Articles

Configuring Cisco Webex Collaboration for Secure Deployment

John Ciarlone John Ciarlone
6 minute read

In April 2026, Cisco disclosed CVE-2026-20184, a critical flaw affecting Cisco Webex collaboration tools through Webex's single sign-on integration with Control Hub. The vulnerability, rated 9.8 on the CVSS scale, stemmed from improper certificate validation and could let an unauthenticated attacker impersonate any user with a crafted token. Cisco patched its side of the service, but any organization using SSO still had to generate and upload a new SAML certificate to Control Hub to close the gap. There was no workaround.

That's the reality of running Cisco Webex collaboration at scale. The platform ships with strong security controls, but those controls only protect your organization if someone configures and maintains them. This guide covers what Webex includes, the security features already built in, and how to configure them so your deployment doesn't depend on Cisco catching every gap for you.

What Webex Includes And How Control Hub Manages It

Cisco Webex collaboration covers three core products, with Control Hub as the single admin console tying them together:

  • Webex Meetings: Video conferencing and virtual meetings

  • Webex App: Messaging, screen sharing, and file sharing

  • Webex Calling: Cloud voice

  • Control Hub: The console where you manage users, devices, policies, and security settings across all three

Organizations in education, healthcare, and professional services all run Webex for the same reason: one dashboard now governs a bigger share of daily operations, which means one dashboard also carries more security weight. 

Security Risks in an Unconfigured Webex Deployment

A default Webex deployment isn't a secure one. Left unconfigured, each of the following turns a routine meeting or a standard offboarding into a real exposure point:

  • Unlocked Personal Meeting Rooms: Ship without passwords or waiting rooms, so anyone with the link can join

  • Unrestricted external file sharing: On by default, so users can send sensitive documents outside the organization without a second thought

  • No MFA enforcement: Single-factor logins remain valid until an admin turns MFA on

  • Orphaned accounts: Access doesn't revoke itself when an employee leaves; deprovisioning is a manual or directory-synced step

Security Features Built Into Webex 

Webex includes meaningful security controls once you turn them on. They’re built into the platform’s architecture, available the moment you enable them:

  • Encryption: SRTP for meeting media and a Key Management Server (KMS) for stored content

  • Federated SSO: SAML 2.0 support for identity providers your team likely already runs, including Azure AD, Okta, Ping Identity, and ADFS

  • Native MFA: Built into Control Hub, not a third-party bolt-on

  • Meeting Locks And Waiting Rooms: Host-controlled access at the session level

  • Compliance Officer Role: eDiscovery access for legal and retention needs

  • Admin-level Policy Controls And DLP Settings: Covered in detail below

Webex Licensing and Prerequisites for Security Features

Not every security feature is available on every plan. Confirm these before you build a configuration checklist around them:

  • Waiting rooms: Typically require a paid plan

  • eDiscovery retention beyond 90 days: Requires the Pro Pack add-on

  • Real-time file inspection: Requires the Pro Pack add-on

  • Native DLP: Doesn't exist as content-scanning DLP; Webex natively supports domain restrictions and space classification only. Full content scanning requires connecting a third-party DLP or CASB platform through the Events API

If your organization needs full DLP coverage, plan for the integration, not just the Webex license. Actual licensing needs may vary based on deployment size and features used, so confirm current plan requirements with your account team before finalizing a rollout.

How To Configure Security Settings 

Everything above is context. This section is where you actually lock the platform down, working through Control Hub in three areas: meetings, user access, and messaging.


If you’re configuring from scratch, work top to bottom in Control Hub: set organization-wide defaults first, then tighten per-group policies where a team needs stricter rules. The settings below are the ones that matter most for keeping a deployment locked down as it grows.

Meeting Security Controls 

Personal Meeting Rooms deserve a specific callout. Unlike scheduled meetings, they don't reset their settings automatically, so a room set up loosely once tends to stay that way.

  • Require a password for every meeting

  • Turn on the waiting room by default

  • Lock meetings once all attendees have joined

  • Limit screen and file sharing to hosts by default

  • Review Personal Meeting Room settings on a recurring schedule, not just at setup

User Access And Permissions 

Permissions drift over time as roles change. A scheduled review catches that drift before it becomes a liability.

  • Enable MFA for all users, not just admins

  • Assign role-based access instead of blanket admin rights

  • Deprovision accounts immediately when employees leave, tied to directory sync through SCIM or AD

  • Audit user permissions on a set schedule

Messaging And File Sharing Security

You have to assign the Compliance Officer role deliberately before eDiscovery and legal hold will work.

