Infrastructure
Your Camera System and Door Locks Are Now an IT Decision
Security cameras and door controllers are network-connected computers now, not standalone hardware. Left on default credentials, outdated firmware, or a flat network, they become an entry point instead of a safeguard. This guide covers the risks, how access control ties into HIPAA facility-access requirements, and a short checklist to run against your current system.
Most businesses still buy a camera system or a door access system the way they'd buy a coffee machine: pick a vendor, get it installed, forget it exists until something breaks.
That approach stopped matching the equipment years ago. A modern security camera is a small network-connected computer with its own operating system, firmware, and IP address. A modern door controller is the same. The moment either one is plugged into your network, it is part of your IT environment, whether anyone planned for that or not.
This guide covers what changed, the specific risks an unmanaged camera or access-control system creates, how it connects to HIPAA facility-access requirements if you handle protected health information, and a short checklist you can run against your current system this week.
What Changed
Older analog camera systems recorded to a DVR. When that DVR was genuinely offline, with no network port and no remote-viewing feature, there was little for an attacker to reach. Many analog systems still in use today aren't actually isolated that way: the DVR itself typically has Ethernet and remote-viewing access, which puts it under the same credential, firmware, and network risks covered below even though the cameras themselves are analog. IP camera systems and networked door controllers work similarly, but the whole system, cameras included, is on the network. Cameras stream video over your network to a Network Video Recorder (NVR). Door controllers check credentials against a database and report events back over the same network. Both are reachable from anywhere else on that network, and if they are exposed to the internet for remote viewing, potentially from outside it too.
That connectivity is what makes remote viewing, mobile unlock, and centralized multi-site management possible. It is also what turns a camera or door controller left on factory settings into a way onto your network, not just a way to watch your parking lot.
Why an Unmanaged System Becomes a Network Risk
A handful of conditions turn security equipment into an attack surface instead of a safeguard.
- Default or shared administrator credentials that were never changed after installation.
- Firmware that hasn't been updated since the system went in, leaving known vulnerabilities unpatched.
- Cameras, NVRs, or door controllers sitting on the same flat network as workstations, servers, and financial systems, instead of a segmented VLAN.
- Direct internet exposure for remote access, without a firewall policy controlling what can reach the device.
- No one monitoring whether a camera has gone offline, a controller has stopped reporting, or firmware has quietly fallen years behind.
None of these require a sophisticated attacker. They are common, avoidable gaps behind a lot of real-world intrusions: a device with a weak or default password, publicly reachable, running old software. The fix is the same discipline already applied to servers and laptops: unique credentials, network segmentation, a firmware update schedule, and monitoring, extended to the cameras and door controllers most businesses never think to include.
Access Control That Isn't Tied to Your HR Process
Physical keys and standalone key fob systems share a problem: when someone leaves the company, getting every copy of every credential back is manual, easy to forget, and hard to verify after the fact. A badge or fob-based access system that isn't connected to your employee directory has the same gap in a more modern form. The credential still works until someone remembers to walk over to the panel and remove it.
A system tied to Active Directory or Microsoft Entra ID closes most of that gap, where the right integration path, licensing, and configuration are in place. Access rights follow employment status and group membership, so a departure is handled as part of the same offboarding step that ends system access, instead of a separate manual trip to the door panel. It also produces a timestamped audit log of credential use, when a valid credential was presented and a door unlocked, which matters more than most businesses realize once a framework or an insurer starts asking for evidence rather than a policy statement.
If your offboarding process already has gaps on the IT side, the physical side usually has the same ones. Our guide on why offboarding often takes three weeks covers the same root cause from the account and device side.
How This Connects to HIPAA
For healthcare practices and business associates, physical access control is not just an operational nicety. The HIPAA Security Rule's Facility Access Controls standard, at 45 CFR ยง 164.310(a), requires policies and procedures that limit physical access to the systems and facilities holding electronic protected health information, while still allowing properly authorized access. The specific implementation steps under that standard, such as a facility security plan and access control procedures, are addressable rather than strictly mandatory: your organization has to evaluate whether each one is reasonable and appropriate for your environment. If it decides one isn't, the rule requires documenting why, then implementing an equivalent alternative only when that alternative is itself reasonable and appropriate, not in every case. "Addressable" is not a synonym for optional.
