My plans to mitigate this, because I think the client is running a 100mb switch, is to run the cameras directly back to the Unifi gigabit PoE switch and into the the Cloud Key and from that switch to the other existing switch so the camera traffic is kept off the main lan, except for the one monitoring station.
I have to ask "Why allow them to keep a 100 meg switch?"
Replace that sucker! Heck it's a bottleneck for most internet connections these days....not to mention if this client does any LAN stuff.
Also I urge caution on selection of the 8 port Unifi switches...a couple of different models, some with only pass through POE...thus limited, and the 60 watt model has some limitations. For a "core" switch (which I wager you'd want)...replacing the clients 100 meg switch...not sure how many ports you need but probably safe to start with at least the 16 port model.
Another quick tip....to help performance throughout the switches, on ports where you have an AP, and on ports where you have the cameras, enable the "port isolation". Don't need LAN broadcasts and visa versa chattering up those ports and adding traffic overhead.
For Unifi switches, for smaller setups you can control ports individually...but as the network grows, there is a feature called Profiles that you apply to the ports, and this becomes very beneficial for configuring the switches. The Profiles are a...profile...you create, where you define the VLANs, POE settings, port isolation, Voice VLAN/LLDP if applicable, and other settings. And you can quickly apply profiles to ports.
So...for example, you have your default VLAN for the primary data network.
And I'll typically create a VLAN for the guest wireless...VLAN3
And I'll typically create a voice VLAN for VoIP, VLAN2...and LLCP that.
Next...I'll create profiles. A default profile for most ports....if no phones, just primary VLAN...no POE.
And I'll create a profile for the ports that the AP will link to...default VLAN, plus guest VLAN, plus POE...plus port isolation.
For the switch port facing the router/gateway...default VLAN and no POE.
For the switch port facing the second ETH port on the firewall for the guest network to exit...I'll make VLAN3 the default VLAN, no POE.
For any switch ports going to office data ports where the client has VoIP..default VLAN, voice VLAN, POE.