Segment by default
A documented standard isolates payment, production, registration, attendee, contractor and management traffic into separate zones — wired-first on the critical paths, verified before go-live.
Trust & Security
When payments, registration, production and streaming share a temporary network, segmentation is not a feature — it is the product. We operate at the transport layer with a documented segmentation standard, a clear data-responsibility boundary, documented acceptance and failover testing, and required cyber and E&O insurance before any deployment.
One accountable operator instead of finger-pointing across venue, AV, payment, registration and carrier vendors — including for security. Here is what that accountability covers, and where the boundaries sit.
A documented standard isolates payment, production, registration, attendee, contractor and management traffic into separate zones — wired-first on the critical paths, verified before go-live.
We operate at the transport layer. We don’t run your payment or registration applications, and we never store or process cardholder or attendee data — we move it across a segmented, monitored network and define the data-responsibility boundary in writing.
Pre-opening acceptance and failover testing before go-live, NOC monitoring through teardown, and required cyber and E&O insurance in force before deployment.
Every Critical Operations Network overlay is built on a documented, acceptance-tested segmentation standard. Traffic classes are isolated so a compromise or congestion in one zone cannot reach payments, production or streaming.
| Zone | Carries | Critical path | Default isolation |
|---|---|---|---|
| Payments | Payment systems the client runs (terminals, registration payments) | Wired-first | Isolated from attendee, contractor and management traffic; data-responsibility boundary defined before contract |
| Production | Show control, encoders, broadcast/stream | Wired-first | Dedicated zone; protected from attendee and contractor contention |
| Registration | Check-in, registration, badging | Wired-first | Separated from payment and attendee zones |
| Attendee | Public / guest access (add-on, never the lead) | Wireless | Walled off from every operational zone |
| Contractor | Vendors, exhibitors, third-party crews | Wireless / wired as scoped | Cannot reach payment, production or management traffic |
| Management | Network devices, monitoring, NOC access | Wired-first | Restricted administrative plane, separate from all event traffic |
We carry payment traffic; we never run your payment or registration applications. Before any engagement that touches payment or registration systems we define the data-responsibility boundary in writing and document who is responsible for what.
We are a network operator, not a data processor. Our role is to move your operational traffic reliably and securely — not to sit on top of your customers' data.
Redundancy you cannot see is redundancy you cannot trust. We prove failover and segmentation before go-live, then watch the network through teardown.
Dual-WAN where venue policy permits; where it does not, an approved single underlay with defined, documented failover behavior. Circuits are dedicated and redundant, procured by us — not resold commodity bandwidth.
Before go-live we verify that segmentation holds, WAN failover lands inside its target window, critical-system redundancy is live, and monitoring is reporting. First-run pass rate is a tracked metric.
An onsite network lead plus NOC monitoring covers the event end to end. Severity-1 connectivity and security incidents are tracked, with mean-time-to-failover as a core measure.
Standing behind a payment and production network means carrying the right coverage and knowing who does what if something goes wrong.
Notification and escalation responsibilities are defined in the shared-responsibility matrix on each deployment: who detects, who notifies, who owns customer and regulator communication, and the timeline for each. Because we operate at the transport layer, application-data breach handling sits with the vendor that owns that data; LGL owns network and transport events on the infrastructure we operate.
The Event Network Risk Assessment documents your zones, data-responsibility boundary and resilience design before any spend — and it's free.