Safeguard surveillance devices from cyberattacks

Issue 6 2023 Surveillance, Information Security


Rudie Opperman.

Regardless of their industry, South African enterprises face significant cybersecurity challenges. Fortunately, enterprises appear to be waking up to that. According to the KPMG Africa Cyber Security Outlook, 34% of surveyed organisations have a fully independent cyber and information security function, with oversight through risk management and internal audit. In comparison, 47% have information security incorporated into IT security.

Cybersecurity concerns extend through the organisation and out among its stakeholders and supply chains. It also covers video surveillance, which is critical to any organisation’s physical security and asset protection strategy. Thanks to network video and connected technologies advancements, video surveillance is more intelligent than ever. However, it also now faces greater risks, which is why enterprises must commit to best practices and ensure their surveillance networks, data, and devices remain protected from any potential vulnerabilities and threat actors seeking to exploit them.

From analogue to digital to connected

Physical security used to be a relatively straightforward process; point a CCTV camera at the thing you want to secure and monitor the feed from a centralised location. Devices stored little to no information and were not connected to any greater network. This all changed during the digital revolution in the 1990s with the advent of the Axis NetEye 200 – the world’s first Internet Protocol camera capable of transmitting footage wirelessly over a computer network.

From there, video surveillance has only grown in technical complexity and functionality. Camera manufacturers have increased their products’ processing capabilities, effectively creating a whole solution at the network's edge, capable of gathering, analysing, and storing data at the point of capture. This yields several benefits, including the ability to place edge solutions in locations that may be logistically challenging or lacking adequate infrastructure, and also reduced labour installation and associated costs.

The trade-off of this innovation has been that cameras are no longer passive devices, but active components of greater organisational IT ecosystems. As a result, like any connected technology, they can be a point of attack for malicious actors.

The perils of cyberspace

The integration of physical security and video surveillance into greater IT networks has resulted in the sector being a potential backdoor for cyberattacks. According to Check Point Research, the first two months of 2023 saw a 41% increase in the average number of weekly attacks per organisation targeting IoT devices, compared to the same period in 2022. In addition, on average, 54% of organisations suffer from attempted cyberattacks targeting IoT devices every week.

Video surveillance devices can suffer from several cyber vulnerabilities. For example, an organisation’s IT and physical security teams may not always be aligned, meaning that there is a failure to adhere to critical shared security policies and guidelines. Security systems may also not be as well maintained or cared for as other systems, resulting in them being more susceptible to intrusions by threat actors.

The risk of these vulnerabilities is measured according to two factors: the probability of a vulnerability being exploited and the impact that that exploitation may have on the rest of the system. Threat actors are getting smarter and have access to advanced technologies such as artificial intelligence (AI) to develop malware and phishing-based strategies. Organisations need to take these threats seriously, and they can do that by adhering to effective best practices when protecting their networks.

Resiliency, efficiency, and performance

Video surveillance networks can range from a single pair of devices to an expansive network made up of dozens, if not hundreds, of interconnected devices. Administrators can face a mammoth task in reinforcing the resiliency of those networks and need access to the right knowledge and tools to maintain efficiency and meet security standards and obligations.

Organisations can take the following steps to ensure the resiliency of their video surveillance devices and networks:

• Keep a complete device inventory: Instead of just prioritising critical assets, organisations should retain clear documentation and information about all devices connected to their networks. Effective device management also means organisations can efficiently troubleshoot or replace devices that may be discontinued by their manufacturer, or no longer receive software support.

• Establish a user account and password policy: Device login details and passwords are commonly shared throughout an organisation, which may result in deliberate or accidental misuse. The solution is to create a multi-layered system of accounts with varying levels of user privilege, as well as user temporary accounts to grant temporary access as required.

• Utilise cost-efficient HTTPS management: Video systems may be subject to regulations regarding traffic encryption between clients, which itself is an important tool for network resiliency. Device management software that manages certificates and HTTPS configuration can both reduce costs and ensure a trusted connection.

• Awareness and mitigation: Organisations must adopt a continuous learning and improvement mentality when it comes to cybersecurity readiness, as well as enshrine a culture of security across their personnel and departments. In addition, they must work with vendors and supply chain partners that have a proven cyber maturity record.

These steps form part of a holistic approach to taking care of your devices. As more enterprises in South Africa leverage the power of video surveillance to secure and improve their business functions, they must also consider the security implications of digital devices.

Resources

- https://www.securitysa.com/*kpmg3

- https://www.axis.com/blog/secure-insights/what-are-the-cybersecurity-issues-in-video-surveillance/

- https://www.deepsentinel.com/blogs/home-security/history-of-surveillance-cameras

- https://www.axis.com/blog/secure-insights/edge-surveillance-solutions/

- https://www.securitysa.com/*checkpoint1

- https://www.axis.com/blog/secure-insights/video-surveillance-secure/


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
Secure, modernise and optimise CCTV
Surveillance Products & Solutions
Industrial and commercial organisations are navigating complex digital transformation processes. With SecuVue, companies can bridge the gap between operational technology and information technology for safer, smarter operations.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
Eagle Eye Precision Person & Vehicle Detection
Surveillance Products & Solutions AI & Data Analytics
Eagle Eye’s new Precision Person & Vehicle Detection feature detects people and vehicles at long distances with high accuracy and is especially designed for customers who actively monitor for intruders

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.