// GENETEC HEALTH CHECK · HANS STUDY · ONTARIO, CANADA

Genetec health check

A Security Center environment can look healthy and still be carrying risk you cannot see. It passes commissioning. The video plays. The doors unlock. And underneath, an Archiver is fighting the Directory for I/O, a Media Router is still pointed at an address that stopped existing two migrations ago, SQL is eating the box unnoticed, and a hardening baseline nobody ever applied. None of it shows up until the system is under load, or until someone asks for footage that was never recorded.

What the health check covers

The assessment looks across the whole stack, because Genetec problems do not stay in one layer. A streaming complaint can be a NIC buffer, a QoS gap, a Media Router redirect, a saturated archive volume, or a throttled CPU, and chasing it in only one of those places is how systems stay broken for months.

The review spans:

GHC-01

Architecture and roles

Role placement, Directory and Archiver separation, sizing against actual camera load and headroom, federation versus distributed design, and the architectural decisions that pass commissioning and fail later.

GHC-02

Servers and tuning

Power plan, SQL Server memory, NIC buffers, TempDB placement, and the configuration gaps that throttle hardware that looks adequate on paper.

GHC-03

Storage and archives

Array design for sustained write performance, RAID protection, allocation unit sizing, indexing and short-name overhead, retention against real bitrate, and failover paths.

GHC-04

Network and connectivity

Traffic separation, QoS, Media Router redirect addresses, and the streaming mismatches that get misdiagnosed as camera faults.

GHC-05

Health monitoring

Whether the Health Monitor role is deployed, whether System status and health history are used operationally, and whether anyone actually gets told when something breaks.

GHC-06

Security and hardening

RBAC, Active Directory integration, certificate management, encrypted communications, and the gap between the install defaults and a defensible baseline.

GHC-07

Cameras and field devices

Default credentials, codec and stream configuration, recording strategy, and standard profiles.

GHC-08

Lifecycle and ownership

Upgrade discipline, backup and rollback, and whether anyone owns the system end to end or whether it lives in the seams between teams.

Common issues identified

Across government, law enforcement, airports, healthcare, and enterprise environments, the same problems repeat. Overloaded roles on undersized servers. Storage sized for capacity with no thought to write performance. Built-in health monitoring switched off or ignored. Cameras left at factory defaults, credentials included. Thin hardening on a system that is supposed to be a security control, not a liability. Federation designed wrong at the architecture phase. Upgrade habits that swing between frozen-three-versions-back and first-week-of-a-.0-release.

Most environments I assess are running five or six of these at once, under a system that technically works. The point of the Health Check is to surface them while they are still cheap to fix.

For the full pattern, see the 10 most common Genetec Security Center issues.

Who this is for

This is for organizations that depend on Security Center and cannot afford to find out about its weak points during an incident. Public sector and critical infrastructure. Law enforcement. Airports. Healthcare. Enterprise security teams running multi-server or multi-site estates.

It is most useful when the system has grown past its original design assumptions, when it changed hands between integrators, when performance has started to drift, or when an audit, an upgrade, or an expansion is coming and you want to walk in knowing where you actually stand.

What you receive

The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.

  • A findings report organized by severity and by system layer, in plain language your security team and your IT team can both act on.
  • Specific, configuration-level recommendations tied to Genetec's published guidance and real operational practice, not generic advice.
  • A prioritized action list that separates what to fix now, what to schedule, and what to design around.
  • A working session to walk through the findings and answer the questions the report raises.

Recommendations do not change based on who is selling. There is no product I am steering you toward at the end of this.

Delivery and scope

Remote delivery via the DHD, a remote access device, where the system cannot be reached over the network.

How the work is delivered

Remote

Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.

DHD

The DHD, a pre-configured remote access device, ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.

Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.

On site

For work that needs someone in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Travel and on-site time are added to the written quote before work starts.

What a health check does not include

Listed because an unstated exclusion is what turns an agreed scope into an argument at invoice time, and that is the exact failure this practice exists to review other people for.

  • Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
  • Configuration changes. Nothing is altered on a live system during a review.
  • Licence, hardware or software costs, which are yours and are bought direct.
  • Vendor support cases, escalations, or dealings with your integrator on your behalf.
  • On-site attendance, unless added explicitly.
  • Ongoing monitoring or a retainer. A health check is a point-in-time assessment.

Checklist preview

The Health Check follows a structured checklist across ten areas: environment overview, servers and roles, storage and archives, network and connectivity, health monitoring and alerts, security and access control, cameras and field devices, integrations and federation, backups, DR, and upgrades, and roles, processes, and ownership.

You can work through the same checklist yourself before we ever talk. It prints cleanly as a leave-behind for your team.

For the host underneath, the Genetec firewall rules and Defender exclusions are published as an open PowerShell script on GitHub.

GHC-10

Genetec health audit (in-depth) →

Long-form audit utility with severity weighting, field notes per question, and PDF export. The same source material the Health Check engagement is built on.

Related advisory areas

GHC-11

Genetec Security Center consulting →

Architecture review, sizing, federation, deployment oversight, and post-deployment troubleshooting beyond the focused Health Check engagement.

GHC-12

CCTV and access control →

Vendor-agnostic CCTV and access control advisory across Genetec, C-CURE, Milestone, Avigilon, Axis, Bosch.

GHC-14

Windows Hardening for Genetec →

Practitioner course covering the Windows side: accounts, attack surface reduction, Defender, audit logging, and Sysmon for Genetec roles.

Common questions

What is a Genetec health check?

A focused, independent assessment of a Genetec Security Center environment across architecture, servers, storage, network, health monitoring, security, cameras, integrations, and lifecycle. It finds the issues that pass commissioning and surface later under load, and turns them into a prioritized remediation plan.

What does the health check cover?

The whole stack, because Genetec problems do not stay in one layer. Role architecture and sizing, server tuning, storage and archive design, network and Media Router configuration, health monitoring, security hardening and RBAC, camera and stream configuration, federation and integrations, and backup, DR, and upgrade discipline.

Who is the Genetec health check for?

Organizations that depend on Security Center and cannot afford to discover its weak points during an incident: public sector and critical infrastructure, law enforcement, airports, healthcare, and enterprise security teams running multi-server or multi-site estates. It is most useful when a system has grown past its original design, changed hands, started to drift, or has an audit, upgrade, or expansion coming.

Will you recommend products or hardware to buy?

No. The work is vendor agnostic, with no commissions and no margin on anything specified. Recommendations do not change based on who is selling, and there is no product being steered toward at the end of the assessment.

What do I receive at the end?

A findings report organized by severity and by system layer, in plain language a security team and an IT team can both act on, specific configuration-level recommendations tied to Genetec guidance and real practice, a prioritized action list separating what to fix now from what to schedule, and a working session to walk through it.

How is this different from a vendor or reseller system review?

A vendor review is scoped to what the vendor sells. This assessment is independent and spans the full stack, including the network, servers, and storage that a Genetec-only review tends to skip, and it is the layer where most real problems live.

Health checks for other platforms

Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.

HC-01

C-CURE 9000 →

CrossFire, iSTAR estate, SQL dependency and integrations.

Start a conversation

If your Security Center environment has grown beyond its original design, changed hands, or simply never had a second set of eyes across the whole stack, that is exactly what this is for.