Securing IP cameras and building management systems under NIS2

IP cameras and building management systems are in NIS2 scope but cannot run agents. See how inline isolation secures them without disrupting operations.
IT and facilities staff reviewing IP camera and building management system security in a European office.

Your IP cameras, HVAC controllers and door access systems sit on the same network as your laptops, and most of them cannot run a single line of security software. Under NIS2 and Belgium’s CyberFundamentals framework, those agentless devices are now in scope, and the deadline to demonstrate a baseline has already come and gone.

This guide is for IT and facilities managers in the mid-market who need to bring building systems under control without ripping out infrastructure or halting operations. It covers why these devices fall under the directive, where the real risk sits, and why network-level isolation, not endpoint software, is the only method that works on hardware that was never built to be secured.

Are building management systems and IP cameras covered by NIS2?

Yes. NIS2 requires organisations to secure all network and information systems that support essential or important services, and building automation connected to the corporate network falls inside that scope. That includes HVAC, smart lighting, physical access control and IP cameras. In Belgium, the CyberFundamentals (CyFun) framework operationalises this, and the deadline to demonstrate the baseline level passed on 18 April 2026.

The practical effect is that a camera or a building controller is no longer “just facilities kit”. If it shares a network with systems that matter to your operation, it is part of your compliance perimeter. Auditors expect you to show that access to these devices is controlled, logged and segmented.

That creates an awkward situation for most mid-market teams. The devices in question are usually managed by external installers or a facilities department, not IT. The governance gap is real, and NIS2 does not care whose budget the camera came out of.

Why are building management systems such an attractive target?

Building systems are attractive because they are widely exposed, rarely patched and almost never monitored. According to Claroty’s State of CPS Security report (October 2025), 75% of organisations have building management system devices on their network that carry known exploited vulnerabilities. That is not a theoretical weakness. It is a live, catalogued flaw sitting on the corporate network.

The Claroty Team82 research goes further, though these figures come from a single source and should be read as such. It reports that 69% of organisations run BMS devices with vulnerabilities that have been used in confirmed ransomware attacks, and that 51% manage BMS devices that both carry known exploited vulnerabilities and are connected directly to the internet.

Building equipment also tends to speak legacy protocols. BACnet and Modbus were designed for reliability on a trusted network, not for a connected world, and they carry no encryption or authentication by default. A device using one of these protocols broadcasts and accepts instructions in plaintext, which means anything else on the same segment can read or manipulate that traffic.

The scale of the exposed device population is hard to overstate. IoT Analytics put the number of active, connected IoT devices worldwide at 21.1 billion at the end of 2025, a figure echoed across market analyses. Cameras, controllers and sensors make up a large slice of that, and very little of it is under active security management.

What specific vulnerabilities affect IP cameras and facility systems?

Cameras, recorders and access control units ship with firmware that is rarely updated and frequently flawed. Ordr’s IoT security analysis (late 2025) found that 55% of network video recorders contain critical vulnerabilities, with an average patch time exceeding 120 days. The same research reports that 39% of physical access control systems carry critical vulnerabilities at the firmware level, and that 52% of operational building management systems contain critical flaws rated CVSS 9 to 10. These are single-source figures, so treat them as indicative rather than settled.

Attack volume against this device class is climbing too. SonicWall’s Cyber Threat Report (early 2025), a single-vendor dataset, recorded a 124% rise in IoT malware attacks, including 17 million blocked attacks against IP cameras. Ordr separately noted a 459% jump in IoT-related attacks against the energy sector between mid-2024 and mid-2025.

The throughline is simple. These devices are easy to find, slow to fix, and increasingly worth attacking. A camera is not just a camera. It is an internet-connected computer with a weak operating system and a permanent place on your network.

How do attackers use cameras and BMS to reach the IT network?

Attackers rarely want the camera itself. They want what the camera is connected to. An unsecured IP camera or building controller is a foothold, a quiet entry point that lets an intruder move sideways toward the systems that hold data or run the business.

The mechanism is lateral movement. If a compromised camera sits on the same VLAN as a workstation, and there is no internal segmentation between them, an attacker who owns the camera can probe and pivot toward that workstation, and from there toward file shares, identity systems or domain controllers. A perimeter firewall at the edge of the building does nothing to stop this, because the malicious traffic never crosses the perimeter. It moves laterally, inside.

This is the blind spot most compliance advice misses. Putting a gateway at the building’s edge feels like a control, but it leaves the interior flat and open. The threat is not only outside-in. It is device-to-device, within the same local network.

Why does traditional endpoint security fail on these devices?

Endpoint detection and response depends on installing an agent, a piece of software that runs on the device and reports back. Cameras and BMS controllers cannot host one. They run minimal, proprietary or outdated operating systems with no capacity to load third-party security software. The agent model, which underpins most modern endpoint protection, simply has no surface to attach to here.

That makes these devices invisible to the tools most organisations already own. A vulnerability scanner that relies on agents will not see an agentless camera at all, and an aggressive network scan can be worse than useless. Older controllers run fragile IP stacks, and active scanning can crash or freeze them, taking out a critical building function in the process.

So the standard playbook breaks down twice. You cannot install protection on the device, and you cannot safely interrogate it with the usual scanning tools. Something else has to carry the load.

