
Ask most organisations who owns the CCTV system and you'll get a pause. Facilities specified it, because it's a building safety matter. They got the security installed to come and fit and they have the passwords for it. IT gave the installed a network port a couple of IP addresses, and hasn't thought about it since. Nobody is patching it. Nobody is monitoring it. Everybody assumes somebody else is.That gap matters. Because a modern camera is not just a camera. It is a Linux computer with a lens, a web server, open network connection and firmware that was last updated when it was boxed up in the factory. Thirty of them on site is thirty unmanaged endpoints, giving people an insight in to your whole business. They may never be rebooted, never be inventoried, and never seen by any Anti-Virus or security software.

THE PATH FROM A CAMERA TO YOUR CORE SYSTEMS
Attackers are not interested in your car park footage. They are interested in what the camera can reach. The route is depressingly consistent, and it takes hours rather than weeks.
Discovery
A recorder or camera web interface is exposed to the internet for remote viewing, or found from inside the network in a two-minute scan. Device banners give away make, model and firmware version.
Easy entry
Default credentials the installer never changed, a shared password used across every site, or a published vulnerability in unpatched firmware. No sophistication required.
A foothold nobody watches
The device becomes a quiet base inside your perimeter. It cannot run your endpoint protection, it generates no alerts, and its traffic looks like it belongs. Attackers have lived on camera estates for months.
Lateral movement
This is the step that hurts. If the camera VLAN is flat or routes freely, the attacker can now reach file servers, domain controllers, backup appliances and line-of-business applications, all from a device your asset register does not list.
Impact
Data theft, ransomware, or the footage itself exfiltrated. That is a personal data breach under UK GDPR, reportable to the ICO within 72 hours, with the ownership question suddenly very urgent.

WHY THE OWNERSHIP GAP CREATES THE RISK.
Physical security and IT security grew up as separate disciplines with separate budgets, and CCTV is where they collide. Facilities buys an outcome: coverage of the loading bay, evidence when something goes missing. IT is handed an implementation detail: some devices need network access. Neither party is being careless — the responsibility simply falls between two job descriptions. The result is a set of predictable conditions. Cameras and recorders share the corporate LAN with servers and staff devices. Remote viewing is enabled through port forwarding rather than a controlled VPN. The installer keeps a maintenance account with a password used at every client they serve. Firmware is treated as a physical maintenance item, so it is only touched when a lens fails. And because the estate is invisible to IT tooling, none of this shows up in a vulnerability report. Smaller organisations without in-house IT feel this hardest. There is no one whose job is to challenge the installer's default configuration — so it ships as-is and stays that way for a decade.

HOW ADDOOCO SECURES IT
The answer is not to take CCTV away from facilities. Facilities should keep owning what the cameras are for. What has to change is that the network they one, and the devices themselves, come under proper IT governance. That is what our Secure and Grid teams do together, usually without needing to replace a single camera.
Segment the estate
A dedicated camera VLAN with firewall rules that permit only what the system genuinely needs: recorder, NTP, management platform. Nothing routes to your servers or user network.
Kill the open door
Port forwarding replaced by brokered remote access, unique credentials per device, MFA on management consoles, and the installer's shared account retired.
See the traffic
Network detection and response watching the camera VLAN, so a device that suddenly talks to a domain controller, or to an address in another country, raises an alert the same day.
Own it properly
Every camera and recorder in the asset register, firmware in a patch cycle, and one written answer to who is accountable, reviewed with facilities, not instead of them.
Most of this is configuration and process rather than capital spend. In our experience the first engagement is a short audit. We map out what is actually on the network, show you what each device can reach, and give you a prioritised list. The urgent items are usually fixed in a day.
Five questions to ask this week
If you cannot answer all five, the gap is real.
- Who is named as accountable for the CCTV system's security, a person rather than a department?
- Are the cameras on their own VLAN, and what can that VLAN reach?
- When was the recorder firmware last updated, and who is responsible for the next one?
- Is anything reachable from the internet, and does remote viewing go through a VPN?
- Would you know within a day if a camera started behaving unusually?
So, IT or facilities? In practice, it's both. Facilities own the purpose, IT own the platform, and the two need one agreed line between them. The organisations that get breached through a camera are not the ones that chose wrongly. They are the ones that never chose at all.
