It's in the guide but very important to never open the default ports used by the NVR on the router. Always customise them. E.g. instead of port 443 use 40443.
When an exploit comes out, script kiddies will scan IP blocks for known ports and check if the exploit works. They don't scan all ports...