Unless its a corporate network the CCTV is likely to be no greater risk than any of the other items already on the network.
Most of the CCTV I have enabled for remote access has low end routers, often using default passwords & dynamic IP's.
I'd normally change router password, port forward & use my DNS provider
On the DVR/ NVR I'd normally change default ports & default passwords.
I've found lots of open or default stuff on the net to play with, many of these items have been up for yrs in default set up!
I made a mistake & left a phone system not fully secured, within 24hrs it had been found & there where thousands of attempts to make sip connections to it, only non std extensions & passwords saved the day.