Advice for small and medium-sized organisations on choosing, setting up and using online meeting services safely
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Advice for small and medium-sized organisations on choosing, setting up and using online meeting services safely
Drazen_ via Getty Images
Online meetings rely on digital tools to support collaboration, but they also introduce security risks. This guidance – aimed at small and medium-sized organisations – outlines steps to keep your online meetings secure; to protect sensitive information and reduce the risk of cyber attacks.
For broader support on securing your organisation, you should visit the NCSC’s Cyber Action Toolkit.
If you use an IT provider, refer to our Managed Service Providers (MSP) guidance to ensure your devices are being secured effectively.
Follow these steps to secure your online meeting services.
Choose a service that works for you:
Only download apps from trusted sources like the Apple App Store, Google Play, or the provider’s official website. Avoid clicking on ads and unsolicited links, which may lead to malicious sites.
Once you’ve selected your service, it's important to secure your account and control who can join your online meeting by following the below steps. For specific instructions, refer to the vendor support website of the service you're using.
Use a strong, unique password.
Enable two-step verification (2SV).
Use passkeys where the provider makes them available.
Keep your app up to date.
Only allow direct access to authenticated users and invited guests.
Require passcodes for unauthenticated users.
Use a waiting area (often referred to as the ‘lobby’) to verify participants before admitting.
Consider blocking calls from outside your organisation and from unknown contacts.
Never share meeting links or passwords in public spaces. If someone joins and you don’t recognise them, politely ask who they are before continuing.
Check your surroundings before joining a call and consider using a background blur or an image for privacy.
Get familiar with basic controls like muting your microphone, turning off your camera, and spotting when a meeting is being recorded.
Review and adjust privacy settings to suit your needs before use.
Know where recordings, transcriptions, chat logs and shared files are stored.
Be aware of AI attendees - these tools may record, transcribe, or analyse meeting content. Understand what data they collect, how it’s used, and whether you can opt out.
Check who has access to your data and how long it is retained. Only individuals and systems who genuinely need the information should be able to access it, and you should only keep personal data for as long as you have a clear reason to.
