Editorial note
Carefully framed- Some examples are deliberately abstracted to keep the judgement useful without exposing private systems, people, weaknesses or operational detail.
- Site-specific AV designs, network configuration, device inventory and remote-access arrangements.
- Employer-specific rooms, events, service failures or operational dependencies.
- Detailed security settings, credentials, monitoring thresholds or supplier information.
The phrase “AV system” can still make people think of equipment in a room.
A display on a wall. A microphone. A projector. A loudspeaker. Perhaps a control panel sitting on a lectern or meeting-room table.
That description is becoming less useful.
Modern AV can include networked audio, control processors, wireless systems, cloud platforms, streaming, remote management, digital signage, video conferencing, room booking, monitoring and software-defined configuration.
It may sit inside a meeting room, an auditorium, an event space, a reception area or an operational environment.
What matters is not the label attached to the technology.
What matters is what happens when it stops working.
If a meeting cannot take place, a live event cannot proceed, an organisation cannot communicate effectively or an operational space becomes unusable because the technology has failed, AV is no longer just equipment.
It is part of the infrastructure.
Dependency changes the conversation
I think this is the more useful way to decide whether something should be treated as infrastructure.
Not whether it looks like traditional IT.
Not whether it sits in a server room.
Not even whether the infrastructure team owns it.
The better question is:
What organisational activity now depends on this service?
The answer changes how the technology needs to be managed.
A display used occasionally can tolerate a different support model from a room that hosts important meetings every day.
A microphone used for an informal gathering is different from an audio system supporting a large event.
Digital signage displaying optional content is different from a communications system that people depend on for timely information.
Dependency creates operational importance.
Operational importance creates the need for ownership, support and resilience.
The network is increasingly part of the signal path
One of the biggest changes has been the convergence between AV and IP networking.
Audio and video can travel across networks.
Devices may depend on VLAN design, multicast behaviour, Quality of Service, DHCP, DNS, PoE and reliable switching.
Control platforms may communicate across several network segments.
Management interfaces may sit in the cloud.
That creates an interesting operational boundary.
An AV specialist can understand the audio or video signal flow perfectly while a network engineer understands the switching environment perfectly.
The service may still fail somewhere between those two views.
I have become increasingly wary of treating these as separate systems simply because different teams understand different parts of them.
Users experience one service.
The operating model should reflect that.
That means infrastructure changes need awareness of AV dependencies, while AV projects need infrastructure involvement before installation rather than after the equipment has already arrived.
AV now has a software lifecycle
The other major shift is software.
Modern AV estates need many of the same lifecycle questions as other technology platforms.
Which firmware is deployed?
Which versions remain supported?
What happens if an update changes compatibility?
Where are configurations backed up?
Who has administrative access?
How is remote support enabled?
Which cloud services are involved?
How are vulnerabilities handled?
What happens when a manufacturer stops supporting a platform?
These are not traditional “projector problems”.
They are lifecycle-management problems.
A room may continue to work long after the vendor considers its underlying platform obsolete.
That gap between “still functioning” and “still supportable” is where operational risk begins to accumulate.
Security follows connectivity
Once a device is connected to an organisational network, security cannot simply be somebody else’s concern.
That does not mean every amplifier, display or control processor presents the same level of risk as a critical server.
It means the risk should be understood.
Default credentials still matter.
Old firmware still matters.
Unnecessary internet access still matters.
Shared administrative accounts still matter.
Vendor remote access still matters.
Unsupported embedded operating systems still matter.
Segmentation still matters.
The right controls should be proportionate to the service and the threat.
Ignoring the issue because something is classified as “AV” rather than “IT” is not a security strategy.
Monitoring should describe the service
There is also a difference between monitoring devices and monitoring an AV service.
Ten devices may answer a ping while the room remains unusable.
The control processor may be online while a critical input has failed.
A network switch may be healthy while the audio path is not.
A conferencing device may be reachable while authentication to its cloud service has failed.
Monitoring is most useful when it helps answer the question users actually care about:
Can I use this space for what it is supposed to do?
That may require device monitoring, but it may also require awareness of signal paths, cloud services, network dependencies, temperatures, amplifier states, software status or other indicators.
The aim is the same as in any other infrastructure discipline.
Find degradation before the user becomes the monitoring system.
The room still shapes the service
AV also has a physical dimension that conventional IT services do not always expose as clearly.
Acoustics affect intelligibility. Sightlines affect whether content is useful. Lighting, room layout and the way people actually interact with a space can determine whether a technically correct system delivers a good experience.
That is one reason AV sits in an interesting position. It combines digital infrastructure with physical space and user experience. Successful operation needs to understand all three.
Treat the service according to its importance
AV does not need to become indistinguishable from every other IT discipline.
Audio engineering is still a specialist skill.
Video systems still have their own constraints.
Live production still requires expertise that conventional infrastructure teams may not possess.
The point is not to erase those differences.
It is to recognise that modern AV now shares many of the same operational characteristics as infrastructure.
It is connected.
It is software-driven.
It has security implications.
It requires lifecycle planning.
It has dependencies.
It can be monitored.
And organisations may no longer be able to work around it easily when it fails.
Once the organisation depends on the service, the way we manage it needs to reflect that reality.
Contents
About the publication
I turn complex infrastructure and cybersecurity responsibility into resilient services, controlled change and evidence leaders can trust.