Blog guideEducational content, not a workshop description

Cybersecurity and continuity

Business security cameras: a planning and installation guide

Planning security cameras for a business is not about filling a cart with a kit. A useful decision begins with the event to observe, continues through scene, network, recording and access, and ends with privacy, ownership, testing and maintenance.

A team plans cameras, coverage zones, network and storage over a business floor plan

What the plan should be able to prove

  • Every camera has a purpose, an approved scene and a testable level of detail.
  • Recording, storage and network capacity are designed together and verified under real conditions.
  • Individual accounts, updates and minimum exposure protect a system that can itself become a risk.
  • The organization defines notices, access, retention, export and deletion before the first incident.

1. Begin with the event and response, not the camera

Describe the problem as an observable event: someone enters after hours, an item moves from inventory, a vehicle crosses a gate or reception activity must be reconstructed. Then define which decision someone would make after seeing it. “Having security” does not reveal where to look, which detail to retain or who responds; a concrete hypothesis can be designed and tested.

Record the purpose, zone, operating period, owner and available response time. Ask whether lighting, access control, inventory, a physical barrier or a procedure can reduce the risk with less image processing. A camera should complement other controls rather than become the only response to an operational problem.

  • Event that must be detected or reconstructed.
  • Person, object or context that needs to be distinguished.
  • Zone and period authorized for observation.
  • Action, owner and channel when an alert or incident appears.
  • Criterion used to accept or reject the installed scene.

If nobody knows what to do with an alert or recording, the operational requirement is not yet complete.

2. Design useful scenes and limit what should not be captured

Walk the site at relevant times. Measure distance, height, width, obstacles, movement, backlight, reflections, rain, dust and nighttime changes. A wide view may show that something occurred without providing the necessary detail. Separate context, observation and detail scenes instead of deciding from megapixels alone.

Draw coverage on a floor plan and review every frame edge. Avoid washrooms, changing areas, break spaces, neighbouring windows, keyboards, clinical screens or any capture disproportionate to the purpose. If a device includes a microphone, analytics, recognition or tracking, treat each function as a separate decision: availability does not make it necessary or appropriate.

  • Day and night reference image for every scene.
  • Documented height, angle, lens and field of view.
  • Test with people or objects at representative distances.
  • Masks or framing adjustments for unjustified areas.
  • Review of additional functions before enabling them.

3. Decide the architecture before mixing cameras, recorder and cloud

A system may record at the camera, a local NVR, a management server, the cloud or a combination. Compare what happens when internet, power, storage, recorder or subscription fails. Define who administers each account, which export exists, how a component is replaced and whether recordings can be retrieved without one application or provider.

Compatibility must be proved by model and function. ONVIF publishes profiles that group mandatory and conditional features for conformant products; a generic “ONVIF compatible” claim does not show that a camera and client share the profile and functions the project requires. Keep the exact model, version, licence and tested-feature inventory.

  • Local, central, cloud or hybrid recording and behavior without internet.
  • Required compatibility for video, events, audio, analytics and export.
  • Ownership of accounts, licences, data and recovery keys.
  • Replacement route when support ends or a component fails.
  • Format and player needed to deliver usable evidence.

Interoperability is a function test between concrete products, not a word printed on two boxes.

4. Size network, power and storage as one system

Estimate throughput for each camera from the intended configuration rather than nominal resolution alone. Compression, frame rate, scene complexity, continuous or event recording and secondary streams change consumption and retention. Add headroom for peaks, growth and protocol overhead, then verify ports, links, recorder and concurrent viewing under load.

For storage, multiply aggregate throughput by recording time and add capacity reserved by the system, redundancy and operating headroom. A calculator provides an expectation, not a guarantee; real activity varies. Verify achieved days after installation and document which settings alter retention. For PoE systems, review power budget, distance, protection, ventilation and backup too.

  • Expected and maximum throughput per camera and link.
  • Recorder usable capacity and target retention days.
  • PoE budget, UPS and behavior during interruption.
  • Network segment, addressing, DNS and reliable time.
  • Headroom for growth, updates and authorized remote review.

5. Protect cameras and recorders as connected systems

Change initial credentials, use individual accounts and limit privileges by role. Enable additional authentication where the platform offers it, document recovery and remove access when an employment or vendor relationship ends. Keep firmware, applications and recorders on supported versions; a forgotten camera remains a networked device carrying video and sometimes audio.

