Data Security
Aetina Corporation, a foremost provider of edge AI solutions and accelerator of edge AI infrastructure, announced the launch of MegaEdge AIP-RQ87, a ready-to-deploy 2U edge agentic AI system designed to help enterprises and system integrators (SIs) rapidly implement AI agent, private LLM, RAG application, multimodal AI, and AI-driven intelligent automation. Powered by Intel® Core™ Ultra processors with high-bandwidth PCIe Gen5 x16 architecture, AIP-RQ87 delivers enterprise-grade AI co...
Netwrix, a recognized pioneer in identity and data security, announces new capabilities across Netwrix PingCastle and Netwrix Threat Manager that extend identity security deeper into the Microsoft cloud, including coverage of AI agents. Organizations are deploying AI agents faster than they can govern them. Each agent is an identity holding real permissions inside the enterprise environment, yet most exist outside any inventory, ownership, or review process. Identities needing access A Cloud...
Matrix Comsec, a provider of enterprise-grade security and telecom solutions, has been recognized at the Gujarat Best Employer Brand Awards 2026 for its focus on building a people-first and future-ready workplace. The recognition was presented on August 11, 2026, at Fairfield by Marriott, Ahmedabad. Matrix integrates its people strategy with its broader business vision. Operating in a technology-driven industry, the company focuses on continuous learning, technical capability development, leade...
Just last December, Plusserver announced a far-reaching cooperation with SHD. Now, IT-BUSINESS reports that the managed hosting provider Plusserver has evolved into a regional cloud provider. For 2023, the Cologne-based company has its sights set on expanding its partner business, having laid the groundwork for this last year. SHD has been operating a data center for ten years, providing infrastructure resources to customers as a service. Under the "SHD Enterprise Cloud" label, SHD will not onl...
Fortinet®, the global cybersecurity pioneer driving the convergence of networking and security, announces new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-assisted operations into FortiEndpoint, Fortinet enables security teams to better govern AI usage, reduce sensitive data exposure, enfo...
Scality, a pioneer in data infrastructure software for the AI era, and OVHcloud, a global cloud provider and European cloud pioneer, announces an expanded technology partnership and a new joint storage platform built for European digital sovereignty. The solution gives organizations full control over sensitive data, with no dependency on U.S. hyperscalers, while delivering the performance and resilience required for the most demanding AI workloads. Deployment options include a 100% dedicated so...
News
Commvault, a pioneer in unified resilience at enterprise scale, announces a strategic partnership with Microsoft that underscores the importance of AI and cyber resilience as enterprises accelerate their move to the cloud, rapidly scale AI utilization, and face increasingly complex data security threats. Through this partnership, Microsoft will offer Commvault’s extensive AI and cyber resilience technologies as a native ISV service on Microsoft Azure. This will give Azure customers the ability to discover, provision, and seamlessly integrate Commvault’s trusted resilience capabilities directly from the Azure cloud platform. Azure cloud platform These capabilities can be used to help enterprises rapidly recover and restore data, applications, and identities if systems are compromised by attacks, outages, or human error. This collaboration will provide a unified experience across procurement, onboarding, and operations, eliminating the need for separate infrastructure, manual integrations, or external tooling for Commvault customers. “For over 25 years, we’ve partnered with Microsoft and now we’re taking that collaboration to the next level,” said Sanjay Mirchandani, President and CEO, Commvault. “Many of our customers rely on Microsoft Azure to scale their business in the cloud, use AI, optimize operations, and bring ideas to life. With this joint commitment, we can also make best-in-class resilience plug-and-play for Microsoft customers.” More seamless experience Girish Bablani, President of Azure Core at Microsoft, said, “Customers rely on Azure as a resilient foundation for their cloud and AI workloads. Supporting Commvault natively gives them more choice in how they protect and recover their data, with a more seamless experience inside Azure.” Banks, retailers, healthcare providers, and other large enterprises are under mounting pressure to simultaneously modernise infrastructure, manage escalating cyber risks, and support AI-driven transformation. Boards and executive teams are increasingly prioritising resilience as a core requirement for digital and AI initiatives. Aligning resilience investments This strategic partnership and native service on Azure are designed to address these needs and deliver key benefits to joint customers: Enable resilient AI adoption: Deliver integrated recovery and resilience capabilities that are well-suited for AI-driven workflows on Azure, helping organizations innovate faster while maintaining data security, trust, and recoverability. Deliver a seamless native Azure experience: With Commvault native on the Azure cloud platform, customers will be able to deploy and manage Commvault’s resilience capabilities alongside their existing Azure services through a consistent, integrated experience. Maximize Azure investments: Customers can purchase Commvault Cloud through the Microsoft Marketplace and apply usage toward their Microsoft Azure Consumption Commitment (MACC), simplifying procurement and aligning resilience investments with broader cloud spend. Commvault and Microsoft will collaborate on joint go-to-market initiatives, including co-selling, solution development, and integrated sales motions designed to accelerate cloud journeys and customer adoption of cyber resilience on Azure. Commvault’s native ISV service on Azure is expected to enter public preview this summer.
