Securing the Security System

There is an awkward irony in most buildings. The systems installed to make the premises secure - cameras, intruder alarms, access control - are frequently the least secure devices on the network, and the ones nobody has looked at since commissioning.

Why these devices are the weak point

Security hardware has a long service life. A camera installed eight years ago is still doing its job, and its firmware is eight years old. Vendors stop issuing updates for older models, and nobody notices because the device still works.

They are also installed by people whose expertise is the security discipline rather than network security, commissioned once, and then left alone. Nothing prompts anyone to revisit them. And they are attractive: a recorder holds footage of everyone entering the building, and an access control system holds a list of who can get in and when.

Devices with default credentials and internet-facing management interfaces are actively scanned for. This is not a theoretical exposure.

The basics that get skipped

Change every default password. Every camera, every recorder, every controller, including the ones nobody logs into. Default credentials for common hardware are published and searchable. If a device cannot have its password changed, it should not be on the network.

Put the security system on its own network segment. A separate VLAN keeps heavy camera traffic away from the business network, and keeps a compromised camera away from everything else. This is the single most effective control available and it costs nothing but planning.

Never expose a recorder or controller to the internet. Port forwarding to an NVR so the client can view footage from home is the most common serious mistake in the trade. Remote access belongs behind a controlled route, not on an open port.

Update firmware deliberately. Not as a response to an incident - as a scheduled task with someone responsible for it. If a device has reached end of support, that is a replacement decision rather than something to defer indefinitely.

Limit and log administrative access. Individual accounts, not one shared login that three former employees still know.

What an installer owes the client

If you install these systems, some of this is now part of the job whether the contract says so or not. A handover that includes credentials the client can change, documentation of what is on which port, and a plain statement of what needs updating and how often, is a materially better handover than a working system and a laminated card.

It also protects you. When a system is compromised, the question of who configured it and what they left in place gets asked quickly.

Where this connects to obligations

Two things bite here. CCTV footage of identifiable people is personal data, so a poorly secured recorder is a data protection exposure as much as a security one - covered in CCTV storage, retention and data protection.

And for organisations in scope of NIS2, network devices form part of the risk management obligation, with supply chain security explicitly included. If you supply or maintain these systems for a customer who is in scope, their obligations will reach you through your contract - see NIS2 in Ireland.

A short audit

For any building you are responsible for:

  • List every networked security device, including ones installed by a previous contractor
  • Confirm none is still on default credentials
  • Confirm none is reachable directly from the internet
  • Check which are still receiving firmware updates, and note the ones that are not
  • Confirm the security system is not on the same flat network as everything else

Most sites fail at least two of these on the first pass, and the fixes are usually configuration rather than replacement.

For the network design side, see IP networks for CCTV.