Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What breaks when organisations rely on video calls…
Cyber Security

What breaks when organisations rely on video calls alone for team collaboration?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Cyber Security

Video calls support communication, but they often fail to replace the shared context that comes from working in the same room. Teams may miss body language, spontaneous problem solving, and the quick back and forth that helps refine ideas. Over time, this can weaken creativity, slow decisions, and make it harder to build a shared understanding across the organisation.

Why This Matters for Security Teams

Video calls are often treated as a full substitute for co-located collaboration, but that assumption creates security and operational blind spots. Teams lose the informal checks that happen in person, including quick clarification, shared situational awareness, and the ability to spot when a discussion is drifting into risky territory. That matters because sensitive decisions, access changes, and incident responses increasingly happen inside collaboration tools.

The exposure is not theoretical. In the State of Secrets Sprawl 2025, GitGuardian found that 38% of secrets incidents in collaboration and project management tools like Slack, Jira, and Confluence were classified as highly critical or urgent. When communication moves entirely into video, organisations often assume the channel is safer than it is, even though the real problem is the loss of shared context and the persistence of sensitive artefacts. The NIST Cybersecurity Framework 2.0 reinforces that governance depends on clear processes, not just tools. In practice, many security teams discover these failures only after a sensitive discussion has already been captured, forwarded, or acted on without proper review.

How It Works in Practice

The main failure mode is that video calls compress collaboration into scheduled, linear conversations while real teamwork depends on faster, messier context exchange. In person, people rely on side conversations, shared whiteboards, and rapid corrections. On video, those cues are weaker, and participants often hesitate to interrupt, challenge assumptions, or surface concerns early. That can slow technical decisions and make risk acceptance less explicit.

Security teams also need to treat video calls as part of the collaboration attack surface, not as a neutral communication layer. Sensitive material is frequently screen-shared, read aloud, copied into chat, or recorded for later reuse. If meeting notes, transcripts, and recordings are retained without controls, they can become a durable repository of secrets, implementation details, or incident context. The Ultimate Guide to NHIs is useful here because many collaboration failures overlap with NHI governance failures: secrets move through tools that were never designed to hold them safely. NHIMG has also documented the risk of tooling sprawl in Code Formatting Tools Credential Leaks, where convenience led to hidden exposure paths.

  • Use video calls for discussion, not as the only place where decisions are made or approved.
  • Separate sensitive operational topics from broad team meetings when the audience is larger than the need to know.
  • Default to written follow-up for decisions, action owners, and risk acceptance so context is preserved.
  • Restrict recording, transcription, and screenshot sharing when the meeting includes secrets, incidents, or privileged access discussion.
  • Treat shared links, chat logs, and meeting artefacts as governed records, not temporary convenience output.

Where this guidance breaks down most often is in high-tempo incident response and distributed engineering environments, because teams under time pressure fall back on whatever channel is easiest, even when that channel is the least controlled.

Common Variations and Edge Cases

Tighter collaboration controls often increase coordination overhead, requiring organisations to balance speed against confidentiality and decision quality. That tradeoff becomes more visible in remote-first teams, customer-facing operations, and regulated environments where recordings, transcriptions, and meeting artefacts may have legal or compliance value.

There is no universal standard for this yet, but current guidance suggests that the answer is not to abandon video calls. Instead, organisations should distinguish between communication, decision-making, and recordkeeping. Video is acceptable for discussion, but sensitive outcomes should be captured in a controlled system of record with clear ownership. This matters even more when collaboration tools are used to move credentials or operational details. NHIMG has seen this pattern repeatedly in Hard-Coded Secrets in VSCode Extensions and the JetBrains Marketplace AI Plugin Campaign, where convenience pathways became exposure pathways.

The practical exception is small, trusted teams with strong written discipline, limited sensitive content, and mature document retention controls. Even there, the risk is not the call itself. It is the false belief that a live conversation automatically creates shared understanding without needing follow-up, controls, or auditability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Collaboration channel risk needs governance and documented risk decisions.
OWASP Non-Human Identity Top 10NHI-01Meeting artefacts often expose secrets, tokens, and access data.
NIST AI RMFGOVERNDistributed collaboration needs accountable governance and process control.
CSA MAESTROCoordination and trust boundaries matter in digital collaboration workflows.
OWASP Agentic AI Top 10Autonomous tool use in meetings can amplify unsafe sharing and leakage.

Prevent secrets from entering chat, transcripts, and recordings by enforcing detection and redaction.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org