The hardening checklist
- Unique strong passwords on every device; no shared installer account left in place after handover.
- A dedicated VLAN for cameras, recorders and controllers, with firewall rules to the rest of the network.
- No port forwarding to a recorder — use the platform's cloud relay or a VPN for remote access.
- Firmware updates on a schedule, with a record of versions in service.
- HTTPS for management, TLS for cloud traffic, OSDP instead of Wiegand at readers.
- Multi-factor authentication on the video and access management consoles.
- Named user accounts with roles, removed on the day someone leaves.
- Logging and alerting on failed logins, configuration changes and devices going offline.
Supply chain matters too
Check where the hardware and its firmware come from, and whether the manufacturer publishes vulnerability advisories and a support lifecycle. Devices banned or restricted in other jurisdictions, or long past end-of-support, are a risk you inherit for the life of the system.
Physical and cyber are one program
An attacker who reaches the video network can watch you; one who reaches the access platform can open doors. Conversely, physical access to a switch or recorder bypasses much of the network security. Lock the equipment room, and treat the two disciplines as one risk register.