A credentialed access system with an audit log, paired with camera coverage of the areas where that equipment lives, gives you exactly the kind of evidence a HIPAA risk analysis or an auditor is looking for: a record of credential presentations, door events, and, where footage is retained, correlated video for the areas that matter, not a guaranteed account of exactly who entered each time. Our practical guide to the HIPAA Security Rule covers the administrative and technical safeguards that sit alongside this physical piece.
A Short Checklist for Your Current System
- Confirm the default administrator password on every camera, NVR, and door controller has been changed to something unique.
- Check when the firmware on that equipment was last updated, and whether anyone owns keeping it current.
- Find out whether your cameras and door controllers sit on their own network segment or share one with your workstations and servers.
- Verify departed employees actually lose door access as part of the same offboarding step that disables their account, not on a separate manual trip to the panel days later.
- Ask whether anyone would notice within a day if a camera went offline or storage filled up, rather than finding out during an incident review.
If you can't answer one or more of these with confidence, that's the gap to close first, and it's usually smaller than it sounds once someone actually looks.
Where Cyber One Solutions Fits
We design and manage physical security systems, access control included, as part of the same network they run on, not as a separate system handed off to a different vendor with different login credentials. That means dedicated network segmentation for camera and door-controller traffic, firmware brought current at installation and kept current under a managed support plan, and access credentials tied to the same directory that governs everyone's email and file access, where your environment supports that integration. Our physical security service covers camera systems, door access control, and the network hardening that keeps both from becoming the easiest way into your environment instead of a layer of protection around it.
If you're not sure where your current camera or access-control system stands against the checklist above, contact us and we'll take a look.
Frequently Asked Questions
Is a consumer camera system from a big-box store a security risk for a business?
It can be, mainly because consumer systems are rarely built with business-grade update and network-management tools, and they're often set up once and never revisited. The risk isn't the camera brand itself. It's whether anyone is changing default credentials, applying firmware updates, and keeping the system off the same network as sensitive business data. A business-grade platform makes that ongoing management realistic instead of something that depends on someone remembering to do it.
Do cameras and door access controllers really need their own network segment?
Yes, where it's practical, and the VLAN needs firewall policy behind it to actually do the job. A VLAN alone separates the traffic, but if the network's gateway still routes freely between segments, that separation doesn't stop much. Paired with firewall policy that restricts what the camera or access-control segment can reach, a compromised device lands somewhere with no route to your servers, workstations, or financial systems, instead of straight onto your main network. Keeping that traffic from competing with everyday business applications on a shared switch or uplink is a separate concern, handled with quality-of-service markings or dedicated capacity, not something segmentation and firewall policy provide on their own.
What happens to someone's door access when they're terminated?
That depends entirely on how the system is set up. With a fob or badge system that isn't tied to your employee directory, access is only removed when someone manually does it at the panel, which is easy to delay or forget. With a system integrated into Active Directory or Entra ID, and the right integration path, licensing, and configuration in place, access is removed as part of the same offboarding step that disables the person's account, rather than a separate manual step days or weeks later. That integration isn't automatic by default: confirm during setup how it actually behaves in your environment.
How long should we keep camera footage?
There's no single right answer. It depends on your retention obligations, insurance requirements, and how quickly an incident is typically noticed and investigated. What matters more than picking a specific number is confirming the storage is actually sized for the retention window you've chosen, since undersized storage silently overwrites footage sooner than most people expect.
Does access control have to be complicated to meet compliance requirements?
No. What matters for HIPAA and most insurer or auditor reviews is that access is limited to authorized people, that changes in employment are reflected promptly, and that you can produce a record of which credentials accessed a space and when. A properly configured system produces that evidence automatically, though it's a record of credential use, not confirmed proof of who physically walked through with it. The complexity is in the setup, not in using it day to day.
