Architecture and roles
Role placement, Directory and Archiver separation, sizing against actual camera load and headroom, federation versus distributed design, and the architectural decisions that pass commissioning and fail later.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// GENETEC HEALTH CHECK · HANS STUDY · ONTARIO, CANADA
A Security Center environment can look healthy and still be carrying risk you cannot see. It passes commissioning. The video plays. The doors unlock. And underneath, an Archiver is fighting the Directory for I/O, a Media Router is still pointed at an address that stopped existing two migrations ago, SQL is eating the box unnoticed, and a hardening baseline nobody ever applied. None of it shows up until the system is under load, or until someone asks for footage that was never recorded.
The assessment looks across the whole stack, because Genetec problems do not stay in one layer. A streaming complaint can be a NIC buffer, a QoS gap, a Media Router redirect, a saturated archive volume, or a throttled CPU, and chasing it in only one of those places is how systems stay broken for months.
The review spans:
Role placement, Directory and Archiver separation, sizing against actual camera load and headroom, federation versus distributed design, and the architectural decisions that pass commissioning and fail later.
Power plan, SQL Server memory, NIC buffers, TempDB placement, and the configuration gaps that throttle hardware that looks adequate on paper.
Array design for sustained write performance, RAID protection, allocation unit sizing, indexing and short-name overhead, retention against real bitrate, and failover paths.
Traffic separation, QoS, Media Router redirect addresses, and the streaming mismatches that get misdiagnosed as camera faults.
Whether the Health Monitor role is deployed, whether System status and health history are used operationally, and whether anyone actually gets told when something breaks.
RBAC, Active Directory integration, certificate management, encrypted communications, and the gap between the install defaults and a defensible baseline.
Default credentials, codec and stream configuration, recording strategy, and standard profiles.
Upgrade discipline, backup and rollback, and whether anyone owns the system end to end or whether it lives in the seams between teams.
Across government, law enforcement, airports, healthcare, and enterprise environments, the same problems repeat. Overloaded roles on undersized servers. Storage sized for capacity with no thought to write performance. Built-in health monitoring switched off or ignored. Cameras left at factory defaults, credentials included. Thin hardening on a system that is supposed to be a security control, not a liability. Federation designed wrong at the architecture phase. Upgrade habits that swing between frozen-three-versions-back and first-week-of-a-.0-release.
Most environments I assess are running five or six of these at once, under a system that technically works. The point of the Health Check is to surface them while they are still cheap to fix.
For the full pattern, see the 10 most common Genetec Security Center issues.
This is for organizations that depend on Security Center and cannot afford to find out about its weak points during an incident. Public sector and critical infrastructure. Law enforcement. Airports. Healthcare. Enterprise security teams running multi-server or multi-site estates.
It is most useful when the system has grown past its original design assumptions, when it changed hands between integrators, when performance has started to drift, or when an audit, an upgrade, or an expansion is coming and you want to walk in knowing where you actually stand.
The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.
Recommendations do not change based on who is selling. There is no product I am steering you toward at the end of this.
Remote delivery via the DHD, a remote access device, where the system cannot be reached over the network.
Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.
The DHD, a pre-configured remote access device, ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.
Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.
For work that needs someone in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Travel and on-site time are added to the written quote before work starts.
Listed because an unstated exclusion is what turns an agreed scope into an argument at invoice time, and that is the exact failure this practice exists to review other people for.
The Health Check follows a structured checklist across ten areas: environment overview, servers and roles, storage and archives, network and connectivity, health monitoring and alerts, security and access control, cameras and field devices, integrations and federation, backups, DR, and upgrades, and roles, processes, and ownership.
You can work through the same checklist yourself before we ever talk. It prints cleanly as a leave-behind for your team.
For the host underneath, the Genetec firewall rules and Defender exclusions are published as an open PowerShell script on GitHub.
Interactive 10-section checklist. Mark progress, take notes, save as PDF. Browser-only, no sign-in, no telemetry.
Long-form audit utility with severity weighting, field notes per question, and PDF export. The same source material the Health Check engagement is built on.
Architecture review, sizing, federation, deployment oversight, and post-deployment troubleshooting beyond the focused Health Check engagement.
Vendor-agnostic CCTV and access control advisory across Genetec, C-CURE, Milestone, Avigilon, Axis, Bosch.
The network underneath Genetec. Most Genetec performance problems are network problems.
Practitioner course covering the Windows side: accounts, attack surface reduction, Defender, audit logging, and Sysmon for Genetec roles.
A focused, independent assessment of a Genetec Security Center environment across architecture, servers, storage, network, health monitoring, security, cameras, integrations, and lifecycle. It finds the issues that pass commissioning and surface later under load, and turns them into a prioritized remediation plan.
The whole stack, because Genetec problems do not stay in one layer. Role architecture and sizing, server tuning, storage and archive design, network and Media Router configuration, health monitoring, security hardening and RBAC, camera and stream configuration, federation and integrations, and backup, DR, and upgrade discipline.
Organizations that depend on Security Center and cannot afford to discover its weak points during an incident: public sector and critical infrastructure, law enforcement, airports, healthcare, and enterprise security teams running multi-server or multi-site estates. It is most useful when a system has grown past its original design, changed hands, started to drift, or has an audit, upgrade, or expansion coming.
No. The work is vendor agnostic, with no commissions and no margin on anything specified. Recommendations do not change based on who is selling, and there is no product being steered toward at the end of the assessment.
A findings report organized by severity and by system layer, in plain language a security team and an IT team can both act on, specific configuration-level recommendations tied to Genetec guidance and real practice, a prioritized action list separating what to fix now from what to schedule, and a working session to walk through it.
A vendor review is scoped to what the vendor sells. This assessment is independent and spans the full stack, including the network, servers, and storage that a Genetec-only review tends to skip, and it is the layer where most real problems live.
Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.
CrossFire, iSTAR estate, SQL dependency and integrations.
Edition, Device Pack currency and support entitlement.
Which product family you are in, and what that decides.
Edge analytics, and the device estate that limits them.
Version position, database age, and access level sprawl.
Edition ceiling, gateway topology, and controller firmware.
If your Security Center environment has grown beyond its original design, changed hands, or simply never had a second set of eyes across the whole stack, that is exactly what this is for.
Related work: a Genetec upgrade and multi-terminal stabilization at an international airport.
Read the 10 most common issues
All Genetec resources: services, tools, field writing, and case studies in one place.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.