Articles

Configuring Cisco Webex Collaboration for Secure Deployment

John Ciarlone John Ciarlone
6 minute read

In April 2026, Cisco disclosed CVE-2026-20184, a critical flaw affecting Cisco Webex collaboration tools through Webex's single sign-on integration with Control Hub. The vulnerability, rated 9.8 on the CVSS scale, stemmed from improper certificate validation and could let an unauthenticated attacker impersonate any user with a crafted token. Cisco patched its side of the service, but any organization using SSO still had to generate and upload a new SAML certificate to Control Hub to close the gap. There was no workaround.

That's the reality of running Cisco Webex collaboration at scale. The platform ships with strong security controls, but those controls only protect your organization if someone configures and maintains them. This guide covers what Webex includes, the security features already built in, and how to configure them so your deployment doesn't depend on Cisco catching every gap for you.

What Webex Includes And How Control Hub Manages It

Cisco Webex collaboration covers three core products, with Control Hub as the single admin console tying them together:

  • Webex Meetings: Video conferencing and virtual meetings

  • Webex App: Messaging, screen sharing, and file sharing

  • Webex Calling: Cloud voice

  • Control Hub: The console where you manage users, devices, policies, and security settings across all three

Organizations in education, healthcare, and professional services all run Webex for the same reason: one dashboard now governs a bigger share of daily operations, which means one dashboard also carries more security weight. 

Security Risks in an Unconfigured Webex Deployment

A default Webex deployment isn't a secure one. Left unconfigured, each of the following turns a routine meeting or a standard offboarding into a real exposure point:

  • Unlocked Personal Meeting Rooms: Ship without passwords or waiting rooms, so anyone with the link can join

  • Unrestricted external file sharing: On by default, so users can send sensitive documents outside the organization without a second thought

  • No MFA enforcement: Single-factor logins remain valid until an admin turns MFA on

  • Orphaned accounts: Access doesn't revoke itself when an employee leaves; deprovisioning is a manual or directory-synced step

Security Features Built Into Webex 

Webex includes meaningful security controls once you turn them on. They’re built into the platform’s architecture, available the moment you enable them:

  • Encryption: SRTP for meeting media and a Key Management Server (KMS) for stored content

  • Federated SSO: SAML 2.0 support for identity providers your team likely already runs, including Azure AD, Okta, Ping Identity, and ADFS

  • Native MFA: Built into Control Hub, not a third-party bolt-on

  • Meeting Locks And Waiting Rooms: Host-controlled access at the session level

  • Compliance Officer Role: eDiscovery access for legal and retention needs

  • Admin-level Policy Controls And DLP Settings: Covered in detail below

Webex Licensing and Prerequisites for Security Features

Not every security feature is available on every plan. Confirm these before you build a configuration checklist around them:

  • Waiting rooms: Typically require a paid plan

  • eDiscovery retention beyond 90 days: Requires the Pro Pack add-on

  • Real-time file inspection: Requires the Pro Pack add-on

  • Native DLP: Doesn't exist as content-scanning DLP; Webex natively supports domain restrictions and space classification only. Full content scanning requires connecting a third-party DLP or CASB platform through the Events API

If your organization needs full DLP coverage, plan for the integration, not just the Webex license. Actual licensing needs may vary based on deployment size and features used, so confirm current plan requirements with your account team before finalizing a rollout.

How To Configure Security Settings 

Everything above is context. This section is where you actually lock the platform down, working through Control Hub in three areas: meetings, user access, and messaging.


If you’re configuring from scratch, work top to bottom in Control Hub: set organization-wide defaults first, then tighten per-group policies where a team needs stricter rules. The settings below are the ones that matter most for keeping a deployment locked down as it grows.

Meeting Security Controls 

Personal Meeting Rooms deserve a specific callout. Unlike scheduled meetings, they don't reset their settings automatically, so a room set up loosely once tends to stay that way.

  • Require a password for every meeting

  • Turn on the waiting room by default

  • Lock meetings once all attendees have joined

  • Limit screen and file sharing to hosts by default

  • Review Personal Meeting Room settings on a recurring schedule, not just at setup

User Access And Permissions 

Permissions drift over time as roles change. A scheduled review catches that drift before it becomes a liability.

  • Enable MFA for all users, not just admins

  • Assign role-based access instead of blanket admin rights

  • Deprovision accounts immediately when employees leave, tied to directory sync through SCIM or AD

  • Audit user permissions on a set schedule

Messaging And File Sharing Security

You have to assign the Compliance Officer role deliberately before eDiscovery and legal hold will work.

  • Set retention policies for messages and files

  • Restrict external sharing to approved domains

  • Assign a Compliance Officer for eDiscovery and legal hold

  • Enable DLP rules to flag sensitive data through a connected CASB or DLP integration, since Webex doesn’t run this natively

  • Monitor shared file activity through admin reporting

Maintaining Webex Security After Initial Setup

Configuration isn't a one-time project. Most exposures trace back to a setting nobody revisited, not a flaw in the platform itself:

  • Review Control Hub settings on a recurring schedule: Defaults can shift with product updates, and new features often launch without security controls turned on

  • Patch the Webex App and connected room and desk devices: Treat them like any other endpoint on your network

  • Subscribe to Cisco's security advisories: You hear about issues like CVE-2026-20184 the day they're disclosed, not weeks later

  • Run basic user training: Password hygiene and meeting settings, on a recurring cadence

Common Security Mistakes to Avoid

Most Webex security gaps come down to a handful of repeat mistakes:

  • Leaving Personal Meeting Rooms unlocked: An open door that never closes on its own

  • Giving Every User Admin-Level Access: One compromised account becomes a full-environment risk

  • Skipping Software Updates: Known vulnerabilities stay open long after a patch exists

  • Assuming DLP Works Automatically: Without a real CASB or DLP integration, sensitive files can leave with nobody noticing

Closing Configuration Gaps With Hummingbird Networks 

Webex security gaps usually develop when nobody revisits the configuration as the environment changes. New users, updated permissions, additional devices, licensing changes, and third-party integrations can all introduce gaps that are easy to overlook. Hummingbird Networks can help IT teams assess their existing Webex environment, identify configuration and access issues, and determine whether the right security controls are in place.

Our team can also help align Webex licensing, identity and access controls, meeting policies, and security integrations with your organization's requirements. Whether you're addressing an existing configuration gap or preparing for a broader Webex rollout, a structured review can help your team strengthen security without disrupting day-to-day collaboration.

Work With Us on Your Webex Deployment

Hummingbird Networks can support your team in configuring, reviewing, and maintaining a secure Webex environment, whether you're deploying Webex for the first time or strengthening an existing setup. Our team can help align security controls, licensing, identity management, and integrations with your organization's collaboration and security requirements. 

Need help securing your Webex environment? Talk with Hummingbird Networks about your deployment, configuration, and collaboration requirements.

« Back to Articles