Recent botnet activity shows what unsecured devices enable

Compromised cameras and IoT devices are recruited at scale into botnets used for large DDoS attacks. Cloudflare’s DDoS threat report recorded a record IoT-botnet attack of 29.7 Tbps in the third quarter of 2025. That kind of firepower is assembled from millions of small, unsecured devices, many of them exactly the cameras and controllers sitting in commercial buildings.

State-linked activity is part of the same picture. Researchers have flagged China-linked botnet operations that exploit weaknesses in cameras and routers to scan and probe critical infrastructure. The specifics of the most recent campaigns are still being confirmed, so the point to hold onto is the pattern rather than any single headline figure: weak edge devices are valuable to attackers, at nation-state scale.

The lesson for a mid-market organisation is not that you will be the target of a record DDoS attack. It is that your unsecured devices are useful enough to be worth conscripting, which tells you exactly how exposed they are.

Why agentless devices need a hardware IT-OT bridge

Because software cannot live on these devices, the security control has to sit next to them on the network instead. An inline IT-OT bridge is placed physically between the device and the rest of the infrastructure, and it enforces strict communication rules from the outside. The device is not modified. Its reachable destinations are.

This is the role of NIAC hardware from platforms like Jimber. The appliance sits inline between an unmanaged device and the switch, and it allows that device to talk only to explicitly authorised destinations. Everything else is denied by default. A camera that should only reach its recorder can be confined to exactly that path, so a compromise of the camera cannot translate into a walk across the network.

The distinction from a perimeter approach matters here. Edge-focused enterprise platforms, including Cato Networks, concentrate on securing the boundary of a site. They are not designed to stop a compromised camera from communicating laterally with a workstation on the same local subnet. Jimber NIAC operates at the local network layer, enforcing per-device rules at the point where lateral movement would otherwise begin. For agentless building systems, that placement is the whole point.

Because NIAC handles both TCP and UDP traffic, it covers the protocols these systems actually use, including BACnet for building controllers. The legacy device keeps running exactly as before. Only the traffic it can send and receive changes.

How inline isolation simplifies your CyFun audit

For a small IT team, the hardest part of a NIS2 audit is often the evidence, not the controls. Demonstrating that access is segmented, logged and governed across dozens of building devices is slow, manual work when each system lives in its own silo. Consolidating network access, firewall policy and device management into one console changes that.

When NIAC isolation, ZTNA access rules, FWaaS policy and SD-WAN connectivity are managed from a single interface, the audit trail comes from one place. You can export logs and network maps that show exactly which device can reach what, and that documentation maps directly onto the evidence a CyFun assessor asks for. The compliance work shrinks from a scavenger hunt into a report.

Two further points make this practical for European mid-market teams specifically. As a Belgian provider, Jimber processes and hosts network and telemetry data inside the EU, which keeps GDPR and NIS2 evidence under European jurisdiction rather than routed through a US platform. And its pricing is per user without bandwidth surcharges, which is the kind of predictable model a partner or an MSP can actually plan around.

Honest limitations you should weigh

Inline hardware is not free, and it is not instant. Installing physical NIAC appliances across local switches means an upfront hardware investment and on-site configuration. A software-only product looks cheaper and faster on day one. The catch is that software-only perimeter tools leave agentless devices unprotected, because those devices cannot run the agent the software depends on, and a perimeter does nothing about lateral movement inside the VLAN. The physical network layer is the only place isolation can actually be enforced for this device class.

Misconfiguration is a genuine risk worth naming. Strict segmentation, applied carelessly, can block legitimate traffic and disrupt something like HVAC or fire safety. The mitigation is a phased rollout. The hardware first runs in a passive monitor mode that only maps traffic to establish a safe baseline, and active enforcement is switched on only after those communication patterns are verified.

That phased approach is also why this method takes longer to activate than active scanning. Passive monitoring needs time to discover and map every device. Active scanning is faster, but it carries the crash risk that fragile building controllers cannot tolerate. For legacy infrastructure, the slower, non-intrusive route is the only safe one, and it is the route that gets you to NIS2 compliance without taking a building function offline.

Frequently asked questions

How does NIS2 bring unmanaged devices under legal obligation?

Article 21 of the directive requires organisations to take appropriate risk management measures across their physical and digital environments. Because building management systems and CCTV are connected to the corporate network, they fall inside the scope of those mandatory security measures.

What is the supply chain risk from external facilities installers under NIS2?

External maintenance providers often keep permanent VPN connections or shared passwords to service BMS and HVAC equipment. These unmonitored access paths are a supply chain risk, which NIS2 expects organisations to assess, control and limit rather than leave standing.

Why is active network scanning dangerous for building automation?

Active scanners send aggressive packets to identify systems. Older building controllers and industrial devices have fragile IP stacks and can crash or hang under that load, which can take a critical building function offline. Passive monitoring avoids this by observing traffic rather than probing it.

How does Jimber NIAC protect legacy protocols like BACnet?

Legacy protocols send data unencrypted. The NIAC hardware acts as an inline isolation layer at the physical port, confining that traffic to authorised destinations so unauthorised devices or attackers on the network cannot intercept or manipulate it.

What penalties apply for missing the Belgian CyFun deadlines?

Under the Belgian law of 26 April 2024, organisations that fail to meet their NIS2 obligations face administrative fines of up to €10 million or 2% of global annual turnover, and board members can be held personally liable.

Ready to bring your cameras and building systems under Zero Trust without taking operations offline? Book a demo and see how inline isolation can be rolled out in phases, mapped to your CyFun evidence, and managed from a single console.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed