencing platforms to meet with clients and collaborate with colleagues.

How Financial Services Firms Can Vet Zoom

Indeed, very few IT managers have had the opportunity to vet these tools, even as they are now known to present a series of security and compliance challenges.

Wealth management professionals are gauging how much risk the use of the Zoom platform introduces. Here are eight tips to keep you and your organization safe on Zoom:

  • Use the latest version. Be sure you are always using the latest version of the application so that your endpoint is protected against known security issues.
  • Never share your Zoom meeting ID publicly. Posting meeting IDs publicly makes it easy for hackers to infiltrate your account by guessing your password. This could result in “zoombombing” or someone getting access to your private chat transcripts or files.
  • Share your meeting password securely. Treat your Zoom meeting password the same way as you would treat your sign-in credentials for your bank account or company workspace. Also, use two-factor authentication, which dramatically lowers the likelihood of getting compromised.
  • Set preferences to host-only. Resist the temptation to designate a co-host, because it increases the likelihood that a breach could take place. What’s more, shut off file transfer, camera and audio settings for all participants. That leaves one person in control of the conference. The end goal is to minimize the possibility that an interloper could gain access.
  • Pay for the enterprise plan. If you are relying on Zoom for business, it’s better to upgrade to the pro or enterprise plans rather than using freemium services.
  • Beware of Zoom phishing emails. If you get a meeting invite from someone with whom you are not familiar, you can log in to the call by connecting to the Zoom website and then manually keying in the meeting ID. That will ensure that the invite is valid. Otherwise, it could be a phishing email aimed at getting you to click a link that will end up harming your device.
  • Perform endpoint hygiene. Patch the endpoints used to access Zoom with up-to-date anti-virus and anti-malware software and make sure to enable device or file-level encryption. These steps will not only help to prevent compromises, but they will serve to mitigate the damage should they occur.
  • Use VPN when possible. This minimizes the likelihood of a man-in-the-middle or denial-of-service attack that could disrupt your productivity. VPNs could create some network bottlenecks, especially if you don’t have much bandwidth to spare, but they will ensure that your sessions have end-to-end encryption, something that most regulators require.

To Zoom or not to Zoom? For wealth management professionals who need to drive as much continuity of service and connection with clients and colleagues, this is an important cybersecurity question.

But by following the right cybersecurity safeguards as outlined here, it doesn’t need to become an existential question for your business.

About the Author
Sid Yenamandra, Founder & CEO at Entreda

Sid Yenamandra co-founded Entreda, the leading provider of comprehensive cybersecurity software, systems and training to the wealth management industry, in 2011 and oversees all aspects of the company’s vision and day-to-day operations. Prior to Entreda, Sid served as vice president of product and business development at Plato Networks, which he sold to Netlogic Microsystems and subsequently was acquired by Broadcom for $4 billion. Prior to Plato Networks, Sid worked on several Silicon Valley ventures and was part of an elite, NSA-funded team that developed a Suite B flow-through cryptographic processor to protect critical U.S. infrastructure. Sid holds Bachelor of Science degrees in Electrical Engineering and Computer Science from University of California Berkeley.

Share This Post

Recent News

View All
Award

K1 Named Top Private Equity Firm of 2025 by GrowthCap

August 20, 2025
Award

K1 Named to Inc.’s 2025 Founder-Friendly Investors for 6th Consecutive Year

Read more
November 15, 2025
Award

30 K1 Portfolio Companies Make the 2025 Inc. 5000 List

Read more
August 13, 2025
View All
Award

K1 Named Top Private Equity Firm of 2025 by GrowthCap

August 20, 2025
Award

K1 Named to Inc.’s 2025 Founder-Friendly Investors for 6th Consecutive Year

Read more
November 15, 2025
Award

30 K1 Portfolio Companies Make the 2025 Inc. 5000 List

Read more
August 13, 2025
About
  • About Us
  • Contact K1
Our Approach
  • Our Approach
Media
  • Press Releases
  • Awards & Appearances
Companies
  • Our Companies
Team
  • Team
  • K1 Careers
  • Portfolio Careers
  • Follow us on LinkedIn

Certain statements about K1 Investment Management LLC (“K1”) made by portfolio company executives herein are intended to illustrate K1's business relationship with such persons, including with respect to K1's facilities as a business partner, rather than K1's capabilities or expertise with respect to investment advisory services. Portfolio company executives were not compensated in connection with their participation, although they generally receive compensation and investment opportunities in connection with their portfolio company roles, and in certain cases are also owners of portfolio company securities and/or investors in K1-sponsored vehicles. Such compensation and investments subject participants to potential conflicts of interest in making the statements herein. For K1, “carbon neutral” means that any greenhouse gas (GHG) emissions derived from a defined scope of K1’s activities are balanced by an equivalent amount removed, including through our purchase of carbon credits. In this report, our “carbon neutral” status is based on our GHG emissions footprint calculated in accordance with the GHG Protocol as of December 31st, 2023 (comprising Scope 2 Electricity and Gas usage and certain Scope 3 categories: Business Travel and Employee Commuting), amounting to an estimated 3,497 metric tons CO2e. K1 then purchased and applied carbon credits in 2024, amounting to an estimated 6,994 metric tons of CO2e. We engaged a third party to assist with the calculation of K1’s estimated GHG emissions for 2023, but we did not obtain independent, third-party verification of our “carbon neutral” status. To address our 2023 emissions, we contributed to the Conservación y Captura de Carbono / Conservation and Carbon Capture (CO2LTZINGO) reforestation carbon removal project in Coltzingo, Mexico (CAR 1464). This project was certified by the Climate Action Reserve (CAR), using the Protocolo Forestal para México (PFM) Versión 1.5 / Mexico Forest Protocol Version 1.5 and the Guía de Cuantificación de Acervos de Carbono y Monitoreo del Proyecto Versión 1.5 / Project Monitoring and Carbon Stock Quantification Guidance Version 1.5 with a validation date of January 15th, 2019.

© 2025, K1 Investment Management

Legal Disclaimer Privacy Policy
BACK TO TOP