Resources 6 min read

Video Surveillance Security and Risk

A surveillance system is a set of networked computers holding a record of who was in your building. That makes it both a security control and a target. The risks that matter, the controls that remove most of them, and what to ask a supplier.

Glowing digital globe with interconnected network nodes representing global cybersecurity and information security infrast

A video surveillance system is a set of networked computers with cameras attached, holding a recording of who was in your building and when. That makes it both a security control and a target, and the second half is the part that gets less attention than it deserves.

The risks

The cameras themselves

Cameras ship with default credentials, run firmware that is rarely updated, and frequently expose more network services than anyone needs. NIST publishes a core baseline of what an internet of things device should be capable of, and it is a useful lens for what goes wrong when a device is not: device identification, device configuration, data protection, logical access to interfaces, software update and cybersecurity state awareness. A camera that cannot restrict access to its own interfaces, cannot be updated and cannot report its own state is not a device you are managing. It is a device that is present.

Flat networks

Cameras placed on the same network as everything else turn a device compromise into a foothold. This is the single most consequential design decision in the system and it costs nothing at installation time.

The footage

The archive is a record of the movements of your staff, your customers and your visitors. Who can view it, who can export it, and whether either action is logged are security questions before they are privacy questions, and they are frequently answered by "everyone with the admin password."

Supply chain

Some equipment is prohibited for federal purposes outright, on national security grounds rather than on quality grounds. FAR 52.204-25 defines covered telecommunications equipment to include, "for the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes," video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company or Dahua Technology Company, or any subsidiary or affiliate of those entities. The same clause covers services provided by those entities or using that equipment. Cameras are often rebranded, so the name on the housing is not a reliable guide to who made what is inside it. See the federal procurement rules for who this binds.

Silent failure

Systems do not usually stop working. One camera stops recording, then another, and nobody finds out until a search comes up empty. Unmonitored decay is the risk that actually materializes in most organizations.

Controls that matter

In the order that removes the most risk for the least effort.

  1. Change every default credential, and use unique ones. A single shared camera password means one leak exposes every device.
  2. Put cameras on their own network segment with tightly limited routes to and from the rest of the network. Assume a camera will eventually be compromised and design so that it matters less when it is.
  3. Do not expose recorders or cameras directly to the internet. Remote viewing should go through the vendor's managed service or your own remote access, never a port forwarded to a recorder.
  4. Keep firmware current, and buy on the basis that you can. Ask for the update mechanism and the supported life before purchase, because after purchase there is nothing to be done about it.
  5. Give access by role and review it. Viewing and exporting are separate permissions. People who change jobs should lose access when they do.
  6. Log and alert. Health alerting so you learn a camera stopped recording, and access logging so an export is attributable. NIST control PE-6 pairs monitoring physical access with reviewing the access logs at a defined frequency and coordinating what those reviews find with your incident response. The review is the part organizations skip.
  7. Protect the footage as data. Encryption where the product supports it, controlled export, and a retention period that is enforced rather than aspirational. Footage kept indefinitely is a liability that grows.

If you want a structure to hang this on rather than a list, the NIST Cybersecurity Framework 2.0 organizes outcomes under six functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Surveillance touches all six, and the one most often missing is GOVERN, which is where "who owns this system" is supposed to be answered.

What to ask a supplier

  • Who manufactures these cameras, and who manufactures the image sensor and the board inside them? Put it in writing.
  • Is any component in this proposal covered by FAR 52.204-25?
  • How is firmware updated, and until what date will updates be published for these models?
  • Can each device restrict access to its interfaces, and can it report its own state to a management system?
  • How will the cameras be segmented from the rest of our network, and who configures that?
  • How is remote access provided, and does it require anything to be exposed to the internet?
  • Are viewing and exporting separate permissions, and is export logged?
  • What alerts us when a camera stops recording, and who receives that alert?
  • Is footage encrypted at rest, and who at your company can access our recordings?
  • What happens to our footage if we end the contract?

A supplier who answers these easily has thought about the system as infrastructure. One who treats them as unusual questions is telling you something useful.

To have your existing system assessed against this list rather than a proposed one, request a free site security assessment. See also the buyer checklist and recording, privacy and the law, and our video surveillance solutions. Who owns these decisions, and how often they are reviewed, is covered in security governance and risk ownership.

Sources

  • National Institute of Standards and Technology, IR 8259A, IoT Device Cybersecurity Capability Core Baseline. Establishes the six device cybersecurity capabilities used here to describe what an unmanageable camera lacks. nvlpubs.nist.gov. Accessed 18 August 2026.
  • General Services Administration, FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. Establishes the quoted definition of covered telecommunications equipment and the three named manufacturers. acquisition.gov. Accessed 18 August 2026.
  • National Institute of Standards and Technology, SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. Establishes control PE-6, which pairs monitoring physical access with reviewing physical access logs at a defined frequency and coordinating the results with incident response. nvlpubs.nist.gov. Accessed 18 August 2026.
  • National Institute of Standards and Technology, Cybersecurity Framework 2.0 (NIST CSWP 29). Establishes the six CSF Core Functions named here. nvlpubs.nist.gov. Accessed 18 August 2026.

About LABUSA

LABUSA is a managed service provider that enables organizations to build a robust digital business model. We provide managed services through an open hybrid cloud strategy integrating public, private, and on-premises computing systems with intelligent edge devices. The company is ISO 9001:2015 certified and our solution extends the information technology environment's efficiency, security, reliability, and cost-effectiveness.

For more Information Contact LABUSA at

+1-281-393-8003