Industry Focus

Walking the Walk

If you attended ISC West last month, you already know the tradeshow was a smashing success. I suppose there are a few that weren’t completely satisfied, but I think overall, this year’s Las Vegas event experienced a well-received outcome. I loaded my schedule as full as possible and still didn’t have enough time to take it all in.

There were several takeaways from the show floor that we’re going to see a lot more of in 2017, and beyond. For starters, cybersecurity is now more than an up and coming concern. Everyone has this as a top of mind concern because once the network is safe, the security equipment will work at its optimum ability. I think we’re going to see camera manufacturers taking another hard look at how to secure the network. They’ve been talking about it, but now it’s time to walk the walk.

Physical and logical security depend on each other, so it is surprising to find that a number of companies still treat them separately, from both a device management and government agencies perspective. Until recently, this was justified because the technology to integrate physical and logical security was not available. Regarding security, most organizations have at least three buying and control centers. The first two are primarily concerned with IP theft, malware and viruses. NetOps handles network security, while InfoSec manages data at rest and data in transit security. The third is physical security, which includes surveillance and access control. In most organizations, the guard at the gates is a separate operations center.

Cybersecurity, meanwhile, depends greatly on physical security. Attackers who can gain physical access to a computer can almost always take advantage of that access to further their efforts. Merely getting access to a physical terminal where a memory device can be plugged in is usually sufficient. Any device present that is connected to the network must be protected to ensure that it cannot be turned into a tool to be used in an attack.

The lack of integration between physical and cybersecurity creates some following challenges.

  • No single system to identify a person’s identity because each functional security department controls its own identity database.
  • Increased potential for theft.
  • Lack of IT management and application of best practices applied to physical security devices, or a lack of best practices applied consistently across departments or organizations.
  • Lack of physical monitoring of logical security devices that can detect tampering; that is, unauthorized access to a logical security device console.

Like all effective security, cyber security is about the depth of your defense. It’s about appropriately protecting your IP camera network at every level—from the products you choose and the partners you work with to the requirements they, and you, set.

Your first layer of defense is choosing network video products with built-in protection: We make sure you can apply the security controls you need to mitigate the threats you face. Because there’s no one-size-fits-all solution to cyber crime, your second layer of defense is a good understanding of the threats you face, their potential costs and how to protect yourself.

Begin with best practices, timely response and transparency. Any end user should apply cybersecurity best practices in the design, development and testing of our products to minimize the risk of flaws that could be exploited in an attack. When critical vulnerabilities are discovered they should be fixed promptly and issue security advisories.

Your best cyber offense is a great cyber defense.

This article originally appeared in the May 2017 issue of Security Today.

About the Author

Ralph C. Jensen is the Publisher/Editor in chief of Security Today magazine.

Featured

  • Evolving Cybersecurity Strategies: Uniting Human Risk Management and Security Awareness Training

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

  • Report: 1 in 3 Easily Exploitable Vulnerabilities Found on Cloud Assets

    CyCognito recently released new research highlighting critical security vulnerabilities across cloud-hosted assets, revealing that one in three easily exploitable vulnerabilities or misconfigurations are found on cloud assets. As organizations increasingly shift to multi-cloud strategies, the findings underscore significant security gaps that could provide attackers with potential footholds into networks. Read Now

  • Built for Today, Ready for Tomorrow

    Selecting the right VMS is critical for any organization that depends on video surveillance to ensure safety, security and operational efficiency. While many organizations focus on immediate needs such as budget and deployment size, let us review some of the long-term considerations that can significantly impact a VMS's utility and flexibility. Read Now

  • Paving the Way to Smart Buildings

    In today's rapidly evolving security landscape, the convergence of on-prem, edge and cloud technologies are critical. The physical security landscape is undergoing a profound transformation, driven by the rapid digitalization of buildings and the evolving needs of modern organizations. As the buildings sector pivots towards smart, AI and data-driven operations, the integration of both edge and cloud technology has become crucial. Read Now

  • The Cybersecurity Time Bomb

    If you work in physical security, you have probably seen it: a camera, access control system, or intrusion detection device installed years ago, humming along without a single update. It is a common scenario that security professionals have come to accept as "normal." But here is the reality: this mindset is actively putting organizations at risk. Read Now

New Products

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.