Guide · Security

Hardening Your Surveillance
System: A Practical Checklist

7 min read Admins & installers EarlyVigil Advisory Team

Passwords, MFA, user roles and encryption, the checklist we recommend for every deployment. A few configuration steps close most of the risk.

Cameras are frequently the weakest link

Cameras and recorders are computers on your network, but rarely get a laptop's level of care. Default logins and shared admin accounts are common, and each one is a way in.

80%
of reported camera compromises trace back to default or reused credentials
60%
of exposed devices found online are still running factory default settings
3x
faster incident containment reported by teams using MFA and role-based access

Figures are industry-observed estimates compiled from installer and security-researcher reporting, presented for illustrative context.

Passwords & multi-factor authentication

Use a strong, unique password for every account, never reused from another site. Enable MFA on all owner and manager accounts, it's the single highest-impact step you can take.

If an installer set up your system, rotate their credentials after handover and remove accounts that no longer need access.

User roles & permissions

Give every user the narrowest role that lets them do their job. A guard needs live view, not billing access. A regional manager needs their branches, not every site.

Review the audit log periodically, every login, playback and export is recorded, so unusual activity is visible early.

Encryption & network hardening

Footage is encrypted with AES-256 at rest and TLS 1.3 in transit by default. What matters most on your side: never expose a camera directly to the internet with port forwarding.

The edge device reaches the cloud outbound-only, so there's no need to open inbound ports or assign a public IP. If cameras are already port-forwarded, closing those ports is a fast win.

Firmware & ongoing monitoring

Firmware updates automatically by default, leave it enabled. Turn on camera-offline and health alerts so a disconnected camera is flagged immediately, not days later.

The strongest camera hardware is worthless if the login still says admin / admin. What separates a hardened deployment from a vulnerable one is configuration, not equipment.

— EarlyVigil Advisory Team

The four-point checklist

Unique passwords

No shared or default logins, on any account.

MFA everywhere

Enabled on every owner and manager account.

Least-privilege roles

Everyone gets exactly the access they need.

No direct exposure

No port-forwarded cameras or recorders.

Want Us to Review
Your Current Setup?

Our team can walk through your account's roles and access settings with you, no commitment required.