Securing camera systems: networks, firmware and remote access
Why cameras and recorders are attacked and how to keep them out of trouble: device capability baselines to check before buying, segmentation and firewall rules, switching off what isn't needed, remote access without exposing the recorder to the internet, firmware updates, an inventory with support dates, and what to do when you find an exposed system.
- Level
- Intermediate
- Length
- About 60 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Explain how compromised cameras and recorders are used by attackers and why end-of-life devices are a particular risk
- Use the NIST IR 8259A capabilities and a manufacturer's stated support period to evaluate a device before purchase
- Write or review firewall rules that let only approved systems reach cameras and recorders
- Provide remote viewing without forwarding recorder or camera ports from the internet
- Keep an inventory with firmware and support dates and plan updates and replacements from it
Course outline
- 1.Securing camera systems: networks, firmware and remote accessVideo · 2 min
- 2.Why camera systems are targetsLesson · 18 min
- 3.Segmentation, rules and servicesLesson · 20 min
- 4.Remote access, firmware and end-of-lifeLesson · 22 min
- 5.Securing camera systems: networks, firmware and remote access: knowledge checkKnowledge check · 20 questions
- 6.The recorder's login page is on the internetScenario
- 7.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CISA and partners: Defending Against China-Nexus Covert Networks of Compromised Devices (AA26-113A) (compromised web cameras and video recorders; end-of-life devices)
- CISA ICS advisory ICSA-25-352-08 (video management software): recommended practices (not accessible from the internet, behind firewalls, VPN for remote access)
- CISA: Product Security Bad Practices (default passwords, known exploited vulnerabilities, stated support period)
- CISA: Securing the Internet of Things (default passwords, updates, whether constant internet connection is needed)
- NIST IR 8259A: IoT Device Cybersecurity Capability Core Baseline (six device capabilities)
- Universal Plug and Play (UPnP IGD port mapping and its security problems)
- UK Home Office / Dstl: UK Police Requirements for CCTV Systems (quality, storage, export, playback) (UK example)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.