Why security systems degrade in year two, and what decision-makers should ask before signing off a project
Ibrahim Awwad, Technical Support Lead, LENSEC
Most escalations that reach my team are not product defects. They are healthy systems that drifted from the design they were installed with. The project was accepted, everyone moved on, and eighteen months later operators face offline cameras, missing archives, and analytics that stopped alerting them.
Across projects, pre-sales, and support, I see the same three patterns in every country and vertical. Behind them is one idea: a security platform is not a construction project. It is a service, and it degrades the way any service does when nobody manages it as one.
1. Sized for Day One, Not Year Three
A video system is sized on a spreadsheet: cameras, resolution, frame rate, retention. The numbers are correct on acceptance day. Then cameras are added without a change request, resolution is raised, retention is extended after an incident. Nobody re-runs the calculation.
The first symptom is not an alert. It is a recording server quietly dropping frames on a saturated network link, until dozens of cameras go offline at once. By then the fix is a hardware purchase.
Capacity must be managed against demand for the life of the service, not designed once. This is where AI earns its place in operations, not only in the video: trend models on storage, throughput, and camera count can forecast the saturation point months ahead.
Ask: What headroom did we design in, who re-validates it when demand changes, and can the system warn us before it runs out? A good answer has a number (we plan for 25 to 30% headroom), an owner, and a forecast.
2. Configuration Drift, and Why AI Makes It Worse
Multi-site programs are delivered to one site at a time. Site one is tuned carefully; sites two through ten are copied from it. Then a camera is moved, a wall is built, and the analytics validated on site one stop producing meaningful events on site seven.
AI analytics amplify this. A detection model is only as good as the scene it was validated on. Change the angle or the lighting and accuracy drops with no error message. Data scientists call it drift.
Operators call it “the system stopped working,” months after it did.
The remedy is discipline: a versioned baseline per site, and the rule that every physical change is assessed against it rather than discovered later. The same AI that suffers from drift can detect it. A sudden fall in event rate on one camera, against its own history and its peers, is an anomaly worth an alert.
Ask: Is there a documented baseline for each site, is every change assessed against it, and does the system flag when analytics output deviate from normal?
3. Busy with Incidents, Blind to Problems
The third pattern is organizational. Most security teams are excellent at incidents: a camera goes offline, someone fixes it. Almost none asks why the same camera went offline eleven times this quarter and removes the cause. The team stays permanently busy, and the system never improves.
This is where AI for operations becomes practical. Correlating events across cameras, servers, network, and storage surfaces what people have no time to find: the switch that drops every night at 02:00, the site whose cameras fail after every power event. Each is one root cause behind dozens of tickets. The machine finds the pattern; people decide the fix.
Ask: How many of our incidents this year were repeated, and who is accountable for making them stop?
Nobody owns “after”
All three patterns share a root. Projects are funded to reach go-live; operations run on whatever is left. The handover meeting is where ownership should transfer, and in most organizations it is where ownership disappears.
Three changes make a measurable difference:
- Treat handover as a transition into service, not a signature. Sizing assumptions, per-site baseline, and agreed service levels are deliverable. Without them the project is not finished.
- Put monitoring in front of operators, with AI filtering. Storage, throughput, camera uptime, and analytics event rates reviewed weekly, with anomaly detection separating the one event that matters from the hundred that do not.
- Budget for operations as a line item. Maintenance, a quarterly configuration review, an annual re-sizing, and a standing review of repeat incidents cost a fraction of an emergency refresh.
A security platform protects people and assets for ten years or more. The first ninety days after go-live decide whether it is still doing that in year five.
Go-live is where the project ends. It is where the service begins.
If any of this sounds familiar in your own environment, I would be glad to talk it through. Reach out to me or the LENSEC support team, and we can look at what a review of your deployment might turn up.