Axis Communications has joined a cybersecurity initiative created by Palo Alto Networks that aims to protect connected devices and critical infrastructure against vulnerabilities that can increasingly be identified and exploited using advanced artificial intelligence.
Axis has become a founding partner of the Frontier AI Critical Defense Program, announced on 20 August. The collaboration will focus on providing network-level protections for joint customers while permanent software updates are developed, tested and deployed.
The development is particularly relevant to physical security because modern surveillance cameras, access control devices and other networked systems increasingly operate as intelligent edge devices, processing and exchanging data across wider enterprise networks.
Virtual patching at the network layer
The programme addresses the narrowing period between vulnerability discovery and potential exploitation.
Axis said developments in advanced AI are increasing the speed at which software vulnerabilities can be identified and weaponised, placing greater pressure on organisations to implement security updates quickly. This can present challenges in critical infrastructure and other high-availability environments where firmware or software changes may need to be tested before deployment.
Through the collaboration, Axis and Palo Alto Networks intend to develop what they describe as network-level “virtual patches”.
Rather than modifying the affected device itself, these protections can be deployed through the surrounding network infrastructure to block potential attacks. This is intended to provide an additional period in which customers can test and install the manufacturer’s permanent software update without leaving the vulnerable system unnecessarily exposed.
It does not remove the requirement for conventional vulnerability remediation. Instead, virtual patching introduces another defensive layer between disclosure and permanent correction.
Cybersecurity becomes a product lifecycle issue
The announcement illustrates how cybersecurity responsibilities surrounding physical security products continue to expand.
Connected cameras and access devices increasingly contribute metadata and operational information to systems beyond traditional physical security. A compromised device could therefore create risks involving not only video or access control, but also the wider IT environment to which it is connected.
This places greater emphasis on vulnerability disclosure, firmware support and the speed at which manufacturers can respond to emerging threats.
For security buyers, cybersecurity should consequently be considered throughout the expected operational life of a product rather than only at the point of specification.
Questions around software support periods, security updates, vulnerability management and manufacturer response procedures are becoming increasingly relevant procurement criteria.
Axis’ collaboration with Palo Alto Networks also points towards closer integration between physical security manufacturers and mainstream cybersecurity providers. As the distinction between physical security networks and wider enterprise infrastructure continues to narrow, protecting connected security devices will increasingly require cooperation across both disciplines.
The challenge for buyers is therefore no longer simply selecting a secure device. It is understanding how that device will continue to be protected as vulnerabilities and attack techniques evolve.