Just under a year ago Videri made some big changes to their leadership team to support the business strategy, including on the Product team. Enter Marco Pasqual, VP of Software Development at Videri. With over 20 years working in technology, 15 of those years dedicated to digital signage, Pasqual brought a fresh perspective that has already delivered significant benefits for Videri during his short tenure. His most recent action was to create the Videri Vulnerability Disclosure Policy.
We interviewed him to find out a bit more, starting with “why is this such a priority for you”?
"Establishing a Vulnerability Disclosure Policy is about maintaining customer trust, giving our users confidence in the security of our platform, and building a strong foundation for our continued growth”
Marco Pasqual, VP Software Development, Videri, Inc.
“At Videri, security is foundational. No matter how efficient or user-friendly our platform is, it holds no value if we don’t ensure the highest standards of security. A vulnerability could not only affect our technology but also erode the trust we’ve built with our customers and partners. Establishing a Vulnerability Disclosure Policy is about maintaining customer trust, giving our users confidence in the security of our platform, and building a strong foundation for our continued growth” stated Pasqual.
Do all digital display/software companies have a policy like this?
Videri is leading the way in digital signage and software security with this policy. While security policies are becoming more common in the tech industry, many digital signage companies still lack formal guidelines for vulnerability disclosures. By taking proactive steps in this area, we’re not only setting a standard but also demonstrating that security is a priority at Videri and that we welcome and value collaboration with the security community.
Are there specific items in the policy that you would like to highlight?
Pasqual highlighted 3 key components that demonstrate our dedication to security and transparency:
- Commitment to Non-Retaliation: We pledge not to pursue legal action against anyone who follows the policy in good faith, creating a safe avenue for researchers to share their findings with us.
- Clear Communication Channels: We’ve established straightforward ways for security researchers to report vulnerabilities directly, ensuring they know exactly where to go and that their submissions are welcomed.
- Coordination and Transparency: Our policy aligns with industry best practices, allowing us to coordinate disclosures responsibly while keeping the public and our stakeholders informed.
Is a policy like this a statement of confidence in our security performance?
Absolutely. Our Vulnerability Disclosure Policy reflects both our confidence in the security of our platform and our commitment to continuous improvement. It’s not only about reassuring customers that we prioritize security; it’s about fostering a culture where we constantly adapt, evolve, and engage with the security community to make Videri’s platform as resilient as possible.
What do you see as the top digital signage security threats in the industry today?
- Data Breaches – When unauthorized individuals gain access to sensitive information stored in digital signage systems.
- Unauthorized Access – These occur when devices on-site are not tamper-proof, or via software management systems.
- Malware and Ransomware – When malicious software is designed by hackers to infiltrate digital signage networks to steal or corrupt data and interrupt functionality.
- Network Attacks – Cloud-supported displays use the internet, making them susceptible to network attacks that seek to flood the network with excessive traffic, overwhelming the system and causing it to crash.
As stated right in the Vulnerability Disclosure Policy itself, Videri welcomes feedback from security researchers and the general public to help with our ongoing improvement efforts. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us.
For more information about Videri reach out to info@videri.com.