Security Practices at Webex Events

Last Revised: June 16, 2026

Trust is the foundation of our security objectives at Webex Events. Our clients trust that we will protect their information with the same level of care and concern that they do. Our clients also trust that our applications will be available when they need them. We work to earn that trust through transparency, security practices, and independent assurance. We are proud to share our security and privacy approach, and additional documentation is available in the Webex Events trust package on the Cisco Trust Portal. If you have additional questions, please contact your Cisco representative.

Solution Overview

The heart of Webex Events is its platform, where event planners configure and operate their events. The Webex Events platform and related web applications are Software-as-a-Service (SaaS) offerings hosted from hybrid Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS). Webex Events operates from a private tenant in the AWS public cloud. Webex Events offerings are provided from a multitenant, multi-tier architecture. Client data separation is maintained at the application layer through rigorous access controls.

Encryption

We believe that unless the data is being used, it needs to be encrypted. That is why we encrypt data-in-transit on both the internal and external networks using HTTPS (TLS 1.2+). All data-at-rest is encrypted using AES-256 with keys managed from our AWS Key Management Service (KMS). Those keys are generated in the KMS, rotated within the KMS, and destroyed in the KMS. After all, the security provided through encryption is only as good as the security of the keys.

Intrusion Detection and Prevention

We are all for support from the Internet community, but not when it comes to administering our systems. Webex Events has adopted a walled-city security model that layers perimeter security controls. AWS security groups and cloud-native controls are deployed and managed at the network perimeter and around internal system resources. All application traffic must also traverse our web application firewall, configured to prevent attacks targeting web applications. High walls are great, but they are not perfect, so we also have intrusion monitoring and alerting utilities to let the Cisco security teams know if a barbarian has made it past the gate.

Incident Response

Our incident management program is comprised of policies and procedures aligned with Cisco’s broader cybersecurity incident response processes. While our goal is to never need it, other than for annual program testing, the program entails notifying impacted clients without undue delay when a security incident affects their data or use of applications, as appropriate and consistent with applicable obligations. Clients can always monitor the status of our applications at https://status.socio.events.

Logging and Monitoring

Your event needs to be secure – that is table stakes – but it also needs to be available. In this age of virtual and hybrid events, even a short disruption can ruin the event. In addition to standard system security logs, we maintain extensive telemetry logs. At Webex Events, the availability security pillar is treated with the same criticality as the confidentiality pillar.

Data Lifecycle

For some clients, prior and ongoing events tell the history of their community. For other clients, the value of event contents begins to decay at the conclusion of the event. Accordingly, event planners can delete or export event data to support their own retention needs. Data retention and deletion practices for Webex Events are described in the Webex Events Offer Disclosure, available through the Cisco Trust Portal. Clients may also request deletion of personal data through Cisco’s Privacy Request Portal. Upon termination of service, client data is deleted in accordance with applicable service lifecycle processes.

Data Access

Authorized personnel access client data only when necessary to provide support or operate the service. Access is limited to individuals with a business need, and access controls are designed to enforce least privilege. Individuals with access to client data are subject to applicable security and privacy training, authentication requirements, and monitoring.

Personnel Security

Webex Events is only as trustworthy as its personnel. Cisco conducts background checks in accordance with applicable law and company policy. Upon hire, and annually thereafter, employees must complete Code of Business Conduct, Security and Privacy training. Upon hire and annually thereafter, all employees must also acknowledge security and confidentiality policies.

Secure Development

Personnel in development roles complete role-based security training in accordance with Cisco requirements. Webex Events follows Cisco’s Secure Development Lifecycle (CSDL), and security practices are integrated into the development process. This includes code review, static and dynamic application security testing, dependency scanning, and other automated security checks as part of development and release workflows.

Security Validation

Secure today may not be secure tomorrow. We regularly re-evaluate our security posture through vulnerability scanning, security testing, and penetration testing. Webex Events performs ongoing vulnerability scanning and is subject to regular internal security testing. An independent third party is also engaged at least annually to perform penetration testing.

Sub-Processor Management

Webex Events uses subprocessors and third-party providers to help deliver its services. Client trust must extend to those providers as well, so Webex Events follows Cisco’s supplier and third-party risk management processes to assess and monitor relevant providers. These processes may include review of assurance documentation such as ISO certifications, SOC 2 reports, security questionnaires, and other relevant security and privacy assessment information.

Like modern software providers, Webex Events also uses open-source and third-party libraries, modules, and utilities within its offerings. These components are monitored through Cisco-aligned software security and dependency management practices to identify vulnerabilities, version changes, and licensing considerations.

Privacy

Like the global policy landscape, the Webex Events privacy program is constantly evolving. A good place to start to learn about our privacy program is the Privacy Data Sheet. You can find it here:

https://trustportal.cisco.com/c/dam/r/ctp/docs/privacydatasheet/collaboration/cisco-webex-events-socio-privacy-data-sheet.pdf

Cisco’s Online Privacy Statement can be viewed here:

https://www.cisco.com/c/en/us/about/legal/privacy-full.html

Assurance Collateral

Webex Events shares its assurance collateral documentation through the Cisco Trust Portal. There you can find available security, privacy, and compliance documentation, including materials such as SOC 2 reports, ISO certificates, and other applicable assurance documents.

https://trustportal.cisco.com/c/r/ctp/trust-portal.html#/trustpackage/079113759426025