Physical security and cybersecurity
The convergence problem treated as an accountability problem: the ownership test, the outage nobody will authorise, and which instrument obligates whom.
Ask who owns the cameras and you convene a meeting. Ask three narrower questions instead and you get names.
Whose cost centre paid for the hardware. Whose pays the maintenance. Who can log in as administrator this afternoon without asking anyone's permission. The three answers are rarely the same, and the third is frequently a company rather than a department. Which of them carries authority decides whether a finding ever becomes a change.
What the maintenance contract buys, and what it inherits#
A video maintenance agreement is an availability agreement. It buys pictures on screens and a response time when they stop. Firmware currency sits outside it, and so does everything downstream of firmware currency — nobody asked at tender, and a fixed annual fee can price site visits and spare parts but not an open-ended stream of patches.
The contract also inherits limits set somewhere it never looked. Milestone's vulnerability management policy targets a patch within two months for CVSS critical findings and three months for high, then says that for medium and low severity "Patches are not provided for already released products." An integrator undertaking to keep your VMS current is undertaking something the manufacturer does not offer below CVSS 7.0. Every vendor has an edge like that somewhere different, and which vendors publish advisories catalogues them.
Nobody will authorise ten minutes of blindness#
A firmware campaign across a few hundred devices does not usually stall for want of money. It stalls because no one signs the outage.
Take a single camera covering a cash office. Updating it means it records nothing while it reboots. Who approves that? Not the security engineer who raised the finding; they do not run the site. Not the integrator, whose contract points the other way — the availability terms make the outage a failure against the one obligation they are actually paid on, and no clause anywhere obliges them to patch. The person with the authority is whoever owns the loss-prevention or life-safety function the camera serves. That person has usually never been asked, and works to an incentive structure in which an outage they approved reads worse than a vulnerability they never heard of.
Stated that way it is a governance defect with a named holder, which is a more tractable thing than a budget gap. The fix is a clause rather than a campaign: who may approve an outage, at what notice, for which camera groups, written into the maintenance schedule at renewal. If the objection is that cameras are no concern of the security programme, Gartner's public definition of continuous threat exposure management covers "digital and physical assets". That is Gartner's wording, not a vendor's.
The credentials are on a workstation, not on the cameras#
Custody of camera credentials is a workstation question before it is a camera question. Nozomi Networks Labs disclosed on 28 January 2026 that in the affected version of Hanwha's Wisenet Device Manager, "any Windows user – even with low privileges – may read the content of this file, decrypt the default username and password, and attempt to obtain control of all cameras." The file lives on whichever PC runs the management tool. Where that PC belongs to the integrator, so does the blast radius, on a host your endpoint controls have never inspected.
So the clause worth negotiating is not the obvious one about who holds the administrative password, but where the tool holding it runs and who administers that machine. Hardening covers removing the integrator's standing access at the end of commissioning; revoking a device account does nothing about a credential file already copied to a laptop.
Whose name is on the vendor account#
Register the manufacturer support account in the customer's name at handover and the argument about who receives advisories never happens. Leave it in the integrator's name and it happens at the worst moment, which is when you change integrator.
Milestone is the sharpest case. The advisory URL Milestone registered with the CVE Program and its software download page resolve to the same Entra-backed identity tenant, so patch and paperwork sit behind one login — a point VMS security develops. The advisories themselves are readable without an account, on doc.milestonesys.com, but only at the exact lower-case path: the capitalised variant that search engines index returns a 404. Genetec's GTAP portal likewise redirects to an OIDC endpoint. None of this is a problem while the partner account is somebody else's, right up until it is yours to reconstruct.
Which rule obligates whom#
The recurring error is a buyer citing a rule that creates no duty on them. An export control restricts exporters; a product rule binds whoever makes or supplies the product; neither tells an operator anything. Tender documents treat all of them as interchangeable.
