Your cameras were hacked? It’s YOUR fault!

Your cameras were hacked? It’s YOUR fault!

IP security cameras are connected to the internet. That's what allows users to access them remotely, to check in on their business, and what lets manufacturers update device software without having to physically visit their business. But this feature can also be a problem. When not secured properly, devices in the so-called Internet of Things (IoT) can be accessed remotely by just about anyone, not just those with whom you want to share access. And that’s a big problem for our industry. According to industry analyst firm, Gartner, by 2020 more than 25 percent of cyberattacks in enterprises will involve IoT devices. That includes the same devices that are supposed to keep us safe. So, when a security camera, or a NVR gets hacked everyone at some level, has to accept responsibility.

Manufacturers: Technology manufacturers should be held accountable for protecting their sales distributors and customers from exploitations of their hardware. It is their responsibility to design products with baked-in cyber security features, to ensure that the security system itself won’t introduce new vulnerabilities onto their customers’ networks. Responsible manufacturers will place security at the heart of their research and development efforts. From the design phase to quality assurance, cyber resiliency needs to be a fundamental part of the R&D process. It is also the manufacturers’ responsibility to put together hardening tools to assist their users through all the steps needed to fully secure every facet of their systems. Because new threats occur all the time, responsible manufacturers should pledge transparency about the latest vulnerabilities to their systems. They should inform their customers, partners and systems integrators about new threats as soon as they are identified and act quickly and diligently to issue timely corrections and patches so that everyone can get back to being fully secured as quickly as possible.

Systems integrators: While it is tempting to think that the cybersecurity responsibility stops with manufacturers, systems integrators have an equally important role to play in ensuring that the systems they install are secure from both a physical and a cyber perspective. To build this confidence, responsible systems integrators should partner with companies and vendors that have strong cyber security policies, dedicated resources, and a clearly articulated plan for combating security vulnerabilities. It’s also a systems integrator’s responsibility to install IP equipment properly and follow the hardening rules provided by manufacturers. This includes re-setting default passwords, utilizing multiple credentials, using the most secure authentication and encryption methods available, and setting defined access privileges for users. And just as importantly, employing and sharing best practices with their customers’ IT, security and operations department will ensure the ongoing safety and security of their people and assets.

Physical security departments: Security professionals know the importance of secure device placement --i.e. cameras should be installed so they cannot be easily tampered with; network and power cabling should run through conduit or behind/through walls and ceilings so that the cables cannot be unplugged or intercepted. Beyond deployment, there are a number of tasks security teams must continually undertake to ensure the ongoing security of their cameras and other devices such as performing regular software updates and ensuring software complies with organizational security standards. But today, the role of security departments goes beyond the placement and care of security devices. Physical security departments can no longer pass the headaches of cyber security to their colleagues in the IT department. As we have just discussed, any internet-enabled security device represents a potential entry door to cyberattacks. Additionally, as these devices increasingly leverage new technologies such as artificial intelligence and machine learning, they are simultaneously providing attackers with enhanced tools for more complex attacks. Physical security departments can no longer operate in a silo and need to work hand in hand with IT departments, procurement departments and management. They need to choose to work with well informed, cyber-educated systems integrators, and specify technology from reliable manufacturers.

IT departments: Similarly, IT departments need to work closely with security departments and set up secure network configurations that physically separate the cameras and recorders from the corporate network, using VLANs (Virtual Local Area Networks). By explicitly specifying who is allowed or denied access to a network device, they can ensure that only the correct people, based upon their computer’s IP addresses have access to the device, and thwart any attacks, hacker scanners, or script-kiddies’ attempts to access the network.

Procurement departments: Procurement departments need to be fully aware of the risks associated with procurement decisions based solely on price, without taking into consideration any possible cybersecurity weaknesses or vulnerabilities. When shown how easy it is to hack into some of the low-cost security hardware that is widely available on the market, people will understand first-hand, the perils that poor procurement choices can cause. In the event that these purchases have already been made, responsible procurement departments should work with their security and IT colleagues to evaluate the vulnerabilities and assess the risks through an analysis of the product and the code, and by performing a penetration test. Once the evaluation is complete, every effort should be made to mitigate the important risks identified and if necessary replace the devices at risk. In the light of so many high-profile data breeches, an increasing number of forward-thinking procurement departments are requesting penetration tests on the products of their suppliers, to ensure the solutions they are choosing are robust and successfully ‘hardened’ against cyber-attacks.

Executive management: Any company can have an employee who unintentionally opens the content of a malicious email or forgets to reset the default password on a camera. For an attacker, this is often the easiest and most effective way to gain access and compromise a company’s confidential data. To protect their organization against this type of attack, corporations need to put in place the necessary resources, procedures and policies to properly educate their employees and help reduce careless, high-risk behaviors. A cyber security culture should seamlessly intertwine security practices with business operations in order to improve an organization’s security posture, and demonstrate that security is not a function relegated to an understaffed and underfunded IT department.

Conclusion

The very devices that are designed to protect customers' property and personal information are increasingly used as a means of seizing sensitive personal and corporate information. It is important not to view cybersecurity as just one person’s or one department’s job: it is a collective responsibility that needs to be taken seriously by every single one of us, whether we are a manufacturer, or a systems integrator, whether we work in IT or procurement, whether we sit at the reception desk or in the executive suite.

Featured

  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West
  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.