3P Security GroupPrevent · Protect · Preserve

Who manages your camera system on the network?

Published Updated 5 min read

A phone view and last night's recording confirm that video is available. They do not show who can change the system, remove access or maintain it after the installer leaves.

For a property owner, the starting point is a review with the integrator and IT vendor together. Ask them to show how responsibility is divided. A camera system can fall between their contracts if one treats it as building equipment and the other treats it as someone else's network device.

We use the security systems audit to review and report. The owner's vendor makes the changes. We do not log into devices, change their configuration or apply updates.

What the Verkada incident showed

In March 2021, The Verge reported access to roughly 150,000 Verkada cameras, citing reporting that included hospitals, schools and detention facilities among affected settings. That was an early account of the reach of the access, not a final count of cameras whose footage was viewed.

Verkada's later incident report described a misconfigured support server exposed to the internet. Attackers obtained support administrator login information there and used an internal support interface to reach customer devices. The revised report said 97 customers had camera video or image data accessed.

If the incident comes up with a board, keep the two figures apart: roughly 150,000 cameras were reported reachable, and Verkada later counted 97 customers whose video or images were accessed. The cause Verkada identified was its own support access, not owners forgetting to change camera passwords.

So a review has to cover the manufacturer's support route as well. An owner's account list may not explain every path available to the vendor. Ask what access support staff can obtain, how the owner approves it and what record remains afterward.

Mirai exposed a different weakness

The 2016 Mirai botnet recruited connected devices using common default login combinations. Network cameras and digital video recorders were among the affected device types described in JVN's notice accompanying US-CERT alert TA16-288A.

Mirai exploited default logins in the devices themselves. Verkada's breach came through the vendor's own support access. Neither means your system has been compromised, but both are good reasons to ask who can administer the equipment and how you would know.

Ask the vendor to identify the actual system and the accounts reviewed, with records showing how the property has configured and maintained them.

Ask for the handover record

Request a current equipment inventory with model names, installed software versions and support status. Include the recorder and the application used to manage it. Old firmware becomes a management problem when nobody is assigned to check support notices or plan updates.

The FTC's camera guidance recommends keeping software current, replacing default passwords and considering a separate network. Although written for home cameras, those topics also give commercial property owners questions to ask their vendors.

Ask the vendor to distinguish a manufacturer's default login from a shared installer login. Replacing the factory password with an installer password used by several technicians still leaves an accountability question. Request named accounts where supported and a documented way to withdraw access when a technician leaves.

The owner also needs an administrator role under its control. Establish who can recover access if the installer closes or the management company changes. Do not put passwords in a meeting agenda or ordinary maintenance email. Ask the vendor to document the handover procedure without exposing the secret itself.

Ask IT to explain the network boundary

Cameras on the same network as office computers should prompt a conversation about separation. Ask IT to describe which systems the camera equipment needs to reach and how other traffic is restricted. A different network name is not enough evidence on its own; request a plain explanation of the enforced boundary.

For a recorder reachable from the internet, ask why that route exists, who uses it and whether the vendor has reviewed a more controlled access method. The review should identify the arrangement without publishing addresses or connection details in a board packet.

Remote viewing through a phone application does not, by itself, prove that the recorder accepts direct internet connections. Have IT distinguish the actual connection method from assumptions made because video works off site. The owner needs a documented answer, not instructions for experimenting with the equipment.

Find out what the logs can answer

NIST's IoT capability catalog includes device identification, software updates, control of logical access and awareness of security state. We translate those topics into evidence requests the owner can discuss with the vendor.

Ask whether the system records administrative sign-ins, changes to user permissions and exports of video. Have the vendor state which events are available for the installed model and subscription. Do not assume every product supplies the same audit log.

If no audit log exists, record that limitation. If logs exist but nobody reviews or retains them, assign responsibility. Ask how an owner would obtain the relevant record after a disputed change, and whether the recorder's clock agrees with the time used in incident reports.

Leave the meeting with assigned work

Send the questions before the meeting so the vendor can bring records rather than answer from memory.

  • Which owner-controlled account can administer the system, and how is it recovered?
  • Which installer and manufacturer support accounts remain available?
  • Who checks firmware support notices, approves downtime and confirms an update completed?
  • Can IT explain the camera network boundary and each remote access route?
  • Which administrative events are logged, and who can retrieve those records?
  • What changes does the vendor recommend, with an owner and completion date for each?

Ask for a written reply where an answer is missing. Separate confirmed findings from assumptions so an unresolved question does not quietly become a statement that everything passed.

For an outside review, send us the equipment list and the vendor agreements. We review the evidence and report the gaps, and your integrator or IT vendor makes the approved changes. How an engagement runs covers the steps.

Sources

  1. March 2021 incident report, revised findingsVerkada · Accessed
  2. March 2021 Verkada breach reportingThe Verge · Accessed
  3. JVN notice accompanying US-CERT alert TA16-288AJPCERT Coordination Center and IPA · Accessed
  4. How to secure your security camerasFederal Trade Commission · Accessed
  5. IoT cybersecurity capabilities catalogNIST · Accessed

Send us the records you want reviewed.

Discuss a review