The cyber blind spot

Steven Kenny, Manager, Architect & Engineering (A&E) Program EMEA at Axis Communications, says organisations must rethink cyber risk in connected security systems.

Security systems are more capable, connected and widely used than ever, protecting people, assets and operations across rapidly evolving cities, critical infrastructure networks, transportation hubs and commercial developments. Frameworks like SIRA and ADMCC have set a high benchmark for how those systems should be designed, installed and operated, as well as helped create environments that are operationally robust and compliant by design.

Yet, there is a growing challenge that industries are only now beginning to address. Security systems may be designed as physical infrastructure, but in reality, they operate as connected digital technologies. This introduces a new layer of risk.

Operational strength meets a cyber gap

Modern security deployments are typically well defined from an operational perspective. Camera coverage is defined, retention periods are specified, monitoring and control requirements are clear, and system resilience is carefully considered. In regulated places, these points are not suggestions; they are enforced.

But cybersecurity is a different story. In many cases, it is handled indirectly through network policies, user access controls and audit trails. While these are all important, they are not enough. There is rarely a structured, detailed approach to device security or vulnerability management. Who owns cyber risk is often murky as well, spread across different departments and organisational leads.

This creates an uncomfortable reality: a system can tick every compliance box and still be wide open to threat actors.

The design gap in connected security systems

Responsibilities across projects are typically clear on paper. Consultants focus on system design and compliance. System integrators handle deployment and configuration. Vendors supply the technology while IT teams manage the network environment.

Cybersecurity, on the other hand, sits between these roles. It is often assumed to fall under IT, yet security systems are not simply another endpoint on a network. They are complex, integrated platforms with unique risk profiles. As a result, cybersecurity is rarely addressed at the design stage and not always fully implemented during deployment. If it is not embedded in design, it becomes significantly harder to effectively implement later.

A lack of convergence across functions

The challenge of bringing physical security, cybersecurity and operational functions together is not unique to any region. Research from ASIS International says full integration between physical security, cybersecurity and business operations is rare; only around one in five organisations report achieving this level of integration. Most organisations operate in silos, barely coordinating between teams even though their risks overlap. With limited coordination, cyber risk is shared across the whole system but not managed as a whole.

The evidence behind the risk

Industry insiders consistently find cybersecurity rarely spelled out in specifications or project tenders. PwC’s Global Digital Trust Insights reports only 2% of organisations have cyber resilience in every part of their business. People know it matters but have not made it part of the process.

Too often, cybersecurity comes up late in the game. It becomes an afterthought forced onto finished systems. That is expensive, complicated and usually less effective. Retrofitting security into an already deployed system is significantly more challenging than building it in from the start.

Addressing the right risk

The Allianz Risk Barometer 2026 ranks cyber incidents as the biggest threat to business. Yet, cybersecurity is still treated as secondary when it comes to physical protection. That matters because connected surveillance systems are becoming targets. Check Point Research finds that network-connected devices, including cameras, are actively probed and targeted by threat actors. This reflects a shift the industry can no longer ignore. Cyber risk is no longer selective. It does not respect sector, geography or organisational intent. As systems become more connected, the likelihood of exposure only increases.

Today, systems are IP-based, cloud-connected and integrated into wider enterprise platforms. They generate data, interact with other systems and play a role in operational decision-making. This means that security technology is no longer only protecting the organisation, it is also a potential entry point into it. If cybersecurity is not designed in, these systems bring risk right into the environment they are meant to secure.

Regulation is raising expectations

Regulatory frameworks are evolving rapidly to address the challenges that cyber risk poses. Case in point, the NIS2 Directive focuses on accountability risk management and supply chain assurance. The Cyber Resilience Act places requirements on product security, including by-design principles and lifecycle vulnerability management. These regulations push expectations higher. Organisations that operate internationally will increasingly be expected to align with these standards. As organisations become more connected, global cybersecurity standards increasingly apply across borders.

For organisations across the region, this shift requires a change in mindset. Consultants need to incorporate cybersecurity into system design and specification. System integrators must consider it during deployment, configuration and handover. End users must evaluate systems not only on functionality and compliance, but also on their long-term security posture.

It is no longer just about whether the system meets the operational requirements. Organisations also need to consider whether systems are secure by design, whether they can be maintained securely over time and who is accountable for managing cyber risk within the system.

What ‘good’ looks like

Luckily, addressing this challenge does not require a complete reinvention of the industry. It does, however, need a shift in mindset and a more integrated approach to security.

Cybersecurity must be considered alongside physical security from the outset. Vendors must be judged on their security, not just their technology. Systems need lifecycle security management, and risk responsibility must be crystal clear for everyone involved.

In short, treat security systems as connected ecosystems, not as isolated tools.

It’s all part of the job

The physical security industry has come a long way in setting standards for deployment and operation across the Middle East and globally. But the world has changed. We are not just dealing with cameras and sensors anymore; we are managing intelligent networked technologies woven into larger digital infrastructures.

The real question is not just, “Does it work?” It is, “Can we trust it?”

Cybersecurity is not a side note; it is built into every part of the system. As everything gets more connected, that shared responsibility becomes even more vital. Managing cyber risk is not optional. It is part of the job.

No Comments

Sorry, the comment form is closed at this time.

1