BRITISH COLUMBIA · SINCE 2015CALL A LOCAL TEAM — (604) 360-7400
(604) 360-7400Book a free site walk-through

Remote access for video systems: VPN, cloud relay, and the security of both

Once you have ruled out a forwarded port, two answers remain. They are both defensible, they fail in completely different ways, and nobody explains the difference at quoting time.

Guard Nation Security8 min read

We have written elsewhere about the port your installer opened so you could watch cameras from your phone, and about why an open inbound door to a video recorder is the wrong answer. That article ends by naming two better answers — a VPN into the site, or a vendor cloud relay — and then leaves them sitting there as though they were interchangeable.

They are not interchangeable. They are both defensible. They trust completely different things, they fail in completely different ways, and the choice between them is usually made by whoever is holding the quote rather than by the person who will live with the consequences.

This article is about that choice. It will not tell you which one is right for your building, because that depends on facts about your site that we cannot see from here. It will tell you what each one is actually doing, so the conversation you have about it is a real one.

The only question that matters: which end starts the conversation

Strip away the branding and every remote access method is answering one question. When you open the app in a parkade in another city, which end of the connection reached out first?

If the answer is you reached in, something at the building had to be waiting for a connection from the outside world. A forwarded port is the crude version of that. A VPN is the disciplined version: still something listening, but a purpose-built piece of security software rather than a camera recorder, and it authenticates you before you touch anything on the inside.

If the answer is the building reached out, the recorder or camera made an outbound connection to a vendor's service and holds it open. Nothing at your site is waiting for strangers. You connect to the vendor, the vendor joins the two halves, and video passes between them. That is a cloud relay.

Everything else — which app, which brand, whether there is a monthly fee — is downstream of that one structural fact.

CISA, the US government's cyber security agency, frames the whole exercise in the same direction. Its exposure reduction guidance tells organizations to "Determine which assets need to be internet-accessible for operational purposes. For those that do not need to be internet accessible, implement measures to remove or restrict access." Both answers satisfy that. A recorder on a VPN is not internet-accessible. A recorder dialling out is not internet-accessible either. What differs is where the remaining risk went.

The VPN answer: you keep the risk, and the work

With a VPN, remote users authenticate to the network and then reach the recorder as though they were standing in the building. The recorder itself is untouched — it goes on believing it lives on a private network, which is what it was designed for.

What this buys you is control. Footage does not leave your premises unless you carry it out. Access is a list you hold. If you dislike a vendor's terms next year, nothing about your video is hostage to that.

What it costs you is that the risk did not vanish; it moved to the VPN, and the VPN is now yours to run. Three things follow, and all three are ordinary rather than exotic.

The VPN is software, and software is patched. CISA's guidance is blunt about keeping systems current and replacing devices no longer receiving security support. A VPN appliance that has not been updated since it was installed is not a security control, it is a second appliance sitting on the internet. This is the single most common way the VPN answer degrades — not by being wrong, but by being installed once and never touched.

Somebody has to own the account list. VPN access is granted to people, and people leave. The property manager who moved firms, the maintenance contractor who did a six-week job in 2023, the strata council member from two terms ago. Nobody's job description says "remove the departed". Ask who reviews the list and how often, and accept that "when we remember" is the honest answer at most sites.

A second factor is not optional here. CISA names multifactor authentication among the mitigations for anything still reachable. A VPN protected by a shared password that three people know is a door with a key under the mat.

The VPN answer is the strongest one available, and it is the right answer for any building that already has real IT support. It is a poor answer for a building that does not, because an unmaintained VPN quietly becomes the thing it was installed to prevent.

Encryption in transit is table stakes; the question is who holds the keys.

The cloud relay answer: you rent the risk, and inherit a posture

With a relay, the recorder dials out. There is no inbound door at all, which removes an entire category of problem permanently and without ongoing effort from you. For a small strata, a single-tenant industrial building, or any site with nobody technical on the payroll, that is a genuine and underrated advantage. The failure mode of a relay is not neglect.

The trade is that you have taken on the vendor's security posture as your own. Their authentication is now your authentication. Their breach is now your incident. Their business continuity is now the reason your app does or does not open.

This is not an argument against relays. It is an argument for asking about the vendor rather than the box, which is the opposite of how CCTV is normally purchased.

Three things are worth understanding about what the relay is actually carrying.

Relay is not the same as cloud recording. Some services only broker the connection — the video lives on the recorder at your site and passes through the vendor in the moment you watch it. Others store footage in the vendor's infrastructure, either instead of or alongside local storage. Owners routinely believe they have the first and have bought the second. Ask directly, because the answer changes where your footage physically sits and who can produce it.

