Security1 distinct publisher3 min readPublished
A Hikvision Europe security director says camera estates routinely outlive the firms that installed them. The privileged-access gap that leaves is a records problem no device setting closes.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The shape of this failure is familiar from privileged access work. A commissioned camera is an administrable device on a corporate network whose only credential is held by a contractor rather than an employee, and the interview is explicitly about what happens when that contractor is gone and the commissioning paperwork with them [1].
Requiring a new password at activation is better than shipping equipment with a universal default, as Janssens argues [10]. It closes the worse hole, which was a secret anyone could look up. It does not touch custody. The replacement secret exists only where the installer wrote it down, and the premise of the year-six question is that this record is lost [1]. So the control that removes a fleet-wide default converts the problem into a per-device records failure [2], and that failure is quieter: video still appears on the wall, so nothing prompts anyone to check who can authenticate.
The arithmetic is the part nobody puts in a tender document. On Janssens' own figures, a camera runs ten years while the installer may not exist in the same form after five [2], which means at least half a device's service life can run with no party holding its configuration knowledge [1]. The year-six case he is asked about still has four years of operational life left in a device that nobody in the organisation can administer [3].
Mandatory password creation, login-failure monitoring, IP filtering and controlled SSH access are all real controls [4], and all of them assume someone is reading the output and applying firmware. Janssens concedes the point himself: the controls work properly only while the device stays under the customer's ownership and is maintained [5], and no manufacturer can compensate for a camera put on the public Internet with its controls off and no patching [13]. That is the boundary. Device defaults reach as far as the device; they cannot produce an asset register or name the person entitled to reset the thing.
Which is why his position on AI is worth taking at face value even though it comes from a manufacturer's cyber security director whose interview also covers source code escrow and country-of-origin rules [14]. He says discovery and configuration checking will benefit, but declines to make AI the answer to a governance problem, putting ownership, governance and a documented recovery process first [6]. A scanner that finds an unmanaged camera has told you the easy half. It cannot tell you who is entitled to its admin account, and it will not hand you the password.
His prescription is that manufacturers should design products so customers can recover control without returning to the original installer [7]. That is a should, not a shipped feature, and the channel the interviewer describes buys on price and never returns to the kit [8].
Ranked by verification strength, evidence, and original report placement.
In a Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator that installed a camera system is gone, the commissioning documentation is lost, and nobody holds the admin credentials, framed as the situation in year six of the estate's life.
Janssens says the situation where the installer has folded and nobody holds admin credentials is more common than the industry would like to admit.
Hikvision requires mandatory password creation during activation, login-failure monitoring, IP filtering and controlled SSH access on its devices, according to Janssens.
Janssens says manufacturers should design products so that the customer can recover control without having to go back to the original installer, and that a customer unable to administer its own cameras is a lifecycle problem.
The same interview also covers source code escrow, country-of-origin rules, and what evidence vendors can and cannot offer critical infrastructure operators.
Janssens says a camera may have a ten-year operational life while the company that installed it may not exist in the same form five years later, as people move jobs, contractors change and documentation gets lost.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source vendor interview, no data
Everything in the cluster comes from one Help Net Security Q&A with one Hikvision Europe executive. The claims are internally coherent and directly quoted, and the lifecycle arithmetic (ten-year device life against roughly five-year installer continuity) follows from what is said, but there is no prevalence data, no incident or scan evidence, no third-party testing of the described controls, and no customer or integrator voice. The captured body is also truncated mid-question on escrow and country-of-origin.
No measurable adoption or deployment data
The cluster contains qualitative disclosures only: a vendor description of shipped device controls and an unattributed statement that some European buyers require escrow, binary analysis or country-of-origin restrictions. There are no device counts, customer numbers, estate sizes, contract references or dated deployments, and nothing quantifies how many estates actually lose administrative access. Adoption cannot be scored without inventing figures.
Mildly overstated prevalence, self-limiting on AI
Slightly positive rather than strongly so. The frequency claim ('more common than the industry would like to admit') and the implied protective value of the listed device controls run ahead of any evidence offered, and the speaker's employer benefits from framing surveillance risk as generic lifecycle governance. Working the other way, the item explicitly refuses the easy AI narrative, concedes that no manufacturer can offset bad network design, and concedes that its own controls only work while the estate is owned and maintained - unusual restraint that keeps the gap small.
Vendor executive in a supplier interview format
The sole speaker is a serving security director at the manufacturer whose products and process are described, and the interview reaches directly into escrow, third-party binary analysis and country-of-origin restrictions - the exact assurance and procurement pressures that bear on that manufacturer's European market access. The publisher's vendor-interview format gives the supplier unmediated framing with no opposing integrator, customer or competitor voice. Incentive to redirect attention from vendor-specific trust questions toward customer-side governance is strong, even where the underlying advice is sound.
Clear attribution, narrow base
Confidence in what was said is high: the item is a direct, quotable interview and the claim ledger maps cleanly onto it. Confidence in the underlying picture is limited by a single publisher, a single interested speaker, absent quantitative support, no adoption measurement and a truncated body. The governance argument is plausible and internally consistent, but nothing here can be triangulated.
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
security
The customer is genuine and the payment is authorized: 55% of banks say scams dominate fraud1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026