Data Security
Thales announces an expanded collaboration with Google Cloud to help enterprises address emerging security and governance challenges associated with agentic AI, bringing integrated protection, visibility, and policy enforcement to AI-driven workflows on Google Cloud. The integration of Thales AI Security Fabric with Google Cloud Gemini Enterprise helps organizations apply security, governance, and visibility across interactions among users, agents, models, and tools in real time. Next generati...
DigiCert, a pioneer in intelligent trust, announces the general availability of DigiCert Quantum Central, part of the DigiCert ONE platform, that helps organizations manage and demonstrate progress toward post-quantum cryptography (PQC) readiness. First introduced in preview in July, Quantum Central offers expanded capabilities that help organizations move from finding cryptographic risks to managing them. Teams can bring together cryptographic data from multiple sources, apply their own securi...
Alibaba Cloud, a global provider of AI infrastructure and the intelligence backbone of Alibaba Group, today announced its latest global infrastructure expansion plan at the 2026 Apsara Conference, alongside a series of new AI capabilities designed to help enterprises build, deploy and scale AI applications more efficiently. The technology company has also announced its comprehensive collaboration with global enterprises including Panasonic Digital, Unity China, Lion Parcel, Loomi Entertainment...
Nutanix, a hybrid cloud pioneer and AI platform company, announces its acquisition of Ryax Technologies (Ryax), an AI-driven compute orchestration and management platform company based in France. The acquisition will accelerate Nutanix’s strategy to empower enterprises to build, run, and govern agentic AI anywhere by integrating the Ryax platform’s advanced GPU utilization and smart scheduling capabilities directly into Nutanix Kubernetes Platform (NKP) and Nutanix Enterprise AI (NAI...
Diligent, the AI pioneer in governance, risk and compliance (GRC) solutions, announces a major enhancement to Diligent One, its native AI platform, at Gartner’s Enterprise Risk, Audit and Compliance Conference (ERAC). “For many organizations, GRC work is slowed by fragmented systems, manual coordination and time-consuming reporting processes,” said Brian Stafford, President and CEO of Diligent. “Our latest agentic capabilities help teams cut through that complexity by co...
Entrust announces new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organizations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography. Evolving comp...
News
Cyera announces the completion of its acquisition of Oasis Security, the access management platform for the agentic enterprise. The acquisition, valued at $1 billion, unites Cyera's AI and Data Security Platform with Oasis's non-human identity (NHI) management capabilities, creating a single platform that determines what every human, machine, and AI agent can see and do. Non-human identities inside Fortune 500 companies grew nearly 500% in the last six months alone, making them the fastest-growing identity type. Agents operate at machine speed, act on valid credentials, and don't need to be compromised to cause damage, yet most organizations have no idea what those agents can access or whether any of it was ever meant to be accessible in the first place. Access management platform The old security model survived on human accountability, where users could coach a person, manage them, and hold them responsible. However, they can't threaten an agent, prosecute an API, or discipline a workload. Once an autonomous system has permission, it acts continuously and without hesitation. That's why a permission granted six months ago can no longer be treated as reliable. That trust needs to be evaluated fresh before every action, not set once and forgotten. Together, Cyera and Oasis are building a new model: one that unifies data and identity into a single system, so every agent is trusted with exactly the data it should reach. Non-human identity “The speed of this deal reflects a shared conviction that AI has changed the game, and the infrastructure to secure it has to move just as fast,” said Yotam Segev, cofounder and CEO at Cyera. “We’ve spent years solving data at enterprise scale, and Oasis has done the same for non-human identity. Put those two things together and you get one system that decides what every agent can see and do, and that's exactly what we’re building.” Oasis Security was founded in 2022 to address non-human identity, one of the fastest-growing and least governed areas of enterprise security. The company built continuous, policy-driven control over which workloads and agents can access which systems, in what context, and for how long. Over three years, Oasis moved the world's largest companies off static, standing permissions and onto a dynamic model built for the speed and scale of agents. Going forward, the Oasis platform will operate as Cyera Identity, the dedicated identity pillar within Cyera's platform, connecting directly to Cyera's data intelligence layer to bring governance of data and identity together for the first time. Most important systems “Joining Cyera marks a new chapter for Oasis and for the customers we've built for. We built Oasis so enterprises could put AI to work on their most important systems and trust every decision it makes,” added Danny Brickman, cofounder and CEO of Oasis. “Cyera shares that same goal and together, we're positioned to deliver a single platform that governs identity and data as one. That's a win for every customer who has been forced to stitch those two things together until now.” For more on what this means for the future of the agentic enterprise, check out the blog post from Cyera Chief Strategy Officer, Jason Clark, and CTO of Cyera Identity, Amit Zimerman.
Aetina Corporation, a foremost provider of edge AI solutions and accelerator of edge AI infrastructure, announced the launch of MegaEdge AIP-RQ87, a ready-to-deploy 2U edge agentic AI system designed to help enterprises and system integrators (SIs) rapidly implement AI agent, private LLM, RAG application, multimodal AI, and AI-driven intelligent automation. Powered by Intel® Core™ Ultra processors with high-bandwidth PCIe Gen5 x16 architecture, AIP-RQ87 delivers enterprise-grade AI computing in a compact 2U rackmount design purpose-built for on-premises and edge deployment. Deploying advanced AI workloads As enterprises transition from AI experimentation to production, organizations demand on-premises solutions delivering robust performance, data security, and seamless integration. Traditional AI servers often require complex infrastructure planning, large footprints, and specialized resources. AIP-RQ87 addresses these challenges with a compact 2U chassis, flexible AI accelerator support, high power capacity, exclusive Power Distribution Board (PDB) design, and modular tool-less maintenance—enabling businesses to reduce deployment complexity while efficiently deploying advanced AI workloads where data is generated. Deconstructing heterogeneous edge computing MegaEdge AIP-RQ87 is purpose-built for system integrators, AI developers, research labs, and SMEs, delivering a flexible on-premises AI platform that eliminates the complexity of traditional infrastructure. The system features high-bandwidth, low-latency PCIe Gen5 x16 architecture with support for both NVIDIA RTX PRO 6000 Blackwell Series GPUs and Qualcomm® Cloud AI 100 Ultra accelerators—allowing enterprises to select optimal computing configurations based on workload requirements, power constraints, and budget.AIP-RQ87 integrates Intel® Core™ Ultra 5/7/9 processors with Intel® Q870 chipset, supporting up to 256GB DDR5 memory within a compact 2U footprint (500mm depth). Optimized for private large-parameter LLMs, RAG, and enterprise AI inference, the platform enables deployment of AI agents, multimodal AI, and intelligent automation across verticals—from knowledge assistants and legal compliance to video analytics and smart retail. Proprietary hardware innovations for maximum field reliability To enable stable operation of dual 600W AI accelerators in a compact 2U edge system, AIP-RQ87 incorporates patent-pending hardware innovations and industrial-grade specifications: Proprietary Power Distribution Board (PDB) [Patent Pending]: Aetina’s innovative “cable-free split-circuitry design” disrupts conventional chassis designs plagued by dense cable bundles. By distributing power through a centralized backplane, this architecture optimizes delivery to high-wattage accelerators, reduces cable clutter, and enhances stability during sustained high-load operations. Modular Tool-Less GPU and SATA Box Design [Patent Pending]: This service-friendly innovation enables instant tool-free hardware installation, upgrades, and maintenance—significantly reducing mean time to repair (MTTR) while improving service efficiency and deployment flexibility 2000W Power Supply: Integrated industrial-grade high-wattage PSU provides maintainable power capacity for mission-critical AI applications—ideal for smart retail, smart cities, enterprise data centers, and edge nodes requiring continuous operation Featured 1x 10G LAN Port (10GbE): High-speed 10GbE transmission eliminates bandwidth bottlenecks in massive data exchange and distributed machine learning, ensuring millisecond-level responsiveness and optimized AI inference performance. Enabling private AI, intelligent automation and real-time decisions As enterprise AI progresses from proof-of-concept toward scaled deployment, organizations prioritize data sovereignty, deployment efficiency, and long-term operations over model performance alone. For enterprises processing sensitive data internally while minimizing cloud dependency, on-premises AI deployment is becoming critical.MegaEdge AIP-RQ87 helps enterprises retain core data internally, reduce cloud transfer costs and latency, and provide controllable computing foundations for private LLMs and AI agents. Key deployment scenarios span three directions: Private AI Knowledge Assistants & Legal Compliance: Integrate product documentation, SOPs, internal knowledge bases, and regulatory data for real-time semantic retrieval and knowledge Q&A. Intelligent Document Processing (IDP) & Business Automation: Support classification, extraction, summarization, and report generation from contracts, invoices, and business records—enhancing workflow approval and operational efficiency. Financial Industry Applications: Serve as intelligent wealth management advisors, smart regulatory compliance assistants, and financial risk management solutions. Richard Hung, Vice President of Product Division at Aetina, stated: “Enterprise AI competitiveness now extends beyond model capabilities to deployment efficiency, data sovereignty, and long-term operations. Aetina MegaEdge AIP-RQ87’s rapidly deployable 2U edge platform helps enterprises and SIs pragmatically implement private LLMs, AI agents, and intelligent automation—making on-premises AI truly achievable.” Expanding global on-premises AI markets MegaEdge AIP-RQ87 has entered mass production with CE, FCC Class A, and UKCA certifications, ready for global deployment. With AIP-RQ87 joining the MegaEdge PCIe Series, Aetina expands its enterprise-grade edge AI infrastructure portfolio—helping customers build secure, scalable, maintainable on-premises AI environments and accelerate from private LLM adoption to large-scale intelligent automation.
