Hikvision Corrects False Cybersecurity Announcement

By: IPVM Team, Published on Jun 18, 2018

Hikvision has corrected a false cybersecurity announcement that claimed a British government-sponsored program endorsed the cybersecurity of Hikvision's products.

Below, highlighted, are the specific false assertions: 

Hikvision Corrects

After IPVM raised concerns to Hikvision corporate, Hikvision acknowledged this, adding the following correction:

Correction

An earlier version of the press release suggested that the Cyber Essentials Plus status relates to products and has caused some confusion. To clarify, Hikvision has been awarded ‘Cyber Essentials Plus’ accreditation, which directly relates to the security and robustness of our own infrastructure within the UK operation. It was never our intention to mislead the reader with inference that the accreditation related in any way to our products. We sincerely apologise for the unclear statement about the award.

Cyber Essentials Plus Explained

Cyber Essentials is a UK sponsored government program that aims to help organizations protect against cyber attacks. The requirements of the program list the scope of this certification as IT infrastructure, not products manufactured:

Assessment and certification can cover the whole of the Applicant's IT infrastructure, or a sub-set. Either way, the boundary of the scope must be clearly defined in terms of the business unit managing it, the network boundary and physical location. [emphasis added]

Hikvision received the Cyber Essentials 'Plus' certification, which consists of an auditor doing a vulnerability assessment of their UK office. The certification costs 1,999 GBP (~$2,655 USD).

History of Misrepresenting Cybersecurity

Hikvision has repeatedly misrepresented the cybersecurity of their products, starting with claiming their backdoor was simply a 'privilege escalation vulnerability', misleading their dealers on the backdoorhiring Cisco and issuing a press release with them the day after the backdoor was confirmed, announcing a 'dedicated' cybersecurity 'hotline' that has since been demoted to generic technical support, opening a 'source code transparency center' that is neither particularly open nor transparent, and now deceptively turning an IT infrastructure certification into a false endorsement of their products.

No Excuse

Hikvision has no excuse here. Hikvision took the certification so they clearly know it is not about a company's products yet Hikvision's announcement over and over again emphasized products. It is either a question or competence or ethics.

Commend The Correction

That noted, we certainly commend Hikvision and, in particular, their new Global PR lead, Karl Erik Traberg, for quickly and responsibly issuing a correction. It is a small step in the greater scheme of things but indisputably positive that Hikvision is willing to acknowledge mistakes and focus on improvement rather than disparaging critics.

Poll / Vote

5 reports cite this report:

2019 Video Surveillance Cameras Overview on Jan 07, 2019
Each year, IPVM summarizes the main advances and changes for video surveillance cameras, based on our industry-leading testing and...
"At Hikvision, We Build Trust" on Jan 03, 2019
Hikvision has joined a growing number of video surveillance manufacturers marketing their trustworthiness. In a recent trade magazine full page ad...
Genetec UL Cybersecurity Certificate (2900-2-3) Examined on Dec 19, 2018
Proving a company is cybersecure has become a major concern for security companies. But how trustworthy are these certificates? Earlier in 2018, a...
2018 Mid-Year Surveillance Industry Guide on Jun 28, 2018
2018 has been an explosive year for the video surveillance industry, with the industry becoming a global political issue, with the expansion of...
Hikvision Covers Up Racial Profiling And AI Error on Jun 25, 2018
Faced with global scrutiny, led by the US government-funded Voice of America (VOA), Hikvision has covered up evidence showing their racial...
Comments (21) : PRO Members only. Login. or Join.

