On handover day, connected security systems are easy to judge. The cameras cover the right areas. The cabling is tidy. The app works on the client’s phone. Everything a buyer can see looks right.

The parts that decide whether it stays right are much harder to inspect. Who can get into the system remotely. How the recorder or controller sits on the client’s network. Whether firmware updates will be applied after the engineers leave. Where footage and user data are stored. What happens when a connection drops or a product reaches end of support.

None of that shows up in a neat proposal. The buyer still carries it.

A bigger decision with less to go on

CCTV, access control, intruder alarms and monitoring platforms increasingly run over IP, connect to cloud services and take software updates. Every connection adds something the buyer is responsible for. Many of the people choosing connected security systems, such as facilities teams, managing agents and smaller organisations, are not IT specialists. They are in no position to assess network configuration or patching practice themselves.

So they judge what they can see: price, the design of the proposal, the brand names on the kit list and how confident the salesperson sounds. Those tell a buyer very little about how a company handles the part of the job nobody can see.

Competence has to be visible to count

This is where a careful installer can lose to a less careful one. Two proposals may specify similar equipment. The difference sits in processes the buyer never sees: how default credentials are changed, how remote access is controlled and how security issues are handled after installation.

In high-trust buying decisions, competence only wins work once a buyer can see it. It has to be shown in a form the buyer can understand and check.

What the proof landscape can tell a buyer

Several signals exist. They do different jobs and carry different weight.

Third-party certification through NSI or SSAIB means an independent certification body audits the company against relevant standards and codes of practice, with regular follow-up audits. It is a well-established signal of installer competence in security.

CySPAG, the BSIA’s Cyber Security Product Assurance Group scheme, looks specifically at the cyber side of connected security systems. For manufacturers, it covers how products are built, updated and supported. For installers, it covers the processes for putting systems onto a client’s network. It is a self-declaration registration scheme rather than independent assessment, so it tells a buyer that a company has declared relevant processes are in place. It is one indicator to weigh alongside others.

No certificate or registration confirms that a particular system on a particular network has been set up well. What these signals do is give a buyer a sound place to start asking questions.

Questions to ask about connected security systems

Before choosing a supplier, buyers and specifiers can ask:

  • Who will have remote access to the system and how is that access controlled?
  • How will the system be kept separate from the rest of our network?
  • Who is responsible for firmware and software updates after handover?
  • Where are footage and system data stored and who can view them?
  • What happens if the internet connection or a key component fails?
  • What certification or scheme registration do you hold and what does it cover?

A certificate covers specific services, so scope is worth checking. There is more on this in ACS or NSI? What Security Buyers Are Actually Looking At.

A supplier who answers clearly and can back those answers with evidence makes the buyer’s decision easier to defend.

What this means for certified companies

For third-party certified fire and security companies, holding certification is only part of proving competence. Buyers also need to understand what it covers, how it applies to connected security systems and what the company does beyond it. That explanation belongs on the website, in proposals and in early conversations, while buyers are still forming their shortlist.

For Paddy Kyle’s perspective from the BSIA and more on where CySPAG fits, read Jo Shaer’s Benchmark article on why physical security decisions are becoming cyber risk decisions.

Lollipop works with third-party certified fire and security companies to make their competence easier for buyers to see, understand and check before they choose.

Struggling to get enough of the Right enquiries?

Since 2010, Lollipop has helped Fire & Security businesses like yours stand out in a crowded market and win millions of pounds of work…

Our Fire & Security Visibility Engine™ gets the Right Message to the Right Person at the Right Time. So you can win more of the Right Work with less effort.

Curious how it could work for your business?

"Genuine enquiries… at a steady pace"
Phil Clarke, CCTV Hire & Sales
Book your free Visibility call with Jo

Limited slots available — book now to secure yours

Happy Fire & Security director

Trusted by the Fire & Security industry for websites, lead generation and sales since 2010...