Operational notes Observatory

Hikvision v. Ottawa: when the camera becomes a matter of state

5 min read

A surveillance camera on a building façade, seen from below
A connected camera is a computer with eyes. The question is who gets to look.

On 27 June 2025 the Canadian government did something rare: it ordered a foreign company to shut down. Not a fine, not a procurement restriction — the total cessation of operations of Hikvision Canada, on national security grounds. Hikvision is the world’s largest manufacturer of surveillance cameras, with a substantial stake held by Chinese state capital. The company has challenged the order before the Federal Court, and the appeal is still pending. But the Canadian case is no bolt from the blue: it is the latest chapter in a story that has run for seven years, and one that closely concerns Europe too — where those same cameras watch over ministries, courts and public offices. Ours included.

The facts, in order

  • October 2019: the US Department of Commerce adds Hikvision to the Entity List, along with 27 other Chinese entities, for involvement in the surveillance of the Uyghur minority in Xinjiang. Since 2019, under the National Defense Authorization Act, US federal agencies have been barred from purchasing its equipment.
  • April 2021: the European Parliament calls for the removal of Hikvision thermal cameras from its own premises in Brussels.
  • December 2021: in Italy, an investigation by the Rai programme Report documents more than 1,100 Hikvision cameras purchased by the Ministry of Justice and installed in the wiretapping rooms of 134 public prosecutors’ offices, alongside devices in ministries and other institutional buildings.
  • November 2022: the American FCC bans any new authorisation for Hikvision and Dahua equipment, calling it “an unacceptable risk to national security”. In the same days the United Kingdom bans Chinese cameras from sensitive government sites, citing China’s 2017 intelligence law, which obliges companies to cooperate with Beijing’s security services.
  • 27 June 2025: Canada, at the end of a review under the Investment Canada Act, orders Hikvision Canada to cease operations. Industry Minister Mélanie Joly also announces a ban on the purchase and use of Hikvision products across all federal departments. The details of the security assessment are not made public.
  • 7 July 2025: Hikvision files its appeal with the Federal Court. The company’s position is unequivocal: the decision “lacks factual basis, procedural fairness and transparency”; Hikvision has always denied posing a security risk to any country. In September the Court dismisses the request for a stay: the closure proceeds, while the case continues on its merits.

It should be said plainly: no Western government has made public any proof of a backdoor. The decisions rest on risk assessments — ownership, jurisdiction, the manufacturer’s legal obligations — not on a documented incident. That is exactly what makes this interesting for anyone buying technology.

Lesson 1: video surveillance is critical infrastructure, even if you don’t treat it as such

A modern IP camera is not a passive eye: it is a computer connected to the network, with firmware that updates remotely, often with onboard computer vision. Whoever controls that firmware controls a sensor inside your perimeter. The governments that have banned Hikvision are not disputing the quality of the products — excellent, at prices that are hard to beat — but the chain of command above the device: a manufacturer subject to a law that can compel it to cooperate with a foreign intelligence service. The reasoning applies to ministries and public prosecutors’ offices, but equally to a manufacturing company monitoring its own production lines or to a public-sector body watching over its own offices: the question is not “does it work?”, but “who can see through it?”.

Lesson 2: the real problem is the installed base, and almost nobody knows it

The European paradox is plain to see: devices banned from sensitive sites in Washington and London remain widespread in public and private buildings across the continent, Italy included. And the blind spot is nearly always the same: the inventory doesn’t exist. Cameras are bought in batches, installed by different integrators, sometimes resold under other brands as OEM. Many organisations do not know how many they have, who owns them, what firmware they run, or what they talk to on the network. Before any decision — replace, segment, keep — an audit of the installed base is needed: it is the same principle we apply to AI systems, because you cannot govern what you cannot see.

Lesson 3: procurement criteria for connected devices need to be written in advance

The Hikvision case shows that geopolitical risk has entered the tender specifications. Anyone buying a connected device today — camera, sensor, industrial controller — should assess, beyond price and performance: the manufacturer’s jurisdiction and the legal obligations it is subject to; the firmware update policy and its guaranteed duration; the possibility of running the device without the manufacturer’s cloud; the replaceability clauses. The European regulatory direction is already clear: the Cyber Resilience Act will impose security and vulnerability-management obligations on manufacturers of connected products, with the first deadlines from September 2026. Arriving there with a compliance posture already in place costs less than playing catch-up.

What to do

  1. Take stock of your cameras and connected devices: how many, where, which make, who installed them, who administers them.
  2. Verify the actual manufacturer, not just the brand on the casing: many devices are OEM.
  3. Segment the network: cameras should not be able to see management systems, nor reach out to the Internet unless strictly necessary.
  4. Check the firmware: versions, known vulnerabilities, update channel.
  5. Write procurement criteria for future purchases: jurisdiction, updates, offline operation, exit options.
  6. Decide according to context: the same camera carries a different risk profile in a warehouse than in a meeting room.

Want a map of your installed base of connected devices — and purchasing criteria that will hold up for the next five years? Half an hour with one of our experts to get started.

Sources