Netwrix, a recognized pioneer in identity and data security, announces new capabilities across Netwrix PingCastle and Netwrix Threat Manager that extend identity security deeper into the Microsoft cloud, including coverage of AI agents. Organizations are deploying AI agents faster than they can govern them. Each agent is an identity holding real permissions inside the enterprise environment, yet most exist outside any inventory, ownership, or review process. Identities needing access A Cloud Security Alliance survey found that fewer than a quarter of organizations have a formally adopted policy for creating or removing the identities their AI systems run on, and more than 16% don't track when a new one is created at all. The consequences are measurable: in its 2026 Data and Identity Security Report, Netwrix found a 43% breach rate among organizations where AI had significantly expanded the number of identities needing access, compared with 11% where it hadn't. Netwrix PingCastle extends its Microsoft Entra ID coverage to 102 risk checks, extending the tool's trusted Active Directory posture assessment into the cloud identity plane. Security teams and administrators can now assess identity risk across both on-premises AD and Entra ID with the same fast, prioritised approach that has made PingCastle a community favorite. Actionable risk insights Netwrix Threat Manager adds new visibility into AI agent identities in Microsoft Entra ID, giving security teams an inventory of the agents operating in their environment and the access they hold. That inventory is the missing foundation for most organizations: the Netwrix report found only 19% of organizations fully govern non-human identities such as service accounts and AI agents. Threat Manager already provides visibility and monitoring for another critical non-human identity category, service accounts, through actionable risk insights, abnormal-behavior detection, and attack context for faster triage; this release extends that coverage to AI agents. Agent-specific threat detection The latest Netwrix Threat Manager release also adds new threat detection for Azure Files, protecting file shares against ransomware, abnormal behavior, and high-risk changes such as the creation of open access. Agent-specific threat detection is planned for a subsequent release, building on the visibility foundation delivered today. The new capabilities complement Microsoft's native tooling with independent assessment and visibility across the Microsoft identity plane. "Earlier this year, we gave organizations visibility into what AI agents can access. This release goes a layer deeper: which agents exist at all," said Jeff Warren, CPO at Netwrix. "Our research found fewer than one in five organizations fully govern non-human identities, and agents are the fastest-growing category. You can't review access for an identity you don't know you have." Independent posture assessment These releases advance Netwrix's strategy to unify identity and data security. PingCastle's assessment engine already powers more than 200 checks within the company's 1Secure™ platform, reflecting the same independent posture assessment approach now extended deeper into the Microsoft identity plane. Netwrix PingCastle 4.0 and Netwrix Threat Manager 3.3 are available now. To learn more, book a meeting with the Netwrix team.
Matrix Comsec, a provider of enterprise-grade security and telecom solutions, has been recognized at the Gujarat Best Employer Brand Awards 2026 for its focus on building a people-first and future-ready workplace. The recognition was presented on August 11, 2026, at Fairfield by Marriott, Ahmedabad. Matrix integrates its people strategy with its broader business vision. Operating in a technology-driven industry, the company focuses on continuous learning, technical capability development, leadership readiness, and cross-functional collaboration. These practices help employees respond to evolving technologies, changing customer expectations, and emerging business opportunities. Changing customer expectations As an organization driven by research, product development, and indigenous technology, Matrix believes that sustainable transformation begins with capable and empowered people. The company encourages employees to strengthen their expertise, take ownership, contribute ideas, and participate in problem-solving and innovation. Matrix also works to foster a culture built on integrity, inclusion, performance, and mutual respect. Its workplace practices support professional growth, open communication, employee recognition, and well-being, enabling employees to contribute effectively to individual and organizational progress. Future-ready competencies The Gujarat Best Employer Brand Awards recognize organizations that align HR strategy with business transformation while strengthening future-ready competencies, talent development, employee engagement, inclusion, well-being, and organizational value. The recognition validates the people practices supporting Matrix’s innovation-led business model. Commenting on the recognition, Ashish Shah - Senior Vice President - Human Resources at Matrix, said, “At Matrix, we believe that sustainable business growth is built by people who are trusted, equipped, and encouraged to realize their potential. Our focus has been on creating an environment where continuous learning, innovation, accountability, and collaboration become part of everyday work. This recognition reinforces our commitment to strengthening these practices as we prepare our people and organization for the opportunities ahead.” For Matrix, the award is an acknowledgement of an ongoing commitment rather than the culmination of its employer-brand journey. The company will continue evolving its workplace practices in line with employee aspirations, technological change, and future business requirements.
Just last December, Plusserver announced a far-reaching cooperation with SHD. Now, IT-BUSINESS reports that the managed hosting provider Plusserver has evolved into a regional cloud provider. For 2023, the Cologne-based company has its sights set on expanding its partner business, having laid the groundwork for this last year. SHD has been operating a data center for ten years, providing infrastructure resources to customers as a service. Under the "SHD Enterprise Cloud" label, SHD will not only sell the cloud provider's offerings in the future, but also use its Pluscloud as the technological basis for its own products and managed services. Providing infrastructure resources By the middle of this year, SHD will migrate existing workloads from its own data center to the Plusserver cloud. The Saxon company views this cooperation as an opportunity to further develop its infrastructure business. This will allow them to provide managed services on a flexible, scalable, and geographically distributed cloud platform. Plusserver operates the Pluscloud in four data centers in Hamburg, Cologne, and Düsseldorf. An important criterion for SHD was also the security certifications that the provider has obtained for its systems. These include certificates and attestations according to the standards ISO 9001, 27001, IDW PH 9.860.1, and the BSI's Cloud Computing Compliance Criteria Catalogue (C5). "The modernization of the SHD Enterprise Cloud is just the first step in a partnership of equals," summarises Ohnacker. "Plusserver meets all data security and privacy requirements for customers, and our solutions thus form the basis for new portfolio elements from SHD."
Fortinet®, the global cybersecurity pioneer driving the convergence of networking and security, announces new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-assisted operations into FortiEndpoint, Fortinet enables security teams to better govern AI usage, reduce sensitive data exposure, enforce risk-aware access, and simplify security operations across distributed environments. Converge critical security “Organizations need a simpler and more effective way to manage security as their environments become more complex and AI-enabled. The Fortinet Security Fabric is designed to converge critical security and networking functions across the enterprise, helping customers reduce complexity, improve visibility, and strengthen protection. With FortiEndpoint, we are extending that strategy by consolidating security, secure access, data security, AI visibility, and assisted operations in a unified endpoint platform, delivered through one agent, one console, and one license,” said Michael Xie, Founder, President, and CTO at Fortinet. Strengthening adaptive access As agents and AI-enabled applications become embedded in everyday work, organizations need better visibility, stronger governance, and integrated protection to securely enable AI while reducing endpoint risk and protecting sensitive data. These needs are even more urgent as threat actors move faster and use increasingly sophisticated techniques to exploit gaps across users, devices, applications, and data. The pressure security teams are facing is compounded by fragmented tools across protection, detection and response, secure access, and data security, which can slow security teams and limit visibility. FortiEndpoint builds on the consolidation strategy previewed at Fortinet Accelerate 2026 by bringing AI visibility and governance, endpoint protection, detection and response, secure remote access, native data security, and FortiAI-assisted operations together through one agent, one console, and one license. Through integration with the Fortinet Security Fabric, endpoint telemetry and risk context can inform connected security controls, strengthening adaptive access, policy enforcement, and enterprise-wide visibility. Data security requirements These capabilities help define Fortinet’s approach to endpoint security for the AI era, advanced through three key areas of innovation: Securing AI Use at the Endpoint - FortiEndpoint provides centralized visibility and control over sanctioned and unsanctioned AI application and agent usage across endpoints, including installed AI apps, agents, and web-based tools. From a single view, organizations can identify agents and applications in use, monitor adoption, and understand user activity to help surface shadow AI, unmanaged applications, and unauthorized tool usage. With granular guardrail policies, security teams can allow, restrict, monitor, or block applications based on corporate security, compliance, and data security requirements. This supports responsible AI adoption while reducing the risk of unsanctioned tools, sensitive data exposure, and policy violations. Stronger data security Reducing AI-Driven Data Exposure and Insider Risk - FortiEndpoint now natively supports DLP to help secure AI interactions and reduce insider risk by automatically inspecting sensitive data exchanged with AI applications, agents, and web services. Built-in user coaching provides real-time policy guidance to help users understand acceptable AI usage and reduce risky behaviours without impacting productivity. This helps prevent the leakage of sensitive data such as personally identifiable information, intellectual property, and financial information directly at the endpoint. By integrating DLP into FortiEndpoint, organizations can safely adopt AI while maintaining stronger data security and compliance controls without adding another point product or management layer. Unified management experience Unifying Endpoint Security, Access, Data Security and AI-Assisted Operations - FortiAI-Assist is built into FortiEndpoint to simplify administration and accelerate day-to-day operations. Security teams can use natural language to investigate events, visualise findings, generate investigation summaries, identify high-risk devices, and troubleshoot issues. It also provides contextual insights, policy recommendations, and risk guidance to help analysts strengthen governance, prioritise threats, scale threat hunting, and improve efficiency through a unified management experience. These assisted workflows are complemented by adaptive zero-trust capabilities with dynamic risk and compliance scoring. By continuously assessing endpoint health, compliance status, and risk posture, FortiEndpoint helps organizations make access decisions based on real-time context, so access to AI applications and protected resources can be adjusted as risk changes. This helps organizations reduce exposure, enforce more consistent policy, and safely support AI-enabled work. Sensitive data leakage Industry analysts are also recognizing the importance of this integrated approach as organizations look for practical ways to govern AI use without adding more tools and complexity. “Fortinet is addressing what many CISOs need now: visibility into AI usage, control over sanctioned and unsanctioned tools, protection against sensitive data leakage, and real-time coaching to help employees use AI responsibly,” said Chris DePuy, Technology Analyst at 650 Group. “Delivering these capabilities through FortiEndpoint gives customers a practical way to manage AI risk with the same agent and license they already rely on for endpoint security.”


