As I stated, cameras should never be online. CCTV is a tried and true method on a DVR with not network. Physical attack is going to be the only method
The problem is companies like Lorex, QSee, Comcast, ADT, wtc. Tell you, hey you can view your cameras wherever you are never mentioning the security risk of your privacy. So everyone wants to be able to view their cameras from their ipad. I had a pharmacy get their cameras hacked because they wanted to view them at home. I warned them that camera systems should be PCI complient and treated just like their internal network that handles customer and payment information, but they didn't want to listen. They didn't even want to get the hardware to run a hardware firewall because they didn't want to pay for the hardware. They changed their tune when they got hacked. The hackers replaced their webview URL with a driveby, it was great!