Cybersecurity
Physical-Cyber Convergence: Why Your Cameras Need Cybersecurity
Physical-Cyber Convergence: Why Your Cameras Need Cybersecurity
Your security cameras are computers. Your access control system is on the network. Your building automation is IP-connected. And all of them are vulnerable to the same cyber threats that target your IT infrastructure.
The Converged Threat Landscape
Real-world attacks on physical security systems:
- Casino hacked through lobby fish tank thermometer (2018)
- Target breached via a phished HVAC vendor's credentials, letting attackers pivot from a third-party contractor's network access onto point-of-sale systems — roughly 40 million payment cards and 70 million customer records exposed (2013–2014; reported by Krebs on Security)
- Verkada, a cloud video security vendor, breached after attackers found super-admin credentials exposed online and used them to reach an internal Jenkins server — resulting in live access to feeds from roughly 150,000 cameras inside hospitals, jails, schools, and corporate sites including Tesla and Cloudflare (2021; the FTC later took enforcement action against Verkada over the incident)
- Chirp Systems' smart-lock access-control app found to contain hardcoded credentials that could let an attacker within Bluetooth range remotely lock or unlock doors across an estimated 50,000 residences nationwide — a critical (CVSS 9.1) flaw first disclosed to the vendor in 2021 and still unresolved when CISA issued a public advisory in 2024
The problem: Physical security systems were designed for physical threats, not cyber attacks.
Vulnerabilities in Physical Security Infrastructure
IP Cameras
Common issues:
- Default credentials (admin/admin) never changed
- Outdated firmware with known vulnerabilities
- Unencrypted video streams
- Direct internet exposure
- Weak authentication
Access Control Systems
Risk areas:
- Controller network connectivity
- Badge reader communications
- Management software vulnerabilities
- Credential storage security
- Integration points (HR, AD)
Building Automation (BAS/BMS)
Attack vectors:
- HVAC system network access
- Lighting control systems
- Elevator controls
- Fire alarm panels
The Convergence Solution: CITADEL + SENTRY
Armorstack uniquely delivers both physical security expertise (CITADEL) and cybersecurity operations (SENTRY), enabling true convergence.
CITADEL CONVERGE: IoT Security for Physical Systems
Network Segmentation
- Dedicated VLANs for security devices
- Firewall rules restricting camera/controller traffic
- Zero Trust access to physical security networks
Device Hardening
- Default credential elimination
- Firmware vulnerability management
- Encrypted communications enforcement
- Certificate-based authentication
Continuous Monitoring
- Real-time device health monitoring
- Anomaly detection for security devices
- Intrusion detection on security networks
SENTRY Integration: Unified Threat Response
Correlated Threat Intelligence
- Physical and cyber events correlation
- Behavioral analytics across both domains
- Unified incident response procedures
Example Scenario: Unauthorized door access attempt triggers:
- CITADEL: Physical alert and video review
- SENTRY: Cyber investigation of door controller
- Unified Response: Identify if physical breach or cyber attack
Best Practices: Securing Physical Security Systems
1. Inventory & Discovery
- Complete inventory of all IP-connected physical security devices
- Network mapping of security system architecture
- Vendor and firmware version tracking
2. Network Architecture
Segmentation Strategy:
"`
<br>
Corporate Network (VLAN 10)
<br>
Physical Security Network (VLAN 50) ← Firewalled
<br>
├─ Cameras (VLAN 51)
<br>
├─ Access Control (VLAN 52)
<br>
└─ Building Automation (VLAN 53)
<br>
"`
3. Access Management
- Privileged Access Management (PAM) for security system administration
- MFA for VMS and access control software
- Role-based access control (RBAC)
- Regular access reviews and certification
4. Vendor Risk Management
- Security requirements in RFPs
- Vendor security assessments
- Secure remote access for vendors (no persistent VPN)
- Third-party penetration testing
Compliance Implications
HIPAA (Healthcare)
IP cameras in patient areas = ePHI considerations
- Encryption requirements
- Access controls
- Audit logging
- Business Associate Agreements with vendors
PCI DSS (Retail/Finance)
Cameras in point-of-sale areas = cardholder data environment
- Network segmentation requirements
- Quarterly vulnerability scans
- Annual penetration testing
Armorstack's Unique Approach
We're one of the few providers delivering both:
CITADEL – Physical security design, installation, and monitoring
- NICET Level III fire alarm expertise
- Video surveillance and access control
- Healthcare life safety systems
SENTRY – Cybersecurity operations and threat response
- 24/7 SOC with integrated NOC
- Network security and segmentation
- IoT/OT security expertise
CITADEL CONVERGE – The integration layer
- Physical security cyber hardening
- Unified monitoring and response
- Correlated threat intelligence
Implementation Roadmap
Phase 1: Assessment (Week 1-2)
- Physical security system inventory
- Vulnerability assessment
- Network architecture review
- Risk prioritization
Phase 2: Quick Wins (Week 3-4)
- Change default credentials
- Deploy critical firmware updates
- Implement basic network segmentation
- Enable logging to SIEM
Phase 3: Architecture (Month 2-3)
- Full network segmentation
- Encrypted communications
- PAM for administration
- 24/7 monitoring integration
Phase 4: Continuous Improvement (Ongoing)
- Regular vulnerability scanning
- Firmware management program
- Security awareness for facilities teams
- Quarterly architecture reviews
Conclusion
Physical security systems are no longer purely physical—they're IP-connected computing infrastructure requiring the same cybersecurity controls as your IT environment.
Organizations that fail to secure their physical security infrastructure create an easily exploitable attack vector for adversaries.
Armorstack's unique combination of physical security expertise (CITADEL) and cybersecurity operations (SENTRY) delivers true physical-cyber convergence.
Secure your physical security systems: Contact us for a physical security infrastructure assessment.