When security cameras become intelligence sources

Author: Guy Bewsher

05 Mar 2026

Recent press reports suggesting that traffic camera were hacked to provide Israeli intelligence with details of the movements and behaviour of senior Iranian officials, highlight an important but often overlooked cyber security risk.

For organisations responsible for protecting sensitive facilities. Surveillance systems create a challenge. They must provide visibility into secure environments, yet many cameras are deployed outside secure perimeters and are built using globally sourced components. If these systems are compromised, they can create opportunities for attackers to observe activity, map operational routines or attempt to exploit connections to other networks.

Surveillance systems: valuable tools, potential vulnerabilities

Security cameras play a critical role in modern security operations. They support investigations, enhance situational awareness and provide essential monitoring across facilities and infrastructure.

Camera systems, however, are often positioned to observe entrances, perimeters and vehicle movements. If attackers gain access to these systems, they may be able to observe:

  • Who enters or leaves a facility;

  • Patterns of activity over time;

  • Operational routines or security procedures.

In the reported case, analysts were allegedly able to monitor traffic flows and identify patterns associated with key individuals and vehicles. For organisations responsible for protecting sensitive locations or personnel, this type of intelligence gathering can present a significant security risk.

The supply chain challenge

Another factor increasing risk is the complexity of the global supply chains behind many connected technologies, including surveillance systems.

Camera platforms frequently incorporate hardware components, firmware and software developed by multiple suppliers across different regions. While this ecosystem enables rapid innovation and cost efficiency, it can also introduce uncertainty about how secure embedded code or update mechanisms may be.

Supply chain compromise has become a recognised cyber threat. One of the most widely documented examples is the SolarWinds Orion supply chain attack, where malicious code was inserted into a widely distributed software update and delivered to thousands of organisations worldwide.

The UK’s National Cyber Security Centre (NCSC) has also highlighted supply chain security as an increasing concern for organisations operating critical systems and services.

These incidents demonstrate how technologies deployed for legitimate purposes can become pathways for attackers when security controls are insufficient.

Why perimeter security alone is not enough

Many organisations still approach cyber security primarily through perimeter defence, relying on firewalls and monitoring tools to prevent malicious access.

While these controls remain important, modern cyber security increasingly recognises that breaches can occur despite strong perimeter protections. Once attackers gain access to a network, they typically attempt to:

  • Move laterally between systems;

  • Access sensitive information;

  • Extract data from the organisation.

This is why many security strategies now focus on controlling how information moves between systems, rather than relying solely on preventing access.

Controlling information flow

One approach to reducing risk is to enforce strict control over how data moves between networks, particularly where lower-trust technologies interact with sensitive environments.

Surveillance systems provide a useful example. Camera networks may need to send video feeds into monitoring platforms or command centres located within secure environments. However, there is rarely a legitimate operational reason for traffic to flow in the opposite direction.

Technologies such as data diodes and cross domain guards enforce these types of one-way information flows at the hardware or policy level. By allowing data to move in only one direction, they help ensure that external or lower-trust systems cannot be used as a pathway into protected networks.

This architectural approach forms part of the broader discipline of secure information exchange, where information is allowed to move between systems only when it meets defined security policies and operational requirements.

Protecting secure monitoring environments

This is the principle behind GuarDiode Camera Edition, developed by Nexor specifically for surveillance deployments.

The solution enables video feeds from camera networks to be transferred into secure monitoring or command environments while enforcing a strictly one-way flow of data. This means the monitoring network can receive camera feeds, but communication cannot travel back to the camera infrastructure.

As a result, even if camera systems deployed outside the secure perimeter were compromised, they cannot be used as a pathway to access or extract information from the protected network.

Lessons for organisations

Recent events serve as a reminder that systems deployed for security purposes can themselves become sources of vulnerability if they are not properly protected. For organisations responsible for sensitive facilities, critical infrastructure or national security operations, several key lessons stand out.

Treat surveillance systems as part of the cyber security estate

Security cameras are often managed as physical security infrastructure, but they are increasingly networked systems that should be secured like any other IT asset.

Consider supply chain exposure

Many connected devices rely on complex international supply chains. Understanding where components, firmware and software originate from is an important part of managing risk.

Assume compromise and control information flow

Perimeter defences alone are no longer sufficient. Security architectures should assume that some systems may become compromised and enforce strict controls over how information can move between networks.

Protect sensitive networks from lower-trust technologies

Technologies such as cross domain guards and one-way data transfer mechanisms can help ensure operational data can move where it needs to go while preventing attackers from exploiting connected devices as pathways into secure environments.

Read more posts on

About the author

Guy Bewsher has been at the forefront of technological innovation, combining deep expertise with a forward-thinking approach. In 1996, he worked as a contractor for DERA, exploring the potential of synthetic environments; now known as AI; to streamline and enhance military decision-making processes. This research contributed to advancements like the Single Information Environment (SInfoE) MVP, driven by Dstl’s SIE and Comms and Nets programs. Through a series of four blogs, Guy will delve into the impact of AI on the battlespace and explain how the SInfoE is central to achieving the Integrated Force vision.

Guy Bewsher on Linkedin

Read more posts by Guy Bewsher

Read more posts on