Hikvision has released its 2026 Cybersecurity White Paper, marking its ongoing commitment to transparent and robust security practices. The latest edition outlines the company’s advanced security framework, designed to address emerging digital challenges for the AI-powered Internet of Things (AIoT) industry. At the core of Hikvision’s security strategy is the Hikvision Security Development Maturity Model (HSDMM). Designed to quantify and standardize security activities throughout product development, the HSDMM integrates structured organizational governance, well-defined management processes, and robust technical measures. Robust technical measures The 2026 White Paper walks readers through the HSDMM across its three core dimensions: security governance, security processes, and security technologies. By systematically implementing this model, Hikvision enhances product confidentiality, integrity, and availability, establishing a reliable digital foundation for global IoT deployments. As technology evolves, the 2026 White Paper details Hikvision’s systematic practices across these three HSDMM dimensions, with a particular focus on managing emerging risks related to data security, privacy protection, and Artificial Intelligence. Key updates in the 2026 edition include: Artificial Intelligence Security: A newly added chapter systematically evaluates and outlines the protection framework for AI models, helping partners navigate security challenges during smart and digital transitions. Advanced Data Protection: The paper introduces updated guidelines for data classification and grading, alongside dedicated security requirements for both edge devices and cloud-based services. Open-Source Software Governance: A dedicated section defines stringent management protocols for open-source software—spanning introduction, audit, and release—to ensure secure, closed-loop integration. Integrated Vulnerability Management: The paper highlights the critical role of vulnerability management and integrates security incident response processes, covering every key phase from detection to mitigation. Product lifecycle security To foster international digital trust, Hikvision actively adopts global best practices and aligns its operations with international standards. In recent years, the company has obtained multiple ISO/IEC certifications for product security and vulnerability handling, alongside compliance alignments with ETSI EN 303645 and NIST CSF 2.0. These milestones reflect the company’s continuous investment in product lifecycle security. “Security is the cornerstone of smart technology,” said the Chief Security Officer at Hikvision. “By sharing our practical insights through this White Paper, we look forward to collaborating with our partners to build a secure, resilient, and collaborative industry ecosystem.” Looking ahead, Hikvision remains committed to integrating technological research with robust governance, delivering reliable security assurance to support digital transformation across diverse industries.
iDenfy, a foremost global company that provides ID verification and fraud prevention services used by over 1,000+ businesses across the globe, has officially added BSN masking for identity verification in the Netherlands. This functionality allows Dutch users to provide an identity document with the Burgerservicenummer (BSN) deliberately masked out while proceeding through the entire verification process. BSN is considered to be sensitive personal data according to both the GDPR and the Dutch national privacy law, and is forbidden for most private companies to collect and store this information. Solving the security limitation Dutch individuals had to consistently cover their BSN with a marker before handing their copies of ID documents for verification, whether by using the official KopieID app, manual photo editing, or covering it up with some physical object. However, most third-party Know Your Customer (KYC) service providers, which were not native to the Dutch market, don’t have the custom-tailored option for users to upload their IDs in a compliant manner in the Netherlands, which resulted in their verification being unaccepted and denied. For businesses operating on a global level, this results in lost conversions in the very first step of the user journey, the account opening. iDenfy solved this security limitation and now offers a compliant, user-friendly option for Dutch clients to complete their KYC. New verfication path End-users can now verify the way Dutch privacy law intends, and the businesses serving the Netherlands traffic can onboard those users without taking on unnecessary risks compliance-wise. The new verification path activates when iDenfy detects that the Netherlands has been selected or auto-identified, and accepts Dutch identity documents, including the national passport, Dutch identity card, and Dutch driving licence, in PDF, JPG, and PNG formats. “The people in the Netherlands have always had the right to keep their BSN covered, and we shouldn’t demand it when asking to perform the identity verification,” said Domantas Ciulde, the CEO of iDenfy. Process details The system also accepts any already-for-masking used method without requiring a specific redaction or original identification card. When a masked BSN is detected, and the document meets the requirements, the user is automatically accepted. On the other hand, if the document is flagged with high-risk indications, the user’s KYC data is sent to the review queue for a double-check, which is done by iDenfy’s in-house expert Review team. That means no case is silently auto-passed, and the BSN is automatically excluded from the verification record to ensure that partners do not inadvertently collect or retain data they have no legal basis to hold. The feature is implemented as an opt-in setting, activated on a case-by-case basis with each existing partner to ensure that current AML controls and review workflows remain deliberate and explicit. No integration changes are required on iDenfy’s partners’ side. Once enabled, all companies receive sandbox access to validate the end-to-end flow before going live. Combining AI powered documents analysis It’s important to mention that the BSN masking capability is built on top of iDenfy’s all-in-one identity verification infrastructure, which combines AI-powered document analysis, biometric matching, and an in-house human review team that operates 24/7 without any delays. Automated identity verifications are completed instantly, while human-supervised checks are typically completed within three minutes. iDenfy’s advanced biometric and facial recognition algorithms confirm if the face presented during verification is live and genuine in order to actively prevent the use of photographs, 3D masks, and other spoofing attempts. In addition, the KYC system is designed to filter deepfakes and flag AI-generated biometric faces with the best in the industry AI solutions and review team supervision to guarantee a maximum success rate. iDenfy is committed to building a verification infrastructure that respects jurisdiction-specific privacy frameworks, rather than treating local data rights as an obstacle to onboarding.
