A Cybersecurity & Industrial Surveillance Case Study by Sidigiqor Technologies
Cybersecurity teams spend millions protecting servers, employee laptops, firewalls, email systems and cloud applications.
But what happens when the attacker doesn’t enter through any of them?
What if the weakest point is a device that everyone considers to be “just a camera”?
This case study from a manufacturing company in the Chandigarh region highlights an important reality of modern cybersecurity: an IP camera is not simply a camera. It is a network-connected computing device and must be treated as part of the organization’s cybersecurity perimeter.
The Incident: The Attack Didn’t Start Where Everyone Expected
The company had a reasonably mature IT security environment.
Employee laptops were protected with Endpoint Detection and Response (EDR). Servers were monitored. Network security controls were in place.
Attackers initially attempted to compromise an employee endpoint with ransomware associated with the Akira ransomware ecosystem.
The company’s endpoint security solution detected the malicious activity and blocked the attempted infection.
At that point, the attackers had a problem.
The easiest route through an employee laptop had been closed.
Instead of giving up, the attackers began looking for another path into the organization’s internal environment.
And this is where the story became interesting.
The Attackers Started Looking for the Weakest Device
Once an attacker obtains some level of access to a network, one of the things they may attempt is internal reconnaissance.
The objective is simple:
Find devices that are connected to the network but are less protected than traditional IT systems.
Employee laptops have EDR.
Servers may have security monitoring.
Firewalls have security policies.
But what about:
- IP cameras?
- NVRs?
- DVRs?
- Printers?
- Biometric attendance machines?
- Access-control systems?
- IoT sensors?
- Building-management systems?
- Smart TVs?
- Industrial IoT devices?
These devices are frequently overlooked during cybersecurity assessments.
In this particular manufacturing environment, an IP camera became one of the critical concerns.
Why an IP Camera Can Become a Cybersecurity Risk
Many people still think of an IP camera as:
Camera → Video → NVR → Monitor
Technically, an IP surveillance system is much more complicated.
Modern IP cameras can contain:
- Embedded Linux or another operating system
- Network interfaces
- Web servers
- APIs
- User authentication
- Storage
- Firmware
- Remote-management functionality
- Network services
- Configuration interfaces
In other words:
An IP camera is a computer with a lens.
And just like computers, network-connected cameras can potentially contain vulnerabilities.
The difference is that organizations generally don’t deploy EDR agents on every camera.
Firmware updates may also be less frequent.
Security logs may be limited.
Default or weak credentials may remain in use.
And network segmentation may not exist.
That combination can create a serious blind spot.
The Critical Problem: CCTV and Corporate IT Were on the Same Network
The major architectural concern identified in this type of environment is not simply the camera itself.
It is where the camera is connected.
If surveillance cameras are placed directly on the same flat network as:
- Employee computers
- File servers
- Domain services
- ERP systems
- Shared folders
- Production systems
- Management systems
then a compromised surveillance device can potentially become a stepping stone for further attacks.
This is why Sidigiqor Technologies repeatedly recommends:
“Don’t Put Your CCTV Network on the Same Network as Your Corporate IT.”
The objective is not to make CCTV independent because it looks technically cleaner.
The objective is risk containment.
What Should Have Happened?
A properly designed enterprise surveillance architecture should separate the surveillance environment from the corporate IT environment.
For example:
Corporate Network
Employee laptops
↓
Business applications
↓
File servers
↓
ERP / CRM
↓
Internet
Separate Surveillance Network
IP Cameras
↓
PoE Switches
↓
CCTV VLAN / Dedicated Network
↓
NVR / VMS
↓
Authorized Monitoring Stations
The two environments can still communicate where necessary through controlled firewall rules.
But they should not operate as one unrestricted flat network.
How Sidigiqor Approached the Problem
When Sidigiqor’s cybersecurity and surveillance specialists assess an environment like this, we don’t look at CCTV independently from IT.
We look at the entire attack surface.
Our assessment typically covers:
1. Network Discovery
We identify devices connected to the organization’s network.
That can include:
- Computers
- Servers
- Switches
- Routers
- Firewalls
- IP cameras
- NVRs
- Printers
- Biometric devices
- IoT devices
- Access-control systems
The goal is to understand:
“What is actually connected to this network?”