Expert commentary
In today’s connected world, attacks are more likely to target digital than physical entry points. From ransomware and firmware tampering to remote hijacking, AI-driven phishing and automated vulnerability discovery, the nature of threats is evolving rapidly, and no industry can afford to neglect them. As our industry has moved from mainly mechanical to increasingly digital solutions, we have long recognized the importance of constantly monitoring and assessing the risks we face. This means not only meeting mandatory regulations but also voluntarily adopting international standards such as ISO 27001, which protects data and systems through a structured and independently audited framework. Today’s fast-changing risk environment is also why the EU introduced the Network and Information Security Directive 2 (NIS2) – to raise the bar for cybersecurity across Europe. But what do measures like NIS2 and the Cyber Resilience Act (CRA) mean in practice? How does the rise of AI fit in? And most importantly, what should our industry be doing to stay secure in such an unpredictable digital landscape? The new regulations Compliance is not just about meeting regulations, it is also a competitive advantage NIS2 is reshaping cybersecurity expectations by setting higher standards to reduce risk, improve transparency, and protect data and services. Alongside it, the CRA introduces mandatory requirements for products with digital components. This makes “secure by design,” regular updates, and compliance checks essential before products can enter the EU market. For companies in our industry, responsibilities now extend well beyond internal systems. Organizations must also ensure that suppliers and service providers comply, with regular risk assessments forming a central part of the process. The consequences of falling short are severe, ranging from significant fines and audits to the potential withdrawal of products from the market. For our customers, the message is clear: security must be built in from the start. Compliance is not just about meeting regulations, it is also a competitive advantage. At ASSA ABLOY Opening Solutions EMEIA, security is part of our DNA. We embed these standards into everything we do, giving customers solutions they can trust to be compliant and resilient. The rise of AI Artificial intelligence is transforming the digital security landscape and it cannot be separated from the regulatory framework shaping our industry. With AI advancing rapidly and new regulations coming into force, we have established a digital compliance framework to stay ahead of the curve and use AI as an enabler for improving security and achieving compliance. On one hand, AI brings powerful benefits, including more intelligent monitoring, faster anomaly detection, and smarter tools for operational efficiency. These capabilities directly support NIS2 and the CRA, particularly in the areas of proactive risk management and incident response. AI and building cybersecurity standards On the other hand, AI introduces new risks. The attack surface is expanding and threats such as deepfakes and smarter phishing create serious threats that regulators are determined to address. Both NIS2 and the CRA emphasize continuous monitoring, transparency and accountability, principles that must now also guide the responsible use of AI. At ASSA ABLOY Opening Solutions EMEIA, we see AI not just as a risk to mitigate, but as a capability to strengthen resilience and trust. That is why we are embedding strong governance practices around AI and building cybersecurity standards into every stage of product development. By doing so, we help our customers align with new regulations while ensuring AI serves as a tool for greater security and confidence. Trust and compliance Beyond our own operations, we are also committed to supporting customers on their compliance journey At ASSA ABLOY Opening Solutions EMEIA, we are taking NIS2, the CRA and the rise of cyber-threats seriously, ensuring compliance and enhancing trust with all our customers. We have reinforced supplier oversight, streamlined incident reporting, and embedded cybersecurity into every stage of product development and lifecycle management. Our teams also conduct ongoing risk assessments and post-incident reviews, ensuring that lessons are learned and improvements are made. By taking these steps, we not only meet regulatory requirements but strengthen the resilience of our supply chain and the trust customers place in us. Beyond our own operations, we are also committed to supporting customers on their compliance journey. Initiatives such as our recently released whitepaper “Enhancing Cyber–Physical Resilience with Digital Access Solutions” and a detailed NIS2 whitepaper developed in Germany last year provide clear, practical guidance. By showing what these regulations mean in practice and how intelligent access solutions can directly support compliance, we aim to make the path forward less complex and more achievable for our customers. Looking ahead The days when security threats to businesses and products were only physical are long passed. Today, we find ourselves in a world where the digital realm poses even more serious and constantly evolving challenges. It is therefore crucial that, as an industry, we take the necessary steps to meet the directives of NIS2 and the CRA and also constantly monitor the rise of AI. Only by doing so can we protect our customers, preserve our reputations, and build the trust that defines true leadership in security.
In today’s fast-evolving aviation landscape, innovation isn’t optional — it’s essential. With passenger traffic in the Asia-Pacific continuing to surge, the region is facing a pivotal moment: adapt with scalable tech, or fall behind. In January 2025 alone, APAC carriers accounted for 56.6% of global passenger traffic growth. Airports are operating at near capacity, with a record-high Passenger Load Factor (PLF) of 82.1%, leading to pronounced congestion at check-in counters, security checkpoints, and boarding gates. Increasing passenger volumes As airports strive to manage increasing passenger volumes without resorting to costly and time-consuming infrastructure expansions, technology — particularly facial recognition and biometric automation — emerges as a viable solution. However, the full realisation of these innovations requires more than just installing new system However, the full realisation of these innovations requires more than just installing new systems. It’s about building the right ecosystem of partners, processes, and policies to ensure sustainable, secure, and scalable growth. Presenting physical documents According to their estimates, over 120 APAC airports have already deployed biometric solutions at key travel touchpoints, including check-in, bag drop, security, and boarding. Thailand exemplifies this shift, with facial recognition deployed at six major airports — Suvarnabhumi, Don Mueang, Chiang Mai, Chiang Rai, Phuket, and Hat Yai — dramatically reducing passenger processing times. These systems allow travelers to verify their identities seamlessly at multiple touchpoints, from check-in and security screening to boarding gates, without presenting physical documents. This case reflects the Airports of Thailand’s (AOT) commitment to leveraging technology to improve operational efficiency and passenger experience. Digital identity programs Biometric solutions also extend beyond the airport: digital identity programs enable travelers to verify their identities before arriving at the terminal, creating seamless journeys from curb to gate. In this environment, facial recognition is not merely a futuristic innovation; it has become an operational imperative. Airports that fail to adapt risk falling behind, unable to manage burgeoning passenger volumes or meet evolving traveler expectations. True operational efficiency Despite its transformative potential, biometric technology cannot be successfully deployed in isolation. Achieving true operational efficiency through facial recognition requires strategic collaboration among technology vendors, IT integrators, airports, airlines, and regulatory authorities. Several pillars underpin a successful biometric implementation: Interoperability: Biometric systems must integrate seamlessly with a wide array of airline platforms, security protocols, and airport infrastructure. Lack of interoperability can lead to fragmented systems that frustrate staff and passengers alike. Scalability: Passenger volumes are forecasted to continue rising. Biometric solutions must be designed to scale rapidly in response to demand surges and future security challenges. Data Privacy and Security: With growing public scrutiny over personal data usage, airports must implement robust security frameworks that prioritize privacy and transparency. Encryption, consent-based use, and strict access controls are critical to gaining and retaining passenger trust. Future security challenges BKI can achieve significant throughput gains without major construction disruptions A case study illustrates these points: Malaysia’s planned revamp of Kota Kinabalu International Airport (BKI) aims to boost capacity by 33% over the next few years. Rather than expanding physical infrastructure alone, authorities are exploring facial recognition solutions to increase efficiency within existing spaces. By integrating biometric checkpoints at key touchpoints, BKI can achieve significant throughput gains without major construction disruptions. Such outcomes are only possible through well-coordinated technology partnerships, where vendors, airports, and integrators work toward a shared vision of future-ready travel. AI-powered computer vision What’s Next: Fully Biometric-Enabled Travel Looking ahead, the pressure on APAC airports is set to intensify. Airports Council International projects 9.5 billion air travelers globally by the end of 2025, a volume traditional processing methods cannot manage effectively. In response, AI-powered computer vision and facial recognition will continue to refine biometric processes, delivering higher accuracy rates and faster verification. Future systems will leverage real-time liveness detection, predictive analytics for crowd management, and seamless integrations across all travel stages. A fully biometric-enabled journey is becoming reality: Check-in with a glance at a kiosk Drop bags without producing an ID or boarding pass Clear security with automated facial recognition portals Board flights through biometric-enabled gates — without ever presenting a physical document. Experiencing significant growth Seamless integration across touchpoints creates a unified, frictionless journey In this vision of the future, identity becomes the ticket. Seamless integration across touchpoints creates a unified, frictionless journey. For APAC airports experiencing significant growth, full biometric enablement is becoming increasingly important for maintaining efficiency and staying competitive. At the same time, such a future demands robust technology ecosystems, where ongoing innovation is supported by partnerships that align regulatory, operational, and technological goals. Expanding physical infrastructure Building the Smart Airports of Tomorrow: Join the Conversation The aviation sector in APAC stands at a critical crossroads. Passenger growth, operational challenges, and heightened security requirements are converging, creating an urgent need for innovation. Facial recognition and biometric automation offer a clear path forward, enabling airports to handle growing volumes, enhance security, and deliver superior passenger experiences without necessarily expanding physical infrastructure. Facial recognition solutions Yet, the success of these innovations hinges on strategic, trusted technology partnerships. Airports must collaborate with technology vendors, IT system integrators, airlines, and regulators to ensure interoperability, scalability, and data security. At RecFaces, they believe the future of APAC airports is fully biometric-enabled. To explore how tech collaborations and advanced facial recognition solutions can transform airport operations, they invite users to join their free online panel discussion on April 30: ‘Smart Airports Start With Smart Tech: Facial Biometrics for APAC Airports.’
