News Security Technology

Is Your Business Prepared For Converged Security Future?

Cybersecurity breach
With physical and cybersecurity increasingly converging, IT now plays a critical and central role in integrating these systems

Like many sectors, surveillance is undergoing a profound transformation. In the past, security was static and passive. Fast-forward to today, and digital technologies have made surveillance systems smarter, while the cloud, IoT, and AI have swung the pendulum even further toward agile and responsive solutions. This evolution allows IT to detect patterns, identify anomalies, and even anticipate potential threats before they escalate.

With physical and cybersecurity increasingly converging, IT now plays a critical and central role in integrating these systems. The shift from traditional, passive surveillance to AI-driven, intelligent systems is fundamentally changing how organisations approach security. A major challenge for many businesses today, as noted by Kiean Khoo, Asia Business Head at Milestone Systems, is the siloed nature of physical security and cybersecurity operations. Historically, these areas have been managed independently, with physical security focused on access control and monitoring, while cybersecurity operations addressed data and network protection.

However, as Khoo points out, in an increasingly interconnected world, this separation can create significant vulnerabilities. Physical security systems, like surveillance cameras and alarms, rely on networks to transmit and store data. If these systems aren’t integrated into the broader cybersecurity strategy, they can become easy entry points for cyberattacks. For example, a vulnerability in a surveillance system could be exploited as a gateway to compromise an entire corporate network.

Video surveillance cameras, which can be viewed as part of an enterprise’s IoT roster, are now prime targets for cybercriminals. The 2016 Mirai attack serves as a stark reminder of this risk. In one of the largest DDoS (distributed denial of service) attacks to date, hackers hijacked over 100,000 devices—including security cameras—to form a botnet. The devices, infected with the Mirai malware, exploited weak or default passwords to gain control, secretly flooding high-profile websites like Amazon and Twitter with traffic. As Khoo notes, this incident underscores how vulnerabilities in physical security systems can lead to major cyber breaches, highlighting the critical need for organisations to adopt integrated, proactive security strategies. While there have been few public IoT-based incidents of this scale since, the Mirai attack serves as a case study from which organisations can always draw reference.

On-premise, cloud, or a hybrid approach?

Today, video surveillance no longer operates in a silo. As physical security systems become connected to enterprise networks, they increasingly converge with cybersecurity. This means that organisations must think of surveillance not just in terms of physical protection, but also in the context of securing data and digital infrastructure. As Khoo explains, an IP camera connected to a company network could become a potential cyber vulnerability if not appropriately protected. In this layered security approach, physical access points and digital threats are managed together to provide a more comprehensive and resilient defence.

When it comes to the difference between on-premise and cloud surveillance, the distinction lies in how and where footage is stored and accessed.

On-premise surveillance systems store video footage locally, typically on internal servers. This gives organisations direct control over their data, which may be preferable for companies with strict compliance or data sovereignty requirements.

Cloud surveillance, on the other hand, stores footage on remote servers managed by third-party providers. This allows for greater scalability, real-time access from any location, and lower upfront infrastructure costs.

Deciding between the two doesn’t have to be an either/or decision. According to Khoo, businesses don’t necessarily have to choose between on-prem and cloud-based systems. Many are now adopting hybrid surveillance models that combine the control of on-prem storage with the flexibility of the cloud. This approach allows for a gradual migration to new infrastructure while maintaining existing physical assets, which is ideal for organisations balancing operational continuity with innovation. Ultimately, the right strategy depends on a business’s specific needs, such as scalability, budget, data sensitivity, and regulatory obligations. What’s critical, Khoo says, is recognising that surveillance today must be considered part of an integrated security strategy that spans both physical and cyber domains.

Overcoming the hurdles to converged security

While a converged approach is vital, many organisations have yet to make the adjustment. One of the biggest hurdles, according to Khoo, is organisational silos. Physical and cybersecurity have traditionally been managed by separate teams with different priorities, budgets, and systems. This separation creates gaps in both visibility and response, especially during a crisis where coordination is critical.

Another challenge is legacy infrastructure. Many organisations still operate outdated surveillance systems that aren’t designed to integrate with modern IT environments. Retrofitting these systems while ensuring business continuity requires careful planning and investment.

There’s also the issue of skills and mindset. Developing a converged strategy demands cross-functional expertise—security professionals who understand IT, and IT leaders who appreciate physical risks. Building that shared language and capability takes time. Lastly, business continuity during crises depends on real-time data and fast decision-making. A converged security approach enables exactly that: linking access control, video, and digital threat detection into a single, actionable view. But to get there, organisations need a clear roadmap, executive buy-in, and interoperable platforms that do not lock them into a single vendor. Khoo believes that open-platform video technology plays a central role in this journey, as it ensures businesses have the flexibility required to evolve their security strategy while maintaining resilience and operational continuity.

IT director’s critical role

A converged security strategy is critical to business transformation, as Khoo explains. By integrating physical and cybersecurity, organisations can ensure a unified response to threats, making it easier to share threat information across teams in real-time. This collaboration enhances situational awareness and allows for quicker decision-making, reducing the risk of disruptions.

IT directors and managers must understand the convergence of physical and cybersecurity, especially in industries such as finance, healthcare, and critical infrastructure. As digital transformation accelerates, IT teams are best positioned to understand network architecture, access control, device vulnerabilities, and data protection. While IT should lead the technical integration of a converged security strategy, successful implementation requires collaboration across departments. It must be a cross-functional effort to align technology with business needs.

Industries that rely heavily on both physical security and data protection, like retail, logistics, and healthcare, are best placed to benefit from this convergence. These sectors often deal with high volumes of sensitive data and assets that require protection from both physical and cyber threats.

Best practices for a proactive stance

The primary goal of any security strategy should be to protect people, assets, data, and operations while ensuring business continuity. A proactive security stance is essential; it allows businesses to identify and address threats before they escalate, reducing the potential for costly breaches and downtime. As Khoo notes, a reactive approach, on the other hand, leaves organisations vulnerable and unprepared for emerging threats.

To successfully implement a converged security strategy, start by ensuring seamless integration between physical and cybersecurity systems. This requires the right technology, such as AI-powered surveillance and cloud solutions that can effectively bridge both domains. Khoo highlights that the rapid adoption of AI is a game-changer, enabling the predictive identification of potential security threats before they escalate. For example, AI can detect anomalies in surveillance footage, such as unusual behaviour patterns, allowing security teams to take proactive action rather than reacting in the aftermath.

On the ground level, Khoo emphasizes that collaboration between IT, physical security, and executive leadership teams is crucial for alignment and effective communication. Regular training and shared threat intelligence will enhance the overall effectiveness of the strategy. Lastly, constantly assessing and updating security systems to adapt to emerging threats is vital. A flexible, scalable approach will ensure an organisation stays resilient and secure in a rapidly changing environment.

Leave a Reply

Your email address will not be published. Required fields are marked *