Security Questions, Clearly Answered

Practical answers about security systems, video surveillance, privacy, cybersecurity, planning and long-term system management for homes and commercial properties across Ontario.

Planning and Procurement

Start with a clear description of the property, its use and the situations that concern you. Note the entrances, outdoor areas, parking spaces, storage rooms, public-facing areas and other locations that may require attention. It is also helpful to prepare information about operating hours, staff or household routines, existing equipment and any previous incidents. Photos, floor plans and a list of current problems can make the initial discussion more productive. You do not need to know which cameras, sensors or platforms you need before speaking with a professional.

A lower price does not always represent a lower total cost or an equivalent system. Compare what each proposal is intended to achieve, which areas are covered, what equipment is included and how the system will be configured. Check whether installation, cabling, programming, testing, training, taxes, recurring fees and future support are included or listed separately. The proposal should also explain what is excluded, such as electrical work, lifts, construction repairs or network changes. A useful proposal connects each recommendation to a specific property need instead of presenting a list of products without context.

A clear scope should identify the property, the areas included and the purpose of the proposed work. It should describe the equipment categories, installation requirements, programming, system integration, testing and handover. If existing equipment will remain, the scope should explain how compatibility will be checked and what limitations may apply. It should also identify responsibilities for electrical work, internet service, network access, construction repairs and other third-party work. Clear documentation reduces misunderstandings and gives both sides a practical reference during the project.

A phased rollout can be appropriate when a property is large, occupied or subject to budget limits. The first phase may address the areas where a security gap would have the greatest operational or financial impact. Future phases should be considered before the first installation so that cabling, network capacity and system architecture do not restrict later expansion. Phasing should not mean installing isolated equipment that cannot work with the planned final system. The proposal should identify what will be completed now, what is reserved for later and how the stages will connect.

Security work can often be coordinated around business hours, household routines, tenant schedules or restricted access periods. The planning discussion should identify quiet hours, sensitive rooms, customer-facing areas, delivery times and any locations that cannot be interrupted. Some work may require temporary access to ceilings, walls, doors, network equipment or electrical panels. A responsible plan should explain expected disruption, site protection, daily cleanup and any temporary loss of coverage. The earlier these conditions are discussed, the easier it is to reduce operational interruptions.

A project becomes more complicated when an owner, property manager, IT provider, operations team, tenant or family member controls part of the decision. Each person may focus on a different issue, such as safety, privacy, convenience, budget or system administration. Before work begins, identify who approves the scope, who provides site access, who controls network credentials and who will manage the system afterward. It is also important to confirm who is authorized to receive recordings or change user permissions. Written responsibilities help prevent delays and reduce the risk of important decisions being left unclear.

Video and Incident Evidence

Recording does not automatically mean that the footage will clearly show what happened. A camera may be pointed too far away, affected by glare, blocked by an object or positioned where a person appears only as a small figure. Poor lighting, motion, weather and incorrect time settings can also reduce the value of a recording. A system may capture movement without capturing the detail needed to identify a person, vehicle or action. Useful surveillance depends on the relationship between camera position, lighting, recording settings, storage and the purpose of the camera.

Higher resolution can provide more detail, but it does not solve every surveillance problem. A high-resolution camera with poor lighting or an unsuitable viewing angle may produce less useful evidence than a lower-resolution camera installed correctly. Storage requirements, network capacity and playback performance can also increase as image quality improves. The correct choice depends on what needs to be seen, how far away it is and how quickly it moves. The goal should be useful evidence for a defined area, not the highest specification available.

Lighting can change how a person, vehicle or object appears in recorded video. Bright background light may create silhouettes, while reflections, headlights, shadows and low-light conditions may hide important details. A camera that looks directly toward a strong light source may produce a different result from one positioned at an angle. Height and distance also matter because a wide overview view may not provide enough detail for identification. Camera placement should be tested under the conditions in which the area is actually used, including nighttime and changing weather.

Motion detection identifies a change in the image, but it does not always establish what caused that change. Wind, rain, shadows, lighting changes, animals and moving vegetation can create alerts without a security event. Event verification involves reviewing the available information to determine whether the activity appears relevant and what action may be appropriate. The distinction is important because a system that produces a large number of alerts may be difficult to manage. Settings should be evaluated according to the property, normal activity and the people responsible for responding.

