What are the cybersecurity issues in video surveillance?

November 2019 Editor's Choice, Surveillance, Information Security

Cybersecurity has become a growing concern for consumers and companies in every sector at every step of the supply chain. The surveillance industry is no exception. Far from the days of CCTV cameras, which held information for a finite time and were not connected to the Internet, the advances in digital video mean that connected IP cameras and associated devices on the network are at risk of being hacked. The importance of the data captured by surveillance cameras – and what can be done with it – has led to a new breed of cybercriminals, looking for insights to steal and sell.

However, even if cybersecurity is recognised as a serious risk, only a handful of organisations feel adequately prepared to mitigate a cyber threat. Many blame their vulnerabilities on legacy systems, but the reality is that no device – old or new – is 100% immune to hacks; at some point, you must open a door to let someone in or out of your system, it’s inevitable.

Protecting your network and the data you hold on your customers doesn’t require you to install military-grade encryption on every device. On the contrary, the first steps are also the most efficient and simple: getting to grips with understanding the Internet of Things (IoT), identifying the vulnerabilities of your system and implementing the best practices to keep them safe.

Potential vulnerabilities in security systems?

Businesses invest vast sums to deploy physical security technology. However, too often physical security systems, such as cameras, can be a back door into IT networks, making them a prime security risk to a business. Proactively implementing the latest cyber defences remains the best practice in ensuring the highest level of cybersecurity.

There are many factors that can contribute in making a network vulnerable, many of which are linked to poor ‘cyber health’ of the network. Sometimes, it’s a lack of alignment between your IT and security teams. Failing to put in place and follow IT security policies can also lead to dire consequences; it’s not a coincidence that so many cyberattacks are due to human error. Similarly, systems that are not well maintained, updated and cared for also suffer from dramatically increased susceptibility from cyberattacks.

New cyber vulnerabilities are discovered frequently, but whether they pose a critical risk depends on two factors: first is the probability that a vulnerability can be easily exploited, second is the impact that its exploitation could have on the rest of the system. Look out for weak passwords, legacy systems and untrained personnel. Finally, consider that the higher the number of devices in your system, the higher the chance of vulnerabilities.

Cybersecurity for your surveillance devices

Maintaining cybersecurity across all devices can be difficult. Businesses should approach cybersecurity in two steps. The first is awareness; if you are not aware of potential cyber vulnerabilities, threats and issues you cannot do anything to prevent them. Step two is mitigation; once you’ve identified a potential problem, you need to take the necessary steps to patch it before it turns into a serious threat.

In other words, you need to keep learning and teaching your staff about possible vulnerabilities, so that you can spot them as early as possible. This is best done when you have clear policies in place for the management of accounts, passwords and devices.

Device lifecycle management is particularly crucial. Proactive maintenance is the best way to ensure a more stable and secure system, that’s why you should always install updates when your manufacturer releases them.

Finally, governments are introducing schemes that list the requirements a system needs to satisfy in order to be recognised as effectively secure; following these guidelines also helps businesses to be compliant with legislations like GDPR.

Cybersecurity needs in different sectors

The suggestions above are generally valid for every sector that is using security cameras, although with some differences in the approach. In finance, for example, the damage of a cyberattack to an institution’s reputation as a safe place can, over time, be more costly than any immediate loss. On the other hand, oil and gas infrastructures face more maintenance challenges, because of the remote locations of their facilities.

Data centres need to have very tight access policies in place, while smart cities need to rely on shared responsibility, that involves both public realities such as the police or the firefighters, as well as private ones like small businesses.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...
What is your ‘real’ security posture? (Part 2)
BlueVision Editor's Choice Information Security Infrastructure
In the second part of this series of articles from BlueVision, we explore the human element: social engineering and insider threats and how red teaming can expose and remedy them.

Read more...
ONVIF to end support for Profile S
News & Events Surveillance
ONVIF has announced that it will end support for ONVIF Profile S and recommends using its successor, Profile T. Profile S is the first-ever profile introduced by ONVIF in 2011.

Read more...
IQ and AI
Leaderware Editor's Choice Surveillance AI & Data Analytics
Following his presentation at the Estate Security Conference in October, Craig Donald delves into the challenge of balancing human operator ‘IQ’ and AI system detection within CCTV control rooms.

Read more...
Onsite AI avoids cloud challenges
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure AI & Data Analytics
Most AI programs today depend on constant cloud connections, which can be a liability for companies operating in secure or high-risk environments. That reliance exposes sensitive data to external networks, but also creates a single point of failure if connectivity drops.

Read more...
Toxic combinations
Editor's Choice
According to Panaseer’s latest research, 70% of major breaches are caused by toxic combinations: overlapping risks that compound and amplify each other, forming a critical vulnerability to be exploited.

Read more...
Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
GenAI fraud forcing banks to shift from identity to intent
AI & Data Analytics Information Security Financial (Industry)
The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools; they need adaptability and expanding the security net.

Read more...
New Edge AI Plus PTZ cameras with analytics
Products & Solutions Surveillance
IDIS has unveiled two new PTZ cameras that are NDAA-compliant, delivering AI auto-tracking, rapid 40x zoom, EIS image stabilisation, and advanced automated AI functionality.

Read more...
Cyber attack surface expanding
Asset Management Information Security Logistics (Industry)
Despite the increasing number of attacks, analysis of Allianz Commercial cyber claims shows that severity is down by 50% and large-claim frequency by 30% in H1 2025, driven by larger companies’ enhanced detection and response capabilities.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.