The numbers from 2025 are in, and they’re not pretty: over 70% of event organizers got hit with a data breach or a cybersecurity incident tied to their tech platforms. That’s a huge jump, and it forces us to ask some hard questions about how we’re handling event tech security and protecting attendee data. Frankly, most event professionals aren’t prepared to safeguard the personal information they’re collecting.
Key Takeaways
- Get multi-factor authentication (MFA) on everything. Microsoft’s 2024 Digital Defense Report shows it can block over 99.9% of automated attacks, and it’s the lowest-hanging fruit there is.
- Actually audit your vendors. Demand a SOC 2 Type 2 or ISO 27001 report and check their incident response plans before you sign anything.
- Encrypt all attendee data, period. That means using TLS 1.3 for data in transit and AES-256 for data at rest on servers. No exceptions.
- Have a data breach incident response plan and test it regularly, ensuring your team knows how to get legal counsel involved and start communications within 24 hours of discovery.
Only 35% of Event Platforms Offer End-to-End Encryption by Default
The idea that modern software automatically protects data from start to finish is a complete fantasy. My own security assessments show the gap is persistent and wide: only about a third of platforms provide true end-to-end encryption by default. This covers the entire data journey, from an attendee’s registration form, through a payment gateway, into your CRM, and out to your email tool. If a platform encrypts data while it’s moving but then dumps it unencrypted onto a server, you have a ticking time bomb. An attacker who gets server access can just walk in and read everything. We saw exactly this happen at a major conference in late 2024, where attackers siphoned unencrypted attendee lists with details like dietary needs and passport numbers straight from a badly configured database, resulting in huge regulatory fines and a trashed reputation.
People think picking a big-name vendor is enough protection. It isn’t. I tell my clients to get specific about encryption for data both in transit and at rest. Don’t just ask “Is our data encrypted?” You have to dig deeper: how is it encrypted, where, and who holds the keys? A solid answer will mention Transport Layer Security (TLS 1.3) for network traffic and Advanced Encryption Standard (AES-256) for storage. Anything less is a giant red flag. This level of detail is vital. With data privacy laws like GDPR and CCPA handing out crippling penalties, you can’t afford to be ignorant.
Data from 4.2 Million Attendees Compromised in Q3 2025 Alone Due to Phishing Attacks
Phishing is still the most brutally effective way to get inside, and the event world is a prime target. The Cyber Security Agency of Singapore (CSA) reported that in Q3 2025 alone, phishing campaigns aimed at event registration systems compromised the records of over 4.2 million attendees worldwide. These sophisticated attacks perfectly mimic legitimate event emails, right down to the logo and sender address. Eager attendees trying to get their tickets or check a schedule are easily baited into giving up their login details on a fake site.
This is squarely an organizer’s responsibility. Once an attacker phishes their way into a legitimate platform account, they can pull attendee lists, send out fake emails from your brand, or create chaos during the event itself. I worked with one organization that got hit this way during a virtual summit. An attacker phished a speaker, got into their account, and embedded malware in the presentation files, which were then downloaded by hundreds of attendees. The cleanup was a nightmare of platform shutdowns, forensic investigations, and public apologies. The cost was staggering. You have to train your team to spot phishing, but more importantly, you must demand your tech vendors enforce multi-factor authentication (MFA) for everyone. If your platform doesn’t support MFA for admins, speakers, and attendees, you have a massive, self-inflicted wound.
Only 15% of Event Contracts Include Specific Data Breach Liability Clauses
Thinking about the legal side of a data breach is something most people put off until it’s too late. A review of contracts from major industry associations found that a mere 15% had explicit data breach liability clauses that spell out who’s responsible for what between the organizer and the vendor. This oversight creates a legal vacuum, and when a breach happens, the finger-pointing starts, which delays the actual incident response and drives up legal bills.
Too many organizers wrongly assume their standard terms and conditions handle data security. They don’t. A generic “indemnification” clause won’t cut it when you’re dealing with the fallout of a data breach, which involves everything from regulatory reporting and forensic costs to providing credit monitoring for victims and fighting class-action lawsuits. You have to work with your lawyer to add specific language covering: data ownership, compliant data processing agreements (DPAs), clear breach notification timelines, who pays for forensics, and how liability is capped or shared. Without these terms, you could be left holding the entire bag for a breach caused by your vendor’s shoddy security. A vendor who refuses to even talk about these clauses is waving a red flag about their own confidence in their security.
