JULY 9, 2026

Have the broadcast newsroom norms changed forever?

Broadcast organizations have spent the past several years expanding support for remote and distributed production workflows. And despite some challenges along the way, the industry has proven that flexible, location-independent work is not only possible, but often preferable.

Key takeaways

Broadcast newsroom workflows are shifting to remote and cloud-based models, making traditional VPN-only security insufficient. Broadcasters are now adopting a zero-trust approach, where every access request is continuously verified to protect distributed teams and complex environments.

  • Move beyond VPNs to zero-trust security
  • Verify every user, device, and access attempt
  • Limit access to only required applications
  • Audit all assets: users, devices, data, services
  • Strengthen identity policies
  • Use layered, segmented security to prevent lateral attacks
  • Continuously monitor and respond to threats

While some aspects of traditional workflows remain, things are not going back entirely to the way they were. With a lasting shift in work culture and expectations, now is the time for broadcasters to ensure their networks are built for a secure, remote-capable newsroom. That is where the zero-trust security model comes in.

Read where zero-trust fits to help secure the media supply chain.

Broadcasters are at a crossroads

For decades, virtual private networks (i.e. VPNs) have been the standard for giving remote workers access to an organization’s network and applications. But there has been an acknowledgement for some time that this needs to change. For a number of years, the US National Institute of Standards and Technology (NIST) has pointed to the expanded ways users access company resources and the continued evolution of cyber threats.

NIST has consistently warned that VPNs alone are no longer sufficient to secure the complex mix of internal networks, remote devices, and cloud services that power today’s far-flung teams of staff reporters, stringers, producers, editors, and post-production facilities and transmission infrastructure.

ITV News in the UK have multiple newsrooms across the country, delivering both regional and national news. Discover their story-centric workflow.

Traditionally, broadcasters have preferred to isolate critical assets physically by keeping them in secured facilities accessed by badged personnel. Most organizations have used or still use company-managed hardware for storage and workflows. But many of these processes and procedures are not well suited to a highly distributed, cloud-connected operating environment.

Rather than relying primarily on VPNs, NIST recommends a move to the zero-trust security model, and many organizations have either adopted or are actively implementing zero-trust principles as part of their broader security strategy.

VPNs or zero-trust?

VPNs use a model known as perimeter security. They are like a security guard or physical access control system at the entrance to your building. The idea is that everything inside the perimeter is considered safe. Anyone working outside the network uses the VPN to penetrate the perimeter. The assumption with VPN security is that anyone with the proper login credentials is a trusted actor—but this doesn’t account for compromised credentials or threats originating inside the network.

This is where a zero-trust security strategy can help. Unlike VPNs, a zero-trust approach assumes nothing: Every request is treated as a potential threat. Only by evaluating multiple signals on a per-access basis can you determine that access is both authentic and authorized. Zero trust is a key part of Avid’s security strategy. Find out more about that here.

Rather than giving every remote user broad network access, each person connects only to the specific applications and services they need. Access decisions are based on identity, device health, location, and context. For example, a freelance editor could access a media asset management system from her home network, but if she logged in from an unfamiliar location, she might be required to complete additional authentication.

Zero-trust architecture protects against insider and external attacks in ways a VPN cannot. Once an attacker gains access via a VPN, lateral movement across systems is often possible. These attacks are difficult to contain with a perimeter-only model. In contrast, a zero-trust approach uses continuous verification across multiple data points (identity, role, network context, etc.), making it far easier to detect and block suspicious behavior before damage occurs.

Decision points for a distributed broadcast workforce

Aside from security, VPNs are not always sophisticated enough to support a highly distributed broadcast workforce and the growing ecosystem of freelancers, contractors, and external partners. Bandwidth can also be a constraint. Modern media workflows—especially those involving high-resolution video, cloud or hybrid-cloud editing, and real-time collaboration—can require significant throughput. Some of this can be mitigated, of course, through the use of proxy resolutions.

If all that traffic is routed through centralized VPN infrastructure, performance bottlenecks and cost increases can follow. One way to strengthen VPN security is to restrict access to company-managed devices. However, supporting a fully managed hardware fleet can be expensive, particularly in environments that rely on freelancers or bring-your-own-device (BYOD) models.

That said, VPNs can still play a role in the short term, especially where existing system infrastructure or rapid expansion of remote access are factors. The main advantage is that most organizations already have VPN infrastructure in place.

The zero-trust journey

Implementing zero-trust takes time. It’s not a single technology like a VPN; it’s a strategic model that requires architectural change—a different way of planning IT infrastructure, assets, and workflows. Making the shift involves coordination across software, hardware, and cloud service providers.

This does not mean starting from scratch. Many organizations already have components of zero-trust in place, such as identity management, multi-factor authentication, and device compliance policies. Adopting zero-trust is an iterative process, with each layer building on the last.

1. Survey your technical architecture

The most critical step is the first: Take stock of the core business assets with a full inventory of users, devices, services, and data. In a zero-trust model, you need clear visibility into what you are protecting and how.

2. Define an identity policy

Determine who has access and how you verify identity. This goes beyond usernames and passwords. Consider device trust, freelance access, BYOD scenarios, and machine-to-machine interactions such as APIs. Define what signals are required to confidently validate every access request.

3. Create a strategy for defining good behavior

Establish baselines for normal activity across users, devices, and applications. This includes ensuring that systems are running verified software and configurations. Combine multiple factors to validate legitimacy, like secure communication protocols, certificate-based authentication, identity frameworks, and behavioral analytics. Unusual activity, such as access from a new region or outside expected hours, should trigger additional scrutiny.

4. Systematically and iteratively re-architect

Move toward a layered security approach in which each layer (i.e. identity, application, network) enforces authentication and authorization. Segment networks and minimize opportunities for lateral movement. Assume the network is already compromised and design to limit the impact.

5. Proactively monitor activities in your network

Modern zero-trust strategies rely heavily on continuous monitoring and analytics. The goal is not just to detect breaches, but also to identify and contain threats in real time. Focus on high-value assets and commonly targeted systems and use as many contextual signals as needed to validate each access attempt.

Get actionable security insights from Avid’s Ilia Murjev in this downloadable guide.

Adjusting to the new security normal

There are two key aspects to today’s security reality. First, the traditional network perimeter is no longer a reliable control point. Users, devices, and applications now operate across cloud, on-premises, and edge environments. Second, organizations must assume compromise and design systems to minimize blast radius.

The goal of a zero-trust strategy is to block attackers from moving freely while enabling seamless, secure access for legitimate users. This shift in mindset is essential in today’s threat landscape, where attacks are more sophisticated and persistent.

Flexible and distributed working patterns are now a permanent feature of the broadcast industry. As a result, security strategies must evolve accordingly. Zero-trust is no longer emerging—it’s quickly becoming the standard. For broadcasters still relying heavily on VPNs, it may be time to rethink.

Avid’s approach to security in Avid Content Core

Learn more
  • © 2026