By Ryan Mueller
For years, physical security and cybersecurity operated in separate worlds.
One team worried about cameras, access control systems, and intrusion detection. The other focused on networks, passwords, firewalls, and cyber threats.
Today, those worlds have collided.
Every camera, access control panel, intercom, and sensor we install is connected to a network. That means physical security professionals are no longer just responsible for protecting doors, buildings, and assets. They are also introducing devices that can create cybersecurity risk if they are not deployed correctly.
One of the most thought-provoking sessions I attended at ISC West 2026 explored this growing challenge and delivered a simple but powerful message:
You do not need to become a cybersecurity expert. You just need to stop making the easy mistakes.
The Industry Training Gap
The session began by highlighting a reality that many in the industry have experienced firsthand.
Most physical security professionals receive extensive training on system design, camera placement, access control architecture, and installation best practices. However, very few receive meaningful training on network security, credential management, encryption, firmware management, or network segmentation.
That is not a failure of individual installers.
It is a gap in how the industry has historically trained its workforce.
As security systems become increasingly connected, that gap becomes more difficult to ignore.
Organizations are investing millions of dollars into sophisticated security technology, yet simple cybersecurity oversights can undermine those investments in a matter of minutes.
The Most Common Mistakes Are Also the Most Preventable
One of the strongest themes throughout the session was that most security breaches are not caused by highly sophisticated attacks.
They are caused by basic mistakes.
Examples discussed included:
- Leaving default credentials in place
- Using the same password across multiple devices
- Deploying unmanaged switches without IT visibility
- Failing to enable encryption
- Running outdated firmware with known vulnerabilities
- Maintaining little or no device documentation
- Installing systems on flat networks with no segmentation
None of these issues require advanced cybersecurity knowledge to fix.
They require process, accountability, and attention to detail.
That distinction is important because it removes the excuse that cybersecurity is “too technical” for physical security professionals.
Default Credentials Are Still a Problem
It is difficult to believe that default usernames and passwords remain one of the industry’s most common vulnerabilities, but they do.
Attackers routinely scan the internet looking for exposed devices that still use factory credentials. In many cases, gaining access is as simple as trying a well-known username and password combination.
What makes this particularly frustrating is that the solution is straightforward:
- Change credentials during installation
- Use unique passwords for every device
- Store credentials securely in a password manager
- Provide proper documentation during project closeout
These steps take minimal effort but dramatically reduce risk.
If IT Does Not Know About It, It Should Not Be Installed
Perhaps the most valuable takeaway from the session was the importance of building stronger relationships with IT teams.
Too often, security integrators install devices, switches, and network-connected hardware without involving the people responsible for managing the network.
The result is predictable.
IT discovers unknown devices months later. Nobody knows what they are, why they were installed, or how they are configured.
That creates operational challenges and security risks.
Instead, the speaker advocated for a simple process:
- Meet with IT before installation
- Review network requirements
- Discuss VLANs and firewall rules
- Coordinate switch and infrastructure needs
- Conduct a closeout review after installation
These conversations do not have to be complicated.
They simply need to happen.
One Compromised Device Should Not Expose Everything
Another key topic was network segmentation.
Many organizations continue to operate security devices on flat networks, meaning cameras, access control systems, servers, user devices, and other business systems all share the same environment.
When that happens, a compromised camera can become a pathway to much more critical systems.
Proper segmentation creates barriers that limit movement within the network and reduce the impact of a breach.
The concept is simple:
A camera should not become the front door to your entire organization.
Cybersecurity Is Not Just Risk Reduction—It Is a Business Opportunity
One of the more interesting discussions centered around recurring revenue opportunities for integrators.
Activities such as:
- Firmware management
- Security reviews
- Credential management
- Documentation updates
- Security audits
are often viewed as additional work.
In reality, they can become valuable services that improve customer security while creating long-term recurring revenue streams.
The organizations that embrace these services will not only provide greater value but will also differentiate themselves in an increasingly competitive market.
Documentation Matters More Than Ever
A recurring theme throughout the session was documentation.
Many organizations cannot easily answer basic questions about their security environment:
- How many cameras are installed?
- What firmware version is running?
- Who owns the credentials?
- What IP addresses are assigned?
- Where are devices physically located?
Without accurate documentation, troubleshooting becomes more difficult, upgrades become riskier, and accountability becomes unclear.
Documentation is no longer an administrative task.
It is a security requirement.
The Future Belongs to Security Professionals Who Understand Both Worlds
Physical security and cybersecurity are no longer separate conversations.
Every deployment now exists at the intersection of both disciplines.
The good news is that organizations do not need every installer to become a cybersecurity engineer. They simply need professionals who understand the importance of secure deployment practices, proper documentation, firmware management, encryption, and collaboration with IT.
Those who embrace that mindset will be better positioned to protect their customers, strengthen their reputations, and create new opportunities for growth.
Final Thoughts
The most powerful message from this session was also the simplest.
The industry does not need perfection.
It needs consistency.
Changing default passwords, enabling encryption, documenting systems, updating firmware, and communicating with IT are not groundbreaking concepts. They are foundational practices that should be part of every deployment.
As physical security continues to converge with cybersecurity, the organizations that master these fundamentals will be the ones that stand apart.
Because the strongest security system is not just the one that protects the building.
It is the one that protects the network it runs on.