Skip to content
Networks

Trust & Security

Security & assurance built for revenue-critical event networks

When payments, registration, production and streaming share a temporary network, segmentation is not a feature — it is the product. We operate at the transport layer with a documented segmentation standard, a clear data-responsibility boundary, documented acceptance and failover testing, and required cyber and E&O insurance before any deployment.

Our security posture in one view

One accountable operator instead of finger-pointing across venue, AV, payment, registration and carrier vendors — including for security. Here is what that accountability covers, and where the boundaries sit.

Segment by default

A documented standard isolates payment, production, registration, attendee, contractor and management traffic into separate zones — wired-first on the critical paths, verified before go-live.

Transport, not data

We operate at the transport layer. We don’t run your payment or registration applications, and we never store or process cardholder or attendee data — we move it across a segmented, monitored network and define the data-responsibility boundary in writing.

Tested & insured

Pre-opening acceptance and failover testing before go-live, NOC monitoring through teardown, and required cyber and E&O insurance in force before deployment.

Segmentation standard

Every Critical Operations Network overlay is built on a documented, acceptance-tested segmentation standard. Traffic classes are isolated so a compromise or congestion in one zone cannot reach payments, production or streaming.

ZoneCarriesCritical pathDefault isolation
PaymentsPayment systems the client runs (terminals, registration payments)Wired-firstIsolated from attendee, contractor and management traffic; data-responsibility boundary defined before contract
ProductionShow control, encoders, broadcast/streamWired-firstDedicated zone; protected from attendee and contractor contention
RegistrationCheck-in, registration, badgingWired-firstSeparated from payment and attendee zones
AttendeePublic / guest access (add-on, never the lead)WirelessWalled off from every operational zone
ContractorVendors, exhibitors, third-party crewsWireless / wired as scopedCannot reach payment, production or management traffic
ManagementNetwork devices, monitoring, NOC accessWired-firstRestricted administrative plane, separate from all event traffic
Wired-first on critical paths. Payments, registration, encoders and production run on wired drops wherever feasible. Wireless serves attendee and ambient use, never the revenue-critical systems. The segmentation standard overview covers this in depth.

Data responsibility & segmentation

We carry payment traffic; we never run your payment or registration applications. Before any engagement that touches payment or registration systems we define the data-responsibility boundary in writing and document who is responsible for what.

How we stay transport-only

  • Data-responsibility boundary documented before the contract is signed
  • Transport-only posture — we run the network, not your applications; cardholder and attendee data never touches or is stored by us
  • Payment traffic isolated in its own segment, separate from attendee and contractor zones
  • Documented segmentation that keeps payment and registration systems on isolated paths
  • A written shared-responsibility matrix on every deployment
What this means for you. Your payment and registration vendors keep their own obligations and their own SLAs. LGL provides the segmented, monitored transport beneath them and defines exactly where our responsibility ends and theirs begins — so there is no ambiguity if an incident or an auditor asks.

Data posture

We are a network operator, not a data processor. Our role is to move your operational traffic reliably and securely — not to sit on top of your customers' data.

What we do. Operate at the transport layer: route, segment, monitor and stand behind the network. Collect the operational telemetry (link health, throughput, failover events) needed to run the NOC and report availability and failover performance against the targets defined for the event.
What we don’t do. Run your payment, registration, production or streaming applications, or act as a data processor for them. Cardholder and attendee data never touches or is stored by us — we carry and isolate it on the wire, nothing more, and we don’t stand behind vendor application uptime.

Resilience & testing

Redundancy you cannot see is redundancy you cannot trust. We prove failover and segmentation before go-live, then watch the network through teardown.

Redundant connectivity

Dual-WAN where venue policy permits; where it does not, an approved single underlay with defined, documented failover behavior. Circuits are dedicated and redundant, procured by us — not resold commodity bandwidth.

Pre-opening acceptance test

Before go-live we verify that segmentation holds, WAN failover lands inside its target window, critical-system redundancy is live, and monitoring is reporting. First-run pass rate is a tracked metric.

Monitoring through teardown

An onsite network lead plus NOC monitoring covers the event end to end. Severity-1 connectivity and security incidents are tracked, with mean-time-to-failover as a core measure.

On dual-WAN & failoverOn the acceptance test

Insurance & incident roles

Standing behind a payment and production network means carrying the right coverage and knowing who does what if something goes wrong.

Coverage in force before deployment

  • Cyber-liability insurance in place before any revenue event
  • Errors & omissions (E&O) coverage as a named prerequisite
  • Certificates of insurance available to organizers and partners on request

Breach-notification roles

Notification and escalation responsibilities are defined in the shared-responsibility matrix on each deployment: who detects, who notifies, who owns customer and regulator communication, and the timeline for each. Because we operate at the transport layer, application-data breach handling sits with the vendor that owns that data; LGL owns network and transport events on the infrastructure we operate.

Get the segmentation and scope mapped for your event

The Event Network Risk Assessment documents your zones, data-responsibility boundary and resilience design before any spend — and it's free.