Because you cannot secure a device you don’t know exists.
2. CCTV Network Assessment
We examine:
- Camera IP addresses
- Network segments
- VLAN configuration
- Camera-to-server communication
- Camera-to-internet communication
- NVR connectivity
- Remote access
- Port exposure
- Authentication
- Firmware status
- Administrative accounts
- Unnecessary services
This provides visibility into whether the surveillance infrastructure has become an unintended cybersecurity entry point.
3. Network Segmentation
This is one of the most important recommendations.
Sidigiqor recommends creating a dedicated:
CCTV VLAN / Surveillance Network
Instead of:
Camera → Corporate LAN
the architecture becomes:
Camera → CCTV VLAN → Firewall / Controlled Access → Authorized Systems
This dramatically reduces unnecessary lateral movement opportunities.
If one camera is compromised, the attacker should not automatically obtain unrestricted access to the company’s business network.
4. Internet Isolation for IP Cameras
This is another area where Sidigiqor takes a strong position.
CCTV cameras normally do not need unrestricted internet access.
A camera primarily needs to communicate with:
- NVR
- VMS
- Authorized management system
- Approved monitoring infrastructure
It generally does not need unrestricted outbound access to the public internet.
Therefore, we commonly recommend:
Dedicated CCTV Internet / Network Architecture
IP Cameras
↓
Dedicated PoE Switch / CCTV VLAN
↓
Firewall
↓
NVR / VMS
↓
Authorized Users
And if internet connectivity is required for a specific function, it should be:
controlled, monitored and explicitly allowed.
Why Sidigiqor Recommends a Separate Internet Connection for IP Cameras
This recommendation is often misunderstood.
We are not saying:
“Every camera must have its own individual internet connection.”
That would be inefficient and unnecessary for most organizations.
Our recommendation is generally to create a separate surveillance network, which may use a dedicated internet connection where the organization’s architecture and remote-access requirements justify it.
The purpose is isolation.
For example:
Network 1 — Corporate IT
Employees
Servers
ERP
Email
Business applications
Internet
Network 2 — CCTV / Surveillance
IP Cameras
NVR
VMS
AI Video Analytics
Security Control Room
This architecture creates a much stronger security boundary.
Why Separation Matters During a Ransomware Attack
Imagine the following scenario:
An attacker compromises a camera.
Without segmentation:
Camera
↓
Corporate LAN
↓
File shares
↓
Servers
↓
Employee systems
↓
Potential ransomware propagation
The camera has become a bridge into the business environment.
Now consider the segmented architecture:
Camera
↓
CCTV VLAN
↓
Firewall
X
Corporate Network
The compromised camera may still be a security incident.
But the potential blast radius is significantly reduced.
This is the fundamental principle:
“Contain the breach before it becomes a business-wide disaster.”
But Isn’t the Firewall Enough?
No.
A firewall is important, but cybersecurity cannot depend on one security control.
A good architecture follows defense in depth.
That means combining:
- Firewall
- VLAN segmentation
- Access-control policies
- Strong credentials
- Firmware management
- Network monitoring
- Vulnerability assessment
- Secure remote access
- Logging
- Endpoint security
- Backup
- Incident response
- User awareness
EDR protects endpoints.
Firewalls protect network boundaries.
VMS manages video.
AI analytics detects events.
But none of these automatically makes every connected device secure.
Where AI Surveillance Fits Into Cybersecurity
This is where modern surveillance becomes much more powerful.
A properly designed AI surveillance system can provide:
- Human detection
- Vehicle detection
- Perimeter intrusion detection
- Line-crossing detection
- Restricted-area monitoring
- ANPR
- Face detection where legally and operationally appropriate
- Crowd analytics
- Object detection
- Smart search
- Event-based alerts
- Video intelligence
But AI video analytics and cybersecurity are two different layers.
AI asks:
“What is happening in front of the camera?”
Cybersecurity asks:
“Can somebody compromise the camera itself?”
A secure industrial surveillance solution needs both.
