SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
ColumnsIntegration Spotlight

Going Beyond the Checklist for Effective Cybersecurity

By Andrew Chisholm
Integration-Spotlight.png
October 2, 2025

“Our cybersecurity posture is good.”    

“Our IT department has the network locked down, so we are in a secure environment and don’t need to secure everything.”   

“We secured our recording server and the cameras are all installed with tamperproof hardware.”   

These statements from actual customers are some of the reasons many security and IoT systems are inherently not secure in a world where they really should be.  

Many large critical infrastructure customers I have worked with over the years take a somewhat lackadaisical stance when it comes to their cybersecurity because their compliance process doesn’t directly call out requirements, so they apply what is on the checklists and move on.  

The reality is that cybersecurity is just as important, and required, as any other means to physically secure infrastructure (servers, network switches, network cabling) and endpoints (access control devices, intrusion panels, cameras, sensors, and even network audio) — possibly even more critical because of the ability for a remote attacker anywhere in the world to use any vulnerability they can to exploit and bypass these systems.  

NIST is one of the mainly accepted frameworks for cybersecurity throughout the U.S. and is also included in other countries as a contributing source, even if it is not specifically legally required. Adopting a cybersecurity framework such as NIST provides something to measure and provides useful metrics and guidelines to use for a successful cybersecurity program. NIST expanded its scope of what it defines as operational technology (OT) in September 2023 in the document NIST SP 800-82 Rev. 3 to explicitly list physical access control systems (PACS) among the items that require attention to properly secure them under this guideline.  

With the addition of security systems in the NIST definition of an OT network, this further enhances our responsibility and liability as security integrators and installers to do the right thing and lead customers and clients down the path of a secure and compliant system. So, what exactly does this mean for the security industry? This inclusion into what has historically been an IT-only framework provides every party involved in the process for a PACS system — and by extension video management systems (VMS), as well as sensors such as radars, perimeter detection solutions, gunshot detection systems, and safety systems that may integrate or contribute to the functionality of PACS systems — with documentation to assist with the process of deploying a cybersecure solution. As an industry, many times there is interest in cybersecurity compliance, but when there are added costs and often project delays, this is one of the first items in the scope of work to be removed or rescheduled for “later.”   

The NIST SP 800-82 Rev. 3 document is a helpful starting point to start on solid footing with a new project, even listing out how to make the business case justifications for including cybersecurity in the project. 

Another welcome inclusion in this standard is the Industrial Internet of Things (IIoT), which are quickly becoming entrenched in security systems to provide data, function as sensors, and even for varying levels of data transmission. Often, IIoT sensors themselves are generally not incredibly cybersecure devices, mostly because they lack the authentication and compute power to effectively use methods like encryption to secure their data payload. The use of edge computing platforms to route IIoT data through authenticated edge gateways so traffic is encrypted is allowing this data to become secured for transport and usage and should be a consideration when using IIoT devices and systems within a PACS or VMS solution. As they say, “a chain is only as strong as its weakest link,” so it’s important to only let secure systems interact with a PACS or VMS system.  IIoT is becoming an important piece of a converged solution, so don’t let it be the weak link. 

This brings us to the key point: cybersecurity is not optional. No company wants to be highlighted on the news or social media for being the one with weak or complacent policies to allow a cybersecurity attack or pay substantial fines (or ransom in outlying cases) when there is a successful attack or compliance issue. The reputational or financial hit from even a minor breach is something that many companies or individuals will never recover from.  

There are some clear steps we can all take to be as compliant as possible with our own employers as well as our customers. These steps include educating ourselves and customers about the solutions we are providing and where the potential vulnerabilities are present. Spoiler alert: it’s usually the people that are the biggest vulnerability. Continuing education is also critical to ensure that personnel are updating their skill sets and becoming more cyber-aware of current threats. Another step is to form a cybersecurity team within your organization, even if your team consists of only a few people. It’s important to have like-minded individuals to discuss requirements and outcomes with. The actual deployment itself can be improved through following industry and manufacturer best practices, and if you are collaborating with vendors and manufacturers that don’t publish their best practices, it may be time to find alternatives who do. Sustainment is the final piece of the equation. Firmware updates, password management, continuing education and awareness, as well as running vulnerability scans on an ongoing basis, can contribute to the overall security of a solution. 

KEYWORDS: cybersecurity NIST

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Andrew chisholm

Andrew Chisholm is director, engineering at Paladin Technologies. Chisholm has more than 26 years of experience, specializing in IP-based system integration and database conversion. Day-to-day, Chisholm is involved in all major decisions related to the engineering department and aides in aligning the departmental goals with that of the entire company.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    Exclusives
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Exclusives
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Exclusives
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • Aiphone

    Go Above & Beyond for Effective Emergency Communication/Notification

    See More
  • Beyond the IoT Hype: A Primer for Security Dealers

    See More
  • KP_KA_ChooseAlert

    Beyond the Basics of Emergency & Mass Notification

    See More

Related Products

See More Products
  • effective.jpg

    Effective Physical Security, 5th Edition

  • 9780128147948.jpg

    Effective Security Management 7th Edition

  • school safety.jpg

    The Handbook for School Safety and Security

See More Products

Events

View AllSubmit An Event
  • April 29, 2026

    Beyond the Fire Panel: How the Right Resources and Support Drive Success

    ON DEMAND: Success in fire alarm projects doesn’t come from great technology alone, it comes from having the right support at every step. Learn how dealers and integrators can deliver smoother installations and stronger customer experiences.
View AllSubmit An Event
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing