}

Network First: Why CCTV and Access Control Fail Without a Stable IT Foundation

IP cameras and digital locks are only as reliable as the underlying network. Why outdated hotel infrastructure becomes a security risk.
Read the article
Read the article
back
back

Network First: Why CCTV and Access Control Fail Without a Stable IT Foundation

Author
Philipp Krey
Time to read
4 min
Published

An access control system that locks every door when the network goes down — or worse, opens them — sounds like an unlikely worst-case scenario. It isn't. It happens. And it doesn't happen in poorly run properties; it happens in hotels that spent real money on modern security technology but overlooked the foundation it runs on.

Security systems are only as reliable as the network infrastructure that carries them. That applies equally to IP cameras, digital door locks, alarm systems, and access control terminals. Treating the network as a secondary concern and investing in endpoints first means building a security concept on unstable ground.

What binds IP cameras and digital locks to the network

Modern hotel security is network technology. That's not an exaggeration — it's a technical fact that doesn't get enough weight in most planning conversations.

  • IP cameras: An IP camera streams video continuously across the network to a recorder or cloud platform. If the connection drops, there is no image — not live, not recorded. For the duration of the outage, the camera is functionally blind. Some models offer local buffer storage, but that's not a given and rarely covers more than a few minutes.
  • Digital door locks: Whether RFID, PIN, or app-based — modern systems communicate continuously with a central management server. Authorisation checks, logging, and lock commands all run through that server. What happens during a network outage depends entirely on how the system is configured:
    • Fail-secure: The door defaults to locked (appropriate for server rooms or vault areas).
    • Fail-safe: The door opens automatically (essential for escape and emergency routes). If that configuration was never deliberately set, the manufacturer default decides. That's not a reassuring thought.
  • Additional infrastructure: Access control terminals, intercom systems, video door stations, and alarm panels all communicate over the network. When it goes down, they lose some or all functionality.

Typical network problems in hotels: what actually happens

The hospitality industry has invested heavily in visible technology over the past decade: new booking systems, digital key cards, and app-based check-in. The network infrastructure in the basement often didn't see that investment.

  • Ageing switches: A switch from 2012 sitting in a distribution cabinet in the basement — nobody sees it, nobody thinks about it, it just runs. Until it doesn't. Old switches offer no VLAN segmentation for different device classes, no quality of service (QoS) for prioritised traffic, and often no management interface for remote diagnostics. They are technically invisible.
  • No redundancy: Many hotels have exactly one internet connection, one core switch, and one uplink. If any single point fails, the whole property is affected — security systems included. A redundant internet connection via a second provider, a mirrored core switch, and a UPS-backed network cabinet aren't luxury measures; they're the baseline for a resilient system.
  • Poor wireless coverage in security areas: This tends to be underestimated because Wi-Fi is primarily seen as a guest amenity. But when cameras in outdoor areas, car parks, or stairwells rely on wireless (because cable installation there is costly), a poor signal becomes a security vulnerability, not a comfort issue.
  • Missing network segmentation: When IP cameras, guest Wi-Fi, the PMS server, and point-of-sale (POS) systems all share the same network segment, any compromised device has theoretical access to everything else. This risk has nothing to do with the quality of the end devices — it's created entirely by absent network design.

What actually happens when the network goes down

Abstract risks rarely convince. So concretely: what does a network outage mean for a hotel that hasn't prepared its security systems?

  1. Scenario One: A switch on the second floor fails. Cameras on that floor go offline. The outage isn't detected because no monitoring exists. Three hours later — after a reported incident of property damage on exactly that corridor — it turns out there's no footage.
  2. Scenario Two: The main internet connection drops. The cloud-based access control system loses its link to the management server. Depending on configuration, doors that should stay closed open — or doors that need to remain passable lock. The emergency exit in the basement can suddenly no longer be opened from the inside.
  3. Scenario Three: A network cable in the plant room is accidentally disconnected during maintenance. The alarm system loses its connection to the monitoring centre. The local alarm triggers — but no one outside the building is notified.

Solutions: redundancy, PoE, and fallback scenarios

The good news is that these risks are entirely manageable. They don't require a complete infrastructure overhaul — but they do require a plan.

  • Redundant internet connectivity: Two providers, two physical routes. If one line fails, the other takes over automatically. The cost of a backup connection is almost always lower than the cost of a multi-hour outage across all network-dependent systems.
  • Managed PoE switches: Power over Ethernet supplies IP cameras and access terminals with power directly through the network cable — no separate power supply or outlet needed. This eliminates additional failure points. Managed PoE switches also enable remote diagnostics, VLAN configuration, and traffic prioritisation.
  • UPS protection: An uninterruptible power supply for network cabinets and servers is the simplest form of resilience. Short power interruptions — seconds to a few minutes — are more common than most people expect, and they're enough to ungracefully restart systems, lose configurations, or create recording gaps.
  • Local fallback functionality: Good access control systems store authorisation data locally at the terminal. If the server connection drops, the terminal can make decisions independently based on the last synchronised dataset. That capability needs to be actively configured and tested, however.
  • Network segmentation (VLANs): Security systems belong in their own VLAN, completely isolated from guest Wi-Fi, office IT, and point-of-sale systems. This limits the blast radius of a compromised device and enables separate security policies for critical systems.
  • Proactive monitoring: A failed switch should be flagged within seconds — not three hours later when a guest complains. Network monitoring is a core precondition for a resilient system. What isn't monitored can't be fixed in time.

FAQ: network infrastructure and hotel security systems

What happens to digital door locks when the network fails?

It depends entirely on the system configuration. Fail-secure locks default to closed when connectivity is lost — appropriate for server rooms, but problematic for escape routes. Fail-safe locks open on connection loss — appropriate for emergency exits, but a risk for security-sensitive areas. Many modern systems offer local buffer storage that retains authorisation data for a defined period. Every hotel operator should know their configuration and test it regularly.

How can I prevent IP cameras from creating recording gaps during network issues?

First, through network redundancy so outages don't occur in the first place. Second, through cameras with local edge storage (like an internal SD card) that record locally during connection loss and automatically sync once the connection is restored. Third, through live network monitoring that flags outages immediately before they become extended gaps.

What does PoE mean for hotel network planning?

Power over Ethernet allows IP cameras, access terminals, and Wi-Fi access points to be powered directly through the data cable. This simplifies installation and maintenance considerably, reduces individual failure points, and enables centralised power protection via a single UPS in the server room. For new security installations, PoE is the absolute standard.

How disruptive is a network upgrade in a hotel that's still running?

With proper planning, significantly less disruptive than feared. A structured approach (full inventory, prioritisation by criticality, phased migration) makes it possible to switch core systems overnight or during low-occupancy periods without meaningful impact on hotel operations. What matters most is having a complete picture of the existing infrastructure before anything is touched.

Conclusion

Investing in access control and video surveillance without first assessing the network means buying expensive technology on an unstable foundation. The network isn't just the supporting infrastructure for security systems — it is their lifeblood, and it deserves the exact same level of attention during budgeting and planning.

DaPhi plans and manages network infrastructure for hotel operators — from the initial inventory and secure segmentation through to complete redundancy design. Talk to us before your next security system goes in.