The Lesson for Manufacturing Companies
Manufacturing companies are particularly exposed because their environments contain a mixture of:
IT + OT + CCTV + IoT + Industrial Systems
A single facility may have:
- Corporate computers
- Servers
- Production systems
- PLC/SCADA environments
- IP cameras
- Access-control systems
- Attendance systems
- Weighbridge systems
- Printers
- Wi-Fi
- Remote-access systems
- Cloud applications
Every connected device expands the organization’s attack surface.
The traditional approach was:
“Protect the server.”
The modern approach needs to be:
“Protect every connected asset.”
Why Hackers Look for the Weakest Link
Attackers don’t necessarily attack the strongest security control first.
They look for the easiest route.
If the laptop has EDR, they may look elsewhere.
If the server is hardened, they may search for another device.
If the firewall is properly configured, they may target an exposed application.
If the employee account is protected, they may search for an unmanaged device.
This is why cybersecurity professionals talk about:
Attack Surface Management
The question is no longer:
“Do we have antivirus?”
The better question is:
“What devices can reach our network, and what can each device reach?”
Sidigiqor’s Approach: IT + Cybersecurity + Surveillance Under One Strategy
This is one of the biggest advantages of working with an organization that understands both IT infrastructure and surveillance.
Sidigiqor approaches surveillance as part of the organization’s overall technology infrastructure.
Our assessment can cover:
IT Infrastructure
- Network design
- Servers
- Switching
- Wi-Fi
- Firewall
- Backup
- Cloud infrastructure
Cybersecurity
- Vulnerability assessment
- VAPT
- Firewall management
- Network segmentation
- Security hardening
- IT security audits
- Incident response planning
Surveillance
- IP CCTV
- NVR / VMS
- AI cameras
- Industrial surveillance
- ANPR
- PTZ
- Thermal surveillance
- AI video analytics
Integration
The objective is to build an environment where these technologies work together without unnecessarily exposing one system to another.
The Chandigarh Manufacturing Case: The Real Takeaway
The most important lesson from this case is not:
“CCTV cameras are dangerous.”
That would be the wrong conclusion.
The correct conclusion is:
Any network-connected device can become part of your cybersecurity attack surface.
A camera isn’t inherently insecure.
A poorly designed architecture is.
A camera with strong credentials, updated firmware, restricted network access, proper VLAN segmentation, controlled remote access and monitoring is significantly safer than a camera sitting unrestricted on the same flat network as critical business systems.
10 Questions Every Manufacturing Company Should Ask About Its CCTV
Before installing or upgrading an IP surveillance system, ask your IT/security team:
- Are our cameras on a separate VLAN?
- Can cameras communicate directly with employee computers?
- Can cameras access the internet?
- Does the NVR have unrestricted network access?
- Are default camera passwords disabled?
- Is camera firmware regularly updated?
- Is remote CCTV access protected by secure authentication?
- Are unnecessary ports and services disabled?
- Are CCTV network events being monitored?
- If one camera is compromised, can the attacker reach our servers?
If your IT team cannot answer these questions clearly, your CCTV infrastructure deserves a security review.
The era of treating CCTV as a simple security appliance is over.
Today’s IP camera is a network-connected computing device.
And anything connected to your network must be considered part of your cybersecurity perimeter.
The strongest EDR, most expensive firewall and largest cybersecurity team cannot compensate for a major blind spot in the network architecture.
Because sometimes the biggest security problem isn’t the server.
It isn’t the employee laptop.
It isn’t even the firewall.
Sometimes, it is the small device hanging on the wall that nobody thought to secure.
Don’t secure only your computers.
Secure the network.
Secure the cameras.
Secure every connected device.
That’s the Sidigiqor approach to Cybersecurity + IT Infrastructure + AI Surveillance.
Sidigiqor Recommendation for Manufacturing & Industrial Businesses
If your factory, warehouse, corporate office or industrial facility uses IP cameras, NVRs, AI cameras or remote CCTV monitoring, consider a professional CCTV & Network Security Assessment.
Sidigiqor can assess your existing infrastructure and identify:
Unsecured Cameras → Flat Networks → Excessive Internet Access → Weak Credentials → Outdated Firmware → Unnecessary Exposure → Lateral-Movement Risks
before they become a business-critical incident.
Sidigiqor Technologies OPC Private Limited: IT Infrastructure | Cybersecurity | AI Surveillance | Network Security | Digital Transformation
Secure the device. Secure the network. Secure the business.