19/06/2026
Your IP cameras and building management systems are in NIS2 scope, and they can't run security software.
That's the catch most mid-market teams hit. These devices sit on the same network as your laptops, but the agent-based tools protecting your endpoints have nothing to attach to. According to Claroty (Oct 2025), 75% of organisations have building devices on their network with known exploited vulnerabilities.
A perimeter firewall won't help. A compromised camera moves sideways to a workstation on the same VLAN, traffic that never crosses the edge.
The fix is network-layer isolation: an inline bridge per device, default deny, no agent, no downtime. Guide in the comments.