Your Security Cameras Are Computers: 5 Cyber Risks Hiding in Your Physical Security System`

Nobody sold you a computer. They sold you a camera.

Walk enough Atlanta buildings and you find the same closet: a recorder humming on a shelf, cameras nobody has touched since the day they went up, and a login nobody in the building can produce. The system does what it was bought to do. It records. And for most of the last twenty years, that was the end of the story, because a camera was a closed circuit and it did not talk to anything.

That changed. Every one of those devices is now a small computer with a processor, an operating system, a network connection, and a password. Which means every one of them can be logged into, left unpatched, or quietly used as a door into everything else you run.

I have designed, installed, and serviced commercial camera systems across metro Atlanta since I founded Verified Security in 2007. Let me sort this the way I would on a walk through your building: the five risks I look for, and what to do about each.

The short version. Yes, business security cameras can be hacked. The five risks I find most often are a default password nobody changed, firmware nobody has updated since the install, cameras sharing one flat network with your business computers, equipment whose support has quietly ended, and a system nobody in the building actually owns. Almost none of it requires replacing your cameras. All of it requires someone to be responsible for them.

One thing up front, because it is the reason this never gets fixed. These five risks do not belong to one person. Three sit with your security company, and that includes mine. One sits with your IT provider. One sits with you. The trouble is that the camera hangs on the wall, so the IT company assumes it is the security company’s problem, and it lives on the network, so the security company assumes it is IT’s. It ends up belonging to nobody. I will mark whose job each one is as we go.

Why a Camera Is a Computer, and Why That Changes Everything

This is not my framing. It is the government’s. In its guidance on buying connected devices, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says these devices are “capable of harboring the same kinds of vulnerabilities as traditional computing assets,” and that attackers “often use the IoT technologies to gain entry into an environment as a stepping-stone to compromise other systems.”

Read that second part again, because it is the part owners miss. The prize is usually not your video. Nobody is desperate to watch your loading dock. The prize is the foothold. A camera is a computer that sits on your network, runs around the clock, and is the one machine in the building nobody is watching.

Risk 1. The Password That Shipped in the Box

Start here, because it is the most common thing I find and the cheapest to fix.

When the National Security Agency and CISA published the ten most common cybersecurity misconfigurations they find inside real organizations, the first one on the list was default configurations, and the first thing named under it is default credentials. The advisory calls out security cameras by name, alongside printers, VoIP phones, and conference room gear, as equipment that “commonly contain default credentials that can be used for easy unauthorized access.” The method is not sophisticated. Attackers find those passwords “with a simple web search” and log in.

This is not theoretical. Researchers at Bitsight scanned the internet in 2025 and found more than 40,000 cameras, business and home alike, streaming live to anyone who cared to look, with no password at all. Roughly 14,000 of them were in the United States. Their note on the skill required is the part that should get your attention: “in most cases, a regular web browser and a curious mind are all it takes.”

Whose job: your security company’s, and that includes mine. Change the passwords on your cameras and your recorder, use a different one for each, turn on multi-factor authentication anywhere the system offers it, and store the credentials where your business actually keeps records. It costs nothing. If you cannot log into your own recorder today, that is the first thing to fix, and it is worth a phone call.

Risk 2. Firmware Nobody Has Touched Since the Install

Every camera and recorder runs software. Flaws get found in that software over time, and the manufacturer publishes a fix called a firmware update. Somebody has to install it. On most systems I walk into, nobody ever has.

The advice you will read everywhere is to update immediately, always. Working installers are more careful than that, because a bad update can knock a camera offline or break something that was working fine. So here is a policy that survives contact with a real building: check for security patches at least quarterly, apply security fixes promptly rather than chasing every feature release, and test before pushing an update across every device at once. Deliberate is not the same as never. Never is what gets you hurt.

Here is what never costs you. CISA maintains a catalog of vulnerabilities it has confirmed are being exploited in the wild, not theorized about, and IP cameras and video recorders sit on that list. One camera flaw on it, CVE-2019-11001, was first identified in 2019 and was not added to the actively-exploited list until December 2024. Five years after the problem was public, criminals were still successfully using it. CISA’s own entry tells owners to stop using the affected cameras if no mitigation is available, which brings us to the part of this that actually costs money.

