// GENETEC HEALTH CHECK · HANS STUDY · ONTARIO, CANADA

Genetec Health Check

A Security Center environment can look healthy and still be carrying risk you cannot see. It passes commissioning. The video plays. The doors unlock. And underneath, an Archiver is fighting the Directory for I/O, a Media Router is still pointed at an address that stopped existing two migrations ago, SQL is quietly eating the box, and a hardening baseline nobody ever applied. None of it shows up until the system is under load, or until someone asks for footage that was never recorded.

What the Health Check covers

The assessment looks across the whole stack, because Genetec problems do not stay in one layer. A streaming complaint can be a NIC buffer, a QoS gap, a Media Router redirect, a saturated archive volume, or a throttled CPU, and chasing it in only one of those places is how systems stay broken for months.

The review spans:

Architecture and roles

Role placement, Directory and Archiver separation, sizing against actual camera load and headroom, federation versus distributed design, and the architectural decisions that pass commissioning and fail later.

Servers and tuning

Power plan, SQL Server memory, NIC buffers, TempDB placement, and the configuration gaps that throttle hardware that looks adequate on paper.

Storage and archives

Array design for sustained write performance, RAID protection, allocation unit sizing, indexing and short-name overhead, retention against real bitrate, and failover paths.

Network and connectivity

Traffic separation, QoS, Media Router redirect addresses, and the streaming mismatches that get misdiagnosed as camera faults.

Health monitoring

Whether the Health Monitor role is deployed, whether System status and health history are used operationally, and whether anyone actually gets told when something breaks.

Security and hardening

RBAC, Active Directory integration, certificate management, encrypted communications, and the gap between the install defaults and a defensible baseline.

Cameras and field devices

Default credentials, codec and stream configuration, recording strategy, and standard profiles.

Lifecycle and ownership

Upgrade discipline, backup and rollback, and whether anyone owns the system end to end or whether it lives in the seams between teams.

Common issues identified

Across government, law enforcement, airports, healthcare, and enterprise environments, the same problems repeat. Overloaded roles on undersized servers. Storage sized for capacity with no thought to write performance. Built-in health monitoring switched off or ignored. Cameras left at factory defaults, credentials included. Thin hardening on a system that is supposed to be a security control, not a liability. Federation designed wrong at the architecture phase. Upgrade habits that swing between frozen-three-versions-back and first-week-of-a-.0-release.

Most environments I assess are running five or six of these at once, under a system that technically works. The point of the Health Check is to surface them while they are still cheap to fix.

For the full pattern, see the 10 most common Genetec Security Center issues.

Who this is for

This is for organizations that depend on Security Center and cannot afford to find out about its weak points during an incident. Public sector and critical infrastructure. Law enforcement. Airports. Healthcare. Enterprise security teams running multi-server or multi-site estates.

It is most useful when the system has grown past its original design assumptions, when it changed hands between integrators, when performance has started to drift, or when an audit, an upgrade, or an expansion is coming and you want to walk in knowing where you actually stand.

What you receive

The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.

  • A findings report organized by severity and by system layer, in plain language your security team and your IT team can both act on.
  • Specific, configuration-level recommendations tied to Genetec's published guidance and real operational practice, not generic advice.
  • A prioritized action list that separates what to fix now, what to schedule, and what to design around.
  • A working session to walk through the findings and answer the questions the report raises.

Recommendations do not change based on who is selling. There is no product I am steering you toward at the end of this.

Scope and pricing

Fixed price, agreed in writing before the work starts. No hourly meter, no scope creep, and no invoice larger than the conversation suggested. Nothing is sold at the end of it either, which is the independence policy.

// Start here

Starter health check

$500

One system, any size

Remote, 90 minutes, live

  • Version position against end of life and end of support
  • The upgrade path in order, with the traps on it
  • Obvious risks visible without a full review
  • A straight answer on whether a full health check is worth your money

Credited in full against a full health check booked within 30 days.

// Most common

Health check, single site

$4,500

One site, up to 150 cameras

Remote. Remote unit or on site available

  • Full review across every layer listed on this page
  • Findings report by severity and by system layer
  • Configuration-level recommendations tied to published guidance
  • Prioritized action list separating now, scheduled, and design-around
  • A 90-minute working session to walk it through

// Multi-site

Health check, multi-site

$9,500

Up to 3 sites, up to 500 cameras

Remote. Remote unit or on site available

  • Everything in the single-site review, across the estate
  • Redundancy, failover and database availability reviewed as one system
  • Cross-site behaviour checked against what the design assumed
  • A 90-minute working session to walk it through

// Larger estates

Enterprise

From $18,000

Beyond 3 sites or 500 cameras

Scoped per engagement

  • Scoped and priced in writing before anything starts
  • Unusual integration, compliance or jurisdictional requirements accommodated

Extend a tier instead of jumping to the next one

Estates rarely land neatly on a boundary. If yours sits just past one, add to the tier below rather than paying for the one above. The rates follow the same slope as the tiers, so extending is never a worse deal than upgrading.