Solink®, the pioneer in agentic vision intelligence, in partnership with AWS, Comcast Business, and Goldman Sachs, announced the Agentic AI Summit — a virtual event focused on what it actually means to deliver AI-driven outcomes in the real world. About Agentic AI Summit Most enterprises have invested heavily in AI. The result? More dashboards. More insights. More data to interpret. But insights alone don’t eliminate theft, prevent threats, or grow revenue. The Agentic AI Summit is built around a single premise: AI must move from generating insights to driving high-value outcomes in the real world, across every physical location. The event will feature leaders from some of the world’s most recognized and innovative brands who are making that shift – and will share how agentic AI is delivering measurable business impact at scale. Event details WHAT: A virtual summit showcasing how agentic AI moves beyond dashboards to eliminate theft, prevent threats, reduce losses, and increase revenue. WHO: Hosted by Solink, sponsored by AWS, Comcast Business, and Goldman Sachs. Built for operators, IT professionals, security and loss prevention leaders, and media and analysts covering enterprise AI. WHEN: Wednesday, June 23, 2026 — 12:00 PM ET / 9:00 AM PT WHERE: Virtual. Registration available at Solink’s Agentic AI Summit registration page. Speaker lineup and agenda to follow.
IQSIGHT, a global pioneer in intelligence-first video security, announces its appointment as a Common Vulnerability and Exposures (CVE) Numbering Authority (CAN) in the CVE® Program. This milestone reinforces IQSIGHTʼs dedication to transparency and proactive security management, allowing the organization to issue unique, standardized identifiers, known as CVE records, for vulnerabilities found in its software and firmware. Critical advisory information Previously accomplished through the Bosch Product Security Incident Response Team, the new CNA designation for IQSIGHT will streamline the process of publishing critical advisory information to the U.S. National Vulnerability Database (NVD) and the EU Vulnerability Database (EUVD). The approval reflects the company's ongoing efforts to ensure data security and cyber resilience in its products by strengthening its vulnerability and incident management process. "Becoming a CVE Numbering Authority is a significant step in our mission to provide intelligence-first video security that leaders can trust," said Thomas Elsässer, Vice President of Research and Development at IQSIGHT. Government compliance requirements "By managing our own CVE assignments, we are ensuring customers receive timely information about potential security risks along with the appropriate mitigation strategies.ˮ IQSIGHT has been onboarded as a CNA under the European Union Agency for Cybersecurity (ENISA), which serves as the organizationʼs Root CNA. Commitment to Global Standards and Compliance As cybersecurity regulations evolve, IQSIGHT remains committed to meeting and exceeding government compliance requirements, such as the European Unionʼs Cyber Resilience Act. By establishing these capabilities now, IQSIGHT ensures it is well-positioned to meet future regulatory demands while prioritising the safety of user data.
