In October 2016, the Mirai botnet commandeered hundreds of thousands of internet-connected devices, a large share of them IP cameras and digital video recorders still running factory-default passwords, and turned them on the DNS provider Dyn, disrupting access to Twitter, Netflix and dozens of other services across the US and Europe. The attack gave boardrooms their first clear sight of a problem security engineers had described for years: the camera watching the loading bay was also a computer on the corporate network, and it often sat outside the routines that kept every other networked machine patched and monitored.
10 years on, Axis Communications and Cisco have put that computer in front of the people who maintain everything else. Through Axis Cloud Connect, the Swedish manufacturer’s hybrid cloud platform, supported Axis devices can now be onboarded and monitored inside the Cisco Meraki Dashboard, part of Cisco Cloud Control, alongside the switches and wireless access points that network teams already run. The companies announced the collaboration on 9 September, with Christian P Andersson, Global Product Manager for Axis Cloud Connect, calling it “a blueprint for the future of converged enterprise systems”.
The integration comes in 2 tiers, with Essentials covering centralised device management and visibility into health, connectivity and maintenance, and Advantage adding historical video access, video analytics and 30-day cloud storage. Axis illustrated the problem it is addressing with a supermarket chain whose IT staff can watch network performance across hundreds of branches while the cameras inside those same branches still demand site-by-site checks to confirm they are online and running current firmware. The announcement carried no pricing, no named customers and no figures on how many devices have been onboarded.
Network teams gain the console while security keeps the evidence
Consolidation of this kind creates an awkward question for any organisation that records video under regulatory scrutiny. Once a camera appears on the network team’s screen, responsibility for it becomes harder to trace, and across the GCC, where the UAE’s Personal Data Protection Law and Saudi Arabia’s PDPL govern how personal data, including footage of identifiable people, is handled and retained, that responsibility carries legal weight.
Rudie Opperman, Manager for Engineering & Training MEA at Axis Communications, separated 2 things that tend to blur once dashboards merge. “I would distinguish between management and ownership,” he said. In his account, the Meraki Dashboard gives authorised IT teams a single place to onboard and monitor supported devices, while the obligations that security, compliance and legal departments already hold over video access, retention and privacy remain with those departments, and the integration gives each side a more coordinated operational foundation to work from.
The separation matters because the signals a network engineer watches reveal little about whether footage will hold up as evidence. A camera can be online, running the latest AXIS OS release and reporting perfect health while the recordings it produces are kept too long, exported without authorisation or viewed by people with no reason to see them. Opperman was clear that the dashboard addresses device health and leaves governance to policy. “Customers still need clear policies for who can access video, how long it is retained, when it can be exported and how privacy obligations are met,” he said.
He argued that most organisations should already have those policies, and that the integration is most useful as a reason to bring IT and security stakeholders together around a shared view of the same devices, since for many companies the two groups have until now worked from different tools, different priorities and different definitions of a working camera.
A decade of camera exploits has taught vendors to choose their words carefully
Networked cameras have remained a recurring target on enterprise networks in the decade since Mirai, which makes the security argument for centralised management the part of the proposition buyers will test hardest. Asked what evidence from live deployments showed that moving cameras into the Meraki Dashboard reduced exposure, Opperman cited no deployment data and chose his words with evident care.
“The risk of cyber exists, and that does not disappear,” he said, before offering what he called the responsible claim: that centralised visibility and management can support a more consistent security posture, because administrators can see device status and operating system versions in the same environment where they already track their network infrastructure and wireless access points.
The proposition is plausible, and it remains unproven in public. Visibility into firmware versions reduces risk only when someone acts on what the dashboard shows, and Axis has released no before-and-after figures on patch times, counts of vulnerable devices or incident rates among customers using the integration. Opperman returned several times to the disciplines that must surround the tool for it to make any difference.
“No integration eliminates the risk on its own,” he said. Customers, in his telling, still need network segmentation, access control over who can reach the devices, secure configuration by the teams that install and commission them, and lifecycle management to keep firmware current. Axis publishes its vulnerabilities openly and runs a dedicated CVE handling team, a process Opperman said would continue as it operates today.
Migration starts with an honest count of what is already on the wall
The practical test for the region lies in older estates. Asked how organisations should handle video infrastructure that is often 5 to 10 years old, Opperman described a migration that begins with an inventory and defers any purchasing decision until that inventory is complete.
“A realistic phased migration starts with having visibility,” he said. Organisations first establish what they own and its condition, then identify which of those devices appear on the list supported by the integration, and only then ask whether centralised management would help them at all. Where the answer is yes, equipment that remains fit for purpose stays in service, and upgrades follow over time according to supportability, changing operational requirements and cybersecurity needs.
“If it’s good, keep using it,” he said. The approach matches the hybrid model Axis set out in its announcement, in which existing supported devices remain in place and cloud management is introduced where it delivers the most value, and it suits customers who have already committed capital to on-premise video. It also leaves open a question the announcement does not settle. Axis says the integration opens up large parts of its portfolio, which means buyers with ageing estates will need to establish for themselves how much of their installed base qualifies before the phased path Opperman described becomes available to them.
Axis is betting that physical security consolidates through coexistence
Asked how physical security would consolidate over the next 3 years, Opperman declined to forecast a single platform that does everything. Listening to customers, he said, Axis expects a future built on integration and coexistence, in which buyers keep the freedom to change devices, applications and workflows as their needs shift.
“The Axis and Cisco collaboration is an example of us seeing the world moving in that direction,” he said. In his description, the arrangement offers simpler coordination between the network, “which is what Cisco does well”, and physical security management, without requiring customers to abandon investments they have already made.
The Mirai operators found their targets in 2016 because thousands of cameras sat on networks with default credentials and nobody checking on them. For CIOs in the region weighing the Axis and Cisco integration, the more useful inheritance from that episode is a set of questions to put to vendors and to their own teams before signing: which of the cameras on site are supported, who approves retention and export once those cameras appear in the network console, and what data the vendor can produce to show that shared visibility has shortened the time between a vulnerability bulletin and a patched device.



