What are the cybersecurity issues in video surveillance?

November 2019 Editor's Choice, Surveillance, Information Security

Cybersecurity has become a growing concern for consumers and companies in every sector at every step of the supply chain. The surveillance industry is no exception. Far from the days of CCTV cameras, which held information for a finite time and were not connected to the Internet, the advances in digital video mean that connected IP cameras and associated devices on the network are at risk of being hacked. The importance of the data captured by surveillance cameras – and what can be done with it – has led to a new breed of cybercriminals, looking for insights to steal and sell.

However, even if cybersecurity is recognised as a serious risk, only a handful of organisations feel adequately prepared to mitigate a cyber threat. Many blame their vulnerabilities on legacy systems, but the reality is that no device – old or new – is 100% immune to hacks; at some point, you must open a door to let someone in or out of your system, it’s inevitable.

Protecting your network and the data you hold on your customers doesn’t require you to install military-grade encryption on every device. On the contrary, the first steps are also the most efficient and simple: getting to grips with understanding the Internet of Things (IoT), identifying the vulnerabilities of your system and implementing the best practices to keep them safe.

Potential vulnerabilities in security systems?

Businesses invest vast sums to deploy physical security technology. However, too often physical security systems, such as cameras, can be a back door into IT networks, making them a prime security risk to a business. Proactively implementing the latest cyber defences remains the best practice in ensuring the highest level of cybersecurity.

There are many factors that can contribute in making a network vulnerable, many of which are linked to poor ‘cyber health’ of the network. Sometimes, it’s a lack of alignment between your IT and security teams. Failing to put in place and follow IT security policies can also lead to dire consequences; it’s not a coincidence that so many cyberattacks are due to human error. Similarly, systems that are not well maintained, updated and cared for also suffer from dramatically increased susceptibility from cyberattacks.

New cyber vulnerabilities are discovered frequently, but whether they pose a critical risk depends on two factors: first is the probability that a vulnerability can be easily exploited, second is the impact that its exploitation could have on the rest of the system. Look out for weak passwords, legacy systems and untrained personnel. Finally, consider that the higher the number of devices in your system, the higher the chance of vulnerabilities.

Cybersecurity for your surveillance devices

Maintaining cybersecurity across all devices can be difficult. Businesses should approach cybersecurity in two steps. The first is awareness; if you are not aware of potential cyber vulnerabilities, threats and issues you cannot do anything to prevent them. Step two is mitigation; once you’ve identified a potential problem, you need to take the necessary steps to patch it before it turns into a serious threat.

In other words, you need to keep learning and teaching your staff about possible vulnerabilities, so that you can spot them as early as possible. This is best done when you have clear policies in place for the management of accounts, passwords and devices.

Device lifecycle management is particularly crucial. Proactive maintenance is the best way to ensure a more stable and secure system, that’s why you should always install updates when your manufacturer releases them.

Finally, governments are introducing schemes that list the requirements a system needs to satisfy in order to be recognised as effectively secure; following these guidelines also helps businesses to be compliant with legislations like GDPR.

Cybersecurity needs in different sectors

The suggestions above are generally valid for every sector that is using security cameras, although with some differences in the approach. In finance, for example, the damage of a cyberattack to an institution’s reputation as a safe place can, over time, be more costly than any immediate loss. On the other hand, oil and gas infrastructures face more maintenance challenges, because of the remote locations of their facilities.

Data centres need to have very tight access policies in place, while smart cities need to rely on shared responsibility, that involves both public realities such as the police or the firefighters, as well as private ones like small businesses.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Surveillance & AI roundtable
DeepAlert Lytehouse Refraime SMART Security Solutions Technews Publishing Editor's Choice Surveillance Integrated Solutions AI & Data Analytics
SMART Security Solutions held an online roundtable with a few surveillance experts to explore the intersection of surveillance and AI, gaining insights into the market and how control rooms are evolving.

Read more...
Duxbury SA Milesight distributor
Duxbury Networking News & Events Surveillance
Duxbury Networking has been appointed the exclusive distributor of Milesight surveillance solutions in South Africa, expanding its surveillance portfolio with a platform designed to deliver AI-driven analytics, rapid deployment, and open integration for modern security environments.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
Transforming video surveillance into strategic intelligence
Secutel Technologies Products & Solutions Surveillance
In a world where risk moves faster, and operations are more interconnected than ever, you need more than footage — you need insight.

Read more...
Coordinated efforts lead to successful crime response
News & Events Surveillance Integrated Solutions
A synchronised operation involving Vumacam’s control room operators, the Johannesburg Metropolitan Police Department (JMPD), and 24/7 Drone Force, resulted in the successful identification and apprehension of a suspect linked to a reported theft case.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
From surveillance to insight across Africa
neaMetrics TRASSIR - neaMetrics Distribution Access Control & Identity Management Surveillance Products & Solutions
TRASSIR is a global developer of intelligent video management and analytics solutions, delivering AI-driven platforms that enable organisations to monitor, analyse, and respond to events across complex physical environments.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.