Technology advances in the security industry are transforming the way modern systems are designed and installed. Customers today are looking for greater scalability and flexibility, lower up-front costs, and operational efficiency. Cloud-based software as a service (SaaS) solutions, AI-enhanced tools, and IoT-enabled sensors and devices are increasingly in demand. The traditional role of the systems integrator is evolving as a result. While security integrators have always worked closely with end users, today’s pioneers go beyond installation and maintenance. They align security strategies with evolving business needs, integrating IT, cybersecurity, and data-driven insights into their offerings. A look at the past and present Integrators are often asked to help tailor solutions and provide expertise in IT and cybersecurity Traditionally, systems integrators specialized in installing and maintaining wired physical security systems like CCTV, access control, and alarms. The service model was built around large, up-front investments and project-based installations. However, today customers are seeking comprehensive solutions. They’re looking to wirelessly integrate security infrastructure with cloud-based SaaS systems and IoT devices. While modern systems are often faster to deploy, they’re most effective when supported by ongoing consulting and strategic planning. Integrators are often asked to help tailor solutions and provide expertise in IT and cybersecurity. Data requirements and modern systems Data requirements have also changed. Modern systems collect vast amounts of data. Advanced analytics, machine learning, and automation are now must-have tools for actionable insights. Security integrators can help end users set up custom dashboards, automations, and continuous system optimization. Let’s look at some of the specific ways the role of systems integrators is evolving and how to adapt and succeed. Strengthen your IT expertise Integrators with IT expertise can ensure that hardware is optimized and maintained for peak performance The competitive landscape today includes not just security specialists but also IT-focused integrators and SaaS providers. Systems integrators with expertise in traditional physical security solutions plus IT experience offer unique value. They understand the real-world security challenges and opportunities, along with cybersecurity and network best practices. Integrators with IT expertise can also ensure that hardware is optimized and maintained for peak performance. Their experience with legacy systems allows them to offer practical recommendations on cost-effective approaches, such as upgrading or integrating older hardware with new digital solutions. Consider who’s making the purchase decisions Traditionally, security integrators primarily sold to security directors, facility managers, and operations teams. Now, multiple stakeholders may be involved in decision-making. IT teams, CIOs, and CTOs often weigh in on purchase decisions when cloud-based security and SaaS solutions are under consideration. Customers today aren’t just shopping for cameras, access control panels, alarms, and other hardware components. They’re looking for security ecosystems that can integrate with enterprise-wide IT infrastructure and business applications. When working with these different teams, consider outlining the system's return on investment (ROI). How can the solution reduce risk for various departments? Can it help improve operational efficiency or reduce the time required to onboard and train staff? Will it make regulatory compliance easier to manage? Focus on the long-term value for the entire organization. Take a consultative approach Another way systems integrators are adding value is by offering vertical specialization Installation fees remain important for many integrators, but there may be additional consultative opportunities to build long-term relationships with customers. Offer services such as roadmap planning, hardware and integration maintenance, training to certify end users on the manufacturer’s product, and cybersecurity services. While cloud-based solutions reduce on-premises maintenance, they don’t eliminate the need for ongoing support and training. Consider offering training opportunities. These can lead to other benefits as well. Better-educated and technically proficient customers are usually more willing to adopt new technologies. They understand the value of these investments and have more confidence that they’ll see results. Another way systems integrators are adding value is by offering vertical specialization. Healthcare, sports venues, critical infrastructure, education, retail - each specialty has its own set of challenges, partner networks, regulatory restrictions, training needs, and business requirements. Integrators who specialize are uniquely positioned to offer key sector-specific insights that are invaluable to their clients. Embrace the cloud A key growth area for integrators is supporting customers in their shift to cloud deployments. Cloud solutions aren’t a one-size-fits-all solution. Each organization is evaluating options and deciding whether cloud, hybrid, or fully on-prem solutions are the right fit for its unique needs. A key growth area for integrators is helping clients in their shift to cloud deployments Helping customers navigate and adopt cloud or hybrid solutions opens new opportunities to expand your business and deepen your relationship with your customers. Systems integrators who sell cloud solutions have the opportunity to add new layers to services for more value for customers. With a cloud solution that's easy and fast to deploy and managed and maintained by the provider, you can reduce overhead costs, staff training, and truck rolls via remote customer support. These benefits also allow you to spend time developing greater expertise in your customers’ processes. Using this knowledge, you can tailor your services towards potential productivity gains for your customers and turn them into additional sales. You ensure that your customers get the most out of the technology that’s available and that they have already purchased. Highlight your focus on cybersecurity Cybersecurity is no longer solely an IT department's responsibility. While dedicated IT security teams may still handle broader network defense, integrators play a crucial role in securing access control, surveillance, and IoT devices within a security framework. If unsecured, these devices can provide an entry point for cyber criminals to gain access to an organization’s network. Cybersecurity is no longer solely an IT department's responsibility To best protect end users from cyberattacks, choose physical security systems with built-in security and privacy-by-design features. Help customers implement best practices to ensure their entire ecosystem is designed, built, and managed with end-to-end security in mind. Once implemented, work with your manufacturers, consultants, and end users to ensure that vulnerabilities are identified and mitigated. Every person on the network plays a role in keeping cyber threats at bay. Lean into the power of partnerships In today’s complex and dynamic security landscape, choosing the right technology partners is crucial. Ask potential partners to share their technology roadmap, and how you can offer feedback or participate in discussions about industry trends. Ideally, your partners will have a program in place to get input from integrators and end users, so they can develop products that are designed to address their most pressing issues and concerns. Your manufacturer partners should be working to help identify the evolving needs of customers and communicate these insights to systems integrators. Seek partners who actively support integrators to understand how security is evolving In addition to a good experience for the end user, strong manufacturer partners also offer solutions to streamline and automate workflows for integrators. It should be easy to order and check your shipping statuses online, for example. These are simple things that save you time and demonstrate your partner’s care for your business. Seek partners who actively support integrators to understand how security is evolving. While training is often offered on-site, some companies are now also offering blended learning models so integrators and their technicians can reduce classroom time and stay out in the field. Evolution is an opportunity Security integrators with traditional physical security expertise remain indispensable because they understand real-world risks and regulatory requirements. They can provide hands-on system deployment and optimization. Now, there are new opportunities to build long term customer relationships. As the physical security industry undergoes this profound shift, adaptation is key. By embracing cloud and hybrid solutions, integrators can unlock new revenue streams, enhance customer relationships, and stay ahead of technological advancements. With the right partnerships and a forward-thinking mindset, systems integrators can navigate this transformation and take advantage of new opportunities being presented by evolving technology. Leverage your deep industry experience while upskilling in cloud, cybersecurity, and IT. The strongest approach is for end users, systems integrators, IT specialists, and manufacturers to work together to navigate industry changes.
