3P Security GroupPrevent · Protect · Preserve
Consulting · Available now

Security systems audit

We walk the property and review the security devices, then document network exposure, account access and the equipment anyone can reach. A camera can cover the right door and still sit on the office network with a shared password. A recorder can be out of sight on a network diagram and within reach of anyone in the hallway. This audit puts both conditions in the same report.

Fig. A

Where a compromised camera can reach

Flat network Camera Camera Recorder Office network A compromised camera can reach the rest Isolated segment Camera Camera Recorder Controlled crossing Office network Only permitted traffic crosses
Flat network Camera Camera Recorder Office network A compromised camera can reach the rest Isolated segment Camera Camera Recorder Controlled crossing Office network Only permitted traffic crosses
On a flat network, the camera shares a path to the rest of the property. An isolated segment puts a controlled crossing between the security devices and general traffic. We document the arrangement we find and recommend changes for your vendor to review.

What the records show

In March 2021, attackers used an exposed super admin credential to reach live feeds from 150,000 Verkada cameras across hospitals, prisons, schools and large companies. Security Magazine and Compliancy Group reported the incident. That level of access was built into the vendor's software; using it required no additional hacking.

The account list belongs in the same review as the equipment cabinet. We examine the security devices and their network connections alongside a walk of the property. The scope is narrower than a general physical risk assessment and does not include an IT penetration test.

How it runs

  1. Agree the scope. We write down the equipment to review, the records needed and any permitted, non-invasive reachability checks before work starts. We test only what you give us permission to test. We do not attempt a login or exploit a vulnerability.
  2. Walk the equipment. We document where the recorder lives, whether its cabinet locks and whether someone standing in a hallway can reach it. We follow the physical route to the cameras and access control panels with the site representative.
  3. Review the network. From network records and settings your administrator demonstrates, we determine whether cameras and recorders use an isolated network segment or share general traffic. We review whether a recorder or camera is reachable from the public internet, using only the checks agreed in the scope.
  4. Review access and firmware. You or your vendor supply account records and firmware versions or demonstrate them while retaining control. We review default or shared credentials on cameras, recorders and access control panels, who holds administrative access, how many accounts exist and which are shared. We compare camera, recorder and supporting switch firmware with manufacturer releases. We check whether an audit log exists and whether anyone reviews it. We do not collect passwords.
  5. Write the findings. Each finding states what we observed, the evidence behind it and the recommended next step. Anything the available records cannot establish is marked unverified. We review the report with you and the vendor responsible for changes.

What you receive

  • A findings register covering network isolation, internet exposure, credentials, account ownership, firmware and audit logs, with a priority and supporting evidence for each finding.
  • A record of the equipment locations and physical exposure, with photographs where permitted.
  • A diagram of the security devices and their connections to general traffic, with unverified connections marked.
  • Written recommendations and questions for your vendor, including who needs to confirm each unresolved item. You or your vendor carry out any changes.

The walk and the device review happen in the same visit and land in the same report, so nothing falls into the gap between the people who watch the property and the people who maintain the network.

What this is not

This is not a penetration test. We do not attack systems. It is not remediation. We document findings and hand them to you or your vendor. It is not device management. We do not log into devices, take administrative control, reconfigure, patch or harden anything. It is not a guard service. We do not post guards, run patrols, monitor property, respond to alarms or install hardware.

The scope and fee are agreed in conversation before work starts.

Ask about this service

The other consulting services