Skip to content

Video Surveillance That Satisfies Insurance and Compliance

By Donovan Brown
September 14, 2026
6 sections
Banking and financial transactions — wire fraud defense
Photo: Mathieu Stern on Unsplash
01

Introduction

LAYERLOGIX Video Surveillance ThatSatisfies Insurance andCompliance Texas managed IT & cybersecurity

A security camera system has two jobs. The obvious one is to record what happens. The quieter one is to hold up when it matters — when an insurer asks for footage after a claim, when an auditor asks how the video is protected, or when a regulator asks who can see it. Plenty of camera installs do the first job and quietly fail the second. Here is how to specify a system that satisfies both your carrier and your compliance obligations, not just the person watching the monitor.

02

What insurers actually look at

Carriers rarely dictate a brand. What they care about is coverage and evidence: are the entrances, points of sale, cash-handling areas, and high-value storage actually in frame, and can you produce clear, time-stamped footage from the day of an incident? Two specifications drive that answer — retention and resolution. Retention is how many days of video you keep before it is overwritten; retention windows vary by carrier and by industry program, and the only number that matters is the one written into your policy, so confirm it with your carrier rather than guessing. Resolution has to be high enough to make a face or a license plate usable as evidence, which means placing cameras for identification at the choke points rather than blanketing a parking lot with wide shots that prove someone was there but not who.

03

The compliance layer most installers skip

Modern cameras are networked computers. The recorder (NVR) sits on your network, and if it is left with default passwords, unpatched firmware, and an open path to the rest of the LAN, it becomes an easy way in. A camera system that ignores this is a liability dressed up as a safeguard. Hardening it is not exotic:

  • Change every default credential on cameras and the recorder before they go live.
  • Put the cameras on their own network segment (VLAN) so a compromised camera cannot reach your servers or workstations.
  • Keep firmware patched — camera vendors ship security fixes, and old firmware is a known target.
  • Restrict who can view and export footage, and log those actions. For regulated environments this matters as much as the video itself.

If your business handles protected health information or card data, the same physical-safeguard thinking that governs your data applies to your surveillance system: control access to the footage, know where it is stored, and be able to show who touched it. This is where physical security and cybersecurity stop being separate departments — see cybersecurity services and physical security systems.

04

Power and cabling: it all rides the same wire

Nearly every modern IP camera is powered over its network cable using Power over Ethernet (PoE), which means one cable carries both data and power. The IEEE 802.3 standards set the budget: IEEE 802.3af (Type 1) specifies up to 15.4 watts from the switch, IEEE 802.3at (PoE+, Type 2) up to 30 watts, and IEEE 802.3bt (Types 3 and 4) up to 60 and 90 watts for cameras with heaters, wipers, or pan-tilt-zoom motors. Getting the PoE budget right at the switch is part of the design, not an afterthought — and because the cameras share the building’s cabling, planning them alongside your structured cabling keeps the whole physical layer coherent.

05

A note on banned equipment

If your organization holds federal contracts, grants, or loans, be careful which cameras you buy. Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the federal government and its contractors from using video surveillance equipment from certain manufacturers — Hikvision, Dahua, Huawei, Hytera, and ZTE, including gear those companies build for other brands. The contractor prohibition, in section 889(a)(1)(B), applies to using the equipment, whether or not it is tied to a specific federal contract. Even organizations with no federal exposure increasingly specify “NDAA-compliant” cameras to stay clear of supply-chain risk. It is a cheap decision to get right at purchase and an expensive one to unwind later.

06

Frequently Asked Questions

How long should security camera footage be retained?

Retention is driven by your insurance policy and any industry requirements, and the number that governs you is the one in your policy, so confirm it with your carrier. The recorder’s storage should be sized to hold that many days at the resolution and frame rate you have chosen.

What makes a camera system NDAA compliant?

NDAA compliance means the equipment is not produced by, or built on components from, the manufacturers named in section 889 of the FY2019 NDAA, Pub. L. 115-232 (Hikvision, Dahua, Huawei, Hytera, ZTE, and their subsidiaries). Organizations with federal contracts, grants, or loans are required to avoid that equipment; many others specify it voluntarily.

Do security cameras create a cybersecurity risk?

They can. An NVR or camera left with default passwords, outdated firmware, or an open path to the main network is a common entry point for attackers. Changing default credentials, segmenting cameras onto their own VLAN, patching firmware, and restricting footage access close that gap.

How are IP cameras powered?

Most use Power over Ethernet, carrying data and power on one cable. The IEEE 802.3 PoE standards specify from 15.4 watts (IEEE 802.3af) to 90 watts (IEEE 802.3bt Type 4) at the switch, and the camera’s power draw has to fit within the switch’s PoE budget.

Specifying cameras for a new build or an upgrade in Texas? We design surveillance that stands up to your insurer and your auditor. See physical security systems and cybersecurity services, or call our Houston office at 713-571-2390. We also spec camera systems for construction projects during design.

Related Services

Need Help With Network Technology?

LayerLogix provides expert network technology solutions for businesses across Houston and nationwide.

Serving Houston, The Woodlands, and nationwideGet a Free Consultation
Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call