Most school security estates were never designed as a whole. They built up over years, from several installers, and the knowledge left with them. Before you repair, replace or sign a new contract, find out what you have: list every device, test it, check what is actually being recorded, regain admin access and write it all down. Do not factory reset anything until you know what it will erase. Then fix in order of risk, not in order of whoever quotes first.
Ask a school business manager what CCTV their school has, and the honest answer is often a shrug. There is a recorder in a cupboard. Some cameras work. Someone, years ago, had the password.
That is not negligence. It is how security estates grow. This guide is for schools that have inherited a system nobody fully understands, and want to get it back under control without being sold a new one they may not need.
How schools end up here
A typical school estate looks something like this. Cameras went in after a break-in a decade ago. A different firm added more when the new block was built. Access control came with an academy conversion, and the intruder alarm predates everyone in the office.
Each installer kept their own records, if they kept any. Staff who knew the system moved on. Maintenance lapsed when a budget was cut, or when the installer closed. Nothing failed dramatically, so nobody looked.
Multi-academy trusts often meet this at scale. A trust that takes on a new school also takes on whatever security it has, usually with no handover at all.
Six symptoms and what they usually mean
| Symptom | Usual causes | First check |
|---|---|---|
| Live picture, but no recordings | Failed or full hard drive, recording schedule off, settings lost after a power cut | Play back a specific hour from last week on every camera |
| Nobody knows the passwords | Installer kept them, or they left with a member of staff | Check contracts and old emails, then ask the installer in writing |
| Installer gone or not answering | Business closed, sold, or lost interest in small contracts | Find the last invoice and contract; note what you paid for |
| Cameras black or blurred at night | Failed infrared, dirty or misted lenses, power or cabling faults | Review footage from after dark, not just daytime |
| Several systems that don't talk | Different installers, platforms and eras | List each system, where its recorder is and who can log in |
| Old firmware, expired warranties | No maintenance contract for years | Note model numbers and check whether the maker still supports them |
The first symptom is the most dangerous, because it is invisible. The live view comes straight from the cameras, so the screen in reception can look perfect while nothing has been saved for months. You only find out when you need footage of an incident.
Why it matters more than it looks
Safeguarding and evidence
CCTV that does not record cannot support an investigation, an allegation or a police request. Footage that exists but is too dark or blurred to identify anyone is little better. Our guide to choosing a school CCTV system covers what usable footage needs.
Data protection
The school is the data controller for its CCTV under UK GDPR, whoever installed it. That means you must be able to find, export and delete footage yourself. If someone asks for footage of themselves, you have one month to respond to a subject access request. You cannot do that from a recorder nobody can log into. See CCTV and data protection.
Network security
Recorders and cameras are computers on your network. Units running years-old firmware, still on default passwords, or reachable from the internet are an easy way in. This is one of the most common findings on inherited systems, and one of the cheapest to fix. Our guide to cyber security for schools explains why.
Martyn's Law and lockdown
Under Martyn's Law, schools with 200 or more people on site will need workable procedures for lockdown, evacuation, invacuation and communication. The Act does not require new equipment, but rehearsing those procedures is often when schools discover the door that will not lock or the alert that does not reach the sports hall. Our complete Martyn's Law guide sets out what the Act actually requires.
Four things not to do
- Don't factory reset the recorder to get back in. On some models a reset wipes configuration, and sometimes recorded footage. Export anything you need first, and try the manufacturer's password recovery route before resetting.
- Don't accept a rip-and-replace quote before an audit. Many inherited systems need drives, firmware and documentation, not new cameras. Replace in phases where equipment is genuinely finished.
- Don't share admin passwords by email or on a sticky note. Once you regain access, record credentials in a password manager or vault, with a named owner and a backup holder.
- Don't sign a maintenance contract without a baseline. If nobody records what was broken on day one, every later argument about what is covered starts from nothing.
A six-step method you can start this week
You can do most of this yourself with a site plan, a clipboard and an afternoon. A specialist makes it faster, but the method is the same.
- List what you think you have. Every system: CCTV, access control, intruder alarm, fire detection. Where the recorder or panel is, who installed it, who maintains it, and any paperwork.
- Walk the site. Mark every camera, door reader, keypad and panel on a plan. You will find devices nobody listed, and listed devices that are not there.
- Check what is actually recorded. Play back footage from a set time last week, in daylight and after dark, for every camera. Note the oldest recording available: that is your real retention period.
- Regain admin access. Ask the original installer in writing. If that fails, use the manufacturer's recovery route, which normally needs proof of ownership and physical access.
- Write it down properly. One asset register: device, make, model, serial number, location, firmware, IP address, and where its credentials are held. Keep passwords in a vault, not in the spreadsheet.
- Agree a baseline and a fix list. What works, what is degraded, what has failed. Rank fixes by risk, then phase them to your budget cycle.
Our free incident log analyser can show where and when incidents cluster on your site, which tells you where working cameras matter most.
When to bring someone in
If the estate is large, spread across several buildings, or nobody can get admin access, a device-level audit is usually quicker and cheaper than piecing it together in-house.
Our Security Estate Audit does exactly the six steps above. Every device is found, tested and logged, admin access is recovered and handed over in a managed vault, and you get a signed baseline and a costed fix list. It is a fixed price agreed before we start, credited in full against your first year if you then take a maintenance contract with us. The asset register and report are yours either way.
Two honest limits. Intruder alarms with police response need an NSI or SSAIB certified maintainer to keep their URN, which Fyrfly does not currently hold, so we will audit the alarm and tell you how to keep police response rather than take it over. For fire detection, check whether your insurer requires third-party certification such as BAFE before changing provider.
If you would rather have a vendor-neutral view of your whole security position against Martyn's Law, DfE guidance, KCSiE and UK GDPR, our Annual Security Audit is designed for that. For keeping systems healthy once they are under control, see our guide to school CCTV maintenance.
Frequently asked questions
Why is our school CCTV showing live pictures but not recording?
The most common causes are a failed or full hard drive, a recording schedule that has been switched off or changed, or a recorder that has lost its settings after a power cut. The live view comes straight from the cameras, so it can look perfect while nothing is being saved. Check playback for a specific time last week; if it is missing, treat it as a fault.
We don't know the password for our CCTV recorder. What should we do?
First ask the original installer, in writing, for the admin credentials. If that fails, most manufacturers have a password recovery route that needs proof of ownership and physical access to the recorder. Avoid a factory reset until you know what it will erase, and export any footage you need to keep first.
Who owns the CCTV system and its passwords: the school or the installer?
Usually the school, if it paid for the equipment. Check the original contract and any maintenance agreement. Whatever the contract says, the school is the data controller for its CCTV under UK GDPR, so it needs to be able to access, export and delete footage itself, for example to answer a subject access request within one month.
Do we have to replace an old CCTV system to fix it?
Not necessarily. Many inherited systems need repairs, new drives, firmware updates and proper documentation rather than replacement. Audit what is there before accepting any rip-and-replace quote, and replace in phases where equipment is genuinely beyond economic repair or no longer supported.
Can a new company take over maintenance of a system someone else installed?
Yes, for CCTV, access control and fire detection of most makes and ages. Intruder alarms with police response are the exception to check carefully: to keep a police Unique Reference Number, the alarm must be maintained by an NSI or SSAIB certified company.