Commvault, a pioneer in unified resilience at enterprise scale, recommends four steps organizations should take to stay resilient in the age of Frontier AI – where advanced AI models are accelerating vulnerability discovery, compressing exploitation timelines, and elevating the need for resilience. Frontier AI is reshaping the threat landscape in two ways. First, advanced models are generating a deluge of Common Vulnerabilities and Exposures (CVEs) – Palo Alto Networks research shows AI cybersecurity models identified more than seven times the typical number of vulnerabilities found within a single month during testing. Second, attacks are becoming autonomous: once a vulnerability is disclosed, AI-assisted exploitation can now emerge within minutes, not weeks. The remediation window for organizations is collapsing – no vendor is immune. Resilience is no longer a recovery plan, it's an operating requirement. Compromised production systems “Frontier models change the economics of vulnerability discovery. AI models will reveal exploitable vulnerabilities at such a fast pace, remediation programs must evolve,” said Nick Patience, VP and AI Practice Lead, Futurum Group. “While a rigorous patching strategy remains critical, the key now is also making sure readiness, resilience, and clean recoveries are top priorities.” To help enterprises prepare for the Frontier AI era, Commvault recommends that organizations embrace a preparedness framework that includes four key steps: Evaluate recovery risks: IT and security teams should assess whether their current recovery posture can withstand fast-moving vulnerability discovery and exploitation cycles. This means looking beyond whether backups exist and asking harder questions: Can critical systems be restored cleanly? Are recovery environments isolated from compromised production systems? Are recovery plans mapped to key dependencies? Make isolated recovery and air gapping the baseline: Organizations should assume that some vulnerabilities, software flaws, or third-party exposures may outpace normal remediation cycles. Maintain immutable, isolated copies of critical data and workloads, separated from production identity, network, and management planes. These copies help provide a clean fallback when patching or when remediation cannot keep pace. Organizations should also pressure-test RTOs and RPOs against realistic attack scenarios – not just failure modes. If your recovery time objective was set before autonomous exploitation was possible, it was set for a different world. Prioritise systems the business cannot operate without: Identify the systems required to function as a minimum viable company, including identity platforms, billing systems, operational databases, and cloud services, and define the order in which they must be recovered. As AI becomes embedded into business operations, organizations should also assess newer dependencies such as data pipelines, model repositories, vector databases, and agentic workflows. Automate resilience and test continuously: Recovery plans cannot remain static documents in the Frontier AI era. Organizations should automate threat scanning, clean recovery point identification, dependency-aware restoration, and recovery orchestration, while regularly testing plans in isolated cleanroom environments before incidents occur. Measurable recovery readiness “Organizations that embrace this four-step process will be better suited to take advantage of rapidly evolving AI models while also mitigating the risks,” said Patience. “Resilience continues to be a high priority for us,” said Jayson Morgan, SVP Infrastructure, BOK Financial Corporation. “What matters isn’t simply whether backups exist, but whether we can recover cleanly, validate integrity, and resume operations fast when it matters most.” ResOps is the operating model that makes this framework actionable. It operationalises resilience through continuous testing, measurable recovery readiness, clean recovery validation, and protection of both production and recovery environments. It’s foundational for business continuity during cyberattacks, outages, and AI-driven disruptions. “AI models will continue to evolve that accelerate remediation timelines and require a new approach to readiness,” said Bill O’Connell, Chief Security Officer, Commvault. “ResOps gives organizations a way to continuously validate readiness, advance clean recoveries, restore systems with confidence, and build resilience into the way they operate.”


Expert commentary
In today’s connected world, attacks are more likely to target digital than physical entry points. From ransomware and firmware tampering to remote hijacking, AI-driven phishing and automated vulnerability discovery, the nature of threats is evolving rapidly, and no industry can afford to neglect them. As our industry has moved from mainly mechanical to increasingly digital solutions, we have long recognized the importance of constantly monitoring and assessing the risks we face. This means not only meeting mandatory regulations but also voluntarily adopting international standards such as ISO 27001, which protects data and systems through a structured and independently audited framework. Today’s fast-changing risk environment is also why the EU introduced the Network and Information Security Directive 2 (NIS2) – to raise the bar for cybersecurity across Europe. But what do measures like NIS2 and the Cyber Resilience Act (CRA) mean in practice? How does the rise of AI fit in? And most importantly, what should our industry be doing to stay secure in such an unpredictable digital landscape? The new regulations Compliance is not just about meeting regulations, it is also a competitive advantage NIS2 is reshaping cybersecurity expectations by setting higher standards to reduce risk, improve transparency, and protect data and services. Alongside it, the CRA introduces mandatory requirements for products with digital components. This makes “secure by design,” regular updates, and compliance checks essential before products can enter the EU market. For companies in our industry, responsibilities now extend well beyond internal systems. Organizations must also ensure that suppliers and service providers comply, with regular risk assessments forming a central part of the process. The consequences of falling short are severe, ranging from significant fines and audits to the potential withdrawal of products from the market. For our customers, the message is clear: security must be built in from the start. Compliance is not just about meeting