Is an ip camera safe? What actually makes one secure in India?
Yes, an IP camera is safe to use if it meets India's ER-01 cybersecurity requirements and you change the default password before connecting it to your network. ER-01 certification means a camera has been officially tested and approved for cybersecurity by MeitY's STQC directorate, which checks for encrypted passwords and secure login credentials.Â
An uncertified camera with a default password like "admin" or "1234" is the single biggest reason IP cameras get hacked, not the technology itself.Â
Once a camera meets ER-01 and you lock down the password, the risk of a stranger accessing your feed drops to something close to negligible.
The confusion around IP camera safety usually comes from two separate things getting mixed up: whether the camera itself is built securely, and whether you've set it up securely. Both matter, and India is one of the few markets where the first one is now a legal requirement, not just good advice.
What makes an IP camera unsafe?
An IP camera becomes a target when one or more of these conditions exist:
- Default credentials left unchanged. Every unit of the same model ships with the same username and password until you change it. A hacker doesn't need to guess your password specifically, they scan for cameras still running the factory default.
- No encryption on the video stream or login page. If the camera's login page doesn't use an HTTPS URL, the username and password you enter aren't encrypted, and a hacker with access to your network traffic can capture them.
- Outdated firmware. Firmware is the camera's built-in software. Manufacturers patch known exploits through firmware updates, so a camera running old firmware is running with known holes still open.
- Port forwarding left open for remote access. Port forwarding gives a direct connection from your phone to the camera across the internet, but it also exposes the camera directly, and a VPN or P2P connection is a safer alternative if lightning-fast response time isn't the priority.
- P2P "plug and play" cameras with known protocol flaws. Budget cameras that use certain peer-to-peer connection systems, including one called iLnkP2P used in millions of devices, let attackers calculate device IDs and connect directly, bypassing your router's firewall entirely. This matters specifically for cheap imported cameras sold without any India certification, since P2P convenience is often the reason they skip encryption altogether.
What ER-01 and STQC certification actually require?
STQC stands for standardisation testing and quality certification, the government body under MeitY that tests electronic products sold in India. ER-01 is one of six essential requirements published in MeitY's April 2024 gazette notification: no default passwords, encrypted video streams over TLS or HTTPS, secure boot with signed firmware, disabled debug and test ports, supply chain transparency on chipset origin, and a published vulnerability disclosure policy.Â
In plain terms, a certified camera cannot ship with a password anyone can guess, cannot send your footage unencrypted, and cannot boot unverified software. That's the difference between "safe if you configure it right" and "safe by design."
IP-based CCTV cameras sold in India have needed ER-01 compliance since April 2025. From April 1, 2026, selling a non-compliant camera can carry penalties, so buying uncertified stock isn't just a security risk anymore; it's a compliance risk for the seller and, in commercial deployments, for the buyer too.
How to secure an IP camera you already own?
If your camera predates ER-01 or you're not sure of its certification status, these steps still apply and cover most of the risk:
- Change the default username and password the moment you unbox it. Use a password you haven't reused anywhere else.
- Turn on two-factor authentication if the camera's app supports it. This adds a second check beyond the password alone.
- Check for and install firmware updates every few months.
- Avoid manual port forwarding for remote access. Use the manufacturer's cloud app or a VPN connection instead.
- For offices or installations with multiple cameras, put them on a separate VLAN from your main network. If a camera is ever compromised, this limits what else on the network is reachable.
How to tell if your camera has been hacked
A few signs are worth checking periodically: unexpected changes to camera settings or names you didn't make, the camera light or speaker activating on its own, unusual account login activity, or a sudden spike in your camera's data usage compared to its usual pattern. Any one of these on its own could be a glitch, but two or more together are worth investigating.
Frequently asked questions
Can any IP camera be hacked?
Any device connected to the internet can technically be attacked, but a certified camera with a changed password, updated firmware, and no open ports is close to the safest setup available to a home or business user today.
Is a wired IP camera safer than a wireless one?
Wired cameras remove the wifi attack surface but still connect to your network and internet, so the same password, firmware, and encryption rules apply either way.


Access Control
Smart Sensors And Automation
Network Adapters and Accessories
PoE Switches
Point To Point Wireless Radio
Routers
IP Cameras
Memory Cards
NVR
Smart WiFi Cameras
Desktop & Laptop RAMs
Internal and External Hard Drives
NAS Storage & Enclosures
SSD and NVMe Drives
USB Flash Drives