Cameras, Sensors and IoT on Jobsites: Securing Connected Devices

Jobsite cameras, trackers and sensors often ship with weak defaults. Learn how to inventory, isolate and maintain connected devices so they are not a way in.

3 min readBy Ironfield Cyber Team

Jobsites are filling up with connected devices: security cameras, time-lapse cameras, equipment trackers, environmental sensors, smart locks, drones, and telematics units on trucks and machinery. Each one improves visibility or productivity. Each one is also a small computer on your network, frequently running outdated software and shipped with weak default settings.

Attackers know this. Internet-connected cameras and devices have long been targets, and security agencies have repeatedly warned about default passwords and exposed devices. The good news is that a few disciplined habits dramatically reduce the risk.

The common problems

  • Default or weak passwords left unchanged after installation.
  • Exposed management interfaces, sometimes opened to the internet through port forwarding so someone can view cameras remotely.
  • Old firmware that never gets updated.
  • No inventory, so devices installed by a subcontractor or vendor are forgotten.
  • Flat networks where a compromised camera can reach company laptops and servers.
  • Vendor cloud accounts with shared logins or accounts tied to a former employee's email.

Step 1: Keep an inventory

For every connected device, record the type, make and model, location, project, owner, how it connects, and who has access to its management account. Include devices that vendors install. Ask equipment suppliers and security vendors to identify what they have placed on your network.

Step 2: Change defaults before deployment

Before a device goes to the field, change the factory password to a unique one, disable unused services, and set the time and logging. Store credentials in a password manager rather than a shared spreadsheet or the side of the box. Where the device supports it, use individual accounts instead of a single admin login.

Step 3: Isolate connected devices

Place IoT devices on their own network segment, separate from staff laptops and servers. Restrict what that segment can reach. Cameras may need to talk to a recorder or a cloud service, but they do not need to access accounting files. Many business-grade routers make this a simple configuration, and it is one of the highest-value steps you can take.

Step 4: Avoid open ports to the internet

Never expose a camera or device interface directly with port forwarding. For remote viewing, use the vendor's secure cloud platform with multi-factor authentication where available, or connect through a managed VPN. If you can find a device through an internet-wide search tool, so can attackers.

Step 5: Update and retire

Establish a basic update routine. Check firmware at deployment and at least a couple of times a year. Subscribe to the vendor's security notices. If a device is no longer supported, plan to replace it, and in the meantime keep it isolated.

Step 6: Secure the cloud side

Many devices are managed through vendor web portals or mobile apps. Treat these as business accounts.

  • Use company email addresses, not personal ones.
  • Enable multi-factor authentication.
  • Limit administrators and review the user list.
  • Remove people who leave the company or project.
  • Review sharing links and guest access, such as live camera views shared with owners.

Step 7: Consider privacy and legal issues

Cameras capture workers, visitors, and neighboring properties. Post required notices, restrict who can view footage, and define retention periods. Consult counsel about local requirements, particularly if cameras record audio. Footage may be evidence in an incident or claim, so protect its integrity and know how to export it.

Step 8: Plan for theft and tampering

Devices in the field get stolen or damaged. Use tamper-resistant mounts, record serial numbers, and make sure a stolen device cannot be used to reach your network. For devices with stored credentials or network keys, be ready to change them if a unit goes missing.

Vendor and subcontractor devices

Subcontractors may bring their own telematics, cameras, or laptops. Set expectations: they use the guest network, not the company network, unless approved. Ask security and equipment vendors how their devices are managed and who can access them remotely.

A practical checklist

  1. Inventory every connected device and its owner.
  2. Change defaults and use unique credentials.
  3. Place devices on an isolated network.
  4. Remove port forwarding and use secure remote access.
  5. Update firmware on a schedule.
  6. Protect vendor cloud accounts with MFA.
  7. Define footage access and retention.
  8. Decommission devices and accounts when the project ends.

Working with Ironfield Cyber

Ironfield Cyber helps contractors and energy companies inventory and secure field devices, design isolated networks, and manage remote viewing safely. If cameras were installed by several vendors across your sites, we can help you find and fix the weak spots.