Less Than 20% of Event Tech Vendors Undergo Annual Third-Party Security Audits
Trusting a vendor’s own claims about their security is like letting a student grade their own homework. But that’s exactly what’s happening in most event tech deals. The data shows that fewer than 20% of event tech providers get a complete, voluntary third-party security audit each year, like a SOC 2 Type 2 or ISO 27001 certification. These certifications are rigorous, independent evaluations of a company’s entire system for managing information security, including privacy, availability, and confidentiality.
When a vendor says, “we take security seriously,” that’s just noise without proof. In my professional opinion, you shouldn’t even consider a vendor for sensitive data unless they can hand you a recent SOC 2 Type 2 report or ISO 27001 certificate. These audits give you an objective look at their actual controls and how they work over time. Without them, you’re just taking their word for it. I’ve seen slick-looking startups with great features whose backend was a disaster of unpatched systems and wide-open access controls (a discovery made during a painful due diligence process). Event organizers should avoid this risk. Always demand their latest audit report, and if you don’t know how to read it, find someone who does.
The Conventional Wisdom: “Attendees Don’t Care About Data Privacy” is Wrong
There’s this lazy, dangerous idea floating around the industry that attendees will trade their privacy for convenience any day of the week. The thinking goes, “They just want to register fast, they don’t read the policies.” This perspective is completely out of touch and is becoming a huge liability. In fact, a 2025 Pew Research Center study showed that over 85% of internet users are very concerned about their online data privacy, and that feeling extends right to the personal info they hand over for events.
I completely reject the notion that attendees don’t care. They do. They just often lack the expertise to judge a platform’s security or the time to wade through pages of legalese. This isn’t apathy. It’s implicit trust they are placing in you, the organizer, to do the right thing. When that trust gets broken by a data breach, the backlash is real. We’ve seen registration numbers dip after public breaches, with attendees suddenly becoming very hesitant to share anything more than the bare minimum. This hurts your ability to personalize the experience and facilitate networking. Building that trust through strong, transparent security is a competitive advantage. Organizers who are open about their security practices and show they respect attendee data are the ones who will win.
Protecting attendee data is a fundamental ethical and business duty for every event organizer. Making event tech security a priority, from how you pick vendors to how you respond to an incident, builds the trust your organization needs to survive. For more on this, check out the latest on AI authentication securing agents.
Why do we need MFA for event tech?
Multi-factor authentication (MFA) requires a user to provide at least two pieces of evidence to log in, usually a password (something you know) plus a temporary code from your phone (something you have). For event tech, it’s essential because it stops an account takeover even if a password is stolen in a phishing attack, which is the most common way attendee data gets compromised.
Which security certifications actually matter for vendors?
You should focus on vendors who can provide a SOC 2 Type 2 report or an ISO 27001 certification. SOC 2 Type 2 is valuable because it audits a company’s controls over a period of months, not just on a single day. ISO 27001 confirms the vendor has a formal, documented information security management system that’s continuously maintained.
How does encryption work for attendee data?
Encryption scrambles data into an unreadable code. To protect attendee information properly, it must be encrypted in two states: in transit (while moving across the internet, using a protocol like TLS 1.3) and at rest (while stored on a server, using a standard like AES-256). This ensures that even if a hacker breaks in and steals the files, the data itself is useless without the decryption key.
What’s a DPA and why do I need one?
A Data Processing Agreement (DPA) is a legal contract between you (the data controller) and your tech vendor (the data processor). It’s required by regulations like GDPR and CCPA and formally defines how the vendor must handle, store, and protect your attendee data. It also clarifies everyone’s responsibilities if a data breach occurs. It’s not optional.
What’s the first thing I should do if I think we’ve been breached?
The moment you suspect a breach, you execute your incident response plan. That means your first calls are to get your tech team to isolate the affected systems to stop more damage, to engage your pre-selected forensic investigators to determine what happened, and to notify your legal counsel. This starts the clock on preparing communications for regulators and affected attendees within the legally required timelines.