IP-based video surveillance systems ā cameras, NVRs, VMS platforms ā are networked devices that often receive less security attention than IT systems despite having web interfaces, network access, and sensitive data (video feeds). Security testing covers: default credential exposure, firmware vulnerability assessment, network segmentation (are cameras on a separate VLAN?), video feed encryption, storage access controls, remote access security, and whether compromised cameras can be used as pivot points into the corporate network.
Technical
Video Surveillance and CCTV Security: Testing IP Camera and Recording Infrastructure for Australian Enterprises
IP cameras are network devices with web interfaces and often default credentials. Testing surveillance infrastructure security. Guidance for AU market.