A security platform that works at one site and fails at six has not run out of capacity. It has run out of decisions that were only ever made once, informally, by whoever commissioned the first building. Scale exposes those decisions all at once, and the cost of reversing them rises with every site added. The useful work happens before the second site, not during the sixth.
What breaks when you add the second site
Nothing breaks technically. That is what makes this hard to argue for in advance. The first expansion usually succeeds, and the problems that eventually stop the estate are established during it.
- Naming. Site one called a camera by where it is. Site two called it by what it watches. Nobody can now write a query that means the same thing at both.
- Retention. Set per recorder, so it becomes whatever each site's hardware happened to support, and there is no estate answer to how long footage is kept.
- Identity. Local accounts per site, created for the installer, inherited by whoever came next. Removing someone's access across the estate becomes a task nobody can complete confidently.
- Time. Devices synchronized to different sources, or to none. Correlating an event across two sites turns into arithmetic, and evidence loses its edge.
- Firmware. Version drift starts at site two and is permanent by site five, because there was never a mechanism for applying a change everywhere.
None of these are capacity problems, and none are solved by a larger platform. They are consistency problems, and they are cheapest to fix while the estate is small enough that fixing them is boring.
The decisions to make once, and centrally
NIST IR 8259A is the most useful reference here, because it describes what a networked device has to be able to do before it can be managed at all rather than what a system should achieve. The capabilities it sets out as a baseline are exactly the ones that decide whether an estate can be operated from one place: the device can be uniquely identified logically and physically, its software configuration can be changed and only by authorized entities, it can protect the data it stores and transmits, access to its interfaces can be controlled, its software can be updated, and its cybersecurity state can be observed.
Read as a purchasing filter rather than a standard, that list is unusually practical. A device that cannot be uniquely identified cannot be inventoried. One whose configuration cannot be changed remotely turns every policy change into a site visit. One that cannot be updated has a fixed expiry date whether or not anyone has written it down. Equipment failing these tests is not cheaper; it moves the cost from the purchase order to the operating budget, where it is harder to see and harder to stop.
The four standards to set before the second site
- A naming convention that encodes site, area and function, and is applied by the installer rather than corrected afterwards.
- One retention policy expressed in days, decided centrally, and implemented per site rather than discovered per site.
- Central identity so that access is granted and revoked in one place. NIST SP 800-53 control PE-6 asks for physical access to be monitored and the logs reviewed at a defined frequency with results coordinated into incident response, and that review is impossible to perform honestly against per site local accounts.
- A single time source for every device in the estate.
The hosting question, which is usually the first one asked, matters less than these four and is genuinely situational. It is treated on its own terms in cloud versus on premise video surveillance.
Procurement constraints outlive the architecture
One constraint deserves naming because it is absolute rather than advisory, and because it is discovered late. Under 48 CFR 52.204-25, executive agencies are prohibited from procuring, obtaining, extending or renewing a contract for any equipment, system or service that uses covered telecommunications equipment or services as a substantial or essential component of any system. For video surveillance the regulation names Hytera Communications, Hangzhou Hikvision Digital Technology and Dahua Technology, along with their subsidiaries and affiliates, where the purpose includes public safety, security of government facilities or physical security surveillance of critical infrastructure.
Two consequences follow for anyone scaling an estate. The prohibition reaches equipment sold under other brand names, because it follows the producer rather than the label, which is why the regulation also defines a reasonable inquiry into who actually produced a device. And it applies at contract renewal, not only at purchase, so an estate standardized on affected equipment does not simply carry on. If any part of the organization holds or intends to hold federal contracts, the standard has to be set with this in view from the first site. The wider treatment is in video surveillance and federal procurement rules.
What good looks like at scale
- A device inventory that is generated rather than maintained, and that matches what is actually on the network.
- One place to answer who has access, and one action to remove it everywhere.
- A firmware position that is known per site and moves on a schedule.
- Health monitored by alert, so a failed device is noticed before the footage is needed.
- Retention stated as an estate policy, and demonstrably applied.
- A new site brought online against a written standard rather than against the memory of the last one.
Two things this does not deliver. It does not make the estate cheaper in the first year; standardization usually costs more up front and pays back through avoided site visits and shorter investigations. And it does not remove the need for local knowledge, because someone still has to know which door the loading bay camera actually watches. The aim is that the estate can be operated without that person being available, not that the role disappears.
If you are running more than one site and cannot answer the inventory, access or retention questions from records, that is the place to start. Request a free site security assessment. For sequencing the work across sites, see how to plan an installation and building a roadmap. What we design, install and support is on our video surveillance solutions page.
Sources
- National Institute of Standards and Technology, NIST IR 8259A, IoT Device Cybersecurity Capability Core Baseline. Establishes the six baseline device capabilities used here as a purchasing filter: device identification, device configuration changeable only by authorized entities, data protection, logical access to interfaces, software update and cybersecurity state awareness. nvlpubs.nist.gov. Accessed 18 August 2026.
- Electronic Code of Federal Regulations, 48 CFR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. Establishes the prohibition on procuring, obtaining, extending or renewing a contract for equipment, systems or services using covered telecommunications equipment as a substantial or essential component, the named video surveillance producers, and the definition of a reasonable inquiry into the producer of equipment in an entity's possession. ecfr.gov. Accessed 18 August 2026.
- National Institute of Standards and Technology, SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. Establishes control PE-6, requiring physical access to be monitored, the logs reviewed at an organization defined frequency, and the results coordinated with the incident response capability. nvlpubs.nist.gov. Accessed 18 August 2026.