The useful answer is rarely “buy the biggest number.” This guide turns the specification sheet into an installation decision you can defend after dark, after handover and when footage is actually needed.

01

Inventory devices and remove defaults

Begin with inventory. Record every model, firmware version, address and owner, then change factory credentials before installation. Each administrator should have an individual account, and viewers should receive only the permissions they need. A shared admin password makes both investigation and offboarding unnecessarily difficult.

02

Segment the surveillance network

Segment the surveillance network and block unsolicited inbound traffic. Prefer a vendor service with strong account security or a properly maintained VPN over port-forwarding a recorder to the internet. Enable multi-factor authentication where available and remove unused plug-ins, protocols and cloud integrations.

03

Maintain firmware and recovery

Security is maintenance, not a commissioning checkbox. Subscribe to vendor advisories, schedule firmware reviews, back up configuration and test restore procedures. Retire equipment that no longer receives fixes, even if the video still looks good.

FIELD NOTE

Commission the system against a written evidence goal. Save reference images and settings so future maintenance can spot gradual changes.

THE HANDOVER TEST

Can another person prove the system still works?

Record the final view, night image, bitrate, alerts, firmware and access method. A system is not finished until the owner can verify recording and export without the installer standing beside it.

Every site is different. Confirm manufacturer instructions, electrical requirements, privacy obligations and local regulations before installation.

QUICK ANSWERS

Frequently asked questions

Can an IP camera be hacked?

Any connected device can be exposed by weak credentials, obsolete firmware or unsafe remote access. Segmentation and maintenance reduce that risk.

Should an NVR be port forwarded?

Direct port forwarding is usually avoidable. A maintained VPN or a vendor service protected by strong account security is generally safer.