SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Trends & Industry IssuesColumnsCybersecurity Chronicles

4 Cybersecurity Traps for Integrators to Avoid

By Chris Maulding, Contributing writer
Cybersecurity Chronicles
February 13, 2024

There exists a common misconception among small to medium-sized organizations regarding their susceptibility to cyber-attacks. This thinking leads to a false sense of security and will only lead to future breaches because attackers don't care about the size of your company — they only care about the data.

Integrators are a prime target just like MSPs and MSSPs, since they have access to many clients. This one-to-many setup allows attackers to spend more time on a single integrator that can provide access to many clients’ data in a single breach or attack.

I’m going to touch on the top things that I have seen integrators do that could lead to breaches.

1. Sharing of corporate passwords for devices — I have seen numerous integrators resort to sharing root or admin passwords across clients. Sharing passwords allows an attacker to crack one password, which then gives them access to all clients that share that password. Once an attacker has one password, they are then able to move from the integrator’s network into their clients and steal more data. If this is discovered as part of  the incident response that the breach was due to a connection with the integrator, it can lead to cyber insurance claims and potential lawsuits.

2. Weak passwords — This is a recurring issue that I have seen impact more than just integrators. Passwords need to be complex and have a minimum of eight characters with a special character and number mixed in. Many places that I have worked with have something simple for access to devices, such as Company123!! as the password. If multi-factor authentication is enforced on the devices then this becomes less of an issue.

3. Having physical security systems on the same internal network — Incorporating physical security systems within the same internal network introduces another vulnerability and system for the client to make sure is patched appropriately. Adhering to best practices involves placing these systems on a separate network (VLAN) and allowing only certain internal IP addresses to establish a connection. This will keep malicious insiders from connecting to the systems and making changes or taking control of the system and causing issues.

4. Allowing any external IP to connect — Many integrators poke a hole in the client firewall to allow remote access to manage the on-prem devices. Knowing that the integrators are not firewall experts, we cannot expect them to know the vulnerability they could be introducing to the client’s network. Integrators should work closely with internal IT teams or the clients’ MSP to make sure that they are only allowing the integrator’s external IP addresses to connect to the system that is on the internal network. Thus keeping the rest of the internet and potential attackers from seeing the third-party system. With that said, if an integrator is breached and the above is true then having this in place won’t matter.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

An example of leaving cameras open to the world and the internet is shown below. These cameras could have been installed by integrators or by individuals themselves without limiting access to these devices. Many tools on the internet can do what is shown below.

The search query in the tool used is in the screenshot below. A subscription to the service is needed to use the filters to narrow searches.

H264DVR.png

The resulting image for this search is for a possible healthcare facility in Arizona. Would you want to visit this healthcare facility knowing that you could be seen on the internet? Based on the timestamp of this image, and that it is black and white, this was scanned by shodan at 12:39 AM, so no one was in the office.

waiting room.png

Evident from the provided screenshots, it becomes apparent how effortlessly an attacker can gain valuable information from the internet. Tools such as that used to gain camera access above were designed to help companies enhance their security posture. There inevitably exist individuals who will abuse technology for malicious purposes leading to breaches and loss of personal or corporate information.

These are just some of the standard best practices to keep in mind when it comes to cybersecurity. Avoid falling into the trap of thinking, “It can't happen to us; we’re too small to attract malicious attention.” Your company size does not determine vulnerability. You may be small, but the data and access to customers’ data you possess categorize you as a more substantial target than you might realize.

KEYWORDS: cybersecurity

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Chris maulding

Chris Maulding is a security engineer and CTO of Plattsburgh, N.Y.-based AlchemyCore, a managed security service provider (MSSP). He works with security integrators to assist them in the role of subject matter expert on cybersecurity matters with their end customers.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    Exclusives
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    State of the Market Series
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Trends & Industry Issues
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • Possibilities Abound for Integrators to Leverage Technology Trends for Growth

    See More
  • gun

    Gunshot Detection: A Life Safety Product for Integrators to Resell

    See More
  • Cybersecurity Chronicles

    Automation With a SOAR for Integrators

    See More

Related Products

See More Products
  • 2019sdm.png

    2019 Top Systems Integrators Report

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • introduction.jpg

    Introduction to Security, 10th Edition

See More Products

Events

View AllSubmit An Event
  • September 25, 2025

    Cloud or On-Premise: Navigating Access Control and Cybersecurity Choices

    ON DEMAND: Security technology is rapidly evolving — and so are the threats. In this webinar, we'll examine the advantages and trade-offs of cloud-based and on-premise solutions, offering clarity for integrators, consultants and end users.
View AllSubmit An Event
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing