A CCTV upgrade replaces or modernises an ageing surveillance system so that it meets today’s operational, legal and cyber security needs. For many Australian organisations that means moving from analogue cameras and recorders to an IP network system, but wholesale replacement is not always the right answer. A sound CCTV upgrade starts with what the system must achieve, then tests how much of the existing cameras, cabling and storage can be kept.
This guide is written for boards, asset owners and facility managers who are responsible for a camera network that has grown old, patchy or hard to trust. It explains the warning signs, the migration options, how to build the business case, how to specify and tender the work, how to accept it, and the privacy and retention duties that come with it. It reflects the approach Agilient takes as an independent CCTV consultant: vendor-neutral advice shaped by risk rather than a product range.
- Most failing systems give warning: footage missing when it is needed, images too poor to identify anyone, and equipment the manufacturer no longer supports.
- Analogue to IP CCTV migration can be staged. Encoders, hybrid recorders and IP over coax let an organisation keep sound cabling while it replaces cameras.
- An operational requirement, written before any product is chosen, is what turns a CCTV upgrade into a system that does its job.
- Privacy law applies to the footage as much as to the cameras, so the upgrade is the right time to refresh signage, notices, access controls and retention settings.
When does a CCTV system need upgrading?
An incident is often what reveals the problem. Security staff go to retrieve footage and find the camera was offline, the recording was overwritten, or the image cannot show who was involved. By then the system has already failed the one test that matters.
The common signs that a CCTV upgrade is due are:
- End of support. Cameras, recorders or video management software that the manufacturer no longer patches or supports, often running mixed software versions from site to site.
- Images that cannot be used. Coverage that shows movement but not faces or number plates, poor night performance, and views blocked by growth, signage or later building works.
- Missing footage. Motion-only recording, retention periods shorter than the time it takes for incidents to be reported, and failed disks that nobody was alerted to.
- No health monitoring. Faults found only when someone looks, and a run-to-fail approach to maintenance.
- Poor integration. A system that cannot link to access control, alarms or a central monitoring room, or cannot be extended to new sites without a second platform.
- Cyber exposure. Networked recorders with default passwords, unsupported operating systems or a flat connection to the corporate network.
- Environmental risk. Recording equipment sitting in hot, dusty or wet plant areas rather than a controlled communications room.
One or two of these can often be fixed within the existing system. Several together usually point to a planned upgrade rather than another round of piecemeal repairs.
What are the options for upgrading analogue CCTV to IP?

Analogue systems send video from each camera over coaxial cable to a digital video recorder. IP systems carry video as data over a network, which is what makes higher resolution, analytics, remote access and multi-site management practical. Moving from one to the other does not have to happen in a single step. The main options are:
- Optimise and retain. Reposition cameras, improve lighting, correct recording settings and fix maintenance. Where the equipment is still supported, this can close most of the gap for little cost.
- Hybrid recording. A hybrid recorder or video encoders bring existing analogue cameras into an IP video management system, so cameras can then be replaced progressively as budgets allow.
- High definition over coax. Higher definition analogue formats reuse the existing coaxial cable. This can be a sensible interim step, but some formats are tied to particular manufacturers and limit future choice.
- IP over existing coax. Ethernet over coax adapters let IP cameras run on the old cable where new cabling would be costly or disruptive, such as in heritage buildings or long external runs.
- Full IP migration. New structured cabling or fibre, network switches that power the cameras, and a new video management platform, either on premises or hosted.
The right mix depends on the condition and length of the existing cable, how many sites are involved, access and construction constraints, the organisation’s network capacity, and its budget cycle. For most multi-site networks the answer is a staged roadmap: urgent risks fixed first, a common platform chosen early, and cameras replaced in a planned sequence. Hosted or cloud video adds its own questions about bandwidth, data location and who can access the footage, and those belong in the options analysis rather than after the contract is signed.
What should the operational requirement for a CCTV upgrade cover?
