Download PDF version Contact company

Following a pandemic-exacerbated rise in data breaches and ransomware attacks, Genetec Inc., a technology provider of unified security, public safety, operations, and business intelligence solutions, guided public sector organisations on how to reduce cyber vulnerabilities of physical security systems that are often overlooked.

IP security cameras and other security devices were put in place to protect people, assets, and environments. But the same network connectivity that enables organisations to monitor operations and update software remotely presents a path into the network for cyber criminals.

Physical security systems

If they are not sufficiently modern or properly shielded, they can pose significant risk to cybersecurity. An attack that originates in a camera or door controller can find its way through the network to block access to critical applications, lock files for ransom, and steal personal data.

If they are not sufficiently modern or properly shielded, they can pose significant risk to cybersecurity

Justin Himelberger, Enterprise Systems Business Development Manager for US Federal and DOD at Genetec Inc., said, “Because these systems – video surveillance, access control, alarms, communications, and more – are increasingly connected to networks and IT infrastructure, they can be quite vulnerable. With the number of cyberattacks increasing around the world, it is becoming clear that government organisations must be more stringent than ever about cybersecurity in their own organisations and throughout their supply chains.”

Changing default passwords

A step organisation can take immediately is making sure each device, as well as the servers used for storing data and hosting monitoring consoles, has the latest version of firmware and software recommended by the manufacturer. Changing default passwords and establishing a process to change them frequently is a critical practice. Improving network design to segment older devices can also help reduce the potential for crossover attack.

To determine the risk of physical security systems, Genetec recommends organisations conduct a posture assessment, creating and maintaining an inventory of all network-connected devices and their connectivity, firmware version, and configuration. As part of the assessment, they must identify models and manufacturers of concern, such as those listed by the U.S. Government under the National Defence Authorisation Act (NDAA) as presenting a high level of cyber risk. They should also document all users with knowledge of security devices and systems.

Comprehensive security program

When developing a replacement program, prioritise strategies that support modernisation

The review can pinpoint devices and systems that should be replaced. When developing a replacement program, prioritise strategies that support modernisation. One effective approach is to unify physical and cybersecurity devices and software on a single, open-architecture platform with centralised management tools and views.

Additionally, while physical security and IT have been approached as separate efforts historically, the risk of cyberattacks through physical security technology is driving change. The U.S. Cybersecurity and Infrastructure Security Agency recommends joining IT and physical security into a single team, so they can develop a comprehensive security program based on a common understanding of risk, responsibilities, strategies, and practices.

In the US, Federal funding may be available to help cover costs associated with replacement programs. The 2021 Investment and Jobs Act includes $1billion earmarked to help state and local governments modernise their cybersecurity. Genetec can provide subject matter experts in public sector and security veterans to speak on this topic upon request.

Download PDF version Download PDF version

In case you missed it

How can the security industry contribute to protecting the environment?
How can the security industry contribute to protecting the environment?

When it comes to protecting the environment, the security industry has historically been perched on the sidelines. For instance, the amount of electricity that physical security sy...

Dahua Technology showcases "The Road to a Sustainable Future" at Intertraffic Amsterdam 2024
Dahua Technology showcases "The Road to a Sustainable Future" at Intertraffic Amsterdam 2024

Dahua Technology, a world-pioneering video-centric AIoT solution and service provider, made its debut at Intertraffic Amsterdam 2024, displaying a diverse range of ITS solutions ta...

Comprehensive K12 security
Comprehensive K12 security

For K12 education pioneers, embarking on a journey to upgrade security controls can present a myriad of questions about finding the best-fit solutions and overcoming funding hurdle...