When a device reaches end of life, the manufacturer stops supporting it entirely. The federal standard on patching, NIST SP 800-40, says the quiet part out loud: for end-of-life software, “a patch for it will never be released.” No update is coming, and no setting makes it safe. That same document calls patching “a cost of doing business,” which is how I wish more owners heard it. You already accept that for your HVAC and your fire extinguishers. Your cameras earned it too.

Whose job: mine, with one part that has to be assigned. Knowing which of your devices the manufacturer still supports, and replacing the ones it does not, is security work and it is what I am for. The quarterly patching in between is a real job that somebody has to be named for, in writing, whether that somebody is your security company, your IT provider, or a person on your staff. What sinks buildings is not choosing wrong. It is never deciding.

Risk 3. One Flat Network, With Everything On It

This is the risk that turns a camera problem into a business problem. In most buildings I walk, everything shares one network. The cameras, the recorder, the door controllers, the point-of-sale terminals, the office computers, the file server, and often the guest Wi-Fi all sit together, able to reach each other freely. The least-defended device in the building has a clear path to the most important one.

The federal guide to securing operational technology, NIST SP 800-82, recommends that organizations consider separate network segments for safety and security systems, and it names cameras, doors, and access card readers directly. CISA is just as blunt about what happens without that. Unsegmented networks, it says, make it “easier for threat actors to move laterally after breaching the IT network,” and weak boundary protection has been the most prevalent finding in its network security assessments since 2015.

If you take credit cards, this pattern has a name. The PCI Security Standards Council describes a common breach where the attacker targets systems the business considers out of scope for PCI DSS, then uses them as stepping stones to the systems where the cardholder data lives. Nobody comes in through the camera because they want the camera. They come in through the camera because it is the thing nobody thought to guard.

Whose job: your IT provider’s, working from what I give them. I am not going to pretend to be your IT company. What I will do is hand them a short, exact list. Put the cameras, the recorder, and the door controllers on their own network segment, separated from your business systems and your guest Wi-Fi. Do not expose the recorder directly to the internet. Set up remote viewing through a secure connection instead of an open port, because you should absolutely still be able to watch your cameras from your phone. Any competent IT provider can execute that. It is the same principle I wrote about with access control wiring in my post on mobile access credentials: securing the device and leaving the path wide open is half a job.

Risk 4. Equipment That Answers to Somebody Else

You have probably heard that some camera equipment is banned. A lot of what gets repeated about that is wrong in ways that cost people money, so let me be precise instead of dramatic. I am not going to name a brand and tell you to panic. I am also not a lawyer, and nothing here is legal advice.

The Federal Communications Commission publishes a Covered List of communications and video surveillance equipment that has been determined to pose an unacceptable risk to national security. For the video surveillance brands, Congress did the naming itself in the 2019 defense bill, and it wrote in a limit almost nobody quotes. That equipment is covered only to the extent it is used “for the purpose of public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes.” Read that limit again if you own a restaurant.

Two things have happened since. In November 2022 the FCC barred equipment on that list from receiving new authorizations. And starting July 16, 2026, it bars the continued importation and marketing of older covered models that had already been approved. That newer rule carries the same limit, applying only to equipment imported or marketed for those covered purposes, and the FCC has suspended the critical infrastructure piece of it until it writes a clearer definition.

So here is the part almost every article on this subject gets wrong. If you are a private business with no federal contract or subcontract, and no federal grant or loan money, owning and operating this equipment is not illegal. No federal rule fines a private end user for it, and none makes you pull it off the wall. The FCC said so itself, in plain words, in the very order that tightened the import rules: the prohibition “will not affect the continued use or operation of already-purchased communications equipment.”

Where this does reach you is federal work. Under Section 889, federal agencies cannot buy this equipment, contractors cannot supply it, and the rule reaches the equipment a contractor uses even outside its federal work. Federal grant and loan dollars cannot pay for it either. So for most businesses this is an eligibility question, not a legal one. If federal or federally funded work is anywhere on your horizon, and that includes subcontracting to somebody who holds a federal contract, take it to your attorney rather than to me. My job is making sure you know what is hanging on your wall before somebody else asks.

