Factory passwords, recorders open to the internet, outdated firmware — how strangers end up watching your cameras. 7 rules for secure CCTV.
A video surveillance system protects your property — but if it isn’t configured properly, it can become a risk itself: thousands of openly accessible camera streams on the internet exist largely thanks to factory settings.
1. Change the factory password — on every device
The recorder (NVR/DVR) and every camera should each have their own strong password. admin/12345 is the first target of automated scanners. Managing dozens of passwords by hand is hard — keep them in a password manager, for example ICOMP Pass.
2. Don’t expose the recorder directly to the internet
Port forwarding on the router makes the recorder’s management panel accessible to the entire internet. For remote viewing it’s better to use:
- VPN — connect to the office network first, then to the cameras;
- or the manufacturer’s official app / cloud service, with a strong password and two-factor authentication.
3. Update the firmware
Manufacturers regularly patch vulnerabilities. Update the firmware of your recorder and cameras several times a year.
4. Cameras — on a separate network
Cameras and the recorder belong in a separate VLAN, isolated from office computers and guest Wi-Fi.
5. A separate account for every employee
Don’t use a single “admin” account for everyone. Security staff get view-only rights, the administrator gets full rights. That way you know who viewed or exported recordings, and when.
6. Correct time and retention period
- Automatic time synchronization on the recorder — accurate time is critical when investigating an incident;
- Decide how many days recordings must be kept, and choose a disk of the right size.
7. Physical protection of the recorder
A recorder on an open shelf is an easy target: carrying it away takes the whole archive with it — the cameras may still work, but no footage is left. Keep the recorder in a locked cabinet, together with an uninterruptible power supply (UPS).