Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier Electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology.
With geopolitical uncertainty increasing scrutiny of security infrastructure, how important has trust become when selecting a video security manufacturer?
It has changed significantly. I joined Dallmeier around eight years ago and, even during that relatively short period, the conversations we have with customers have evolved.
When I joined, discussions were primarily about features: what does the technology provide and what can the product do? A few years ago, we had an initial meeting with a large energy supplier in Germany, and the first questions had nothing to do with products or features. They asked what we were doing about cybersecurity and privacy, whether we could document it and whether we could prove the measures we had in place.
We now hear those questions increasingly early in conversations with customers and system integrators.
Trust is therefore becoming more important, particularly in the geopolitical environment we are operating in. Product quality obviously remains essential. Cameras are physical devices that may be installed in difficult locations and are expected to operate for many years, so build quality matters.
However, customers are also looking at the integrity of the manufacturer, cybersecurity, the legal environment in which products are developed, supply chain control and the long-term financial stability of the vendor. They want to know whether the organisation will still be supporting that technology in five or ten years.
There is no single factor that creates trust. It is the combination of product quality, cybersecurity, transparency, supply chain integrity, support and longevity.
Cyber resilience has become central to physical security. What should end users be paying closest attention to?
Cybersecurity has to be approached holistically.
Critical infrastructure organisations are increasingly governed by regulations designed to improve resilience, whether that is NIS2 within Europe, NDAA requirements in the United States or equivalent regulations elsewhere. Even if an organisation is not categorised as critical infrastructure, many of the principles contained within those standards remain good practice.
The threat is not exclusively geopolitical either. Cyberattacks are frequently criminal activities intended to extort money, steal intellectual property or disrupt operations.
Organisations therefore need to look beyond individual products. They should understand where systems are developed, how software is produced, who has access to it and how manufacturers manage their supply chains.
Then there are the technical measures: how is data transmitted? How is user authorisation managed? Are operating systems hardened? How regularly are systems tested and updated?
Certification is another useful indicator. Dallmeier, for example, is ISO 27001 certified. End users should be looking at whether manufacturers can demonstrate that they follow recognised cybersecurity processes rather than simply claiming that their products are secure.
Software support is equally important. We provide ten years of updates and security patches for our software, firmware, cameras and recording systems. That becomes a significant consideration when calculating the real lifetime of a security investment.