regulations, it is also a competitive advantage. At ASSA ABLOY Opening Solutions EMEIA, security is part of our DNA. We embed these standards into everything we do, giving customers solutions they can trust to be compliant and resilient. The rise of AI Artificial intelligence is transforming the digital security landscape and it cannot be separated from the regulatory framework shaping our industry. With AI advancing rapidly and new regulations coming into force, we have established a digital compliance framework to stay ahead of the curve and use AI as an enabler for improving security and achieving compliance. On one hand, AI brings powerful benefits, including more intelligent monitoring, faster anomaly detection, and smarter tools for operational efficiency. These capabilities directly support NIS2 and the CRA, particularly in the areas of proactive risk management and incident response. AI and building cybersecurity standards On the other hand, AI introduces new risks. The attack surface is expanding and threats such as deepfakes and smarter phishing create serious threats that regulators are determined to address. Both NIS2 and the CRA emphasize continuous monitoring, transparency and accountability, principles that must now also guide the responsible use of AI. At ASSA ABLOY Opening Solutions EMEIA, we see AI not just as a risk to mitigate, but as a capability to strengthen resilience and trust. That is why we are embedding strong governance practices around AI and building cybersecurity standards into every stage of product development. By doing so, we help our customers align with new regulations while ensuring AI serves as a tool for greater security and confidence. Trust and compliance Beyond our own operations, we are also committed to supporting customers on their compliance journey At ASSA ABLOY Opening Solutions EMEIA, we are taking NIS2, the CRA and the rise of cyber-threats seriously, ensuring compliance and enhancing trust with all our customers. We have reinforced supplier oversight, streamlined incident reporting, and embedded cybersecurity into every stage of product development and lifecycle management. Our teams also conduct ongoing risk assessments and post-incident reviews, ensuring that lessons are learned and improvements are made. By taking these steps, we not only meet regulatory requirements but strengthen the resilience of our supply chain and the trust customers place in us. Beyond our own operations, we are also committed to supporting customers on their compliance journey. Initiatives such as our recently released whitepaper “Enhancing Cyber–Physical Resilience with Digital Access Solutions” and a detailed NIS2 whitepaper developed in Germany last year provide clear, practical guidance. By showing what these regulations mean in practice and how intelligent access solutions can directly support compliance, we aim to make the path forward less complex and more achievable for our customers. Looking ahead The days when security threats to businesses and products were only physical are long passed. Today, we find ourselves in a world where the digital realm poses even more serious and constantly evolving challenges. It is therefore crucial that, as an industry, we take the necessary steps to meet the directives of NIS2 and the CRA and also constantly monitor the rise of AI. Only by doing so can we protect our customers, preserve our reputations, and build the trust that defines true leadership in security.
In today’s fast-evolving aviation landscape, innovation isn’t optional — it’s essential. With passenger traffic in the Asia-Pacific continuing to surge, the region is facing a pivotal moment: adapt with scalable tech, or fall behind. In January 2025 alone, APAC carriers accounted for 56.6% of global passenger traffic growth. Airports are operating at near capacity, with a record-high Passenger Load Factor (PLF) of 82.1%, leading to pronounced congestion at check-in counters, security checkpoints, and boarding gates. Increasing passenger volumes As airports strive to manage increasing passenger volumes without resorting to costly and time-consuming infrastructure expansions, technology — particularly facial recognition and biometric automation — emerges as a viable solution. However, the full realisation of these innovations requires more than just installing new system However, the full realisation of these innovations requires more than just installing new systems. It’s about building the right ecosystem of partners, processes, and policies to ensure sustainable, secure, and scalable growth. Presenting physical documents According to their estimates, over 120 APAC airports have already deployed biometric solutions at key travel touchpoints, including check-in, bag drop, security, and boarding. Thailand exemplifies this shift, with facial recognition deployed at six major airports — Suvarnabhumi, Don Mueang, Chiang Mai, Chiang Rai, Phuket, and Hat Yai — dramatically reducing passenger processing times. These systems allow travelers to verify their identities seamlessly at multiple touchpoints, from check-in and security screening to boarding gates, without presenting physical documents. This case reflects the Airports of Thailand’s (AOT) commitment to leveraging technology to improve operational efficiency and passenger experience. Digital identity programs Biometric solutions also extend beyond the airport: digital identity programs enable travelers to verify their identities before arriving at the terminal, creating seamless journeys from curb to gate. In this environment, facial recognition is not merely a futuristic innovation; it has become an operational imperative. Airports that fail to adapt risk falling behind, unable to manage burgeoning passenger volumes or meet evolving traveler expectations. True operational efficiency Despite its transformative potential, biometric technology cannot be successfully deployed in isolation. Achieving true operational efficiency through facial recognition requires strategic collaboration among technology vendors, IT integrators, airports, airlines, and regulatory authorities. Several pillars underpin a successful biometric implementation: Interoperability: Biometric systems must integrate seamlessly with a wide array of airline platforms, security protocols, and airport infrastructure. Lack of interoperability can lead to fragmented systems that frustrate staff and passengers alike. Scalability: Passenger volumes are forecasted to continue rising. Biometric solutions must be designed to scale rapidly in response to demand