An operational requirement is a short, plain statement of what each camera or area must achieve and why. It is written before any product is chosen, and it becomes the yardstick for the specification, the tender evaluation and acceptance testing. Without one, a CCTV upgrade tends to be judged on camera counts and resolution figures rather than on whether the system does its job.
A useful operational requirement records, for each area:
- The risk the camera addresses and the purpose of the view, from general situational awareness through to identifying a person or reading a number plate.
- Who uses the footage, whether it is watched live or reviewed after an event, and what response is expected.
- Lighting conditions by day and night, and the hours the area is in use.
- Recording mode, frame rate, retention period and how evidence will be exported.
- Links to access control, alarms, intercoms or a monitoring room.
The Australian and New Zealand adoption of the international video surveillance standards, the AS/NZS 62676 series published in 2020, covers system requirements, video transmission, camera performance and application guidelines.1 Part 4, the application guidelines, relates what an operator needs to see to the pixel density a camera must deliver on a target. The international edition of that part was revised as IEC 62676-4:2025, which updated the observation categories.2 Referencing these standards in the operational requirement gives designers and tenderers a common, measurable language.
How do you build the business case for a CCTV upgrade?
Boards and executives approve CCTV upgrades on risk, compliance and whole-of-life cost, not on technology. A business case that holds up in a board paper sets out the current state honestly, compares a small number of realistic options, and gives an order-of-magnitude cost for each so that preliminary approval can be sought before detailed design money is spent.
The costs that are most often missed are recurring ones: software licences, storage growth, network capacity, maintenance contracts, cyber security patching and the staff time to manage the system. On the benefit side, the case should state which risks the upgrade reduces, which obligations it helps meet, and what the organisation loses each time footage is unavailable. Staging the work across budget years, with the highest-risk sites first, often makes the difference between a deferred project and an approved one.
Questions worth putting to the board or executive before approving a CCTV upgrade:
- What is the system for, and who relies on the footage?
- When did it last fail to produce footage that was needed, and why?
- Which components are out of support, and what is the plan for them?
- Has the advice come from someone with no interest in selling the equipment?
- Who will own and manage the system after installation?
How should a CCTV upgrade be specified and tendered?
A performance-based specification describes the outcomes the system must deliver and the standards it must meet, rather than naming a brand. That keeps the market competitive and puts the burden on tenderers to show how their proposal meets the operational requirement. Open interoperability standards, such as the ONVIF profiles for IP video devices, help protect the organisation from being locked into one supplier’s cameras or software.
The tender documents should set out:
- The scope by site and stage, with separable portions where the work will be staged.
- Technical requirements linked back to the operational requirement.
- Cyber security requirements for devices, recorders and remote access, agreed with the organisation’s ICT team.
- Weighted evaluation criteria that balance compliance, capability, whole-of-life cost and support, not price alone.
- Acceptance testing, warranty, defects liability, maintenance service levels, ownership of data and configuration, and training for in-house staff.
Clear documentation also reduces variations once work begins. In one engagement, an independent review of a council’s CCTV and access control gave it a tender-ready Statement of Works and a clear upgrade path; the council CCTV review and procurement case study describes the approach.
What does commissioning and acceptance testing involve?
Acceptance is where the organisation confirms that it has received what it paid for. It should be tested against the operational requirement, camera by camera, not signed off from a walk-through or an installer’s checklist. A typical acceptance process covers:
- Field of view and image detail at the target distance, checked by day and at night.
- Recording, retention and retrieval, including a test export of evidence in a usable format with correct time and date.
- Health monitoring and fault alerts, confirmed by simulating a camera or disk failure.
- Cyber hardening: default credentials changed, current firmware installed and network segmentation in place.
- As-built drawings, configuration records, operating procedures and training for the people who will run the system.
Where an old system is being replaced, running the two in parallel during cutover avoids a gap in coverage. A short trial period after practical completion, with defects recorded and closed out, gives the organisation evidence that the system performs in real conditions before final payment and handover.
What privacy and retention obligations apply to CCTV in Australia?
