onathon Squires, Head of Product Strategy at Synectics, explains why surveillance has become a critical dependency in city operations – and why its cyber resilience demands far greater attention.
J
City infrastructure is now defined by connectivity. And increasingly, by its ability to remain secure and operational under cyber threat.
Across transport networks, public spaces, civic estates and utilities, systems are increasingly integrated. Data moves constantly, decisions are made in real time, and operational teams depend on accurate, immediate insight to maintain safety and service continuity.
At the centre of all this sits surveillance. Its role has expanded significantly. It is no longer confined to evidential recording; it is now a live, operational system underpinning real-time decision-making.
A fully integrated security and surveillance system verifies alarms, provides context to unfolding incidents and enables coordinated responses across multiple services and between different stakeholders. In transport environments, this can include validating trackside or station incidents in real time. In policing and publicly accessible locations, it underpins situational awareness and coordinated response. Within utilities and grid infrastructure, it provides visibility across geographically dispersed and often unmanned assets.
This shift has elevated both its importance and exposure. As a result, expectations are changing – not just around how systems perform, but how securely they are designed, deployed and managed over time.
From a resilience perspective, security and surveillance systems should receive the same level of focus as any other mission- critical digital system. And that starts with understanding what good looks like.
Enforce security by design at every step
In practice, vulnerabilities rarely appear overnight. They emerge gradually through the way systems are configured and managed over time.
Devices are added, integrations evolve and access requirements shift. In this reality, small inconsistencies begin to accumulate. Default credentials remain in place, permissions extend beyond their original
Rethinking
scope, and temporary fixes become permanent features.
The impact of configuration drift is a material risk. This is where secure-by- design principles become critical. Security and surveillance systems should not depend on perfect user behaviour to remain secure. They should be engineered to reduce the likelihood of error in the first place, with controls that guide users towards best practice and surface deviations early.
In practice, that means enforcing strong password policies at setup, preventing the reuse of default credentials, and requiring role-based access to be defined before systems can be used. It means built-in prompts that flag excessive permissions, alert administrators to dormant accounts, and highlight when devices fall behind on firmware updates.
Without this, exposure is not a possibility. It is an inevitability at scale.
Ensure every device on your network can be trusted
As already highlighted, modern surveillance environments extend well beyond a single platform. Cameras, servers, operator workstations and third-party systems all interact within the same ecosystem. In city deployments, this often spans multiple sites, technologies and suppliers.
15 © CITY SECURITY MAGAZINE – SUMMER 2026
In such a highly connected setting, device authentication is crucial. A compromised device within a transport system or energy network can have cascading operational impacts beyond the immediate site.
Each connected device should be uniquely identified and authenticated before it can operate within the system, typically through certificate-based authentication or secure provisioning processes that prevent unauthorised devices from joining the network.
Restrict access to reduce unnecessary exposure
City security and surveillance systems are accessed by a wide range of users, including control room operators, external contractors, and partner agencies. This makes precision in access authorisation and control essential. In policing and public space operations, where multiple agencies may require controlled access to the same system, this becomes especially important to ensure both operational effectiveness and governance.
Permissions that extend beyond what is operationally necessary introduce avoidable risk, often through routine use rather than deliberate misuse.
Effective systems tightly align access with defined roles (often referred to as RBAC, or role-based access control), making it easier to enforce least-privilege principles
www.citysecuritymagazine.com
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36