Cyber-Physical Convergence: Why Your Cameras and Access Control Are Now an IT Security Problem
For years, the camera system and the network were run by two different people who barely spoke to each other. The integrator installed the cameras, ran the cabling, and configured the NVR. The IT team managed the servers, the firewall, and the Wi-Fi. Nobody owned the seam between them, and that seam is exactly where attackers are now getting in. A camera, a door controller, or an intercom panel is not a passive piece of hardware anymore; it is a small embedded computer running Linux, with its own IP address, its own firmware, its own login credentials, and in most installations, direct access to the same switch and the same internal network as the accounting server. When that device is unsegmented, unpatched, or still running its factory-default password, it is not a physical security weak point. It is an open port into the entire business, and in 2026 that distinction has stopped being theoretical.
The math on this is not new, but it has gotten worse as camera counts have grown. Multifamily properties, medical offices, and light industrial sites that once ran four or five analog cameras now routinely run 40, 80, or 150 IP cameras plus door controllers, intercoms, and environmental sensors, each one a network endpoint. Recent industry reporting on IoT and OT security consistently flags video surveillance and access control hardware among the most-exploited device categories on converged networks, largely because these devices are purchased and installed by a physical security vendor, not by IT, and often never make it onto a patch management schedule at all. A camera that shipped in 2022 and has never received a firmware update is not an edge case; it is close to the norm on properties that treated the camera project as a one-time capital purchase rather than an ongoing system that needs the same lifecycle management as a server.
The attack path is straightforward once you think of a camera as a computer instead of a lens. An attacker who compromises an internet-facing camera or a misconfigured NVR with port forwarding enabled does not need to "hack video." They need the camera to be sitting on the same flat network as everything else, because from there they can pivot: scan for open shares, harvest credentials from a Windows box with saved passwords, or drop ransomware onto file servers that have nothing to do with security footage. Security researchers and vendors have documented this pattern repeatedly -- botnets built from compromised cameras and DVRs, and separately, camera and access-control footholds used as the initial entry point in broader network intrusions. The device itself is rarely the target. It is the door that was left unlocked because nobody thought of it as a door.

Access control systems carry the same risk in a different shape. A modern door access panel is a networked device that talks to a cloud or on-premises controller, stores credential data, and often has an admin web interface reachable from inside the building network -- sometimes, if misconfigured, from the internet. If that panel shares a VLAN with office workstations, a compromise of one becomes a compromise path to the other in both directions. An attacker who gets into the IT network through a phished employee can potentially reach the access control system and manipulate door schedules or credentials; an attacker who compromises the access panel through a known firmware vulnerability can potentially move laterally into HR and finance systems. This is precisely the scenario our recent piece on touchless and mobile credential access control flags as a governance issue, not just a convenience upgrade: every credential and every controller you add is now an identity security decision, not just a physical security one.
Regulators and insurers are starting to treat it that way too. Cyber insurance applications increasingly ask about network segmentation for IoT and OT devices specifically, and carriers have begun excluding or limiting claims where an unsegmented camera or badge system was the documented entry point for a breach. On the compliance side, frameworks like NIST CSF 2.0 and CMMC explicitly extend asset inventory and access control requirements to any networked device, not just servers and laptops -- which means a defense subcontractor's camera system is now squarely inside the scope of an assessment, not outside it. Property owners subject to HIPAA face a similar reality: a compromised camera feed or access log that touches resident or patient movement data can trigger the same breach notification obligations as a stolen laptop, a point we've detailed in our HIPAA risk assessment guidance for senior living properties.
The fix is not complicated in concept, even though it requires actual engineering discipline to execute. Physical security devices need their own VLAN, isolated from the general office and resident/tenant network, with firewall rules that allow only the specific traffic those devices need -- typically outbound to the recording server and management platform, nothing else, and no default route to the internet. Default credentials get changed on day one, not left as a punch-list item. Firmware updates get scheduled the same way server patches do, on a cadence, with someone accountable for confirming they happened. Remote access to camera and access control management interfaces goes through the same VPN or zero-trust access path as everything else IT manages, not a separate port-forwarded shortcut the installer set up for convenience during commissioning. None of this is exotic; it is the same segmentation and hygiene practice IT departments have applied to servers for two decades, just extended to a device category that historically sat outside that discipline.
What makes 2026 different is not that the vulnerability is new -- it is that the tooling to actually see it has caught up, and so has the expectation that someone will use it. Unified platforms that manage cameras, access control, and network visibility from one pane make it possible to spot an unpatched device or an anomalous connection from a camera in the same dashboard where you'd spot a compromised laptop, an approach we cover in more depth in our piece on unified security platforms versus siloed systems. The properties still running physical security and IT as two separate vendor relationships, with two separate networks nobody has actually diagrammed together, are the ones showing up in the after-action reports when something goes wrong. Convergence is not a marketing term for bundling two invoices; it is a recognition that the underlying risk was always one network, and treating it as two has been a gap the whole time.
This is also where the design decisions made at install time matter more than most property owners realize. A camera and access control system speced without VLAN segmentation, firmware management, and credential hygiene built into the design is going to be exactly the liability described above, regardless of how good the camera resolution is or how sleek the door reader looks. Mytek Pros designs and installs surveillance and CCTV systems as converged network infrastructure from the first design conversation, not as a bolt-on to a network someone else built -- segmented VLANs, hardened remote access, documented firmware lifecycle, and integration with the same identity and monitoring stack that protects the rest of the business, so the camera system strengthens your security posture instead of quietly undermining it. If you are not sure which compliance framework applies to your camera and access control data -- HIPAA, CMMC, NIST, or something else -- our free Compliance Framework Finder will point you to the right one in a few minutes. Call (619) 353-5702 or email inquire@mytekpros.com to have us walk your existing camera and access control network and tell you, plainly, where the seams are.
Questions about design/build? Get in touch or explore our Design/Build services.