Testing should be based on realistic scenarios rather than a general statement that the cameras are working. Walk through important entrances, driveways, loading areas, corridors or restricted zones and review what the system records from the relevant viewpoint. Check daytime and nighttime conditions, movement at different distances, image clarity, timestamps and the ability to retrieve a recording. If the system sends alerts, test whether they reach the correct users and whether the alert contains enough information to support a decision. Testing should be documented so that future changes can be compared with the original result.

Identify the approximate date, time and location as soon as possible because recordings may be overwritten according to the system settings. Preserve the original file or export where possible, rather than relying only on a screen recording or a shortened clip. Record who accessed the footage, when it was exported and to whom it was provided. Avoid editing the original evidence, and keep any working copy clearly identified. If the matter may involve insurance, employment, litigation or law enforcement, obtain appropriate legal or professional guidance about preservation and disclosure.

Privacy and Responsible Use

A camera should be positioned and configured for a legitimate security purpose connected to the property. Recording a wider area than necessary can create unnecessary privacy concerns, especially where neighbours, tenants, employees or members of the public may be visible. Privacy masking, narrower fields of view, adjusted camera angles and limited recording zones may reduce unintended collection. The property owner or organization should understand what the cameras capture and why that area is necessary. Privacy requirements can depend on the property, the organization and the circumstances, so complex situations should be reviewed with qualified privacy or legal counsel.

Audio can be more intrusive than video because conversations may be captured even when people do not expect to be recorded. It may also collect information that is not necessary for the security purpose. Before enabling audio, consider whether it is genuinely required, who may be recorded and how the information will be protected. The feature should not be activated simply because the equipment includes it. A privacy review should address notice, purpose, access, retention and any applicable legal requirements.

Access should be limited to people who need it for a defined responsibility. A business may separate access for owners, managers, security personnel, IT staff and investigators instead of giving every user full administrative control. At home, it may be necessary to distinguish between household members, temporary guests and service providers. Individual accounts are preferable to one shared login because they make access easier to manage and review. Permissions should be removed or changed when a person leaves, changes roles or no longer requires access.

There is no single retention period that is appropriate for every property or purpose. The period should reflect the reason for recording, the time needed to identify and review incidents, operational requirements and applicable privacy obligations. Keeping footage indefinitely can increase storage costs and privacy risks without providing a clear benefit. A written retention rule should explain when routine recordings are deleted and how relevant footage is preserved after an incident. The Office of the Privacy Commissioner of Canada recommends retaining recordings only as long as necessary for the purpose for which they were collected.

People should receive clear information about the presence and purpose of surveillance where notice is required or appropriate. The explanation should identify what is being recorded, the general areas covered, the reason for collection and who may access the information. Businesses should also consider how cameras relate to workplace monitoring, employee expectations and internal policies. In Ontario, certain employers with 25 or more employees on January 1 must have a written electronic monitoring policy in place by March 1 of that year, ontario.ca The exact requirements depend on the organization and the monitoring practices being used.

Sharing footage publicly can create privacy, identification and reputational risks. A recording may include people who are not involved in an incident, private information, vehicle plates, children or details about a person’s movements. Before sharing, consider whether the disclosure is necessary, whether the people shown can be identified and whether the footage should first be provided to law enforcement, an insurer or legal counsel. Limit copies and use a secure method when footage must be shared with an authorized recipient. Public posting should not be treated as a substitute for proper incident handling.

Cybersecurity and System Governance

Ask where system data is stored, how remote access is protected and whether individual user accounts are supported. Confirm how security updates are delivered, what happens when a product reaches the end of its supported life and whether recordings can be exported in a usable format. You should also understand which parts of the system depend on a cloud platform, local network, internet connection or third-party service. A security system can create a new digital access point if it is not managed carefully. Cybersecurity should therefore be considered during selection, not only after installation.

Default passwords are often known, reused or easy to discover. A shared login makes it difficult to determine who accessed a system, change one person’s permissions or remove access without affecting everyone else. Each authorized user should have an individual account with an appropriate level of access. Strong, unique passwords and multi-factor authentication should be used where the platform supports them. Canadian cybersecurity guidance recommends changing default passwords and protecting networks with current security standards such as WPA2 or WPA3.

