Your cameras, doors and alarms
are all quietly online.
Who's watching them?
Obelvion tests, audits and hardens CCTV, access-control and alarm systems — from device firmware to the network they sit on — before someone else finds the gap first.
Cameras, door controllers and alarm panels are treated as fixtures, not endpoints — installed once, patched rarely, and left facing the internet. They're often the softest target on the network: a foothold with a direct line to VLANs, storage, and the rest of the building's systems. We assess CCTV, access-control, alarm and building-automation estates the way an attacker would, then hand back a plan your team can actually action.
Engineers on the ground, not just a report in your inbox
Every assessment involves people physically on your estate — checking cameras, tracing cable runs, and testing the doors and panels a remote scan can't reach.
What we test
Every engagement is scoped to the estate in front of us — cameras, access control, alarms, and the network fabric between them.
CCTV & NVR Penetration Testing
Black- and grey-box testing of camera firmware, web interfaces, and recorder appliances for auth bypass, RCE and privilege escalation.
Access Control & Door Controller Testing
Testing of badge readers, door controllers and exit hardware for credential cloning, auth bypass and unlock-command injection.
Alarm & Intrusion-Detection Review
Assessment of panel firmware, keypad authentication and monitoring-service links for tamper bypass and silent-disarm paths.
RTSP / ONVIF Protocol Hardening
Review of stream authentication, discovery services, and protocol exposure that let attackers pull or inject video undetected.
Network Segmentation Review
VLAN and firewall audit to confirm surveillance and access-control traffic is actually isolated from corporate and OT networks — not just on paper.
Firmware & Update-Chain Audits
Verification of update signing, rollback protection and vendor supply-chain integrity across your camera, access-control and alarm fleet.
Building Automation (BMS) Assessment
Review of BACnet, Modbus and other building-automation protocols for unauthenticated control of HVAC, lighting and door systems.
Physical & Placement Assessment
On-site review of camera coverage, reader and sensor placement, tamper resistance, and real intrusion paths across the estate.
Incident Response & Forensics
Chain-of-custody handling and forensic review of footage, access logs and alarm events following a suspected breach or tamper event.
How it runs
A fixed sequence, start to close-out — you get a retest, not just a report.
Recon & Asset Inventory
We map every camera, door controller, alarm panel, and endpoint on the estate — including the ones nobody remembers installing.
Vulnerability Assessment
Firmware, protocol, and network-level scanning against known and unpublished weaknesses.
Exploitation & Proof of Concept
Controlled exploitation to confirm real-world impact — no theoretical findings padding the report.
Remediation Roadmap
Prioritised fixes ranked by exploitability and business impact, written for both engineers and management.
Verification Retest
We come back and try again. Closed findings get confirmed closed, not assumed closed.
Start a conversation
Tell us what's on your network. We'll scope an assessment from there.