A business owner in Nairobi buys a cheap IP camera from an electronics shop in River Road, plugs it in, opens the manufacturer's app, and within minutes is watching a live feed of their shop from their phone while sitting in traffic on Thika Road. It feels like a small technical win, convenient, affordable, and reassuring. What that business owner usually does not realise is that the same convenience often comes from the camera being connected directly to the open internet, with a factory-default password nobody thought to change, sitting there quietly reachable by anyone in the world who happens to be scanning for exactly that kind of device.
This is not a rare or unusual setup. It is close to the default way IP cameras get installed across a huge number of small and mid-sized Kenyan businesses, and understanding why that matters, and what more mature markets like the European Union have started requiring instead, is genuinely useful for any business owner trying to decide whether their surveillance system is actually protecting them or quietly exposing them.
What "CCTV Hijacking" Actually Means
Before going further, it helps to be precise about the terms involved. An IP camera, short for Internet Protocol camera, is a camera that connects directly to a network and transmits its video feed as digital data, rather than through the older analogue cable-based systems traditional CCTV setups once relied on. This is what makes remote viewing on a phone possible in the first place.
CCTV hijacking refers to an unauthorised person gaining access to that camera feed, and in more serious cases, using the camera as an entry point into the wider network it is connected to. This second part is the piece most business owners underestimate. A compromised camera is not just a privacy problem where someone can watch your premises. It can become a foothold that lets an attacker move further into whatever else shares that same network, point-of-sale systems, accounting software, customer databases, depending on how the network was set up.
Global research into this exact problem gives a sense of scale. Internet-scanning research has repeatedly found tens of thousands of security cameras worldwide reachable directly from the public internet, spanning shops, restaurants, gyms, construction sites, and even hospitals and data centres, often because of exactly the kind of do-it-yourself installation described above. A widely reported 2021 breach at a US-based camera company, Verkada, saw attackers gain access to roughly 150,000 connected cameras across hospitals, schools, and companies, illustrating how a single vulnerability in how cameras are managed can cascade across an enormous number of sites at once. Kenya has no reason to assume it is exempt from this same underlying pattern, since the specific mistakes that create this exposure, weak default passwords, direct internet exposure, and no separation between the camera network and the rest of a business's systems, are just as common locally as anywhere else.
Why Kenyan Businesses Are Particularly Exposed
A few specific, common practices explain why this risk shows up so often locally. Cost sensitivity drives many businesses toward the cheapest available IP cameras, often without much scrutiny of the manufacturer's security track record or whether the device receives regular firmware updates, meaning fixes for known vulnerabilities. Firmware, in simple terms, is the built-in software that runs a device like a camera, and outdated firmware is one of the most common ways attackers gain entry, since publicly known vulnerabilities in older firmware versions are actively scanned for by automated tools worldwide.
Installers focused purely on getting a camera feed working quickly often enable remote access by connecting the camera directly to the internet through port forwarding, a router setting that opens a specific pathway from the public internet straight to a device on the internal network, without placing any additional protection in between. This is usually done to make remote viewing convenient, and it usually works exactly as intended for the legitimate user. Unfortunately, it works just as well for anyone else who finds that same open port.
Perhaps most significantly, very few Kenyan businesses separate their camera network from the rest of their business network. A camera and a till system, an office computer, or a customer database often sit on the exact same flat network, meaning a compromised camera is not a contained, isolated incident. It is a direct route into everything else connected to that same network.
The European Benchmark: What NIS2 Actually Requires
The European Union's approach to this exact problem offers a useful, concrete comparison. NIS2, formally the second Network and Information Security Directive, is EU legislation that came into force in January 2023, with member states required to have it written into national law by October 2024. It significantly expands cybersecurity obligations for a wide range of organisations, including those providing digital infrastructure and connected device services, and it treats the security of IoT devices, meaning Internet of Things devices, ordinary physical devices like cameras or sensors that connect to a network, as a serious compliance matter rather than an afterthought.
Several of NIS2's specific requirements map directly onto the exact gaps described above in typical Kenyan camera installations. Encrypted streams are required so that video data moving between a camera and its viewing platform cannot simply be intercepted and read by anyone monitoring network traffic. Firmware management obligations require organisations to keep device software current and to have a documented process for applying security updates, rather than leaving a camera running years-old software indefinitely. VLAN isolation, meaning the use of Virtual Local Area Networks to separate different categories of device onto logically distinct network segments even when they share the same physical infrastructure, is a core recommended control, specifically to ensure that a compromised IoT device like a camera cannot be used as a stepping stone into more sensitive systems on the same network.
It is worth being clear that NIS2 applies specifically to organisations operating within, or providing services into, the European Union, and Kenyan businesses are not legally bound by it. What makes it a useful benchmark regardless is that it represents a considered, expert-driven response to precisely the vulnerability pattern Kenyan businesses commonly display, which makes its specific technical requirements a genuinely practical checklist to borrow from voluntarily.
Practical Steps Kenyan Businesses Can Take Without Full NIS2 Compliance
Adopting the spirit of these requirements does not require Kenyan businesses to pursue formal EU-style compliance, since that framework was not designed with local businesses in mind. It does mean addressing the same underlying gaps in practical, achievable ways:
- Change default camera passwords immediately upon installation, using genuinely strong, unique credentials, to close the single most common entry point exploited by automated scanning tools.
- Keep camera firmware updated, and check periodically whether a manufacturer has released security patches, closing another major and often ignored gap.
- Avoid direct port forwarding to camera devices, and instead use a secure VPN, a private, encrypted connection method, for remote viewing, removing the direct internet exposure that makes cameras trivially discoverable in the first place.
- Separate camera devices onto their own isolated network segment, even a relatively simple version of VLAN isolation, so a compromised camera cannot become a direct route into more sensitive business systems.
Choosing a CCTV Provider Who Understands This
Not every CCTV installer in Kenya configures systems with these protections in mind, and business owners should ask directly whether a provider changes default credentials, applies firmware updates as standard practice, and avoids exposing cameras directly to the public internet without additional safeguards. A provider who cannot answer these questions confidently is likely installing exactly the kind of exposed setup described throughout this article.
Comparing providers on this specific capability, rather than assuming all CCTV installation services are functionally interchangeable, is worth the extra diligence. Platforms such as Secuwatch Tech can help Kenyan business owners find and compare vetted CCTV and security technology providers who understand network security fundamentals, rather than committing to whichever installer offers the fastest, cheapest setup without considering what happens once that camera is actually connected to the internet.
A Grounded Conclusion
The convenience of a cheap IP camera streaming straight to a phone app is real, but it often comes bundled with an exposure most Kenyan business owners never intended to accept. The European Union's NIS2 directive did not invent the idea that cameras need encryption, updated firmware, and network isolation out of caution for its own sake. It formalised a response to a well-documented, global pattern of exactly the kind of exposure common in Kenyan installations today. Borrowing that same practical checklist, even without any formal obligation to do so, is one of the more straightforward ways a Kenyan business can close a gap that, right now, may already be sitting wide open.