Encryption in transit is table stakes; the question is who holds the keys. Video crossing the public internet should be encrypted, and on any current platform it is. The more revealing question is whether the vendor can decrypt the stream themselves. Some architectures let them, by design, because features like server-side analytics or web playback require it. Others do not. Neither is disqualifying, but you should know which one you bought, and a vendor who cannot answer plainly has told you something.

Your account is now the perimeter. When the door is gone, the login becomes the whole defence. Multifactor authentication on the video platform matters more than it does on almost anything else you own, because the thing behind it is a live view of the inside of your building.

The camera behind the recorder is still a device

Both answers protect the recorder. Neither automatically protects the cameras, which are themselves small networked computers with their own logins and their own firmware.

ONVIF, the standards body for interoperability between video devices, deprecated its Profile Q in April 2022, and the stated reason is worth reading in full because it is a device-level problem that no remote access design fixes: "ONVIF deprecated Profile Q on April 1, 2022 because its specification requires a Profile Q conformant device to allow anonymous access to all ONVIF commands during the setup process in the factory default state. This does not follow current cybersecurity best practices."

Factory default state is not a hypothetical. It is the state of any camera nobody finished commissioning, any replacement unit swapped in during a service call, any device reset to clear a fault. A locked front door does not help if the devices inside are unfinished.

There is a related trap on the specifying side. ONVIF is developing Profile V, which addresses precisely the cloud video territory this article is about — outbound connections to a cloud service, modern authentication, browser-based streaming. It is not released. It carries Release Candidate status, and it does not appear in ONVIF's own list of profiles for video systems. If a proposal you are reading offers Profile V as something already deliverable, that proposal is ahead of the standard, and you should discount the rest of it accordingly.

For system-level design there is a current international application guideline for video surveillance — IEC 62676-4 — which is the document a competent designer works from. Its 2014 edition was withdrawn in October 2025 and replaced by a second edition, which is a useful thing to know if a specification you are handed cites the old one.

The obligation nobody mentions at quoting time

Recorded video of identifiable people is personal information, and a private organization in British Columbia holding it has duties under the Personal Information Protection Act. Among them, s.34 requires reasonable security arrangements to protect personal information in your custody — including against unauthorized access.

Read that against this article's subject. A remote access design is not a convenience feature that happens to have a security dimension. It is one of the arrangements. An open inbound port to a recorder holding footage of your tenants is hard to describe as reasonable, and "our installer set it up that way" is a description of how it happened, not a defence.

We are not offering that as legal advice, and the threshold of what is reasonable is not something an integrator gets to declare. The point is narrower: the question of how people reach your video from outside is a compliance question as well as a technical one, and it is worth raising with whoever advises you on privacy rather than leaving it entirely with whoever installed the cameras.

What to ask, in writing

Five questions. Any competent provider answers all five without difficulty, and the one they become vague about is the one that mattered.

1. Which direction does the connection go, and is there any inbound port open at the site? This is the question from the previous article and it remains the first one. Accept a specific answer, not a reassurance.

2. If it is a relay: does my footage rest on the vendor's infrastructure, or only pass through it? And if it rests there, where, and for how long.

3. If it is a VPN: who patches it, who holds the account list, and when was that list last reviewed? Ask for the date of the last review. The pause before the answer is informative.

4. Is multifactor authentication enabled — not available, enabled — on every account that can view video? Equipment that can do something is not equipment that is doing it, and this distinction is where most remote access weakness actually lives.

5. What is the review cadence? CISA's last step is the one everybody skips: establish routine assessments. Exposure is not a state you fix once. Contractors change, staff leave, a device gets swapped, a temporary rule from a bad week in some past year is still in place because removing it was never anybody's job.

The honest summary

Neither answer is a security product you buy once. A VPN is a commitment to maintenance; a relay is a commitment to a vendor. Both are enormously better than a forwarded port, and the gap between them is smaller than the gap between either of them and doing nothing.

If your building has real IT support, the VPN keeps your footage and your control on your premises, and you should use it. If it does not, a relay from a vendor who publishes their security practices removes an entire class of risk that would otherwise sit unmaintained for a decade, and the honest trade is that you are trusting somebody else to do the work.

What is not defensible is not knowing which one you have. Ask the question, keep the answer in the building file, and put a date on when you will ask it again.

Written by the Guard Nation Security team — from the sites we install, monitor, guard and investigate across British Columbia, and have since 2015.
Sources

Sources

  • CISA, Internet Exposure Reduction Guidance (published 4 June 2025) — https://www.cisa.gov/resources-tools/resources/exposure-reduction
  • ONVIF, Profile Q and Profile V — https://www.onvif.org/profiles/profile-q/
  • IEC 62676-4 — Video surveillance systems for use in security applications, Part 4: Application guidelines — https://webstore.iec.ch/en/publication/83425
  • Personal Information Protection Act (SBC 2003, c. 63) — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01

Want a second opinion on your doors?