What should I do if a camera has been accessed or compromised?
Unexplained access logs, a camera that has been moved remotely, or unexplained bandwidth consumption all point to inadequate hardening.
- Change credentials immediately: remove every default account, disable unused ones, and use 12-character-plus passwords mixing upper and lower case, digits and symbols, unique per device.
- Close unnecessary public exposure: do not forward device ports to the internet unless it is genuinely required. Prefer cloud P2P or VPN access and keep devices behind the firewall.
- Disable unused services: switch off Telnet, FTP and UPnP where not needed to reduce the attack surface, and enable lockout on failed logins plus alerting.
- Update firmware: vendors continuously patch disclosed vulnerabilities, so build firmware version review into routine maintenance.
- Segment the network: place video devices in their own VLAN, separate from the office network, so a compromise cannot pivot laterally.
Security is a process, not a one-off configuration. Put accounts, firmware and exposed services on a quarterly checklist.