| Instrument | Obligation runs to | What it asks of a camera operator |
|---|---|---|
| Sec. 889(a)(1)(A) | Executive agencies, in their own procurement | Nothing directly |
| FAR 52.204-25(b)(1) | Contractors supplying the Government | Supply the Government nothing using covered equipment as a substantial or essential component |
| Sec. 889(a)(1)(B), via FAR 52.204-25(b)(2) | The Government, which may not contract with an entity that uses covered equipment | Represent on your own estate after a "reasonable inquiry", if you want the contract |
| 2 CFR 200.216 | Recipients and subrecipients of federal grants and loans | No award funds on covered equipment; accepting the award is the certification |
| FY2024 NDAA s.805 (Pub. L. 118-31) | The Secretary of Defense, in DoD contracting | Nothing directly; it removes 1260H-listed suppliers from the DoD market |
| Entity List, 15 CFR 744 Supp. 4 | Exporters of items subject to the EAR to the listed entities | Nothing. It does not restrict buying or operating their cameras |
| UK PSTI, S.I. 2023/1007 | The supply side of the UK market | Nothing directly. It fixes what a lawfully sold camera must do: unique or user-defined passwords, a published reporting contact, a published minimum update period |
| CRA (EU) 2024/2847 | Manufacturers | Nothing directly. Ch. IV from 11 Jun 2026; Art. 14 from 11 Sep 2026; the rest 11 Dec 2027 |
| RED Art. 3(3)(d)–(f), via Del. Reg. (EU) 2022/30 | Manufacturers of internet-connectable radio equipment | Nothing directly, and a PoE-only camera is not radio equipment |
| WMS HCWS386, 24 Nov 2022 | UK Government departments | Sensitive sites on the Government estate; not police forces, councils or private buyers |
| CISA Secure by Design Pledge | Voluntary signatories, for enterprise software and cloud services | Nothing. Not binding, and IoT hardware sits outside its stated scope |
Read FAR 52.204-25(b)(2) carefully, because it is the row most often misread. It does not reach organisations outside federal contracting — it reaches how far into a contractor's own estate the question goes: the prohibition "applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract." The instrument that reaches organisations holding no federal contract at all is 2 CFR 200.216, which binds anyone spending grant or loan money.
The representation is only as strong as the record behind it, and the bar is deliberately low: "reasonable inquiry" means an inquiry into information in the entity's possession "that excludes the need to include an internal or third-party audit." Low, and awkward, when the only complete list of what is installed sits in an integrator's project files.
Section 805 of the FY2024 NDAA is the row this page owns. It bars the Secretary of Defense from entering into, renewing or extending a contract with an entity on the Section 1260H list from 30 June 2026, and from contracting for goods or services produced or developed by such an entity from 30 June 2027; components as defined in 41 U.S.C. 105 are excluded from that indirect bar, and pre-existing contracts survive modification, extension and renewal. The Department of Defense's 1260H list published at 91 FR 35189 on 10 June 2026 names both Hikvision and Dahua. Dates and scope for everything else in the table sit at procurement rules that now govern surveillance equipment.
The UK row rewards close reading. On 18 November 2025 the Minister for Security confirmed that "all sensitive Government sites originally identified with such equipment have now finished their replacement work." That is the completion of a worklist drawn up in 2022, not a statement about the estate.
None of these instruments assigns accountability inside an organisation. They decide what may be bought, and by whom, and then stop. The question they leave open is the one you started with, and its answer is whoever can log in this afternoon.
Sources
- Public Law 115-232, Sec. 889 — Prohibition on Certain Telecommunications and Video Surveillance Services or Equipment. U.S. Congress (congress.gov), 2018-08-13
- 48 CFR 52.204-25 — Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (NOV 2021). eCFR, 2021-11
- 2 CFR 200.216 — Prohibition on certain telecommunications and video surveillance equipment or services. eCFR, undated
- Public Law 118-31, Sec. 805 — Prohibition of Department of Defense Procurement Related to Entities Identified as Chinese Military Companies Operating in the United States. U.S. Congress (congress.gov), 2023-12-22
- 91 FR 35189 — Notice of Availability of Designation of Chinese Military Companies. U.S. Department of Defense / Federal Register, 2026-06-10
- 15 CFR Part 744, Supplement No. 4 — Entity List. eCFR, current
- The Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, Schedule 3. legislation.gov.uk, 2023
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71. EUR-Lex, 2024-11-20
- Commission Delegated Regulation (EU) 2026/339 repealing Delegated Regulation (EU) 2022/30. EUR-Lex, 2026-04-29
- Hansard Written Statement HCWS386 — Security Update on Surveillance Equipment. UK Parliament (Hansard API), 2022-11-24
- Hansard Written Statements HCWS1065 (18 Nov 2025) and HCWS90 (4 Jun 2026) — China-manufactured Surveillance Equipment: Sensitive Sites. UK Parliament (Hansard API), 2026-06-04
- Secure by Design Pledge. CISA, undated
- XProtect VMS Vulnerability Management Policy (PDF). Milestone Systems, unknown (no date printed in document)
- Milestone Security Advisory — CVE-2026-3014. Milestone Systems, 2026-07-15
- Download software. Milestone Systems, 2026-09-05
- Trust and cybersecurity resources. Genetec, 2026-09-05
- Smile, You're Being Hacked: Nozomi Networks Labs Finds Five New Flaws in Hanwha Wisenet Cameras. Nozomi Networks Labs, 2026-01-28
- CNAsList.json — data behind the CVE Program partner list. CVE Program, 2026-09-05
- Gartner Identifies the Top Cybersecurity Trends for 2024. Gartner, 2024-02-22