Security beat
Anyone who has been in a proverbial cave for the last couple of years faced a language barrier at this year’s ISC West 2025 trade show. The industry’s latest wave of innovation has brought with it a new bounty of jargon and buzzwords, some of which I heard at ISC West for the first time. As a public service, we are happy to provide the following partial glossary to promote better understanding of the newer terms. (Some are new to the security industry but have been around in the IT world for years.) Obviously, if we can’t understand the meaning of the industry’s lexicon (and agree on the meaning of terms!), we will struggle to embrace the full benefits of the latest industry innovation. Not to mention we will struggle to communicate. Generative AI Generative AI can identify an object in an image based on its understanding of previous objects This was perhaps the most common new(ish) term I heard bouncing around at ISC West. While the term artificial intelligence (AI) now rolls off everyone’s tongue, the generative “version” of the term is catching up. Generative AI uses what it has learned to create something new. The name comes from the core function of this type of artificial intelligence: it can generate (or create) new content. It doesn’t just copy and paste; it understands the underlying patterns and creates something original based on that understanding. In the case of video, for example, generative AI can identify an object in an image based on its understanding of previous objects it has seen. Video and security Generative AI can tell you something digitally about what is happening in an environment. There is no longer a need to write “rules;” the system can take in data, contextualize it, and understand it, even if it does not exactly match something it has seen before. In the case of video and security, generative AI offers more flexibility and better understanding. From 2014 to 2024, the emphasis was on detecting and classifying things; today AI is expanding to allow new ways to handle data, not so prescriptive and no more rules engines. Agentic AI Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals, with minimal to no direct human intervention. In addition to the capabilities of generative AI, agentic AI can take action based on what it detects and understands. Use of agentic AI typically revolves around an if/then scenario. That is, if action A occurs, then the system should proceed with action B. For example, if an AI system “sees” a fire, then it will shut down that part of the building automatically without a human having to initiate the shutdown. There is a lot of discussion in the industry about the need to keep humans involved in the decision-making loop, so use of truly autonomous systems will likely be limited in the foreseeable future. However, the ability of agentic AI to act on critical information in a timely manner, in effect to serve as an “agent” in place of a human decision-maker, will find its place in physical security as we move forward. Inference Inference is another common term related to AI. It refers to the process by which an AI model uses the knowledge it gained during its training phase to make predictions, classifications, or generate outputs on new, unseen data. The direct relationship of this term to physical security and video is obvious. In the simplest terms, an AI system is “trained” by learning patterns, relationships, and features from a large dataset. During inference, the trained model is presented with new questions (data it hasn't seen before), and it applies what it learned during training to provide answers or make decisions. Simply put, inference is what makes AI systems intelligent. Containerization Dividing a massive security management system into several separate containers enables management of the various parts In IT, containerization is a form of operating system-level virtualization that allows you to package an application and all its dependencies (libraries, binaries, configuration files) into a single, portable image called a container. This container can then be run consistently across any infrastructure that supports containerization, such as a developer's laptop, a testing environment, or a server in the cloud. In the physical security industry, you hear “containerization” used in the context of separating out the various components of a larger system. Dividing a massive security management system into several independent containers enables the various parts to be managed, updated, and enhanced without impacting the larger whole. Genetec’s SecurityCenter cloud platform Think of it like shipping containers in the real world. Each container holds everything an application needs to run, isolated from other applications and from the underlying system. This ensures that the application will work the same way regardless of the environment it is deployed in. “It took us five years to containerize Genetec’s SecurityCenter cloud platform, but containerization now simplifies delivering updates to products whenever we want,” says Andrew Elvish, Genetec’s VP Marketing. Among other benefits, containerization enables Genetec to provide more frequent updates--every 12 days. Headless appliance Headless appliance is a device that is managed and controlled remotely through a network or web interface A headless appliance is a device that is managed and controlled remotely through a network or web interface. The device is like a “body without a head” in the traditional sense of computer interaction: It performs its intended function, but without any visual output or input device for local interaction. In physical security, such devices are increasingly part of cloud-based systems in which the centralized software manages and operates all the disparate “headless” devices. A headless appliance does not have a Windows management system. “The whole thing is managed through the as-a-service cloud system,” says Elvish. With a headless device, you just plug it into the network, and it is managed by your system. You manage the Linux-based device remotely, so configuring and deploying it is easy. Democratizing AI You hear the term democratizing AI used by camera manufacturers who are looking to expand AI capabilities throughout their camera lines, including value-priced models. For example, even i-PRO’s value-priced cameras (U series) now have AI – fulfilling their promise to democratize AI. Another approach is to connect non-AI-equipped cameras to the network by way of an AI-equipped camera, a process known as “AI-relay.” For instance, i-PRO can incorporate non-AI cameras into a system by routing/connecting them through an X-series camera to provide AI functionality. Bosch is also embracing AI throughout its video camera line and enabling customers to choose application-specific analytics for each use case, in effect, tailoring each camera to the application, and providing AI to everyone. Context Cloud system also enables users to ask open-ended queries that involve context, in addition to detection Context refers to an AI system that can understand the “why” of a situation. For example, if someone stops in an area and triggers a video “loitering” analytic, the event might trigger an alarm involving an operator. However, if an AI system can provide “context” (e.g., he stopped to tie his shoe), then the event can be easily dismissed by the automated system without involving an operator. Bosch’s IVA-Pro Context product is a service-based model that adds context to edge detection. The cloud system also enables users to ask open-ended questions that involve context in addition to detection. For example, rather than asking "do you see a gas can?" you can ask "do you see any safety hazards in this scene?" The pre-trained model understands most common objects, and understands correlations, such as "a gas can could be a safety hazard.” A scaled-down on-premise version of the IVA Context product will be available in 2026. Bosch showed a prototype at ISC West. Most video data is never viewed by an operator. Context allows a system to look at all the video with "almost human eyes." Cameras are essentially watching themselves, and understanding why something happened and what we can do. All that previously unwatched video is now being watched by the system itself, boosted by the ability to add “context” to the system. Any meaningful information based on context can trigger a response by an operator. Data lake A data lake is a centralized repository that allows one to store vast amounts of structured, semi-structured, and unstructured data in its native format. In the case of the physical security marketplace, a data lake includes data generated by systems outside the physical security infrastructure, from inventory and logistics systems, for example. A data lake is where an enterprise can accumulate all their data, from the weather to Point-of-Sale information to logistics, to whatever they can gather. Putting the data in one place (a “data lake”) enables them to mine that data and parse it in different ways using AI to provide information and insights into their business. Notably, a data lake contains all a company’s data, not just security or video data, which opens up new opportunities to leverage the value of data beyond security and safety applications. Crunching the various information in a data lake, therefore, security technology can be used to maximize business operations.