Related Reports

Last Chance - Register Now - October 2019 IP Networking Course on Oct 10, 2019
Last Chance - Register Now - Fall 2019 IP Networking Course. The course starts next week. This is the only networking course designed...
Hikvision ColorVu is Smart Marketing on Oct 03, 2019
Hikvision ColorVu (see IPVM test results) is smart marketing, a lesson to be learned by competitors and a rising trend. Inside this note, we...
Directory of 70 Video Surveillance Startups on Sep 18, 2019
This directory provides a list of video surveillance startups to help you see and research what companies are new or not yet broadly known. 2019...
ASIS GSX 2019 Final Show Report on Sep 12, 2019
IPVM went to Chicago for ASIS GSX 2019, with many exhibitors disappointed about traffic and the exhibitor schedule changing next year. However,...
Critical Vulnerability Across 18+ Network Switch Vendors: Cisco, Netgear, More on Aug 26, 2019
Cisco, Netgear and more than a dozen other brands, including small Asian ones, have been found to share the same critical vulnerability, discovered...
Dahua Wiretapping Vulnerability on Aug 02, 2019
IPVM has validated, with testing, and from Dahua, that many Dahua cameras have a wiretapping vulnerability. Even if the camera's audio has been...
"Stats Don't Lie" Says Deceptive IFSEC on Jul 30, 2019
While IFSEC has declared #statsdontlie and trumpeted seemingly skyrocketing visitor numbers, they are decieving about their show's problems. On...
ZeroEyes Gun Detection Startup on Jul 16, 2019
A gun detection video analytics startup, ZeroEyes, is being led by a group of 6 former Navy SEALs, aiming to "save lives" by using AI to assist...
Bosch Integrating Sony Video Security Sales And Marketing Team on Jul 03, 2019
What is the future of Sony in video surveillance? In 2016, Bosch and Sony announced an atypical 'partnership'. Now, Bosch tells IPVM that they...
Ivideon Russian VSaaS Profile on Jun 27, 2019
Ivideon was an early VSaaS entrant, initially focusing on the consumer market, claiming massive growth to IPVM in 2014. We spoke to Ivideon, to...

Most Recent Industry Reports

Government-Owned Hikvision Wants To Keep Politics Out Of Security on Oct 21, 2019
'Politics' made Hikvision the goliath it is today. It was PRC China 'politics' that created Hikvision, funded it, and blocked its foreign...
Integrated IR Camera Usage Statistics 2019 on Oct 21, 2019
Virtually every IP camera now comes with integrated IR but how many actually make use of IR or choose 'super' low light cameras without IR? In...
Alarm Veteran "Demands A Criminal Investigation" Of UL on Oct 18, 2019
The Interceptor's Project pressure against UL continues to rise. Following Keith Jentoft's allegation that "UL Has Blood On Their Hands", Jentoft...
Camect "Worlds Smartest Camera Hub" Tested on Oct 18, 2019
Camect is a Silicon Valley startup that claims the "Smartest AI Object Detection On The Market", detecting not only people and vehicles, but...
Hikvision Global News Reports Directory on Oct 17, 2019
Hikvision has received the most global news reporting of any video surveillance company, ever, ranging from the WSJ, the Financial Times, Reuters,...
Camera Calculator V3.1 Release Improves User Experience on Oct 17, 2019
IPVM has released a new version of our Camera Calculator, V3.1, with significant user experience improvements, a new development plan, and an...
Securing Access Control Installations Tutorial on Oct 17, 2019
The physical security of access control components is critical to ensuring that a facility is truly secure. Otherwise, the entire system can be...
Access Control Course Fall 2019 - Last Chance on Oct 17, 2019
Register Now - Fall 2019 Access Control Course. Thursday, October 17th is the last day to register. IPVM offers the most comprehensive access...
US DoD Comments on Huawei, Hikvision, Dahua Cyber Security Concerns on Oct 16, 2019
A senior DoD official said the US is "concerned" with the cybersecurity of Hikvision, Dahua, and Huawei due to "CCP" (China Communist Party)...
Pelco Sarix Pro3 Camera Tested on Oct 16, 2019
Pelco has released their Sarix Professional Series 3 cameras, claiming "more security detail in challenging scenes with excellent low light and...