Access management for cameras, alarms and intercoms across all your sites
A camera system stopped being only about the picture a long time ago. It is about control: who can watch, who can export, who changed a setting, and can a former employee still log in? We make that manageable again. One login per person, permissions per site, an audit trail of who did what. Even with mixed camera brands.
- Cameras, alarms and intercoms
- Multiple sites in one overview
- Any brand, one way of managing it
To be clear up front: Nx Witness does not make your organisation NIS2 or ISO 27001 compliant by itself, and we are not a certification body. What we do is set up your camera, alarm and intercom systems so that the measures behind those frameworks are demonstrable and manageable. Personal accounts, permissions, revoking access and logging.
Recognisable
Why are shared passwords on a camera system a problem?
Because you cannot prove anything with them, and you cannot take access away from one person without giving everyone a new password. A shared login is not illegal. It is just impossible to defend.
We see it at almost every organisation with more than one site. Years ago the installer set up a recorder and handed the login to someone at reception. That person left five years ago. In the meantime ten others got the same details, on a note, in an email, in a chat message.
Eleven people know the login now. Nobody knows who.
Site two has a different recorder with a different login. Site three has an intercom with its own app. And the alarm code has not changed in years.
“It is like keys used to be. You could have them copied endlessly, and after a few years nobody knew who still had one. With camera systems, that key is now the shared login.”
Marc Herdes, co-founder CameraInstallatie.nl
Check yourself
Where does your organisation stand?
Fifteen questions, each linked to the NIS2 article, ISO 27001 control or GDPR principle it is about. Your result appears straight away, without leaving any details. Take the access check.
The questions
Which questions should you be able to answer about your camera system?
An auditor, your ISO coordinator or your board will ask them sooner or later. With separate recorders and a shared login, none of them gets an honest answer.
Who can access which cameras?
Per person, per site, per camera.
Who played back footage?
Which camera, which time window, when.
Who exported something?
And what happened to that file?
Who changed a setting?
A camera switched off, a recording schedule changed.
Can a former employee still log in?
And how do you know for sure?
Who is administrator?
And is anyone still logging in as ‘admin’?
User management
How do you manage users on a security camera system properly?
By giving everyone their own account and tying permissions to a role instead of a password. In Nx Witness every user gets a personal login, on their own email address or through your Active Directory, with only the cameras and actions that fit their job.
That is least privilege. Reception sees the entrance and the car park, a site manager sees their own site, the board sees everything. Who may export, move a PTZ camera or change settings is set per role.
- One account per person. No shared logins, not for the night shift and not for the external guard company.
- Roles, not loose permissions. Put a new starter in the group for their job and they see the right cameras straight away.
- Administrator is a function, not a password. The admin account is used for administration only, with a strong unique password that does not circulate.
- Two-factor login where possible. For personal cloud accounts you can make it mandatory.
Leavers
Can a former employee still see your camera footage?
With separate recorders and a shared login, often yes, and you would never notice. With personal accounts you remove that one person and everything else keeps working.
Connect Nx Witness to Active Directory and it follows automatically. Someone removed there loses access to the cameras within about ten minutes. Without that link you remove them once, and they are gone from every server in that system.
What we won’t promise: one button that removes someone from cameras, alarm and intercom at the same time. It doesn’t exist. What you do get is one list with three actions, instead of a tour of every site. The list itself is in our offboarding checklist for security systems.
Audit trail
Which camera system shows which user did what?
Nx Witness keeps an audit trail. It records who logged in and from which address, who watched live or played back, which camera and which time window, who exported and who changed a setting. By default for 183 days, longer if you want.
That changes the conversation. From “I think someone looked at that footage yesterday” to “this account played back camera 7 for twenty minutes at 14:32”. In an internal incident, an employment dispute or a police request, that is the difference between a suspicion and an answer.
One caveat that belongs here: the audit trail is stored per server. On a system with several servers we read it out centrally and combine it into one export. More on the audit trail of your camera system.
How it works
How do you bring camera systems from several sites together?
Each site probably has a recorder with cameras attached. We take that recorder out, put an Nx Witness server in its place, and through the cloud you see every site with one login. Take an organisation with three sites: 6 people in one, 8 in another and 60 in the third.
| Now: three islands | After: one way of managing | |
|---|---|---|
| Each site | Its own recorder, its own shared login | An Nx Witness server where the recorder was |
| Accounts | Three shared logins, nobody knows who has them | 74 personal accounts, each with a role per site |
| Someone leaves | Change three passwords and tell everyone. Or, usually, nothing. | One action, or automatic through Active Directory |
| Who played what back? | Unknown | The audit trail shows it |
With a few sites on good connections, everything goes into one system. With more sites, or a link that sometimes drops, each site gets its own system that keeps running on its own, brought together in one cloud environment. We decide that in the design, not afterwards.