  • Set retention policies for messages and files

  • Restrict external sharing to approved domains

  • Assign a Compliance Officer for eDiscovery and legal hold

  • Enable DLP rules to flag sensitive data through a connected CASB or DLP integration, since Webex doesn’t run this natively

  • Monitor shared file activity through admin reporting

Maintaining Webex Security After Initial Setup

Configuration isn't a one-time project. Most exposures trace back to a setting nobody revisited, not a flaw in the platform itself:

  • Review Control Hub settings on a recurring schedule: Defaults can shift with product updates, and new features often launch without security controls turned on

  • Patch the Webex App and connected room and desk devices: Treat them like any other endpoint on your network

  • Subscribe to Cisco's security advisories: You hear about issues like CVE-2026-20184 the day they're disclosed, not weeks later

  • Run basic user training: Password hygiene and meeting settings, on a recurring cadence

Common Security Mistakes to Avoid

Most Webex security gaps come down to a handful of repeat mistakes:

  • Leaving Personal Meeting Rooms unlocked: An open door that never closes on its own

  • Giving Every User Admin-Level Access: One compromised account becomes a full-environment risk

  • Skipping Software Updates: Known vulnerabilities stay open long after a patch exists

  • Assuming DLP Works Automatically: Without a real CASB or DLP integration, sensitive files can leave with nobody noticing

FAQs

Is Cisco Webex compliant with regulations like HIPAA and SOC 2?

Yes, though it depends on your environment. Webex holds SOC 2, ISO 27001, and supports HIPAA when you sign a Business Associate Agreement with Cisco and configure it correctly. Standard commercial Webex is not FedRAMP authorized, so public-sector teams that need to run Webex for Government, a separate environment. Compliance capability is not the same as compliance by default; the configuration still has to match the requirement.

When we use SSO, do we enforce MFA in Webex or in our identity provider?

At your identity provider. Once you configure SAML single sign-on in Control Hub, Webex hands authentication to your IdP, so Azure AD, Okta, or Ping is where you set and enforce the MFA policy. Webex's native MFA mainly applies to accounts that authenticate directly against Control Hub without SSO. Enabling both without understanding which one governs login is a common source of confusion.

Does Webex encryption mean Cisco can't see our meeting content?

Not by default. Standard Webex encryption (SRTP for media, KMS for stored content) protects data in transit and at rest, but Cisco manages the keys. For meetings where no third party should ever hold the keys, Webex offers a separate end-to-end encryption mode you turn on deliberately. It raises the security bar but disables features that depend on server access, including cloud recording, dial-in phone audio, and browser-based joining, so it's a per-use tradeoff.

Do these security settings still apply when people join from personal or unmanaged devices?

Your Control Hub policies (meeting passwords, waiting rooms, sharing restrictions) apply to everyone regardless of device. What personal devices change is endpoint risk: an unpatched laptop or an unmanaged phone sits outside your control. Pair the Webex settings above with device posture checks or MDM enrollment for managed access, and lean on SSO so identity, not the device, is what grants entry.

Does Webex Calling need separate security attention from meetings?

Yes. Meeting locks and waiting rooms don't touch voices. Webex Calling has its own considerations: toll-fraud protection through call-restriction policies, securing any SIP trunk or PSTN gateway integration, and applying the same role-based access and MFA to calling admins. If you've rolled out cloud voice alongside meetings, treat it as its own configuration surface rather than assuming the meeting settings are carried over.

Closing Configuration Gaps With Hummingbird Networks 

Webex security gaps usually develop when nobody revisits the configuration as the environment changes. New users, updated permissions, additional devices, licensing changes, and third-party integrations can all introduce gaps that are easy to overlook. Hummingbird Networks can help IT teams assess their existing Webex environment, identify configuration and access issues, and determine whether the right security controls are in place.

Our team can also help align Webex licensing, identity and access controls, meeting policies, and security integrations with your organization's requirements. Whether you're addressing an existing configuration gap or preparing for a broader Webex rollout, a structured review can help your team strengthen security without disrupting day-to-day collaboration.

Work With Us on Your Webex Deployment

Hummingbird Networks can support your team in configuring, reviewing, and maintaining a secure Webex environment, whether you're deploying Webex for the first time or strengthening an existing setup. Our team can help align security controls, licensing, identity management, and integrations with your organization's collaboration and security requirements. 

Need help securing your Webex environment? Talk with Hummingbird Networks about your deployment, configuration, and collaboration requirements.

« Back to Articles