CCTV footage that shows identifiable people is personal information. The Privacy Act 1988 applies to Australian Government agencies and to organisations with an annual turnover above $3 million, among others. Covered entities must tell people that their image may be captured before they are recorded, keep recorded personal information secure, and destroy or de-identify it when it is no longer needed.3 Those duties flow from the Australian Privacy Principles, particularly APP 5 on notification and APP 11 on security and destruction.4 State and territory agencies are generally covered by their own privacy laws.
State and territory surveillance and workplace laws apply as well. In New South Wales, the Workplace Surveillance Act 2005 requires written notice to employees at least 14 days before camera surveillance begins, with cameras clearly visible and signs at each entrance to the place under surveillance.5 Victoria’s Surveillance Devices Act 1999 prohibits the use of surveillance devices to monitor workers in workplace toilets, washrooms, change rooms and lactation rooms.6 The Australian Capital Territory has its own Workplace Privacy Act 2011.
There is no single national retention period for CCTV footage. Retention should be set in a documented policy based on the purpose of each camera, how long incidents usually take to be reported, evidence and legal hold requirements, and any licence or sector conditions that apply. Keeping footage longer than needed adds storage cost and privacy risk.
New analytics raise the stakes. The Office of the Australian Information Commissioner treats biometric information, including facial images used for automated verification or identification, as sensitive information, which generally requires consent to collect.7 Any facial recognition or similar analytics proposed in a CCTV upgrade should go through a privacy impact assessment before it is specified, not after it is installed.
How Agilient supports a CCTV upgrade
Agilient provides independent CCTV advice as part of its electronic security consulting. Agilient is not aligned with any vendor and does not sell or install equipment. Organisations often come to Agilient after speaking with suppliers and feeling confused or oversold, or after a vendor-led system has disappointed. The work often starts with getting more out of the existing system, and moves to replacement only where the evidence supports it. CCTV advice sits within a wider physical and facility security program, and is usually grounded in a security risk assessment so that cameras are placed where the risk is.
Condition and options review
An assessment of the existing cameras, cabling, recording and maintenance, with clear options.
Order-of-magnitude costings
Costed options that boards and executives can use to give preliminary approval.
Operational requirement
A plain statement of what each camera must achieve, agreed with the people who use it.
Specification and tender
Vendor-neutral RFQ and tender documents, evaluation support and contract advice.
Implementation and trial validation
Oversight during installation and acceptance testing against the requirement.
Knowledge transfer
Working alongside ICT and security teams so the organisation can run its own system.
Agilient works with councils, racing and sporting bodies, health services, universities, water utilities, venue operators and critical infrastructure owners across Sydney, Melbourne, Brisbane, Adelaide and Canberra.
For a quick view of where your system stands, try the free CCTV health check.
Plan your CCTV upgrade with independent advice
A short review of the existing system is usually enough to show whether it can be improved, needs staged replacement, or needs a full CCTV upgrade.
Frequently asked questions about CCTV upgrades
What is a CCTV upgrade?
How do you know if a CCTV system needs replacing?
Can analogue CCTV be upgraded to IP without replacing the cabling?
How long should CCTV footage be kept in Australia?
Which Australian standards apply to CCTV systems?
Why use an independent CCTV consultant for an upgrade?

- Standards Australia, AS/NZS 62676.4:2020 Video surveillance systems for use in security applications, Part 4: Application guidelines, standards.org.au
- International Electrotechnical Commission, IEC 62676-4:2025 Video surveillance systems for use in security applications, Part 4: Application guidelines, iec.ch
- Office of the Australian Information Commissioner, Security cameras, oaic.gov.au
- Office of the Australian Information Commissioner, Australian Privacy Principles quick reference, oaic.gov.au
- NSW Government, Workplace Surveillance Act 2005, legislation.nsw.gov.au
- Victorian Government, Surveillance Devices Act 1999, legislation.vic.gov.au
- Office of the Australian Information Commissioner, Facial recognition technology: a guide to assessing the privacy risks, oaic.gov.au
