CCTV and Video Management System Security Assessments
A video management system is usually thought of as a physical security control. It is also one of the largest stores of sensitive information many organisations hold, and one of the least protected.
CCircle provides independent security assessments of CCTV and video management systems, covering the cameras, the VMS platform, the storage behind it, and the way footage is accessed, retained and released.
Video is data
Footage is information. It shows who entered a facility, when, with whom, and what they did. On a sensitive site, it can reveal the layout of secure areas, the movement of personnel, the operation of controls, and the identity of people whose identity is meant to be protected.
That means a video management system is not simply a camera network. It is a system holding a large volume of sensitive, and often personal, information. It should be governed accordingly. In most organisations, it is not.
The same pattern applies here as elsewhere in physical security. These systems were once standalone, so they were treated as building systems. Today they are networked, integrated, and frequently sit on or adjacent to the corporate network, but the way they are managed has not caught up. They are patched less, monitored less and reviewed less than any corporate system holding comparable information.
The camera fleet
Cameras are the part most often overlooked. An organisation may have hundreds of them, each one a networked device running firmware, and in many cases that firmware has not been updated since the day the system was commissioned.
A camera is an endpoint. It has an operating system, a network interface, credentials and a management interface. Treated as a fixture rather than a device, it can quietly become the least protected thing on the network, and the easiest way onto it.
Supply chain and vendor risk
Camera and recorder hardware carries supply chain considerations that other physical security equipment does not. In Australian Government, Defence and critical infrastructure environments, the provenance of a device matters as much as its configuration.
We assess whether the equipment deployed on your site is appropriate for the environment it sits in, including NDAA compliance, which has become the practical procurement benchmark for surveillance equipment across allied government environments.
This is a common and uncomfortable finding. Equipment installed years ago, under procurement rules that no longer apply, is often still in service, and an organisation can be operating a camera fleet that would not be permitted if it were purchased today. We identify what is deployed, whether it remains acceptable, and what a realistic replacement path looks like.
What we assess
The VMS platform.
The server, operating system and database. Patching and currency, hardening against the manufacturer's published guidance, service accounts, and audit logging.
Cameras and recorders.
Firmware currency, default and shared credentials, exposed management interfaces, unnecessary services, and the security of the protocols in use.
Network position.
Whether the camera network is segmented from the corporate network, whether it is monitored, and what an attacker who reached that segment could reach next. Camera networks are frequently flat, and frequently trusted.
Access to footage.
Who can view, search, export and delete. Export is the point at which sensitive footage leaves your control, and it is often the least governed action in the entire system.
Retention and storage.
How long footage is held, where it is stored, whether it is encrypted, and whether retention actually matches your obligations rather than the size of the disk.
Evidentiary integrity.
Whether footage can be relied on if it is ever needed. Audit logging, protection against tampering, and a defensible process for export and release.
Privacy and information handling.
Footage of individuals is personal information. We assess how it is handled, disclosed and disposed of, and whether that stands up to scrutiny.
Alignment with Australian requirements.
Assessment against the ISM and ACSC guidance, manufacturer hardening guidance, and where relevant the Protective Security Policy Framework.
What we typically find
- No vulnerability scanning of the camera or VMS environment, ever
- Camera firmware never updated after commissioning
- Video management and recording servers running old, unsupported versions with no patching regime
- Operating system patches not applied to VMS or recording servers
- Guard and operator workstations sharing a single login, so no action can be attributed to a person
- No multi factor authentication and no identity management across the platform
- Remote access via a weak VPN configuration, commonly a pre shared key with absent or unsuitable encryption for the tunnel
- No process to review access, and no process to revoke it when someone no longer needs it
- Manufacturer hardening guidance published, but never applied
- Camera networks flat, unsegmented and unmonitored
- Footage export with no approval, no logging and no oversight
- Retention periods that reflect available storage rather than any actual requirement
Individually these look like operational shortcuts. Together they usually mean the video system is neither secure nor reliably able to produce the footage it was installed to capture.
Architecture review
Beyond assessing what is deployed, our consultants provide advice on the architecture itself.
Many video environments were not designed so much as accumulated, expanded site by site and camera by camera over years, without an overall design holding it together. We identify the gaps in that architecture, including segmentation, remote access, identity, storage and resilience, and advise on a target design that is defensible and workable.
Systems we work with
We are independent of the manufacturers and work across the platforms in common use in Australia, including Milestone, Avigilon and Geutebrück, as well as other video management systems.
Our assessments apply the same standards regardless of platform, drawing on the manufacturer's published hardening guidance alongside the ISM and ACSC guidance.
Where CCircle fits
Our consultants work in the physical security systems space specifically, and understand these platforms in depth. That matters, because a control applied without understanding the system will break the operation, and a control that breaks the operation gets reversed.
A camera network that has been secured but no longer records reliably has not been improved. Our objective is a system that is genuinely defensible and still does the job it was installed to do.
Who this is for
Government agencies, Defence organisations, government suppliers and critical infrastructure operators, particularly where footage captures sensitive areas, sensitive activity, or people whose identity requires protection.
Talk to us
To discuss an independent assessment of your CCTV or video management system, call 1300 045 483 or email info@ccircle.com.au