Treat connected security like IT: remove default passwords, use named accounts and MFA, segment the network, install updates and restrict remote access. Document support lifetime, configuration backups and recovery too.

Key points

  • No default or shared accounts.
  • Restrict and monitor the security network.
  • Plan updates with backups.
  • Make support access temporary and traceable.

Regulatory content reviewed on 8 September 2026. Check official sources for your specific situation.

Physical security is digital

Cameras and controllers process sensitive images, rights and logs.

Plan cybersecurity during selection, installation and maintenance.

  • Images
  • Rights
  • Logs
  • Availability
  • Business network

Accounts

Change defaults, use individual least-privilege roles and separate daily viewing from administration.

Enable MFA and remove old users and devices.

  • Unique password
  • MFA
  • Roles
  • Named users
  • Recovery

Network segmentation

Allow only required connections to recorders, time and authorised services.

Avoid direct internet port exposure.

MeasurePurposeEvidenceOwner
Named accountsTrace accessUser listOperator
MFAProtect accountEnabledIT
SegmentationLimit movementRulesIT
UpdatesPatchVersion logIT/installer
BackupRecoverTestNamed owner

Updates and support

Ask for update policy and end-of-support date.

Back up before updates and test camera, recorder and integrations afterwards.

  • Policy
  • Support end
  • Backup
  • Maintenance window
  • Test

Remote support

Use temporary named access with limited rights and logs.

Manage mobile devices and notification privacy.

  • Temporary
  • Log
  • Device
  • Revoke
  • Notifications

Encryption and backup

Protect connections and exports and avoid permanent public links.

Back up configurations and test recovery.

  • TLS
  • Export
  • Configuration
  • Separate copy
  • Recovery

Incident response

Isolate, preserve logs and change access from a safe device.

Assess impact, fix the cause and monitor after recovery.

  • Isolate
  • Logs
  • Credentials
  • Impact
  • Monitor

FAQ

Should a camera be exposed directly to the internet?

Avoid direct exposure and use a documented secure architecture.

Is MFA useful for camera apps?

Yes. A stolen password alone is then less likely to grant access.

Who performs updates?

Assign responsibility between customer, IT and installer.

What if compromise is suspected?

Isolate the device, preserve logs and have the incident assessed.

Sources consulted