Additional 100 devices $1,200

Cameras, doors, readers or controllers beyond the tier allowance. Counted as configured, not as licensed. (per 100)

Additional site $2,000

A further site beyond the tier allowance, reviewed to the same depth and included in the same report. (per site)

Remote unit deployment $450

Pre-configured appliance shipped to site and returned. See delivery below. (per deployment)

On-site day $2,400

Where physical inspection is required. Travel agreed in writing before it is incurred. (per day, plus travel at cost)

Additional working session $650

A further 90-minute session, usually for a different audience such as IT, operations or a vendor. (per session)

Board-ready executive summary $800

The findings translated into a short document for a board, council or executive, written to be read by somebody non-technical. (one-off)

Expedited turnaround 25% surcharge

Findings inside five business days rather than the standard window. Subject to availability.

How the work is delivered

Remote Included

Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.

Remote unit $450

A pre-configured unit ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.

Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.

On site Quoted

Where the work genuinely requires being in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Day rate plus travel at cost, agreed in writing up front and never added afterwards.

What a health check does not include

Listed because an unstated exclusion is what turns a fixed price into an argument at invoice time, and that is the exact failure this practice exists to review other people for.

  • Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
  • Configuration changes. Nothing is altered on a live system during a review.
  • Licence, hardware or software costs, which are yours and are bought direct.
  • Vendor support cases, escalations, or dealings with your integrator on your behalf.
  • On-site attendance, unless added explicitly.
  • Ongoing monitoring or a retainer. A health check is a point-in-time assessment.

Prices are for a Genetec Security Center environment and are held for 30 days from quotation. Travel, where an on-site day is added, is charged at cost and agreed in writing before it is incurred.

Checklist preview

The Health Check follows a structured checklist across ten areas: environment overview, servers and roles, storage and archives, network and connectivity, health monitoring and alerts, security and access control, cameras and field devices, integrations and federation, backups, DR, and upgrades, and roles, processes, and ownership.

You can work through the same checklist yourself before we ever talk. It prints cleanly as a leave-behind for your team.

Genetec Health Check Checklist →

Interactive 10-section checklist. Mark progress, take notes, save as PDF. Browser-only, no sign-in, no telemetry.

Genetec Health Audit (in-depth) →

Long-form audit utility with severity weighting, field notes per question, and PDF export. The same source material the Health Check engagement is built on.

Related advisory areas

Genetec Security Center Consulting →

Architecture review, sizing, federation, deployment oversight, and post-deployment troubleshooting beyond the focused Health Check engagement.

CCTV and Access Control →

Vendor-agnostic CCTV and access control advisory across Genetec, C-CURE, Milestone, Avigilon, Axis, Bosch.

Enterprise Network Architecture →

The network underneath Genetec. Most Genetec performance problems are network problems.

Windows Hardening for Genetec →

Practitioner course covering the Windows side: accounts, attack surface reduction, Defender, audit logging, and Sysmon for Genetec roles.

Common questions

What is a Genetec Health Check?

A focused, independent assessment of a Genetec Security Center environment across architecture, servers, storage, network, health monitoring, security, cameras, integrations, and lifecycle. It finds the issues that pass commissioning and surface later under load, and turns them into a prioritized remediation plan.

What does the Health Check cover?

The whole stack, because Genetec problems do not stay in one layer. Role architecture and sizing, server tuning, storage and archive design, network and Media Router configuration, health monitoring, security hardening and RBAC, camera and stream configuration, federation and integrations, and backup, DR, and upgrade discipline.

Who is the Genetec Health Check for?

Organizations that depend on Security Center and cannot afford to discover its weak points during an incident: public sector and critical infrastructure, law enforcement, airports, healthcare, and enterprise security teams running multi-server or multi-site estates. It is most useful when a system has grown past its original design, changed hands, started to drift, or has an audit, upgrade, or expansion coming.

Will you recommend products or hardware to buy?

No. The work is vendor agnostic, with no commissions and no margin on anything specified. Recommendations do not change based on who is selling, and there is no product being steered toward at the end of the assessment.

What do I receive at the end?

A findings report organized by severity and by system layer, in plain language a security team and an IT team can both act on, specific configuration-level recommendations tied to Genetec guidance and real practice, a prioritized action list separating what to fix now from what to schedule, and a working session to walk through it.

How is this different from a vendor or reseller system review?

A vendor review is scoped to what the vendor sells. This assessment is independent and spans the full stack, including the network, servers, and storage that a Genetec-only review tends to skip, and it is the layer where most real problems live.

Health checks for other platforms

Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.

C-CURE 9000 →

CrossFire, iSTAR estate, SQL dependency and integrations.

Milestone XProtect →

Edition, Device Pack currency and support entitlement.

Avigilon Unity and Alta →

Which product family you are in, and what that decides.

AXIS Camera Station →

Edge analytics, and the device estate that limits them.

Lenel OnGuard →

Version position, database age, and access level sprawl.

Kantech EntraPass →

Edition ceiling, gateway topology, and controller firmware.

Start a conversation

If your Security Center environment has grown beyond its original design, changed hands, or simply never had a second set of eyes across the whole stack, that is exactly what this is for.