Axis Communications’ Steven Kenny makes the case for treating secure maintenance and long-term control as fundamental requirements when specifying connected security systems for data centers.
A data center project can reach handover with every camera installed, its coverage confirmed and its integrations working. The real test begins after the contractors leave: will operators still be able to trust and control every connected device in five or ten years’ time?
That question must be asked at the start of procurement. Product and supplier choices determine whether a device can be configured, updated and supported securely. Wider system design establishes who can access it and how closely it can be monitored once operational.
Network cameras are software-driven computers which collect potentially sensitive data and remain connected around the clock. If breached, they may expose information about the facility or provide an entry point from which an attacker can examine the wider network. Yet because cameras are procured as physical security equipment, their own cybersecurity can receive less attention than other connected technology.
Buyers and consultants have the earliest opportunity to set the boundaries and ensure that security networks can be administered efficiently throughout their lifespan. Integrators are there to turn their requirements into a working architecture; operators inherit the decisions made by both. All have an interest in ensuring that security hardware remains manageable and supported.
Procurement defines the future risk
Data centers support communications, financial activity, supply chains and essential services, which makes them attractive targets for criminals and state-aligned actors, including those prepared to spend time observing a site before attempting disruption.
Hostile reconnaissance rarely announces itself. An attacker who compromises a connected security device could gain insight into physical layouts, staff activity or sensitive operational areas. The device may also provide a low-profile base from which to map the wider network. Ironically, the system intended to give the operator visibility may offer the same advantage to an adversary.
The risk is especially easy to underestimate if physical security and IT security follow separate procurement routes. Cameras may be selected by one team, installed by another and connected to infrastructure managed elsewhere. If the specification concentrates on image quality, coverage and integration, the requirements governing cyber protection and long-term maintenance could become secondary or remain unstated.
Specify the support behind the device
It is important for buyers to see beyond the spec sheet. Seek evidence of how a device was developed, how vulnerabilities are handled and how long its software will be supported, because these factors determine whether an operator will be able to respond when the threat inevitably changes.
Manufacturers should be able to explain their secure development practices and vulnerability-management process. They should provide a dependable route for firmware updates, communicate security issues clearly and define the expected support period. End-of-support arrangements also need attention, particularly where replacing equipment may require access to sensitive areas or interruption to normal operations.
Provenance forms another part of that assessment. Connected hardware may incorporate components and software from several suppliers, while a compromised update can introduce risk after installation. Buyers cannot eliminate every dependency, but they can ask who controls development and maintenance, how updates are protected and what happens when a weakness is found in a third-party component.
These technical questions have direct commercial consequences. A cheaper device may prove expensive if it cannot be patched or its supplier cannot provide timely support. Early replacement can push its total cost well beyond that of equipment specified for a longer life.
Architecture limits the consequences
Secure products still need a defensible system design. Connected security devices should be placed in network zones appropriate to their function, with access limited to the people and systems that require it. Credentials, configuration and firmware status need continued oversight after commissioning.
This affects the work of consultants and integrators as much as the final operator. Network boundaries, administrative access and update processes should be agreed during design, then documented properly at handover. The operator needs an accurate record of what has been installed, how it is configured and who can change it. Without that information, even equipment which appears to be functioning correctly can drift into an unknown state.
Integration also needs discipline. A camera may exchange information with video management, access control or other operational systems. Each connection has a legitimate purpose, but it also creates a data flow and trust relationship that must be understood and maintained. Buyers should require enough openness to support integration while keeping permissions proportionate to the task.
Close the ownership gap
The remaining problem is accountability. Architects define requirements, manufacturers support products, integrators deliver the system and operators keep it running. Responsibility can fall into the gaps unless the project states who owns each decision after handover.
Cost, availability or programme pressure may lead a project to accept a known risk. That can be a legitimate decision when someone is accountable for it, the reasoning is recorded and a review point has been set. Otherwise, the issue may persist unnoticed until a vulnerability, support change or incident forces the question.
The EU Critical Entities Resilience Directive is a regulatory signal of the growing expectation for continuity and demonstrable assurance. An installation audit captures one moment. Operators must also be able to show that their controls remain effective as software, suppliers and threats change.
Security buyers are in the strongest position to establish that expectation through clear tender documents and contracts. The resulting controls should be reviewed throughout the system’s life. The decisive test at handover is whether the organisation can keep the system secure as circumstances change. Equipment that works today but cannot be supported tomorrow carries a future risk the project has failed to account for.