surges and future security challenges. Data Privacy and Security: With growing public scrutiny over personal data usage, airports must implement robust security frameworks that prioritize privacy and transparency. Encryption, consent-based use, and strict access controls are critical to gaining and retaining passenger trust. Future security challenges BKI can achieve significant throughput gains without major construction disruptions A case study illustrates these points: Malaysia’s planned revamp of Kota Kinabalu International Airport (BKI) aims to boost capacity by 33% over the next few years. Rather than expanding physical infrastructure alone, authorities are exploring facial recognition solutions to increase efficiency within existing spaces. By integrating biometric checkpoints at key touchpoints, BKI can achieve significant throughput gains without major construction disruptions. Such outcomes are only possible through well-coordinated technology partnerships, where vendors, airports, and integrators work toward a shared vision of future-ready travel. AI-powered computer vision What’s Next: Fully Biometric-Enabled Travel Looking ahead, the pressure on APAC airports is set to intensify. Airports Council International projects 9.5 billion air travelers globally by the end of 2025, a volume traditional processing methods cannot manage effectively. In response, AI-powered computer vision and facial recognition will continue to refine biometric processes, delivering higher accuracy rates and faster verification. Future systems will leverage real-time liveness detection, predictive analytics for crowd management, and seamless integrations across all travel stages. A fully biometric-enabled journey is becoming reality: Check-in with a glance at a kiosk Drop bags without producing an ID or boarding pass Clear security with automated facial recognition portals Board flights through biometric-enabled gates — without ever presenting a physical document. Experiencing significant growth Seamless integration across touchpoints creates a unified, frictionless journey In this vision of the future, identity becomes the ticket. Seamless integration across touchpoints creates a unified, frictionless journey. For APAC airports experiencing significant growth, full biometric enablement is becoming increasingly important for maintaining efficiency and staying competitive. At the same time, such a future demands robust technology ecosystems, where ongoing innovation is supported by partnerships that align regulatory, operational, and technological goals. Expanding physical infrastructure Building the Smart Airports of Tomorrow: Join the Conversation The aviation sector in APAC stands at a critical crossroads. Passenger growth, operational challenges, and heightened security requirements are converging, creating an urgent need for innovation. Facial recognition and biometric automation offer a clear path forward, enabling airports to handle growing volumes, enhance security, and deliver superior passenger experiences without necessarily expanding physical infrastructure. Facial recognition solutions Yet, the success of these innovations hinges on strategic, trusted technology partnerships. Airports must collaborate with technology vendors, IT system integrators, airlines, and regulators to ensure interoperability, scalability, and data security. At RecFaces, they believe the future of APAC airports is fully biometric-enabled. To explore how tech collaborations and advanced facial recognition solutions can transform airport operations, they invite users to join their free online panel discussion on April 30: ‘Smart Airports Start With Smart Tech: Facial Biometrics for APAC Airports.’
Technology advances in the security industry are transforming the way modern systems are designed and installed. Customers today are looking for greater scalability and flexibility, lower up-front costs, and operational efficiency. Cloud-based software as a service (SaaS) solutions, AI-enhanced tools, and IoT-enabled sensors and devices are increasingly in demand. The traditional role of the systems integrator is evolving as a result. While security integrators have always worked closely with end users, today’s pioneers go beyond installation and maintenance. They align security strategies with evolving business needs, integrating IT, cybersecurity, and data-driven insights into their offerings. A look at the past and present Integrators are often asked to help tailor solutions and provide expertise in IT and cybersecurity Traditionally, systems integrators specialized in installing and maintaining wired physical security systems like CCTV, access control, and alarms. The service model was built around large, up-front investments and project-based installations. However, today customers are seeking comprehensive solutions. They’re looking to wirelessly integrate security infrastructure with cloud-based SaaS systems and IoT devices. While modern systems are often faster to deploy, they’re most effective when supported by ongoing consulting and strategic planning. Integrators are often asked to help tailor solutions and provide expertise in IT and cybersecurity. Data requirements and modern systems Data requirements have also changed. Modern systems collect vast amounts of data. Advanced analytics, machine learning, and automation are now must-have tools for actionable insights. Security integrators can help end users set up custom dashboards, automations, and continuous system optimization. Let’s look at some of the specific ways the role of systems integrators is evolving and how to adapt and succeed. Strengthen your IT expertise Integrators with IT expertise can ensure that hardware is optimized and maintained for peak performance The competitive landscape today includes not just security specialists but also IT-focused integrators and SaaS providers. Systems integrators with expertise in traditional physical security solutions plus IT experience offer unique value. They understand the real-world security challenges and opportunities, along with cybersecurity and network best practices. Integrators with IT expertise can also ensure that hardware is optimized and maintained for peak performance. Their experience with legacy systems allows them to offer practical recommendations on cost-effective approaches, such as upgrading or integrating older hardware with new digital solutions. Consider who’s making the purchase decisions Traditionally, security integrators primarily sold to security directors, facility managers, and operations