The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel. The shocking event raised awareness in board rooms around the world about the need for, and challenges of, executive protection. Questions followed immediately, including why was the high-level executive not protected? Combination of risk and reward UnitedHealthcare’s stock price has gone down more than 20% since the shooting The event also highlighted what is at stake for companies, extending beyond the safety of executives and impacting many factors, even including a company’s stock price. UnitedHealthcare’s stock price has gone down more than 20% since the shooting, equating to tens of billions of dollars. “Companies are considering the combination of risk and reward like never before when it comes to executive protection,” says Glen Kucera, President of Allied Universal Enhanced Protection Services. “What are the chances this could happen? Before Dec. 4 many thought it was zero. And what are the financial implications for a company if it happens? Executive protection is a small investment to protect against a worst-case scenario.” Evaluation of an executive protection Before the UnitedHealthcare shooting raised awareness, fewer than 50% of executives had protection. But concerns that previously fell on deaf ears now have the full attention of companies, says Kucera. “Boards of directors are having to figure this out,” he adds. “They may not have executive protection, but now they have to do it.” A threat assessment, conducted by a company such as Allied Universal, provides an independent evaluation of a company’s executive protection needs. The assessment evaluates factors such as an executive’s travel habits, the safety of their home, etc. Does the executive need protection 24/7, or just when they travel into more dangerous areas? Risks increase related to corporate earnings Sometimes, cases increase the need for executive protection, such as an internal threat In assessing threats, security professionals also look beyond the individual to consider the safety of a corporate facility, for example. “Is there a visual deterrent, controlling who comes and goes?” asks Kucera. “If there is good security, it all ties together. We do home assessment, facility assessment, route assessment, and travel assessment as needed.” Sometimes, circumstances increase the need for executive protection, such as an internal threat. Timing is a factor, and risks increase related to corporate earnings releases, new product announcements, and corporate layoffs or consolidation. Monitoring social media tracks shifting threats that impact the need for executive protection. UnitedHealthcare shooting “He didn’t have it and probably didn’t think he needed it,” comments Kucera about the UnitedHealthcare executive who was gunned down in the streets of New York City. “He was staying at the hotel across the street and was used to walking down the street every day.” “Sometimes executives want to preserve their privacy and be able to walk down the street,” says Kucera. “Getting protection can be seen as a sign of weakness. Some CEOs in the past have said they just didn’t want it.” However, the UnitedHealthcare shooting raised the stakes of the need for more vigilance. “The bottom line is you have to yet beyond objections and make the investment to protect against a worst-case scenario,” says Kucera. Anti-capitalist sentiment in the general population An internal police bulletin warned of an online hit list naming eight executives and their salaries Threats to executives sometimes arise from anti-capitalist sentiment in the general population about perceived inequalities in wealth and power. Executives provide symbolic targets for anyone who fights the system, and social media has amplified the voices of those who oppose capitalism. For example, a "Most Wanted CEO” card deck seeks to shine a spotlight on "titans of greed." Also, in the aftermath of the UnitedHealthcare shooting, CEO "wanted" posters appeared across New York City, threatening various executives of large companies. An internal police bulletin warned of an online hit list naming eight executives and their salaries. Careful monitoring of social media posts Careful monitoring of social media posts and other sources enables executive protection professionals to analyze data and separate the dangerous threats from the merely negative ones. Sadly, positive support of the UnitedHealthcare shooting was expressed by the 300,000 or so followers of the shooter, who became a celebrity of sorts. A huge outcry of negative sentiment toward the insurance industry led to fear that copycat incidents might occur. “There has been an unprecedented amount of positive support for committing murder,” commented Kucera. Executive protection requests HR executives can be at risk, especially at a time of layoffs or consolidation “Let’s face it, there has been a lot of controversy, from COVID to the Middle East crisis, to the political campaign, and there is negativity on both sides,” says Kucera. “People have opportunities to pick sides, and there is a lot of sentiment going both ways, and there is a small percentage of people who will act aggressively.” Executive protection requests now extend beyond the CEO to include others in the management ranks of companies. Basically, any public-facing executive is at risk, including anyone who makes statements to the press. Human resource (HR) executives can be at risk, especially at a time of layoffs or consolidation. Private information on the Internet Typically, an executive is assigned a single armed operative for protection. The firearm serves primarily as a visual deterrent that hopefully makes a potential perpetrator think twice. “When they plan an event like this, their expectation is that it will be a soft target,” says Kucera. “If there is an officer, it gives them pause.” Controversial or high-profile CEOs are typically protected 24/7, including when they travel with their family. Adding risks is the fact that private information is now posted on the Internet, including where an executive lives and where their children go to school. Internet monitoring Internet monitoring also includes the “dark web,” which includes sometimes dangerous information “We offer social media monitoring, and we advise them to be more careful with what they post,” says Kucera. “We monitor reactions to posts including any that might be threatening. We watch social media carefully if a company announces earnings or a change in their service or product offering.” Internet monitoring also includes the “dark web,” which includes sometimes dangerous information that is intentionally hidden and requires specific software, configurations, or authorization to access. Own layer of protection Public and government officials can also come under fire in a variety of scenarios. FEMA officials faced threats after the recent floods in the Southeast, for example, among other situations where perceived unfair treatment promotes thoughts of retribution. Although government agencies have their own layer of protection, there are instances when they call on companies such as Allied Universal for additional help. Ad hoc protection for various executives In the aftermath of the UnitedHealthcare shooting, calls to Allied Universal’s Command Center increased by 600%, reflecting requests for ad hoc protection for various executives. These requests are in addition to the company’s business providing “embedded” operatives that travel with executives all or some of the time. On that side of the business, requests for services are up probably 300%, says Kucera.
The information age is changing. Today, we are at the center of addressing one of the most critical issues in the digital age: the misinformation age. While most awareness of this problem has emerged in the consumer and political worlds, the issue cannot be ignored when it comes to the authenticity and protection of video and security data. Video surveillance data SWEAR is a company with the mission to ensure the integrity of video surveillance data by mapping video data and writing it into the blockchain, providing real-time, immutable proof of authenticity. Blockchain, which is the underlying technology that enables cryptocurrencies, is a decentralized digital ledger that securely stores records across a network of computers in a way that is transparent, immutable, and resistant to tampering. SWEAR solution The SWEAR solution is based on proactive, foundational protection that validates data at the source The SWEAR solution is based on proactive, foundational protection that validates data at the source before any opportunity for manipulation can occur. “Our technology is about proving what’s real and our goal is to ensure that security content and video surveillance data remain untampered with and reliable when needed,” says Jason Crawforth, Founder and CEO of SWEAR. Real-time authentication Security leaders need to ensure that the content they are relying on to make mission-critical decisions is authentic. Once verified, organizations can be sure that their investment in video can be trusted for critical use cases, including intelligence operations, legal investigations, and enterprise-scale security strategies. SWEAR seeks to embed trust and authenticity directly into video surveillance content at the point of creation. This ensures real-time authentication while proactively preventing tampering or manipulation before it can happen. AI-generated content The rise of AI-generated content, such as deepfakes, introduces significant challenges As AI transforms the landscape of video surveillance by enhancing threat detection and predictive analysis, it also introduces the very real risk of manipulation through AI-generated content. This presents a significant challenge in protecting critical security data, especially in mission-critical applications. The rise of AI-generated content, such as deepfakes, introduces significant challenges when it comes to ensuring the protection of digital media like video surveillance. Recent study findings It is a fact that digital media content is being questioned more regularly, which puts businesses, legal systems, and public trust at risk. A recent study from the Pew Research Center found that 63 percent of Americans believe altered videos and images create significant confusion about the facts of current issues. Last month, California Governor Gavin Newsom signed three bills aimed at curbing the use of AI to create fake images or videos in political ads ahead of the 2024 election. Footage authenticity “While most of the news cycle has centered on the use of fake content in politics, we need to think about how manipulated videos could affect security,” says Crawforth. “In video surveillance, ensuring the authenticity of footage is critical for keeping operations secure and safe around the world. That means verifying and protecting video data is a must.” Organizations must be capable of performing thorough digital investigations, which involve retrieving and analyzing video and security data from devices and networks through a chain of evidence. Digital forensic capabilities Strong digital forensic capabilities also enhance incident response, risk management, and proactive security An in-depth understanding of who has handled video data, how it was handled, and where it has been is an important step in responding to security incidents, safeguarding assets, and protecting critical infrastructure. Strong digital forensic capabilities also enhance incident response, risk management, and proactive security measures, all essential for risk management, regulatory compliance, and cost control, says Crawforth. An unbroken chain of custody “By using tools to identify, preserve, and analyze digital evidence, organizations can ensure swift and accurate responses to security incidents,” he adds. “Using the latest tools and techniques is vital for maintaining a strong security posture." "But you must ensure your digital content isn’t manipulated.” SWEAR’s technology provides an unbroken chain of custody, ensuring that video evidence can be trusted and admissible in court and forensic applications. Authenticating content Authenticating content also strengthens accountability and trust, protecting organizations By verifying video content is protected from tampering, manipulation, or forgery, organizations can be sure that they have reliable evidence that produces actionable results. Authenticating content also strengthens accountability and trust, protecting organizations from legal disputes or compliance violations. Safeguarding digital content “With an increasing amount of disinformation in today’s world, we sought to develop an innovative solution to safeguard the integrity of digital content,” says Crawforth. SWEAR safeguards security content using real-time “digital DNA” encoding. It integrates directly at the video management system level, ensuring it is preserved with a secure chain of custody and maintains integrity for evidentiary purposes. Real-time “digital DNA” encoding The digital DNA is then stored on a blockchain, creating an immutable record The solution integrates with cameras and other recording devices to map this digital DNA of the video data, all in real-time. The digital DNA is then stored on a blockchain, creating an immutable record that tracks the content’s history and integrity. Any attempt to manipulate the media can be instantly detected by comparing the current state of the media to its original, authenticated version. SWEAR is actively collaborating with video management solution providers to integrate the technology into their platforms. Video and security data benefits “We’re still in the early stages of our collaboration in this space, but it is clear that the industry recognizes that we have to work together to mitigate this risk proactively before it becomes a significant issue,” says Crawforth. “The feedback we have received from the industry to date has been beyond our expectations, and we expect to have more integration partners to highlight shortly.” “We should approach this as a collaborative effort across the industry, as ensuring the authenticity of video and security data benefits everyone involved,” says Crawforth.