Brands
Does everything have to be one brand?
No. Different brands can stay. You manage them as one system.
According to Network Optix, Nx Witness automatically discovers about 99% of IP cameras on the market, with native drivers for the big brands and ONVIF for the rest. We check first what is still usable. What works stays. What no longer works or no longer gets updates, we replace selectively. Licences are per camera, not per server or site, so an extra server needs no extra server licence.
Frameworks
What do NIS2, ISO 27001 and GDPR actually ask for here?
None of them mentions cameras. All three ask that you can show who has access and that you can take that access away. If your camera system sits on your network, or watches the room where your servers are, it is part of that.
| Source | What it says | What it means for your camera system |
|---|---|---|
| NIS2 Directive Article 21 | Risk-management measures including access control policies, asset management, human resources security, and multi-factor authentication where appropriate. | Personal accounts, revoking access when people leave, an up-to-date list of cameras and servers. |
| Dutch implementation Cyberbeveiligingsbesluit art. 15 | A written policy on logical and physical access, applied demonstrably, including issuing, monitoring and revoking identities and authorisations. | An example of how a member state makes access control concrete. |
| ISO 27001:2022 Annex A | Among others access control (5.15), access rights (5.18), responsibilities after termination (6.5), privileged access (8.2), logging (8.15) and physical security monitoring (7.4). | Roles per job, no shared admin, a leaver procedure that includes the cameras. |
| GDPR Articles 5, 32, 33 | Appropriate security against unauthorised access, being able to demonstrate it, and reporting a breach within 72 hours unless it is unlikely to pose a risk. | Recording who may watch, and being able to check what was viewed. |
What the directive asks in general, from registration to incident reporting and fines, is on what is NIS2.
Which organisations fall under NIS2 depends on sector and size, and on how your member state has implemented it. Check your own position with your national authority or legal adviser.
Who we are
Why CameraInstallatie.nl for this part of NIS2 and ISO?
Because we handle the whole part that concerns your security systems. Advice and inventory, migration, installation including cabling and network, and the management after. We don’t refer you elsewhere. If something breaks, we fix it.
CameraInstallatie.nl has worked in security since 1999, with our own engineers and our own stock. For Nx Witness, technical support runs through the authorised reseller, and that is us. We also supply Milestone XProtect and Genetec, and compare them honestly in video management software for business.
Two situations we see a lot: schools and trusts, where the footage shows pupils, see CCTV for schools. And sites with gates and barriers, see LPR software with Nx Witness.
What we don’t do, we say. We don’t write your information security policy and we don’t certify. For the risk assessment of your whole organisation you work with your own ISO consultant or auditor. We connect to that and deliver what they want to see for this part: the permissions overview, the audit trail, the leaver procedure and documentation of what we configured.
What IT managers and consultants ask us
Which security camera system is NIS2 compliant?
None, because NIS2 is about your organisation, not about a product. There is no NIS2 certificate for cameras. What counts is whether you can show who has access, revoke it, and keep track of what is running. Nx Witness gives you the tools for that.
Does Nx Witness integrate with Active Directory or Microsoft Entra ID?
With Active Directory and other LDAP servers, yes. Users and groups sync every ten minutes by default. Microsoft Entra ID and SAML single sign-on are not supported up to version 6.1. Network Optix has announced it for the Enterprise edition.
Does Nx Witness support two-factor authentication?
Yes, for cloud accounts, with an authenticator app, and an administrator can make it mandatory. Local accounts and accounts from Active Directory have no two-factor login inside Nx Witness. So there is a trade-off between 2FA in Nx and the account lifecycle from AD, which we work out with your IT team.
Does Nx Witness support RADIUS?
We have not found RADIUS for user logins; Nx Witness uses LDAP for that. For the network ports your cameras connect to, RADIUS can be used through 802.1X on the switch.
Can we keep our existing cameras?
Usually, yes. We check them against the supported devices list and ONVIF first. Cameras locked to one brand’s recorder or cloud, and old analogue cameras, need an encoder or a replacement. You hear that before anything changes.
Do you work outside the Netherlands?
Yes. We supply licences and servers across Europe and configure systems remotely. Installation and cabling we do in the Netherlands and the immediate border region.
Back in control of who can see your footage?
Talk to us about your access management. We think along, we don’t refer you elsewhere, we fix it ourselves. Bring what you know, even if that is almost nothing.

A quick word
Questions about your situation? Call John.
Watches over the part you only notice years later: continuity, and agreements that hold. Describe your situation and you will hear straight away what we would do — with no obligation.
John van den Bosch · Co-founder