The network strategy physical security needs

According to Mohamad Saad, Country Manager for Saudi Arabia at Genetec, physical security has become part of the IT attack surface.

For years, physical security systems operated in their own world, apart from IT. Video surveillance and access control systems ran on closed networks managed mostly by facilities and physical security teams.

Today, those same systems are interconnected, running on IP networks, right alongside business applications and data. In other words, they’re part of the IT landscape and the attack surface. Despite this shift, many organisations and their IT teams still consider physical security to be outside their scope of responsibility. That gap leaves blind spots in network visibility and cybersecurity.

Why the disconnect still exists

Physical security started as an operational function focused on protecting people and property, while IT focused on managing data and connectivity. As devices became digital, the systems converged, but in many organisations, the teams did not.

Many facilities and physical security teams still purchase and maintain cameras or access control systems independently, without looping in IT. They may not have the tools or expertise to handle firmware updates, certificate renewals or network segmentation. Meanwhile, IT teams may not know how many connected devices are on their networks or what risks they pose.

When physical security becomes a cyber problem

Physical security devices might not look like computers, but they function like them. They have IP addresses, firmware and credentials that must be secured. If ignored, they can become easy entry points for attackers.

The most common weaknesses are the same ones IT professionals have fought for years: Unchanged default passwords, outdated software, expired certificates and devices left unmonitored for months or years. For example, once a bad actor compromises a single connected camera, they can move laterally through the network, potentially reaching unrelated, sensitive business systems.

The moment physical security runs on the same network as corporate IT without proper network segmentation, exposure increases dramatically.

The growing attack surface

Implementing video surveillance and access control systems delivers significant benefits, including centralised visibility and data-driven insights. But every new device also expands the attack surface.

Each sensor and camera becomes another endpoint that needs to be monitored and protected. Without clear ownership or consistent oversight, vulnerabilities multiply quickly. That’s why IT needs to take an active role in securing these systems.

Where to start: Fundamentals that make a difference

The good news is that securing physical security devices doesn’t require reinventing the wheel. Many of the same best practices IT already uses apply here, too.

  1. Use different passwords: Often, integrators set the same password for every camera in a system to make setup and maintenance easier. The downside is that if that one password is leaked, every camera becomes vulnerable. Whenever possible, use different passwords and certificate-based or multifactor authentication.
  2. Stay current on firmware and software: Firmware updates often include critical security patches. Schedule updates regularly rather than waiting for an incident to prompt them.
  3. Encrypt device communications: Use encryption like HTTPS to secure data in transit. Unencrypted streams can be intercepted or manipulated, especially in systems that transmit sensitive video or access data.
  4. Segment the network: Place physical security devices on their own virtual local area network (VLAN), separate from core business systems. That way, even if a camera or badge reader is compromised, the attacker can’t easily move to critical assets.
  5. Schedule regular maintenance and audits: Firmware, certificates and access credentials should be reviewed and updated on a defined schedule. Building these steps into IT workflows helps reduce vulnerabilities over time.

Building collaboration between IT and security teams

No one expects physical security teams to suddenly become cybersecurity experts, or for IT to learn the ins and outs of video surveillance or access control overnight. The goal is collaboration, which starts with shared visibility.

IT can help provide insight into which devices are connected, identify existing vulnerabilities and track where data is flowing. In turn, physical security teams can provide context on which systems are mission-critical, when maintenance windows are available, and what operational requirements need to be met.

Some practical ways to strengthen this partnership:

  • Include IT and cybersecurity departments early in the procurement process: Cybersecurity teams can define operational needs, while IT sets cybersecurity standards.
  • Create clear ownership for updates and credentials: IT can handle the technical side of patching and certificate renewals, while security teams focus on monitoring and operating the physical security system.
  • Establish shared security policies: Even if physical security systems aren’t covered by ISO 27001, using the same best practices, such as strong authentication, encryption and regular audits, helps keep security consistent across the whole organisation.

When both groups are aligned, updates happen faster and risks are reduced.

Designing the network with security in mind

When managing physical security devices, it’s important to design systems that are secure, efficient and resilient from the start. These systems come with unique demands that traditional IT infrastructure wasn’t always built to handle.

  • Bandwidth and latency: Video traffic is data-heavy and unpredictable. Network planning needs to account for how much bandwidth cameras consume, especially in large deployments.
  • Storage management: Choosing between on-premises, cloud or hybrid deployments depends on the organisation’s needs. For example, some companies may keep recent footage on local servers for quick access while archiving older video in the cloud for scalability. Cloud platforms can also simplify updates and reduce the need for on-site maintenance.
  • Redundancy: Security systems can’t go dark. Redundant links and failover paths ensure critical functions stay online even if a network segment fails.
  • Privacy and compliance: Regulations, such as the EU’s GDPR, classify video as personally identifiable information (PII). This means footage must be stored securely and retained only as long as necessary. Organisations operating in multiple jurisdictions must also align storage policies with local privacy laws.

Looking ahead

The line between physical security and cybersecurity is becoming increasingly blurred. Cameras, sensors and access readers are now as connected as laptops and smartphones. These systems fall under the scope and expertise of both IT and physical security teams, whose collaboration can strengthen defences across the entire organisation, keeping people safe, operations running and risks contained.

Tags:
No Comments

Sorry, the comment form is closed at this time.

1