One more thing you will hear is “NDAA-compliant,” used like a certification. It is not one. No federal agency tests it or issues it. It is a representation your manufacturer and your integrator are making to you, so ask for it in writing, and ask what is inside the box rather than whose logo is on the front.

Whose job: mine. Telling you what is actually on your wall, whether it sits on the federal list, and what that means for the work you want to win. That part is an afternoon, and it costs you nothing.

Risk 5. The System Nobody Owns

The last one is not technical at all, and it is the reason the other four survive. Ask who is responsible for your camera system and you will often watch a small silence happen. IT figures it belongs to facilities, because it is cameras. Facilities figures it belongs to IT, because it is on the network. So the system sits there, owned by no one, running software nobody updates, on a network nobody reviews.

The government has a name for the device at the center of this. In February 2026, CISA, the FBI, and the United Kingdom’s National Cyber Security Centre jointly told organizations to “actively scan networks for undocumented and outdated edge devices,” to keep an inventory of each one along with its support end date, and to review that inventory regularly. Undocumented device. That is as close as the federal government comes to a name for the camera nobody remembers installing.

This is bedrock, not a nice-to-have. Inventory is the first of the CIS Critical Security Controls, Control 1 of 18, and it explicitly covers IoT devices, which is exactly what your cameras, recorder, and door controllers are. CISA’s baseline goals for small and mid-sized organizations go one step further: they call for security roles to be established, communicated, and enforced, because the risk being addressed is a “lack of sufficient cybersecurity accountability.”

So here is the question I would ask before any technical one. Whose name is on your camera system? If the honest answer is nobody, you do not have four technical problems. You have one management problem that produced four technical problems, and it is fixable this week.

Whose job: yours. This is the only one on the list I cannot do for you. Somebody in your building has to own the camera system by name, the way somebody owns the fire panel and somebody owns the alarm code. Once that person exists, the other four get fixed. Until they do, they come back.

Most of This Costs You Nothing

This is usually where a quote appears. Here is the honest read instead. Most of what I have described gets fixed without replacing a single camera. Changing default passwords costs nothing. Getting your recorder off the open internet costs nothing. Closing ports nobody needs costs nothing. Building an inventory of what you own and who supports it is an afternoon with a clipboard, and it is the highest-value hour on this page.

Do not take my word for it. When the FBI issued its notice to private industry about attackers scanning internet-exposed cameras and recorders, its recommendations were exactly this ordinary: change default and weak passwords, patch firmware as manufacturer updates become available, require multi-factor authentication wherever possible, close unnecessary ports, segment the network, and consider removing devices the manufacturer no longer supports. Not one of those requires a new camera.

Real money enters in exactly one place, and I would rather be plain about it than coy. If your equipment is past end of support, no patch is ever coming for it, and it has to be replaced. That is not a sales tactic, it is arithmetic, and it is the work I do. And if your system is modern, segmented, actually updated, and someone in your building owns it, you are in good shape, and I will tell you that rather than write you a proposal. While you are looking, it is worth knowing what your existing cameras can already do, which I covered in my post on what AI security cameras actually do.

If This Is New to You, Here’s the Order I’d Put It In

  1. Find out what you actually have. Every camera, every recorder, every door controller, the model, and whether the manufacturer still supports it. You cannot protect what you have not counted, and this is the step everyone skips.
  2. Change every default password today, and turn on multi-factor authentication. A unique password on each device, stored where your business keeps records, plus a second factor anywhere the system offers one. It is free, it takes an afternoon, and it is the cheapest risk on this page to eliminate.
  3. Hand your IT provider the network spec. Cameras, recorder, and door controllers on their own segment, away from your computers and your guest Wi-Fi. No recorder exposed to the open internet. Remote viewing through a secure connection, not an open port.
  4. Put firmware on a schedule, and replace what is past support. Check quarterly, apply security fixes promptly, and retire anything the manufacturer has stopped supporting. Deliberate beats both blind updating and never.
  5. Ask the one question. Whose name is on this system? If nobody in the building can answer, you have found the root cause, and everything above stays broken until you fix it.

