Video Attack Surface Management
The practice of continuously discovering, assessing and reducing the cyber attack surface created by cameras, recorders, video-management platforms and the services they depend on.
A large organisation's video estate is frequently its least-inventoried set of networked computers. The devices are bought on a capital budget, installed by a contractor, commissioned once, and then run for a decade. They hold credentials, they speak several protocols, many of them reach outbound to a vendor cloud, and almost none of them appear in the asset register that the security team actually uses.
Video ASM names the gap and gives it a shape: six stages, a maturity ladder, and a set of questions that can be answered with evidence rather than assertion. It is written to be argued with. Where the framework asserts something we cannot support, it says so.
Start here
What Video ASM is
The definition, its boundaries, and what it deliberately excludes.
The framework
Discover, identify, assess, prioritise, remediate, monitor โ with the artefact each stage is supposed to produce.
The maturity model
Six levels, each with a test you can fail. Levels you cannot evidence do not count.
Where this sits
Video ASM is not a replacement for attack surface management, IoT security or vulnerability management. It is the application of those disciplines to a class of asset that generally escapes them. The boundary pages set out the differences explicitly, including the cases where an existing tool already covers the ground.
For implementation detail on individual technologies, the hardening guides at VideoCybersecurity go deeper than this framework does.