Wrap security around insecure components
Whilst the inevitable march towards tight cloud-integration may present problems for some systems, there should never be a complete reliance on any individual vendor or component to maintain overall security... it is all about the architecture.
For Hikvision NVR appliances, you do not need to use the Hik-Connect cloud service: you can just stick the NVR into an isolated subnet, with filtered / blocked access to the Internet or the rest of the internal network and use your own VPN to remotely connect to it.
I do appreciate that for the average home or small business, they will just connect these devices to a single network and rely on whatever cloud service is included to bypass NAT, so there is an argument for protecting less sophisticated users who just want to Plug & Play...
But is it unrealistic of me to expect that for any government facility, especially sensitive ones, *any* brand of CCTV equipment would be deployed and integrated in a more secure and thoughtful manner?
(Perhaps I don't want to know the answer.....!)