Case studies
Working in the heavily regulated and frequently targeted financial services industry, the client (a global financial services group) needed to ensure its cybersecurity posture was extremely robust to protect its infrastructure and customer data from threats. The previous threat detection solution posed challenges, notably with a high volume of false positives. Without a robust SIEM tool and relying on less effective UEBA processes, the team recognized the need to fortify its security framework to align with their stringent standards. Another key area of focus was enhancing visibility within their security infrastructure. The existing setup presented an opportunity for improvement in consolidating monitoring capabilities into a unified interface. Additionally, the team wanted to enhance oversight of active directory actions, specifically addressing enumeration attacks, and monitoring the controlled export of company data by internal users. The solution Brought in to increase visibility and reduce overall risk, RiverSafe suggested they implement Exabeam, which would provide the company with all the best-in-class UEBA tools needed. RiverSafe suggested Exabeam due to the platform’s efficient data processing, simple architecture, scalability, and ease of deployment. The off-the-shelf content within Exabeam’s UEBA dashboards and reporting tools offered another key benefit, giving the security team access to data pre-built models and statistics that would allow them to start monitoring and flagging events immediately. Finally, Exabeam’s smart timeline feature that merges all user activity into one stream would address the visibility issue. Security and monitoring purposes With the client ready to implement, RiverSafe deployed Exabeam on their AWS Environment following best practice guidelines. The team mapped out relevant log sources for the system, and onboarded all data streams, filtering and fine-tuning everything to ensure any information being ingested was relevant for security and monitoring purposes. RiverSafe then developed and deployed use cases scoped out in partnership with the client, helping them to get maximum value from their Exabeam implementation. This documentation included custom roles, models and parses, as well as other quality of life improvements, additional search filters, and guidance on maintenance and monitoring techniques. The outcome The client now has an established monitoring workflow for its security team that’s baked into their day-to-day tasks. The team can monitor the entire environment quickly, and has significantly reduced the time it takes to assess threats like phishing and brute force attacks, and investigate unusual internal behaviours. Following RiverSafe’s advice, the client has been able to scale its Exabeam solution by accessing the right hardware required to run the product efficiently. Data loss and maintaining data integrity Noise from the SIEM has been reduced thanks to the optimization work conducted on log source onboarding. This has resulted in less complexity, fewer false positives, and easier access to the precise information that the team really needs. The security team now has visibility into email, endpoint, active directory, and web activity, and is able to monitor these frequently targeted areas for suspicious events and behavior. This visibility now also extends to file activity, protecting the company from potential data loss and maintaining data integrity. Managing security data and identifying trigger points Siloes have been eliminated, with security insights now located in a single repository for maximum perceptibility. From server performance to traffic flows, whatever’s happening across its pan-global regions, the security team know about it. Exabeam has equipped the team with a simpler, more effective way of managing security data and identifying trigger points—resulting in a 30% reduction in time spent on threat hunting.
The client, a large telecommunications provider, had teams working across multiple time zones and operated a sprawling and complex IT system. The scale and density of this system made gaining visibility into IT services extremely difficult, leaving the security team blind to what was happening with its IT environment. With little-to-no operations monitoring tools in place to proactively monitor these systems, the team had no visibility on the availability of its IT services or KPIs such as failure rates, send request times, and response times. This lack of oversight made it difficult for the team to prioritise issues — and nearly impossible for them to find the root cause of any problem. Proactive measures Without the ability to investigate the source of issues, the team was unable to take proactive measures to prevent them from reoccurring, severely impacting service performance. This was not only a problem for IT teams, but also for executives, who lacked the insight into IT business operations that would help them make decisions. The solution The company needed a solution that would map KPIs to critical service components, enabling the operations team to effectively drill down into issues in real time and conduct in-depth investigations to find resolutions. RiverSafe had previously implemented Splunk Enterprise Security for the customer and given the success of the implementation and the positive client feedback on the platform, RiverSafe was again engaged to deploy Splunk’s IT Service Intelligence (ITSI) tool to help it tackle its visibility problem. Data collection metrics Splunk ITSI uses machine learning to analyse existing data and predict future issues. As well as forecasting potential services bottlenecks, it can also troubleshoot problems and help users resolve issues fast. Delivering comprehensive monitoring across the entire IT environment, Splunk ITSI would also give the team full observability of their IT infrastructure. In particular, the engineering team wanted to gather metric data relating to the Kubernetes platform. RiverSafe reconfigured and implemented data collection metrics used elsewhere in the IT environment in Splunk to allow engineers to collate and access this information from different data sources in one place. The outcome: Actionable insights in days, not weeks In less than a week, the RiverSafe team implemented Splunk ITSI and began running monitoring services. With data from existing KPIs already indexed by the Splunk platform, the team are now able to access service insights even faster. These KPIs allow the operations team to identify trends, detect patterns, and proactively address any anomalies that occur before issues arise. Instant visibility with glass table visualisations To enable rapid and proactive issue resolution, RiverSafe implemented custom glass table visualisations in Splunk ITSI. This enables the team to navigate large volumes of data and reduce the time needed to identify and resolve problems. This simple and accessible dashboard gives the team an instant, digestible overview of its web portal performance metrics. These KPIs included the number of open tickets and failed login attempts, memory usage, API call success rates, average response times, and overall health of container services. Event analytics in Splunk ITSI As a result of RiverSafe’s work, the team has been able to centralize events from all its previously siloed solutions into a single interface with Splunk ITSI. The event analytics in Splunk ITSI help to prioritise responses and react more quickly to customers’ infrastructure events, empowering them to provide a better service. This is thanks in part to Splunk ITSI’s ability to identify and filter out false positives from the event management process. Excluding these invalid events reduced the total event volume by 40%, helping operators focus on the events that really matter. With fewer events to process, a single interface to work from, and a streamlined event analytics framework in Splunk ITSI, operators now process events eight minutes faster on average. This boost in efficiency has led to a major improvement in the company’s SLA performance. Best practices for using Splunk ITSI Overall, Splunk ITSI has delivered enhanced operational visibility, meaning the team can locate bottlenecks in workflows quickly and deliver fast recovery and troubleshooting solutions. Along the way, RiverSafe also provided best practices for using Splunk ITSI and recommended the most effective ways to collect data, including proposing an alternative metric type that would save on storage space when collecting logs.
In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organization. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimize operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialized expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organization. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimize the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.
With an extensive network of customers spanning the globe, cybersecurity is a primary concern for our client. Protecting extensive infrastructure and customer data requires a robust cybersecurity posture and effective tools, but the team found its SIEM solution lacking. Flooding its security team with an unmanageable number of false positives, the solution was diverting attention away from genuine threats and leaving them vulnerable. A substandard SIEM solution was not the only security issue. With no UEBA platform in place to help detect insider threats and data breaches, the company was faced with a number of gaps and weak spots in its security infrastructure that needed to be addressed. Three key issues The biggest concerns centred around three key issues: A lack of insider threat detection: Without a UEBA solution, the company had difficulty identifying insider threats and anomalous user behaviour within the network. Time spent on manual investigation: Security analysts spent significant amounts of time manually correlating events and investigating incidents, leading to delays in incident response and inefficient use of resources. Alert fatigue: The company’s existing SIEM solution generated a high volume of alerts, making it challenging for analysts to identify genuine threats among the many false positives. The solution The company engaged with RiverSafe to create a bespoke implementation plan that would address its primary issues and properly secure its digital infrastructure. Working in collaboration with the in-house security team, RiverSafe got to grips with existing infrastructure, gathered requirements and outlined the desired outcomes of the project. With all challenges and end goals collated, the RiverSafe team developed a solution that would meet all requirements and eliminate current security weaknesses. The team suggested Exabeam’s Fusion SIEM platform as it addressed the key concerns: Incident management: Delivering streamlined incident management processes by automating the correlation and enrichment of security events, Fusion SIEM equips analysts with actionable insights and real-time alerts. This improved visibility helps analysts hone in on genuine threats more quickly and reduce response times. Behaviour analytics: Tackling the company’s lack of UEBA issue, Exabeam’s advanced machine learning algorithms were configured to establish baseline behaviour for all users and systems. Any deviation from this baseline alerts analysts, enabling them to investigate anomalous activities and potential security issues, including insider threats. Data integration: The platform was integrated with various data sources, including logs from firewalls, servers, applications, and network devices to ensure comprehensive visibility across the organization’s infrastructure. The outcome The implementation of Exabeam’s Fusion SIEM solution has yielded significant benefits, including: Enhanced threat detection: Exabeam’s behavioural analytics (AA) and machine learning (ML) capabilities have improved the accuracy of threat detection, enabling analysts to identify and respond to security incidents more effectively. Faster incident response: Exabeam’s automated incident enrichment and real-time alerts are helping the security team to respond to incidents promptly, minimizing the impact of potential breaches. Reduced alert fatigue: The platform’s next-generation event analysis capabilities have reduced the number of false positives generated, reducing alert fatigue and giving analysts more time to focus on genuine threats. Improved insider threat detection: With its advanced behaviour analytics, Fusion SIEM is enabling the team to detect insider threats by identifying abnormal user activities and deviations from established behavioural patterns.
