Physical-Cyber Convergence: Why Your Cameras Need Cybersecurity

← All Insights
CITADEL
Cybersecurity

Physical-Cyber Convergence: Why Your Cameras Need Cybersecurity

IP-connected security cameras and access control systems are becoming prime targets for cyber attacks. Learn how to protect your physical security infrastructure from digital threats.
This article is part of our Converged Security framework. Read the full pillar page →

Physical-Cyber Convergence: Why Your Cameras Need Cybersecurity

Your security cameras are computers. Your access control system is on the network. Your building automation is IP-connected. And all of them are vulnerable to the same cyber threats that target your IT infrastructure.

The Converged Threat Landscape

Real-world attacks on physical security systems:

  • Casino hacked through lobby fish tank thermometer (2018)
  • Target breached via a phished HVAC vendor's credentials, letting attackers pivot from a third-party contractor's network access onto point-of-sale systems — roughly 40 million payment cards and 70 million customer records exposed (2013–2014; reported by Krebs on Security)
  • Verkada, a cloud video security vendor, breached after attackers found super-admin credentials exposed online and used them to reach an internal Jenkins server — resulting in live access to feeds from roughly 150,000 cameras inside hospitals, jails, schools, and corporate sites including Tesla and Cloudflare (2021; the FTC later took enforcement action against Verkada over the incident)
  • Chirp Systems' smart-lock access-control app found to contain hardcoded credentials that could let an attacker within Bluetooth range remotely lock or unlock doors across an estimated 50,000 residences nationwide — a critical (CVSS 9.1) flaw first disclosed to the vendor in 2021 and still unresolved when CISA issued a public advisory in 2024

The problem: Physical security systems were designed for physical threats, not cyber attacks.

Vulnerabilities in Physical Security Infrastructure

IP Cameras

Common issues:

  • Default credentials (admin/admin) never changed
  • Outdated firmware with known vulnerabilities
  • Unencrypted video streams
  • Direct internet exposure
  • Weak authentication

Access Control Systems

Risk areas:

  • Controller network connectivity
  • Badge reader communications
  • Management software vulnerabilities
  • Credential storage security
  • Integration points (HR, AD)

Building Automation (BAS/BMS)

Attack vectors:

  • HVAC system network access
  • Lighting control systems
  • Elevator controls
  • Fire alarm panels

The Convergence Solution: CITADEL + SENTRY

Armorstack uniquely delivers both physical security expertise (CITADEL) and cybersecurity operations (SENTRY), enabling true convergence.

CITADEL CONVERGE: IoT Security for Physical Systems

Network Segmentation

  • Dedicated VLANs for security devices
  • Firewall rules restricting camera/controller traffic
  • Zero Trust access to physical security networks

Device Hardening

  • Default credential elimination
  • Firmware vulnerability management
  • Encrypted communications enforcement
  • Certificate-based authentication

Continuous Monitoring

  • Real-time device health monitoring
  • Anomaly detection for security devices
  • Intrusion detection on security networks

SENTRY Integration: Unified Threat Response

Correlated Threat Intelligence

  • Physical and cyber events correlation
  • Behavioral analytics across both domains
  • Unified incident response procedures

Example Scenario: Unauthorized door access attempt triggers:

  1. CITADEL: Physical alert and video review
  2. SENTRY: Cyber investigation of door controller
  3. Unified Response: Identify if physical breach or cyber attack

Best Practices: Securing Physical Security Systems

1. Inventory & Discovery

  • Complete inventory of all IP-connected physical security devices
  • Network mapping of security system architecture
  • Vendor and firmware version tracking

2. Network Architecture

Segmentation Strategy:


"`
<br>
Corporate Network (VLAN 10)
<br>
Physical Security Network (VLAN 50) ← Firewalled
<br>
├─ Cameras (VLAN 51)
<br>
├─ Access Control (VLAN 52)
<br>
└─ Building Automation (VLAN 53)
<br>
"`

3. Access Management

  • Privileged Access Management (PAM) for security system administration
  • MFA for VMS and access control software
  • Role-based access control (RBAC)
  • Regular access reviews and certification

4. Vendor Risk Management

  • Security requirements in RFPs
  • Vendor security assessments
  • Secure remote access for vendors (no persistent VPN)
  • Third-party penetration testing

Compliance Implications

HIPAA (Healthcare)

IP cameras in patient areas = ePHI considerations

  • Encryption requirements
  • Access controls
  • Audit logging
  • Business Associate Agreements with vendors

PCI DSS (Retail/Finance)

Cameras in point-of-sale areas = cardholder data environment

  • Network segmentation requirements
  • Quarterly vulnerability scans
  • Annual penetration testing

Armorstack's Unique Approach

We're one of the few providers delivering both:

CITADEL – Physical security design, installation, and monitoring

  • NICET Level III fire alarm expertise
  • Video surveillance and access control
  • Healthcare life safety systems

SENTRY – Cybersecurity operations and threat response

  • 24/7 SOC with integrated NOC
  • Network security and segmentation
  • IoT/OT security expertise

CITADEL CONVERGE – The integration layer

  • Physical security cyber hardening
  • Unified monitoring and response
  • Correlated threat intelligence

Implementation Roadmap

Phase 1: Assessment (Week 1-2)

  • Physical security system inventory
  • Vulnerability assessment
  • Network architecture review
  • Risk prioritization

Phase 2: Quick Wins (Week 3-4)

  • Change default credentials
  • Deploy critical firmware updates
  • Implement basic network segmentation
  • Enable logging to SIEM

Phase 3: Architecture (Month 2-3)

  • Full network segmentation
  • Encrypted communications
  • PAM for administration
  • 24/7 monitoring integration

Phase 4: Continuous Improvement (Ongoing)

  • Regular vulnerability scanning
  • Firmware management program
  • Security awareness for facilities teams
  • Quarterly architecture reviews

Conclusion

Physical security systems are no longer purely physical—they're IP-connected computing infrastructure requiring the same cybersecurity controls as your IT environment.

Organizations that fail to secure their physical security infrastructure create an easily exploitable attack vector for adversaries.

Armorstack's unique combination of physical security expertise (CITADEL) and cybersecurity operations (SENTRY) delivers true physical-cyber convergence.

Secure your physical security systems: Contact us for a physical security infrastructure assessment.