Your cameras were hacked? It’s YOUR fault!

Your cameras were hacked? It’s YOUR fault!

IP security cameras are connected to the internet. That's what allows users to access them remotely, to check in on their business, and what lets manufacturers update device software without having to physically visit their business. But this feature can also be a problem. When not secured properly, devices in the so-called Internet of Things (IoT) can be accessed remotely by just about anyone, not just those with whom you want to share access. And that’s a big problem for our industry. According to industry analyst firm, Gartner, by 2020 more than 25 percent of cyberattacks in enterprises will involve IoT devices. That includes the same devices that are supposed to keep us safe. So, when a security camera, or a NVR gets hacked everyone at some level, has to accept responsibility.

Manufacturers: Technology manufacturers should be held accountable for protecting their sales distributors and customers from exploitations of their hardware. It is their responsibility to design products with baked-in cyber security features, to ensure that the security system itself won’t introduce new vulnerabilities onto their customers’ networks. Responsible manufacturers will place security at the heart of their research and development efforts. From the design phase to quality assurance, cyber resiliency needs to be a fundamental part of the R&D process. It is also the manufacturers’ responsibility to put together hardening tools to assist their users through all the steps needed to fully secure every facet of their systems. Because new threats occur all the time, responsible manufacturers should pledge transparency about the latest vulnerabilities to their systems. They should inform their customers, partners and systems integrators about new threats as soon as they are identified and act quickly and diligently to issue timely corrections and patches so that everyone can get back to being fully secured as quickly as possible.

Systems integrators: While it is tempting to think that the cybersecurity responsibility stops with manufacturers, systems integrators have an equally important role to play in ensuring that the systems they install are secure from both a physical and a cyber perspective. To build this confidence, responsible systems integrators should partner with companies and vendors that have strong cyber security policies, dedicated resources, and a clearly articulated plan for combating security vulnerabilities. It’s also a systems integrator’s responsibility to install IP equipment properly and follow the hardening rules provided by manufacturers. This includes re-setting default passwords, utilizing multiple credentials, using the most secure authentication and encryption methods available, and setting defined access privileges for users. And just as importantly, employing and sharing best practices with their customers’ IT, security and operations department will ensure the ongoing safety and security of their people and assets.

Physical security departments: Security professionals know the importance of secure device placement --i.e. cameras should be installed so they cannot be easily tampered with; network and power cabling should run through conduit or behind/through walls and ceilings so that the cables cannot be unplugged or intercepted. Beyond deployment, there are a number of tasks security teams must continually undertake to ensure the ongoing security of their cameras and other devices such as performing regular software updates and ensuring software complies with organizational security standards. But today, the role of security departments goes beyond the placement and care of security devices. Physical security departments can no longer pass the headaches of cyber security to their colleagues in the IT department. As we have just discussed, any internet-enabled security device represents a potential entry door to cyberattacks. Additionally, as these devices increasingly leverage new technologies such as artificial intelligence and machine learning, they are simultaneously providing attackers with enhanced tools for more complex attacks. Physical security departments can no longer operate in a silo and need to work hand in hand with IT departments, procurement departments and management. They need to choose to work with well informed, cyber-educated systems integrators, and specify technology from reliable manufacturers.

IT departments: Similarly, IT departments need to work closely with security departments and set up secure network configurations that physically separate the cameras and recorders from the corporate network, using VLANs (Virtual Local Area Networks). By explicitly specifying who is allowed or denied access to a network device, they can ensure that only the correct people, based upon their computer’s IP addresses have access to the device, and thwart any attacks, hacker scanners, or script-kiddies’ attempts to access the network.

Procurement departments: Procurement departments need to be fully aware of the risks associated with procurement decisions based solely on price, without taking into consideration any possible cybersecurity weaknesses or vulnerabilities. When shown how easy it is to hack into some of the low-cost security hardware that is widely available on the market, people will understand first-hand, the perils that poor procurement choices can cause. In the event that these purchases have already been made, responsible procurement departments should work with their security and IT colleagues to evaluate the vulnerabilities and assess the risks through an analysis of the product and the code, and by performing a penetration test. Once the evaluation is complete, every effort should be made to mitigate the important risks identified and if necessary replace the devices at risk. In the light of so many high-profile data breeches, an increasing number of forward-thinking procurement departments are requesting penetration tests on the products of their suppliers, to ensure the solutions they are choosing are robust and successfully ‘hardened’ against cyber-attacks.

Executive management: Any company can have an employee who unintentionally opens the content of a malicious email or forgets to reset the default password on a camera. For an attacker, this is often the easiest and most effective way to gain access and compromise a company’s confidential data. To protect their organization against this type of attack, corporations need to put in place the necessary resources, procedures and policies to properly educate their employees and help reduce careless, high-risk behaviors. A cyber security culture should seamlessly intertwine security practices with business operations in order to improve an organization’s security posture, and demonstrate that security is not a function relegated to an understaffed and underfunded IT department.

Conclusion

The very devices that are designed to protect customers' property and personal information are increasingly used as a means of seizing sensitive personal and corporate information. It is important not to view cybersecurity as just one person’s or one department’s job: it is a collective responsibility that needs to be taken seriously by every single one of us, whether we are a manufacturer, or a systems integrator, whether we work in IT or procurement, whether we sit at the reception desk or in the executive suite.

Featured

  • 2025 Gun Violence Statistics Show Signs of Progress

    Omnilert, a national leader in AI-powered safety and emergency communications, has released its 2025 Gun Violence Statistics, along with a new interactive infographic examining national and school-related gun violence trends. In 2025, the U.S. recorded 38,762 gun-violence deaths, highlighting the continued importance of prevention, early detection, and coordinated response. Read Now

  • Big Brand Tire & Service Rolls Out Interface Virtual Perimeter Guard

    Interface Systems, a managed service provider delivering remote video monitoring, commercial security systems, business intelligence, and network services for multi-location enterprises, today announced that Big Brand Tire & Service, one of the nation’s fastest-growing independent tire and automotive service providers, has eliminated costly overnight break-ins and significantly reduced trespassing and vandalism at a high-risk location. The company achieved these results by deploying Interface Virtual Perimeter Guard, an AI-powered perimeter security solution designed to deter incidents before they occur. Read Now

  • The Evolution of ID Card Printing: Customer Challenges and Solutions

    The landscape of ID card printing is evolving to meet changing customer needs, transitioning from slow, manual processes to smart, on-demand printing solutions that address increasingly complex enrollment workflows. Read Now

  • TSA Awards Rohde & Schwarz Contract for Advanced Airport Screening Ahead of Soccer World Cup 2026

    Rohde & Schwarz, a provider of AI-based millimeter wave screening technology, announced today it has won a multi-million dollar award from TSA to supply its QPS201 AIT security scanners to passenger security screening checkpoints at selected Soccer World Cup 2026 host city airports. Read Now

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.