Separate cameras from workstations and servers where infrastructure allows it. Reduce enabled services and avoid publishing administrative interfaces directly through port forwarding or UPnP. The FTC and NCSC recommend changing default passwords, maintaining software, using available encrypted connections and disabling unneeded remote access. Record who accesses the system, from where and which administrative changes occur.

  • Inventory of address, model, serial, version and owner.
  • Unique passwords, minimum roles and available second factor.
  • Separate network, firewall and administration without direct exposure.
  • Update schedule and known support-end date.
  • Logs, alerts and procedure for a compromised account or camera.

A camera protecting one entrance can open another if it retains factory credentials or an internet-exposed console.

6. Define purpose, transparency and custody in Panama

Panama’s ANTAI explains that surveillance images may be personal data and that processing should comply with Law 81 of 2019 and Executive Decree 285 of 2021. Cited principles include lawfulness, purpose, proportionality, data security, transparency and confidentiality. The responsible organization therefore needs to know why it records, which zones it covers, who accesses data, how long it retains it and how applicable rights are handled.

In its frequently asked questions, ANTAI recommends visible notices at entrances to monitored areas containing the responsible party and contact details, purpose, rights and access to the relevant policy, plus a more detailed document covering access, retention and custody protocols. The authority has also warned against arbitrary disclosure and recommended impact assessments. Employment, residential, healthcare or public contexts may add requirements, so validate the use case with qualified advice.

  • Documented purpose and applicable basis before recording.
  • Map of zones, affected people and captures to avoid.
  • Accessible notices and policy with responsible party and contact channel.
  • Defined retention, deletion, requests and release to authorities.
  • Agreement and controls for vendors with access or storage.

This guide supports technical and operational preparation; it does not replace legal assessment of the specific use.

7. Accept the installation through reproducible tests

Test every scene in representative conditions: bright light, night, open doors, walking people and expected movement. Confirm date, timezone and synchronization; a recording with the wrong time complicates searches and correlation with other events. Simulate internet loss and, where in scope, a power interruption to observe what continues and how service returns.

Find a known interval, play it, export it and open the file on another authorized device. Verify accounts, mobile application, alerts and permissions without using an administrator password for daily tasks. Handover should include inventory, plan, ports, addressing, versions, capacity, observed retention, owners, credentials through a secure channel and backup or restoration procedure.

  • Scene list with acceptance image and known limitations.
  • Timed search and export performed by an operator.
  • Playback of the exported file with identifiable date and camera.
  • Role-based access test and revocation of an example account.
  • Repeatable documentation and training without installer dependence.

8. Keep evidence available before it is needed

Schedule checks of cleanliness, focus, framing, time, recording, drive health, alerts, firmware, users and capacity. A camera may appear online while pointing elsewhere, carrying a dirty lens or no longer saving the primary stream. Perform periodic test exports and compare actual retention days with the approved target.

Define an incident procedure: who preserves the interval, how overwrite is prevented, who authorizes a copy, which custody record is retained and who may receive it. If an account, platform or device is compromised, isolate it according to plan, preserve logs, change credentials and assess notification duties. Retiring a camera also means revoking accounts and deleting or retaining data according to the applicable process.

  • Visual and recording inspection at a defined frequency.
  • Drive health, capacity and alerts reviewed.
  • Reconciled users, vendors and authorized devices.
  • Test export and escalation contact available.
  • Secure retirement of devices, accounts, media and cloud services.

Frequently asked questions

Questions that should be settled before acting

Do more megapixels always produce better evidence?

No. Detail also depends on lens, distance, angle, light, movement, compression, focus and pixel density on the target. Test the scene against the concrete task.

Is a local NVR or cloud storage better?

It depends on connectivity, retention, continuity, cost, access, export and risk. A hybrid design may address some failures but adds dependencies. Compare what happens without internet, without power and after ending a subscription.

Should cameras record only on motion?

It may reduce storage, but poor detection can omit the beginning or entire event. Test sensitivity, zones, pre-record, post-record and night conditions; keep continuous recording where risk justifies it.

How long should images be retained?

There is no universal technical number. The organization should justify the period against purpose, risk, obligations and capacity, then configure coherent deletion. Seek qualified advice for a legal decision in Panama.

What should the installer hand over?

At minimum: inventory, plan, models, network, relevant configuration, users, licences, observed retention, tests, export procedure, warranty, maintenance and ownership of accounts and data according to the contract.

Sources and further reading