Frequently Asked Questions

Can business security cameras be hacked?

Yes. A networked camera is a small computer, and it can be logged into like one. The most common way in is not sophisticated. The NSA and CISA list default configurations and credentials first among the ten most common misconfigurations they find, and their advisory names security cameras specifically. Researchers scanning the internet in 2025 found more than 40,000 cameras streaming publicly with no password at all. The good news is that the most common attacks are also the easiest to shut down.

How do I know if my security cameras have been hacked?

Look for the same signs an IT person would look for on any computer. Unfamiliar user accounts on the camera or recorder, logins at hours when nobody was working, settings or passwords that changed on their own, cameras rebooting or dropping offline for no reason, and unusual outbound traffic from the camera network are all worth investigating. Most recorders keep an access log, and that is the first place to look. If your system is reachable from the open internet with a default password, assume it has at least been scanned.

How often should camera firmware be updated?

Check for updates at least quarterly and apply security patches promptly rather than waiting. Do not auto-update every device the moment any release appears, because a bad firmware push can knock a camera offline, so test before rolling an update across a whole building. The rule that matters most comes at the end of the road: if the manufacturer has stopped supporting the device, no patch is ever coming for it, and it should be replaced.

Should security cameras be on a separate network?

Yes. The federal guide to securing operational technology, NIST SP 800-82, recommends that organizations consider separate network segments for physical security systems, and it names cameras and access card readers directly. Putting cameras, recorders, and door controllers on their own segment, separated from your business computers, point-of-sale systems, and guest Wi-Fi, means a compromised camera cannot be used as a path into the systems that actually run your company.

What is NDAA-compliant equipment, and is my current camera illegal?

For a private business with no federal contract and no federal grant money, there is no federal law that makes owning or operating this equipment illegal. Section 889 of the 2019 defense authorization act bars federal agencies from buying certain video surveillance equipment, bars federal contractors from supplying it, bars federal grant and loan dollars from paying for it, and bars agencies from contracting with a company that uses it. Separately, the FCC has stopped authorizing this equipment, and starting July 16, 2026 it bars importing and marketing older approved models for public safety, government facility, and other covered purposes. Those rules govern federal purchasing, federal contracting, and what can be imported and sold. The FCC has said plainly that they do not affect the continued use or operation of already-purchased equipment. “NDAA-compliant” is industry shorthand for equipment free of the producers named in that statute. It is not a government certification, so ask your integrator to put it in writing. If you hold federal contracts or take federal grant money, get advice on your own situation.

What should I ask my security company about cybersecurity?

Four questions will tell you most of what you need to know. Have the default passwords on every device been changed, and can you show me? Which of our devices are still supported by the manufacturer, and which have reached end of life? Is the system on its own network segment, separate from our business computers, and if that is not your work, what do we hand our IT provider? And who is responsible for applying firmware updates going forward? A good partner will walk you through all four on the spot.

Not Sure What’s on Your Network? Let’s Take a Look.

If you cannot say for certain when your cameras were last updated, whether they still use the passwords they shipped with, or who is responsible for any of it, contact us. We will inventory every camera, recorder, and door controller you have. We will tell you which ones the manufacturer still supports and which are past end of life, confirm whether the credentials are still the ones from the factory, and tell you whether anything on your wall sits on the federal Covered List. You will also get a written list of exactly what your IT provider needs to do on the network side.

If your system is in good shape, we will say so and you are done. And if my company installed your system, call us anyway, and we will tell you exactly where it stands. We have protected Atlanta businesses since 2007, and I would rather find the open door with you in a review than have you find it the hard way. Reach my team at 678-924-7480.


Current as of July 2026. The rules in the equipment section change, so we review this post quarterly.

Scott Hightower founded Verified Security in 2007 and has spent nearly two decades designing, installing, and servicing commercial security systems across metro Atlanta. Verified Security is a hand-picked member of Honeywell’s Commercial Security certification program and specializes in access control, video surveillance, intrusion, and fire alarm systems. Reach Scott’s team at 678-924-7480.