Data center security: Specifying cameras for the full lifecycle

Axis Communications’ Steven Kenny makes the case for treating secure maintenance and long-term control as fundamental ……
Data center security: Specifying cameras for the full lifecycle - securitybuyer.com

Share this article:

Axis Communications’ Steven Kenny makes the case for treating secure maintenance and long-term control as fundamental requirements when specifying connected security systems for data centers.

A data center project can reach handover with every camera installed, its coverage confirmed and its integrations working. The real test begins after the contractors leave: will operators still be able to trust and control every connected device in five or ten years’ time?

That question must be asked at the start of procurement. Product and supplier choices determine whether a device can be configured, updated and supported securely. Wider system design establishes who can access it and how closely it can be monitored once operational.

Network cameras are software-driven computers which collect potentially sensitive data and remain connected around the clock. If breached, they may expose information about the facility or provide an entry point from which an attacker can examine the wider network. Yet because cameras are procured as physical security equipment, their own cybersecurity can receive less attention than other connected technology.

Buyers and consultants have the earliest opportunity to set the boundaries and ensure that security networks can be administered efficiently throughout their lifespan. Integrators are there to turn their requirements into a working architecture; operators inherit the decisions made by both. All have an interest in ensuring that security hardware remains manageable and supported.

Procurement defines the future risk

Data centers support communications, financial activity, supply chains and essential services, which makes them attractive targets for criminals and state-aligned actors, including those prepared to spend time observing a site before attempting disruption.

Hostile reconnaissance rarely announces itself. An attacker who compromises a connected security device could gain insight into physical layouts, staff activity or sensitive operational areas. The device may also provide a low-profile base from which to map the wider network. Ironically, the system intended to give the operator visibility may offer the same advantage to an adversary.

The risk is especially easy to underestimate if physical security and IT security follow separate procurement routes. Cameras may be selected by one team, installed by another and connected to infrastructure managed elsewhere. If the specification concentrates on image quality, coverage and integration, the requirements governing cyber protection and long-term maintenance could become secondary or remain unstated.

Specify the support behind the device

It is important for buyers to see beyond the spec sheet. Seek evidence of how a device was developed, how vulnerabilities are handled and how long its software will be supported, because these factors determine whether an operator will be able to respond when the threat inevitably changes.

Manufacturers should be able to explain their secure development practices and vulnerability-management process. They should provide a dependable route for firmware updates, communicate security issues clearly and define the expected support period. End-of-support arrangements also need attention, particularly where replacing equipment may require access to sensitive areas or interruption to normal operations.

Provenance forms another part of that assessment. Connected hardware may incorporate components and software from several suppliers, while a compromised update can introduce risk after installation. Buyers cannot eliminate every dependency, but they can ask who controls development and maintenance, how updates are protected and what happens when a weakness is found in a third-party component.

These technical questions have direct commercial consequences. A cheaper device may prove expensive if it cannot be patched or its supplier cannot provide timely support. Early replacement can push its total cost well beyond that of equipment specified for a longer life.

Architecture limits the consequences

Secure products still need a defensible system design. Connected security devices should be placed in network zones appropriate to their function, with access limited to the people and systems that require it. Credentials, configuration and firmware status need continued oversight after commissioning.

This affects the work of consultants and integrators as much as the final operator. Network boundaries, administrative access and update processes should be agreed during design, then documented properly at handover. The operator needs an accurate record of what has been installed, how it is configured and who can change it. Without that information, even equipment which appears to be functioning correctly can drift into an unknown state.

Integration also needs discipline. A camera may exchange information with video management, access control or other operational systems. Each connection has a legitimate purpose, but it also creates a data flow and trust relationship that must be understood and maintained. Buyers should require enough openness to support integration while keeping permissions proportionate to the task.

Close the ownership gap

The remaining problem is accountability. Architects define requirements, manufacturers support products, integrators deliver the system and operators keep it running. Responsibility can fall into the gaps unless the project states who owns each decision after handover.

Cost, availability or programme pressure may lead a project to accept a known risk. That can be a legitimate decision when someone is accountable for it, the reasoning is recorded and a review point has been set. Otherwise, the issue may persist unnoticed until a vulnerability, support change or incident forces the question.

The EU Critical Entities Resilience Directive is a regulatory signal of the growing expectation for continuity and demonstrable assurance. An installation audit captures one moment. Operators must also be able to show that their controls remain effective as software, suppliers and threats change.

Security buyers are in the strongest position to establish that expectation through clear tender documents and contracts. The resulting controls should be reviewed throughout the system’s life. The decisive test at handover is whether the organisation can keep the system secure as circumstances change. Equipment that works today but cannot be supported tomorrow carries a future risk the project has failed to account for.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top