Security systems used to be separate: their own cabling, their own recorder, installed by a security company and never touched by IT.

Now cameras, door entry, intercoms and alarm panels are network devices. That makes them your IT responsibility whether or not anybody has said so.

They belong on their own segment

The most important decision, and the most frequently skipped.

Camera and access control equipment is among the least maintained on any network. Firmware is rarely updated. Default credentials survive for years. The software is often built by manufacturers whose security practices are not their strength.

These devices are also permanently powered, permanently connected and rarely looked at — which makes them an ideal foothold. Compromised camera systems have been used as entry points into business networks and as participants in large-scale attacks.

Put them on their own segment with no route to business systems, and permit only what they genuinely need — usually a connection to their recorder and, if required, a controlled path for updates. See VLANs explained.

Bandwidth and cabling

Cameras produce a continuous stream, and higher resolutions produce a great deal of it. A dozen cameras at high resolution can saturate a link that seemed adequate.

Practical measures: keep camera traffic on its own segment so it does not compete with business use; connect the recorder to the switch on a fast link; and consider whether cameras and recorder can sit on the same switch so the traffic never crosses the wider network.

Power over Ethernet is standard for cameras and door entry, which means one cable per device and a switch with an adequate power budget. Calculate the total draw before ordering the switch — this is a common oversight, and a switch that runs out of power budget drops devices unpredictably.

Put the recorder and the switches on an uninterruptible power supply. A brief power interruption that takes out the camera system also takes out your record of what happened during it.

Storage, calculated before purchase

Retention requirement multiplied by camera count multiplied by resolution and frame rate. Do this arithmetic before buying, because the common discovery is that a system sold as sufficient holds nine days rather than the thirty the business assumed.

Also consider what happens when a disk fails, because it will. A recorder with redundant storage keeps recording through a failure; one without loses everything at once.

And consider where the recorder lives. A recorder in an unlocked cupboard by the front door is the first thing a burglar removes. Somewhere secure, or with footage also copied off site.

Data protection obligations

CCTV capturing identifiable people is processing personal data, and the obligations are real.

  • A lawful basis for the recording, documented. Usually legitimate interests, with an assessment behind it.
  • Clear signage stating that recording is taking place, who operates it and how to make contact.
  • A retention period that is justified and actually applied. Keeping footage indefinitely because the disk is large is not defensible.
  • A process for access requests. Individuals can request footage of themselves, and you have a limited time to respond. This is difficult if nobody has ever done it, so work out how in advance.
  • Restricted access, with a record of who viewed what. Casual viewing of footage by anyone who wanders past the monitor is a problem.
  • Care about coverage. Cameras pointing at areas beyond your property, or into spaces where people expect privacy, raise separate issues.

Access control systems produce records of who entered where and when, which is also personal data and also subject to retention rules.

A camera system is a data processing operation with a lens attached. Treat it with the same discipline you would apply to a customer database.

Remote access, done safely

The wrong way, and the common way, is forwarding a port on the firewall to the recorder. Systems exposed like this are found by automated scanning within hours and are regularly compromised.

The right way is brokered access — a controlled path that authenticates the user before connecting them to the system, without exposing the recorder to the internet. See remote access done safely.

Manufacturer cloud services can be convenient and vary considerably in quality. Ask where footage is stored, who can access it, and what happens if the manufacturer's service is discontinued.

Maintenance nobody schedules

Firmware updates on every device, including the ones on the roof. Default credentials changed and recorded. Individual accounts rather than one shared password. Recording verified — periodically check that footage actually exists for a chosen time rather than assuming.

That last check finds problems regularly. Cameras fail, disks fill, and a system that appears to be recording may have stopped weeks ago.

Who is responsible

Worth settling explicitly. The security installer maintains the cameras; who patches them? Who holds the credentials? Who is accountable if the system is compromised?

The answer should be written down, because "the security company" and "IT" each assuming the other is handling it is the normal state of affairs.

Our infrastructure team designs networks for camera and access control systems across Suffolk and Norfolk, with proper segmentation and remote access. Start a conversation.