The property owner or responsible organization should retain control of the primary administrator account. An installer may need temporary access during configuration, but permanent ownership should not depend on one employee, contractor or service provider. The account recovery email, phone number and authentication method should belong to the responsible owner or organization. Credentials should be transferred securely and recorded in an appropriate internal system. This protects continuity if staff change, a contract ends or a provider becomes unavailable.

Updates may correct security weaknesses, improve compatibility or resolve system problems. Delaying them indefinitely can leave connected equipment exposed, but applying an update without checking compatibility can also interrupt a functioning system. Establish who monitors updates, who approves them and how changes are documented. Important systems should be checked after an update to confirm that recording, alerts, remote access and integrations still work. The update process should also include a plan for unsupported equipment that can no longer receive security fixes.

That depends on the equipment, network design and level of control available. Separating security devices from ordinary user devices can limit the effect of a compromised computer or account. A professional network design may use separate network segments, controlled permissions and limited remote access. This should be coordinated with the person responsible for IT because incorrect changes can interrupt cameras, alarms or other connected systems. Network security is part of the overall security design, not an issue limited to the internet service provider.

Keep the final equipment list, camera or device locations, network information, account ownership details and system diagrams. Records should also identify warranty terms, service contacts, update responsibilities, user permissions and any recurring subscriptions. After testing, save the results and note any limitations that were accepted. For businesses, include internal procedures for access requests, incident exports, staff changes and privacy complaints. Good documentation reduces dependence on individual staff members and makes future troubleshooting or expansion more efficient.

Cost, Ownership and Long-Term Management

The number of cameras does not show how difficult the property is to cover or what the system must achieve. Cost can be affected by cable distances, mounting surfaces, lighting, network capacity, storage requirements, access points, door hardware, working hours and site access. A small property may require more complex work than a larger one if the structure is difficult to reach or existing infrastructure is limited. The required level of detail also changes the equipment and configuration. A responsible estimate should be based on the property and the intended outcome rather than a simple device count.

Recurring costs may include monitoring, cloud storage, software licences, cellular communication, technical support, maintenance and internet service. Some systems also require periodic replacement of storage devices, batteries or other components. These expenses may be billed by different providers, so they should be identified separately from the installation price. Ask whether a feature depends on a subscription and what functions remain available if the subscription ends. Understanding recurring costs helps prevent a system from becoming more expensive or less useful than expected.

Compare the initial installation cost with recurring charges, expected maintenance, upgrades and possible replacement of unsupported equipment. Consider whether the proposal includes training, documentation, testing and post-installation adjustments. Review the assumptions behind storage capacity, monitoring coverage, user numbers and future expansion. A lower initial price may rely on limited storage, fewer services or equipment that is difficult to expand. A multi-year comparison does not predict every future expense, but it gives a more realistic picture than the first invoice alone.

Additional work may include electrical changes, network upgrades, lift rental, after-hours access, masonry repairs, painting, ceiling restoration or work by another contractor. A property may also require permits, landlord approval, coordination with a fire or access-control contractor, or temporary protection during construction. These items are not automatically part of every security installation. Ask the provider to identify assumptions, exclusions and conditions that could change the price. Written clarification is especially important for commercial properties with multiple trades or strict site requirements.

Transferability depends on the equipment, software platform, contract and the type of data involved. Some systems use open standards or exportable files, while others rely heavily on a manufacturer-specific platform. Before signing, ask who owns the hardware, who controls the administrator account and whether recordings, settings and user lists can be exported. Also confirm whether the previous provider must assist with decommissioning or handover. Planning for a future provider change does not mean expecting one, but it prevents unnecessary dependence on a single company.

A review is useful when the property, people, operations or risks change. Examples include a renovation, new entrance, business expansion, change in tenants, staff turnover, new parking arrangement or a shift from daytime to extended hours. The system should also be reviewed when users report recurring alerts, missing details in footage or difficulty retrieving events. A periodic review can identify small changes before they become larger operational problems. The goal is to confirm that the system still reflects how the property is actually used.

Contact TNSG

Tell Us About Your Security Needs

Tell us about the property, your current concerns and what you would like to improve. Our team will review the details and help determine the most appropriate next step, whether you need a new system, an upgrade or a professional assessment.

Prefer to speak with someone directly?

For technical support with an existing TNSG system, please visit our Help Center.

TELL US ABOUT YOUR PROJECT