Decoding Data Privacy Regulations

There are three types of organizations: Those who have been hacked; those who are doing everything in their power to not be hacked; and those who are being hacked right now, without even knowing it. This is the reality we now live in, made evident by the endless stream of news stories about large-scale data breaches affecting companies, big and small, across nearly every industry. But this doesn’t just affect the private sector—the federal government is facing similar challenges and taking action to both prevent and deter cyber-attacks through legislation.

With these escalating cyber threats affecting the United States Government, compromised devices, servers, data, and user accounts have quickly become definite risks to our national security. In the face of this ever-evolving landscape, both federal and state governments are taking action to better safeguard both Department of Defense (DoD) and consumer data. If this sounds complex, you’re not alone; but it’s easier to decode than you might think.

Data Privacy Decoded

In response to these threats, U.S. congress has amended the National Defense Authorization Act (NDAA) by signing into law the John S. McCain NDAA, outlining both budgets and expenditures for DoD programs. This includes the Chinese hardware ban, placed into effect in August of 2019, barring all government agencies from buying, or even contracting to buy, video surveillance equipment from specified manufacturers. This also extends to vendors that have OEM, ODM, and JDM relationships—or those who utilize “essential components” and “crucial technology” from those companies.

These new regulations, including the prominent Defense Federal Acquisition and Regulation Supplement (DFARS), will now require all outside contractors to provide “adequate security” measures for defense information that is processed, stored, or transmitted on the contractor’s internal information system or network. But it isn’t just the federal government stepping in, individual states have begun to enact their own regulations to better safeguard their citizens as well, like the California Consumer Privacy Act (CCPA). All this to say, there is no escaping the changes posed by these new digital hazards.

What does this mean for the physical security industry? This not only points to cybersecurity becoming a mainstay consideration for end users; it also means manufacturers and integrators will be held to a higher standard. While deficient cybersecurity standards reflect poorly on integrators, they can also make them complicit in any issues that may arise in the future. For example, in 2018 ADT was forced to settle a $16 million class action lawsuit when the company installed wireless systems that left users open to hacks.

Evaluating Your Risks

Surveillance solutions are collecting unprecedented amounts of data, with the ability to track everything from facial expressions to body characteristics, behavior, actions, location, and more. While the technology itself isn’t posing an issue, the way it’s used can easily become one. Foreign entities and hackers alike are increasingly exploiting security devices to gain access to private systems. No matter your industry, there are organizations around the world interested in obtaining data from your network to manipulate information that can impact your business and consumers.

With the proliferation of Internet of Things (IoT)-enabled devices, there is no doubt that physical security systems have become more intelligent than ever before, but this doesn’t come without some drawbacks. While they may be smart, IoT devices are often considered “soft” targets that cybercriminals can make use of to cripple a physical security system from the inside out. These interconnected systems can only be as strong as their weakest link, making data protection measures key.

While data breaches, ransomware, and hacks are the usual concerns, many organizations also overlook the physical danger presented by weak cybersecurity practices. Large organizations that utilize surveillance devices alongside advanced analytics programs often leave themselves open to a physical attack without realizing it. By paralyzing a physical security system remotely, intruders can then enter facilities undetected, putting workers and assets in harm’s way.

Protecting Yourself

As a starting point, knowing where your video surveillance system comes from is crucial. With named foreign governments utilizing video surveillance technology to spy on their own citizens, the question must be asked: Where is your security system manufactured?

Decentralized technology is another important factor to consider. This basic concept ensures data collection and analytics are completely self-managing and inherently protected from a system-wide breach. Simply put, this means the surveillance system itself has minimized the points of access for hackers.

Technology aside, there are also some best practices that both integrators and end users can employ to help secure their surveillance systems. Keeping camera firmware up to date, always changing default passwords, and creating user groups with separate rights to ensure they only have the access they need are all simple ways for end users to keep up their cyber hygiene. Additionally, setting encryption keys for surveillance recordings can safeguard footage and prevent hackers from accessing the system through a backdoor.

Similarly, integrators should always advise end users to program and enable notifications in order to keep up-to-date with all system happenings, and to check their web server log on a regular basis to see who is accessing the system. Configuring a virtual private network (VPN) connection can also aid in secured remote access.

In this new era of data privacy regulations, it truly takes a village. End users will need to demand devices and software with cyber-protections built in; manufacturers must place a higher priority upon cybersecurity; and integrators will have to be more informed about the technology they choose to install.

Looking toward the future, these changes may seem daunting, but they are intended to bring about a new world of possibilities for the industry. Integrators that ease their client’s cyber-woes will be a step ahead of the pack. By choosing to work with cyber-focused manufacturers who prioritize device penetrating testing, encryption, and best practices, integrators can quickly gain a competitive advantage.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.