UNV bullet, turret and PTZ security cameras displayed against a modern commercial warehouse background.

CCTV Cybersecurity Checklist: How to Harden Cameras, NVRs and Security Networks

Essential Security Supplies

A CCTV cybersecurity checklist should cover the entire service: cameras, recorders, operator workstations, remote access and maintenance. Changing a default password is necessary where applicable, but it does not resolve an unsupported device, exposed recorder or uncontrolled administrator account. NZ installers need a documented baseline and a process for keeping it current.

Create an inventory with support status

Record exact models, firmware, network addresses and the owner of each device. Identify the manufacturer's support and update information before deployment. Separate a device that functions today from one that remains supported. Keep a record of approved firmware and configuration changes. Product origin or a procurement compliance label is not a substitute for this assessment and should not be presented as a cybersecurity guarantee.

Restrict administration and operator privileges

Use individual accounts wherever supported and give operators the minimum rights needed. Restrict configuration, user management, export and deletion independently when the platform allows it. Replace shared installer credentials through an agreed handover procedure. Disable unused accounts and services after checking the system dependencies. Document emergency access securely, with an owner and an auditable process rather than a password circulated to several organisations.

IPC2128SB-ADF28KMC-I0 - UniView 8MP HD Fixed Active Deterrence Camera
IPC2128SB-ADF28KMC-I0 - UniView 8MP HD Fixed Active Deterrence Camera. Genuine supplier catalogue photograph.

Build segmentation with enforceable rules

A dedicated VLAN can organise camera traffic, but it is not sufficient isolation on its own. Define routing and firewall rules for the required clients, time service and maintenance systems. Deny unnecessary paths and test the result. Keep management access separate from routine video viewing where supported. Review switch administration and physical ports as part of the same design. Show the approved connections in the network diagram.

Control remote access

Avoid exposing device administration directly to the public internet as a convenience. Use the client's approved remote-access arrangement and multifactor authentication where the selected service supports it. Review any manufacturer relay or cloud service with the client's IT owner. Record the data path and account ownership. Disable automatic port-opening functions unless explicitly required and approved. Test that removed access really stops a former maintainer connecting.

UniView IPC3605SB-ADF16KM-I0 Prime-series H265 5MP PoE IP EXIR (20m)
UniView IPC3605SB-ADF16KM-I0 Prime-series H265 5MP PoE IP EXIR (20m). Genuine supplier catalogue photograph.

Manage firmware changes and recovery

Read release notes and compatibility information before updating. Back up settings, schedule a test window and define recovery if the update fails. Check recording, events, time and remote viewing after the change. Do not assume every newer firmware version is interchangeable across regional or hardware variants. Axis hardening guidance provides a useful primary-source framework, but model-specific procedures must come from the equipment actually being installed.

Make monitoring and handover actionable

Define which security and equipment events are reviewed, who receives them and how quickly they act. Include failed logins where supported, offline devices, storage faults and unauthorised configuration changes. Give the client a current register, approved access diagram and secure backup. Agree an update review interval. A checklist completed once is not an ongoing control if devices and operator accounts continue changing without review.

UniView IPC675LFW-AX4DUPKC-VG - Easy-series LightHunter Active-Deterrence
UniView IPC675LFW-AX4DUPKC-VG - Easy-series LightHunter Active-Deterrence. Genuine supplier catalogue photograph.

Apply the design to the actual project

Use an access matrix that shows each source, destination, service and purpose. Camera-to-recorder traffic, operator viewing, administration and remote maintenance should each have an explicit route. Test from representative workstations rather than relying only on a firewall rule screenshot. Record denied paths as well as successful connections. Axis guidance can inform the design approach, but use Uniview or the selected manufacturer's documentation for its actual firmware settings and supported services.

Include account removal in the acceptance tests. Disable a test operator and revoke a temporary maintenance account, then confirm that stored client credentials or an existing remote service do not preserve unintended access. Review configuration backups for sensitive information and store them under the client's approved controls. Agree what happens when a vulnerability advisory arrives: who reviews it, who approves an update and who verifies the recording service afterwards. These responsibilities should remain clear when the original installer is no longer the routine maintainer.

Commission evidence quality and failure recovery

Test the recorded image at the actual distance where the event matters. Use someone walking through the scene and a representative vehicle where relevant. Review the result on the client workstation, then export a short clip and open it independently. Live viewing, playback and export are different stages, and all three should pass. Include daylight, darkness and a transition in lighting when the objective depends on continuous coverage. Note any zone where the required detail is not achieved.

Disconnect an authorised test camera or network link under a controlled commissioning plan. Confirm that the fault reaches the responsible operator and that normal recording resumes after restoration. Where local recording or automatic retrieval is required, demonstrate that behaviour with the selected firmware and client. Do not assume that an SD-card slot or an interoperability logo proves that missing footage will be recovered. Record the outage interval, expected behaviour and actual result.

Commissioning acceptance checklist

Agree the expected result before testing. Use the installed configuration and retain evidence of each outcome, including a failure that must be corrected. The following checks supplement the exact manufacturer procedures and the approved project design.

Required check Record to retain
Test permitted and prohibited network paths from the actual user locations. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.
Verify named account privileges and removal of obsolete remote access. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.
Restore a configuration backup in an approved test and confirm recording after updates. Expected behaviour, actual result, configuration tested and responsible person. Resolve an unexpected outcome before accepting this requirement.

Repeat affected checks after a material equipment, software or site change. Keep the test record with the as-built schedule so the next maintainer can understand which configuration passed and which assumptions still need review.

Equipment candidates and specification checks

These are relevant active catalogue candidates for a project review, rather than a universal recommendation or a promise of immediate stock. Use the full product page and current manufacturer information to confirm the supplied variant and its role in your design.

Review the relevant Essential Security Supplies equipment range alongside the intended workflow. For further context, read our related installer guide.

Frequently asked questions

Does a separate VLAN make CCTV secure?

Only when the network also enforces the intended access rules and its administration is controlled.

Is NDAA status a cybersecurity certification?

No. Procurement compliance and security hardening are separate assessments.

Should firmware updates be automatic?

Choose an approved update process based on support, compatibility and recovery needs; always verify the system afterwards.

Primary references and technical scope

Use the primary manufacturer or technical reference for the claims it covers. General design guidance does not replace the selected product's installation manual. Confirm current firmware, model variants and the approved project requirements before ordering or commissioning.

For site policy, consult the New Zealand Privacy Commissioner's CCTV guidance.

Get specification help from Essential Security Supplies

Send your site layout, equipment schedule, intended workflow and any existing model details to Essential Security Supplies for specification help and a project quotation. Identify the functions that must be demonstrated and the interfaces owned by other contractors. Our enquiry route supports a documented equipment review without publishing prices or assuming unverified compatibility.