Your cameras were hacked? It’s YOUR fault!
IP security cameras are connected to the internet. That's what allows users to access them remotely, to check in on their business, and what lets manufacturers update device software without having to physically visit their business. But this feature can also be a problem. When not secured properly, devices in the so-called Internet of Things (IoT) can be accessed remotely by just about anyone, not just those with whom you want to share access. And that’s a big problem for our industry. According to industry analyst firm, Gartner, by 2020 more than 25 percent of cyberattacks in enterprises will involve IoT devices. That includes the same devices that are supposed to keep us safe. So, when a security camera, or a NVR gets hacked everyone at some level, has to accept responsibility.
Manufacturers: Technology manufacturers should be held accountable for protecting their sales distributors and customers from exploitations of their hardware. It is their responsibility to design products with baked-in cyber security features, to ensure that the security system itself won’t introduce new vulnerabilities onto their customers’ networks. Responsible manufacturers will place security at the heart of their research and development efforts. From the design phase to quality assurance, cyber resiliency needs to be a fundamental part of the R&D process. It is also the manufacturers’ responsibility to put together hardening tools to assist their users through all the steps needed to fully secure every facet of their systems. Because new threats occur all the time, responsible manufacturers should pledge transparency about the latest vulnerabilities to their systems. They should inform their customers, partners and systems integrators about new threats as soon as they are identified and act quickly and diligently to issue timely corrections and patches so that everyone can get back to being fully secured as quickly as possible.
Systems integrators: While it is tempting to think that the cybersecurity responsibility stops with manufacturers, systems integrators have an equally important role to play in ensuring that the systems they install are secure from both a physical and a cyber perspective. To build this confidence, responsible systems integrators should partner with companies and vendors that have strong cyber security policies, dedicated resources, and a clearly articulated plan for combating security vulnerabilities. It’s also a systems integrator’s responsibility to install IP equipment properly and follow the hardening rules provided by manufacturers. This includes re-setting default passwords, utilizing multiple credentials, using the most secure authentication and encryption methods available, and setting defined access privileges for users. And just as importantly, employing and sharing best practices with their customers’ IT, security and operations department will ensure the ongoing safety and security of their people and assets.
Physical security departments: Security professionals know the importance of secure device placement --i.e. cameras should be installed so they cannot be easily tampered with; network and power cabling should run through conduit or behind/through walls and ceilings so that the cables cannot be unplugged or intercepted. Beyond deployment, there are a number of tasks security teams must continually undertake to ensure the ongoing security of their cameras and other devices such as performing regular software updates and ensuring software complies with organizational security standards. But today, the role of security departments goes beyond the placement and care of security devices. Physical security departments can no longer pass the headaches of cyber security to their colleagues in the IT department. As we have just discussed, any internet-enabled security device represents a potential entry door to cyberattacks. Additionally, as these devices increasingly leverage new technologies such as artificial intelligence and machine learning, they are simultaneously providing attackers with enhanced tools for more complex attacks. Physical security departments can no longer operate in a silo and need to work hand in hand with IT departments, procurement departments and management. They need to choose to work with well informed, cyber-educated systems integrators, and specify technology from reliable manufacturers.
IT departments: Similarly, IT departments need to work closely with security departments and set up secure network configurations that physically separate the cameras and recorders from the corporate network, using VLANs (Virtual Local Area Networks). By explicitly specifying who is allowed or denied access to a network device, they can ensure that only the correct people, based upon their computer’s IP addresses have access to the device, and thwart any attacks, hacker scanners, or script-kiddies’ attempts to access the network.
Procurement departments: Procurement departments need to be fully aware of the risks associated with procurement decisions based solely on price, without taking into consideration any possible cybersecurity weaknesses or vulnerabilities. When shown how easy it is to hack into some of the low-cost security hardware that is widely available on the market, people will understand first-hand, the perils that poor procurement choices can cause. In the event that these purchases have already been made, responsible procurement departments should work with their security and IT colleagues to evaluate the vulnerabilities and assess the risks through an analysis of the product and the code, and by performing a penetration test. Once the evaluation is complete, every effort should be made to mitigate the important risks identified and if necessary replace the devices at risk. In the light of so many high-profile data breeches, an increasing number of forward-thinking procurement departments are requesting penetration tests on the products of their suppliers, to ensure the solutions they are choosing are robust and successfully ‘hardened’ against cyber-attacks.
Executive management: Any company can have an employee who unintentionally opens the content of a malicious email or forgets to reset the default password on a camera. For an attacker, this is often the easiest and most effective way to gain access and compromise a company’s confidential data. To protect their organization against this type of attack, corporations need to put in place the necessary resources, procedures and policies to properly educate their employees and help reduce careless, high-risk behaviors. A cyber security culture should seamlessly intertwine security practices with business operations in order to improve an organization’s security posture, and demonstrate that security is not a function relegated to an understaffed and underfunded IT department.
Conclusion
The very devices that are designed to protect customers' property and personal information are increasingly used as a means of seizing sensitive personal and corporate information. It is important not to view cybersecurity as just one person’s or one department’s job: it is a collective responsibility that needs to be taken seriously by every single one of us, whether we are a manufacturer, or a systems integrator, whether we work in IT or procurement, whether we sit at the reception desk or in the executive suite.