Dakota Murphey looks at how organisers can digitally safeguard event attendee and vendor data
Many aren’t aware of the sheer volume of sensitive data that passes through large-scale events like trade shows, exhibitions and conferences. From attendee details to payment information and financial records, the amount of data that exists in the realms of a big event (be it virtual, face-to-face, or hybrid) can be enormous.

Unfortunately, organisers and vendors that administer and process this data are often the targets of cybercriminals opportunistically seeking to exploit it. This is why comprehensive and robust digital security is crucial. Safeguarding attendee and vendor data at major events might seem complicated but when you break the individual strategies and steps down, it’s easily executable. This guide outlines all of that and more for your perusal.
Are Events Safe From Cybercrime?
With connected registration systems, vendor networks, and swathes of guest devices onsite, major events are a goldmine for malicious actors. Many organisers underestimate the digital threats that exist throughout the event, and often wrongly assume that events are somehow immune from cyber attacks.
Breaches at events put attendee data, finances, and reputations at risk, especially if vendors and organisers are not prepared. It’s all well and good to attract more attendees, but your event can only be considered successful if it goes off without a hitch.
If compromised, it could be indicative of an imminent PR nightmare for brands, and subsequently, their income and customer trust could be shattered.
Events suffer cyber attacks in various ways, including:
- Malware infecting registration systems to steal attendees’ personal information
- Onsite WiFi networks hacked to syphon off guest traffic and data
- Vendor point-of-sale systems compromised to steal payment info
- Ransomware crippling event IT systems and demanding big payouts
- Phishing emails tricking staff into wiring funds to criminals
- Spoofed emails compromising executive accounts to authorise fraudulent payments
With brands potentially facing losses of nearly £19,400 (DCMS) following a cyber incident, not to mention the prospect of irreparable reputation damage, it’s no wonder events must step up their digital defences pronto.
How to Safeguard Event and Attendee Data
Test Registration and Badging Systems for Vulnerabilities
Events like conferences usually denote attendees and vendors by badges at registration, which usually consist of valuable data when scanned. Names, companies, addresses and contact information can therefore end up stored in event organisers’ systems and in the cloud. It’s therefore pivotal that these systems are tested for vulnerabilities at every endpoint.
Companies can usually get a firmer grip on the security posture of their entire infrastructure with thorough penetration testing services, which encompass registration and badge technologies. In this scenario, skilled ethical hackers simulate targeted cyber attacks to uncover weaknesses in systems (such as unpatched systems, access control vulnerabilities and insufficient encryption), which are then communicated to organisers to then mitigate.
Ideally, if this exercise is conducted before attendees access the data, anyone organising an event can fortify systems and ensure that any captured data is encrypted and not used maliciously. Attackers constantly probe networks for new vulnerabilities which is why continuous monitoring is key during registration and beyond. Therefore, penetration testing should not be considered a ‘one-and-done’ simulation, but something to deploy at various stages as your event organisation scales.
Review Cyber Controls for Onsite Personnel
Face-to-face events like conferences and exhibitions will likely have a plethora of different companies onsite, each with its own incumbent devices and technology to hand. Whether this is construction companies carrying out onsite renovations, caterers, or vendors with their own booths or stands, all carry a cyber security risk.
It would be naive to assume all personnel on site are familiar with cyber security best practices and are well-equipped with optimum security measures. If not, ensure there is a bare minimum standard that all can meet.
This can be done with the following steps:
- Conduct due diligence reviews of potential vendors’ cyber controls, tools and past security performance.
- Mandate a minimum level of compliance and cybersecurity criteria to meet when issuing vendor contracts. For example, stipulate that any onsite devices are encrypted and not open-source, request ISO 27001 certification from vendors, etc.
- Segment vendor networks from other systems. Possibly create guest networks or VPNs for vendors and separate ones for contractors and guests, as an example.
- Employ layered defences like firewalls and 24/7 incident response protocols and intrusion detection between vendor and event networks. This helps prevent lateral movement after breaches.
Encrypt and Limit Data Access
Even virtual and hybrid events collect data that’s attractive to hackers. Ultimately, the more you collect and retain, the more of a prime target you become.
This is why you should take steps to preserve the integrity of your data:
- Encrypt data in transit and at rest, using protocols like TLS and SSL, and encrypt any devices that store data.
- Anonymise transactions and remove personally identifiable information.
- Limit data access to appointed personnel with administrative access, and restrict access for those that don’t need to reach it.
- Securely wipe data once it is no longer needed, per data protection regulations.
Perform Proactive Assessments
Careful and proactive planning is key for creating a digitally secure event; if you wait until the last minute, you could be walking into a proverbial minefield.
Ensure you assess all potential risks and your cyber readiness via:
- Tabletop exercises. Bring your team together to discuss and simulate responses to cyber incidents. Uncover and outline weak points in your response plan, and refine your policies as needed.
- Red teaming. Authorise offsite red team assessments against your systems to find critical flaws before any criminals do.
- Physical evaluations. Check all onsite data and systems for vulnerabilities. Look for unsecured computers, passwords on display, and accessible networks.
Addressing issues identified in these assessments bolsters cyber resilience. You reduce the chances of an incident and improve response capabilities if one does occur.
Secure Networks & Require Strong Authentication
Making your event WiFi network publicly accessible and free to access invites hackers and cybercriminals. This can be one of the most common points of exploitation and puts all connected device holders at risk.
Protect network perimeters and inside access with:
- Strong, unique passwords: These should only be administered to authorised attendees or vendors.
- Firewalls and internet protection tools: Establishing these ensures that inbound and internal traffic is constantly monitored.
- VPNs for remote access: These bolster security for attendees accessing event material and data remotely.
- User permissions: Ensure that you explicitly authorise access to data and networks for specific personnel, such as your IT team.
- Multi-factor authentication (MFA): Where applicable, request any shared systems to prompt users to verify their requests for access, such as one-time codes sent to devices, emails, or biometric verification. MFA is crucial for blocking many thefts and unauthorised access attempts.
- The latest security updates: Patch and update operating systems, apps, and network infrastructure to ensure any known vulnerabilities are accounted for.
Together these measures help stop attackers from infiltrating networks and accessing sensitive data.
With cyber threats only growing, attendee and vendor trust, and reputation depend on stringent and reliable data security. Follow the steps in this article to demonstrate your commitment to protecting information and establishing a solid cyber security posture during your next exhibition or trade show.