teams. Now, multiple stakeholders may be involved in decision-making. IT teams, CIOs, and CTOs often weigh in on purchase decisions when cloud-based security and SaaS solutions are under consideration. Customers today aren’t just shopping for cameras, access control panels, alarms, and other hardware components. They’re looking for security ecosystems that can integrate with enterprise-wide IT infrastructure and business applications. When working with these different teams, consider outlining the system's return on investment (ROI). How can the solution reduce risk for various departments? Can it help improve operational efficiency or reduce the time required to onboard and train staff? Will it make regulatory compliance easier to manage? Focus on the long-term value for the entire organization. Take a consultative approach Another way systems integrators are adding value is by offering vertical specialization Installation fees remain important for many integrators, but there may be additional consultative opportunities to build long-term relationships with customers. Offer services such as roadmap planning, hardware and integration maintenance, training to certify end users on the manufacturer’s product, and cybersecurity services. While cloud-based solutions reduce on-premises maintenance, they don’t eliminate the need for ongoing support and training. Consider offering training opportunities. These can lead to other benefits as well. Better-educated and technically proficient customers are usually more willing to adopt new technologies. They understand the value of these investments and have more confidence that they’ll see results. Another way systems integrators are adding value is by offering vertical specialization. Healthcare, sports venues, critical infrastructure, education, retail - each specialty has its own set of challenges, partner networks, regulatory restrictions, training needs, and business requirements. Integrators who specialize are uniquely positioned to offer key sector-specific insights that are invaluable to their clients. Embrace the cloud A key growth area for integrators is supporting customers in their shift to cloud deployments. Cloud solutions aren’t a one-size-fits-all solution. Each organization is evaluating options and deciding whether cloud, hybrid, or fully on-prem solutions are the right fit for its unique needs. A key growth area for integrators is helping clients in their shift to cloud deployments Helping customers navigate and adopt cloud or hybrid solutions opens new opportunities to expand your business and deepen your relationship with your customers. Systems integrators who sell cloud solutions have the opportunity to add new layers to services for more value for customers. With a cloud solution that's easy and fast to deploy and managed and maintained by the provider, you can reduce overhead costs, staff training, and truck rolls via remote customer support. These benefits also allow you to spend time developing greater expertise in your customers’ processes. Using this knowledge, you can tailor your services towards potential productivity gains for your customers and turn them into additional sales. You ensure that your customers get the most out of the technology that’s available and that they have already purchased. Highlight your focus on cybersecurity Cybersecurity is no longer solely an IT department's responsibility. While dedicated IT security teams may still handle broader network defense, integrators play a crucial role in securing access control, surveillance, and IoT devices within a security framework. If unsecured, these devices can provide an entry point for cyber criminals to gain access to an organization’s network. Cybersecurity is no longer solely an IT department's responsibility To best protect end users from cyberattacks, choose physical security systems with built-in security and privacy-by-design features. Help customers implement best practices to ensure their entire ecosystem is designed, built, and managed with end-to-end security in mind. Once implemented, work with your manufacturers, consultants, and end users to ensure that vulnerabilities are identified and mitigated. Every person on the network plays a role in keeping cyber threats at bay. Lean into the power of partnerships In today’s complex and dynamic security landscape, choosing the right technology partners is crucial. Ask potential partners to share their technology roadmap, and how you can offer feedback or participate in discussions about industry trends. Ideally, your partners will have a program in place to get input from integrators and end users, so they can develop products that are designed to address their most pressing issues and concerns. Your manufacturer partners should be working to help identify the evolving needs of customers and communicate these insights to systems integrators. Seek partners who actively support integrators to understand how security is evolving In addition to a good experience for the end user, strong manufacturer partners also offer solutions to streamline and automate workflows for integrators. It should be easy to order and check your shipping statuses online, for example. These are simple things that save you time and demonstrate your partner’s care for your business. Seek partners who actively support integrators to understand how security is evolving. While training is often offered on-site, some companies are now also offering blended learning models so integrators and their technicians can reduce classroom time and stay out in the field. Evolution is an opportunity Security integrators with traditional physical security expertise remain indispensable because they understand real-world risks and regulatory requirements. They can provide hands-on system deployment and optimization. Now, there are new opportunities to build long term customer relationships. As the physical security industry undergoes this profound shift, adaptation is key. By embracing cloud and hybrid solutions, integrators can unlock new revenue streams, enhance customer relationships, and stay ahead of technological advancements. With the right partnerships and a forward-thinking mindset, systems integrators can navigate this transformation and take advantage of new opportunities being presented by evolving technology. Leverage your deep industry experience while upskilling in cloud, cybersecurity, and IT. The strongest approach is for end users, systems integrators, IT specialists, and manufacturers to work together to navigate industry changes.
