Jobsites are filling up with connected devices: security cameras, time-lapse cameras, equipment trackers, environmental sensors, smart locks, drones, and telematics units on trucks and machinery. Each one improves visibility or productivity. Each one is also a small computer on your network, frequently running outdated software and shipped with weak default settings.
Attackers know this. Internet-connected cameras and devices have long been targets, and security agencies have repeatedly warned about default passwords and exposed devices. The good news is that a few disciplined habits dramatically reduce the risk.
The common problems
- Default or weak passwords left unchanged after installation.
- Exposed management interfaces, sometimes opened to the internet through port forwarding so someone can view cameras remotely.
- Old firmware that never gets updated.
- No inventory, so devices installed by a subcontractor or vendor are forgotten.
- Flat networks where a compromised camera can reach company laptops and servers.
- Vendor cloud accounts with shared logins or accounts tied to a former employee's email.
Step 1: Keep an inventory
For every connected device, record the type, make and model, location, project, owner, how it connects, and who has access to its management account. Include devices that vendors install. Ask equipment suppliers and security vendors to identify what they have placed on your network.
Step 2: Change defaults before deployment
Before a device goes to the field, change the factory password to a unique one, disable unused services, and set the time and logging. Store credentials in a password manager rather than a shared spreadsheet or the side of the box. Where the device supports it, use individual accounts instead of a single admin login.
Step 3: Isolate connected devices
Place IoT devices on their own network segment, separate from staff laptops and servers. Restrict what that segment can reach. Cameras may need to talk to a recorder or a cloud service, but they do not need to access accounting files. Many business-grade routers make this a simple configuration, and it is one of the highest-value steps you can take.
Step 4: Avoid open ports to the internet
Never expose a camera or device interface directly with port forwarding. For remote viewing, use the vendor's secure cloud platform with multi-factor authentication where available, or connect through a managed VPN. If you can find a device through an internet-wide search tool, so can attackers.
Step 5: Update and retire
Establish a basic update routine. Check firmware at deployment and at least a couple of times a year. Subscribe to the vendor's security notices. If a device is no longer supported, plan to replace it, and in the meantime keep it isolated.
Step 6: Secure the cloud side
Many devices are managed through vendor web portals or mobile apps. Treat these as business accounts.
- Use company email addresses, not personal ones.
- Enable multi-factor authentication.
- Limit administrators and review the user list.
- Remove people who leave the company or project.
- Review sharing links and guest access, such as live camera views shared with owners.
Step 7: Consider privacy and legal issues
Cameras capture workers, visitors, and neighboring properties. Post required notices, restrict who can view footage, and define retention periods. Consult counsel about local requirements, particularly if cameras record audio. Footage may be evidence in an incident or claim, so protect its integrity and know how to export it.
Step 8: Plan for theft and tampering
Devices in the field get stolen or damaged. Use tamper-resistant mounts, record serial numbers, and make sure a stolen device cannot be used to reach your network. For devices with stored credentials or network keys, be ready to change them if a unit goes missing.
Vendor and subcontractor devices
Subcontractors may bring their own telematics, cameras, or laptops. Set expectations: they use the guest network, not the company network, unless approved. Ask security and equipment vendors how their devices are managed and who can access them remotely.
A practical checklist
- Inventory every connected device and its owner.
- Change defaults and use unique credentials.
- Place devices on an isolated network.
- Remove port forwarding and use secure remote access.
- Update firmware on a schedule.
- Protect vendor cloud accounts with MFA.
- Define footage access and retention.
- Decommission devices and accounts when the project ends.
Working with Ironfield Cyber
Ironfield Cyber helps contractors and energy companies inventory and secure field devices, design isolated networks, and manage remote viewing safely. If cameras were installed by several vendors across your sites, we can help you find and fix the weak spots.