The client, a pioneering oil and gas corporation, faced significant challenges in knowledge management. The software engineering function struggled with locating the right documentation across multiple platforms such as ADO Repo, Confluence, SharePoint, and others. This fragmented system created delays and inefficiencies, with engineers spending valuable time searching for answers rather than focusing on delivery. Slow Access to Technical Information The sheer volume of documentation, continuously growing, compounded the problem. Onboarding tools for cloud services Onboarding tools for cloud services was also cumbersome, often dependent on a “hero culture” where finding the right person for help was the norm. This led to frequent meetings, wasted time, and a negative engineering experience, significantly slowing down workflows. RiverSafe was brought in to improve the engineer experience and increase velocity by enabling engineers to complete tasks more efficiently, reduce reliance on individual knowledge holders, and minimize time spent searching for outdated or misplaced documentation. The solution AI-enabled knowledge discovery They introduced an engineering portal powered by AI and natural language processing (NLP). Using a closed-domain RAG model, this portal introduced a ChatGPT-style interface where engineers could engage in natural language conversations to query documentation and receive consolidated answers, dramatically reducing the time spent locating information. The portal’s capabilities include rich content support such as diagrams, graphs, videos, and even in-platform automation for tasks like tool onboarding, further streamlining processes. The platform draws from multiple high-quality content repositories, creating a unified search experience across ADO Repo, Confluence, Internal document management systems, SharePoint, and more. Crucially, they implemented near-real-time monitoring for key model metrics, ensuring that each user’s question and answer interactions delivers unparalleled accuracy and relevance. This guarantees that the portal continuously provides genuine value through its responses. Recognizing the challenges posed by response degradation and hallucinations in AI-driven systems, they have developed a set of innovative solutions designed to optimize each interaction’s impact. The outcome Eliminating wasted time and accelerating software delivery The portal has transformed the way engineers work, saving significant time and boosting efficiency across the board. One engineer commented, “I’ve been here for 15 years, and this is the best product for software delivery in our organization. Previously, it could take me 2 weeks just to find out how to build a cloud environment. Now I get the answer straight away.” Key outcomes Time and Cost Savings: Engineers now save between 45 minutes and 10 days when searching for technical solutions. The portal has saved the organization 68,000 engineering hours annually, equating to over £4 million in cost savings within the first year. Improved Document Quality: The platform collects and analyses data on the usefulness and quality of documents. This feedback loop ensures that outdated or low-quality documents are flagged for improvement, keeping the knowledge base relevant and focused on high-value content. High-Fidelity Responses: Engineers receive immediate, detailed responses with links to relevant documentation, images, videos, and graphs. This reduces reliance on outdated information and significantly improves the quality of software delivery. Onboarding and Automation: Engineers can complete tasks directly within the platform, such as onboarding new tools, without needing to switch between systems, further streamlining workflows. User feedback and performance data The portal continues to gather user feedback and performance data, ensuring that it remains an invaluable tool for the organization, consistently improving the engineer experience and accelerating software delivery. The organization has also engaged NeuroLogik to build on these successes. NeuroLogik specialises in providing deep insights into entire codebases, ensuring that engineers can easily locate and reuse existing code across the organization, further enhancing efficiency and reducing duplication of effort.
The client, a British media and telecommunications company, was looking to increase operational efficiency, save time spent on identifying and addressing vulnerabilities and reduce risk by increasing visibility across their environment. With multiple security tools in different places, security data was siloed and needed to be accessed separately. This led to long periods of time spent jumping between tools to find data, and a lot of context switching when it came to looking at the results. Developers, security teams and senior directors were forced to search in multiple places for critical, often time-sensitive information about vulnerabilities. Risk of vulnerabilities Not only did this eat into their valuable time, but it also meant they had no overall visibility into the organization’s security posture. This lack of visibility significantly hampered the development process, as developers struggled to locate and address security issues. In addition, the organization did not have centralized CI/CDs, instead running different pipelines for individual developers or teams. Combined with poor visibility, this lack of efficiency was causing major frustration for the development team, slowing down development and increasing the risk of vulnerabilities in the code going undetected. The solution RiverSafe was initially brought on board to address the issue of decentralized security data, and help improve operational efficiency. The team’s goal was to allow for the results to be sent directly to the developers without them needing to access and search multiple security platforms to find the information they needed. The RiverSafe team created an integration script for the developers to execute when they were running their pipelines. Once triggered, the script would send a notification to a server that RiverSafe had specifically designed, which collated the identified vulnerabilities and relayed them back to the developers’ pull request. This ensured the development team got the information they needed to improve the security of their code. The next phase: Developing the data insights RiverSafe consultants worked alongside the client’s team to take all the security data that was being collected and, rather than sending it to individual developers’ pull requests, instead created and directed it to a pane-of-glass tool. This tool allows the developers to log in and see their repositories and projects in one place. For management, it allows them to have a complete picture of all the vulnerabilities and what they are impacting, on both individual repositories or a given product. The tool also allows them to build reports and includes a scoring model to give a visual rating so everyone can easily see if their repositories are secure or not. The scoring system, ranging from insecure to excellent sends alerts to let the developers know if their repositories fall below a certain level so they don’t need to continually monitor themselves. The RiverSafe team also provides advice on the steps that should be taken to remediate any identified vulnerabilities. Multiple security operations A key requirement of this tool was that it supported multiple security operations, including SAST (Static Application Security Testing), which would look at code smells and general quality of life, Source Code Analysis (SCA), which would look at which libraries are being used and also Secret Scanning to look for secrets in the code. RiverSafe also wanted to ensure that all of this is serverless on AWS to minimize the time spent on infrastructure maintenance. After launching, RiverSafe continued to work on improving this tool, making quality improvements, performing maintenance, and enhancing the integration via the shell scripts. The outcome The tool now brings together data from over 22,000 code repositories into one centralized place, allowing the client to see all of their security information, what libraries were most common, where the vulnerabilities were, and to start looking for trends. Developers and other stakeholders no longer need to scour multiple locations for vulnerability data, saving the company huge amounts of time and making its development process more efficient. With the bespoke script in place, the data comes to them. This increase in visibility has also led to improvements in response times to zero-day vulnerabilities. Previously, it could take weeks or even months to find all the affected repositories. However, since implementing RiverSafe’s custom tool, the team has been able to locate repositories featuring the vulnerable package immediately and remediate any issues quickly, massively improving their overall security posture. Thanks to this uplift in operational efficiency, the development team is now able to spend more time improving their code. RiverSafe and the client’s team are now working on expanding coverage throughout the organization, improving analytics and alerting, and centralizing CI/CD pipelines.


Round table discussion
Emphasizing proactive rather than reactive security shifts the focus from dealing with crises and damage control to prevention. Advantages of a proactive approach include cost efficiency, better business continuity, and fewer crises that draw attention away from strategic improvements. Staying ahead of threats is a core mission of the security department, and technology has evolved to enable security professionals to deliver on that mission better than ever. We asked our Expert Panel Roundtable: How are security systems transitioning from reactive to proactive, and what is the benefit?
Data overload is real. Sometimes it seems we are bombarded by the sheer volume, velocity, and variety of data available in our personal lives, and in our work lives. The solution is to figure out how to make sense of the data and transform it into real information we can use. In the case of physical security systems, new opportunities are emerging every day to utilize data to make our businesses safer and better managed. We asked our Expert Panel Roundtable: What is the expanding role of data in physical security systems? Why does it matter?
New technology advancements significantly increase efficiency and productivity in any industry, including physical security. Enhanced innovation both creates new products and services and improves existing products, all for the benefit of security manufacturers, integrators, and end users. Companies that embrace new technology stay ahead of the curve and gain a significant competitive advantage. In addition, they can differentiate themselves in the marketplace. We asked this week's Expert Panel Roundtable: What are the most promising new technologies in the physical security industry?
Products


White papers
Technology's Role In Securing Banks And Financial Institutions
Download
Securing The Modern Data Center
Download
An End User's Guide To Physical Security For Data Centers
Download
The User-Centric Security Revolution
Download
One System, One Card
Download
Aligning Physical And Cyber Defence For Total Protection
Download
Understanding AI-Powered Video Analytics
Download
The Power Of Integration In Physical Security Systems
Download
Using Artificial Intelligence (AI) To Automate Physical Security Systems
Download
A Modern Guide To Data Loss Prevention
Download
7 Proven Solutions For Law Enforcement Key Control And Asset Management
Download
Palm Vein Recognition
Download
Cybersecurity For Enterprise: The Essential Guide To Protecting Your Business
Download
The Security Challenges Of Data Centers
Download
Access Control System Planning Phase 2
Download