Security beat
Anyone who has been in a proverbial cave for the last couple of years faced a language barrier at this year’s ISC West 2025 trade show. The industry’s latest wave of innovation has brought with it a new bounty of jargon and buzzwords, some of which I heard at ISC West for the first time. As a public service, we are happy to provide the following partial glossary to promote better understanding of the newer terms. (Some are new to the security industry but have been around in the IT world for years.) Obviously, if we can’t understand the meaning of the industry’s lexicon (and agree on the meaning of terms!), we will struggle to embrace the full benefits of the latest industry innovation. Not to mention we will struggle to communicate. Generative AI Generative AI can identify an object in an image based on its understanding of previous objects This was perhaps the most common new(ish) term I heard bouncing around at ISC West. While the term artificial intelligence (AI) now rolls off everyone’s tongue, the generative “version” of the term is catching up. Generative AI uses what it has learned to create something new. The name comes from the core function of this type of artificial intelligence: it can generate (or create) new content. It doesn’t just copy and paste; it understands the underlying patterns and creates something original based on that understanding. In the case of video, for example, generative AI can identify an object in an image based on its understanding of previous objects it has seen. Video and security Generative AI can tell you something digitally about what is happening in an environment. There is no longer a need to write “rules;” the system can take in data, contextualize it, and understand it, even if it does not exactly match something it has seen before. In the case of video and security, generative AI offers more flexibility and better understanding. From 2014 to 2024, the emphasis was on detecting and classifying things; today AI is expanding to allow new ways to handle data, not so prescriptive and no more rules engines. Agentic AI Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals, with minimal to no direct human intervention. In addition to the capabilities of generative AI, agentic AI can take action based on what it detects and understands. Use of agentic AI typically revolves around an if/then scenario. That is, if action A occurs, then the system should proceed with action B. For example, if an AI system “sees” a fire, then it will shut down that part of the building automatically without a human having to initiate the shutdown. There is a lot of discussion in the industry about the need to keep humans involved in the decision-making loop, so use of truly autonomous systems will likely be limited in the foreseeable future. However, the ability of agentic AI to act on critical information in a timely manner, in effect to serve as an “agent” in place of a human decision-maker, will find its place in physical security as we move forward. Inference Inference is another common term related to AI. It refers to the process by which an AI model uses the knowledge it gained during its training phase to make predictions, classifications, or generate outputs on new, unseen data. The direct relationship of this term to physical security and video is obvious. In the simplest terms, an AI system is “trained” by learning patterns, relationships, and features from a large dataset. During inference, the trained model is presented with new questions (data it hasn't seen before), and it applies what it learned during training to provide answers or make decisions. Simply put, inference is what makes AI systems intelligent. Containerization Dividing a massive security management system into several separate containers enables management of the various parts In IT, containerization is a form of operating system-level virtualization that allows you to package an application and all its dependencies (libraries, binaries, configuration files) into a single, portable image called a container. This container can then be run consistently across any infrastructure that supports containerization, such as a developer's laptop, a testing environment, or a server in the cloud. In the physical security industry, you hear “containerization” used in the context of separating out the various components of a larger system. Dividing a massive security management system into several independent containers enables the various parts to be managed, updated, and enhanced without impacting the larger whole. Genetec’s SecurityCenter cloud platform Think of it like shipping containers in the real world. Each container holds everything an application needs to run, isolated from other applications and from the underlying system. This ensures that the application will work the same way regardless of the environment it is deployed in. “It took us five years to containerize Genetec’s SecurityCenter cloud platform, but containerization now simplifies delivering updates to products whenever we want,” says Andrew Elvish, Genetec’s VP Marketing. Among other benefits, containerization enables Genetec to provide more frequent updates--every 12 days. Headless appliance Headless appliance is a device that is managed and controlled remotely through a network or web interface A headless appliance is a device that is managed and controlled remotely through a network or web interface. The device is like a “body without a head” in the traditional sense of computer interaction: It performs its intended function, but without any visual output or input device for local interaction. In physical security, such devices are increasingly part of cloud-based systems in which the centralized software manages and operates all the disparate “headless” devices. A headless appliance does not have a Windows management system. “The whole thing is managed through the as-a-service cloud system,” says Elvish. With a headless device, you just plug it into the network, and it is managed by your system. You manage the Linux-based device remotely, so configuring and deploying it is easy. Democratizing AI You hear the term democratizing AI used by camera manufacturers who are looking to expand AI capabilities throughout their camera lines, including value-priced models. For example, even i-PRO’s value-priced cameras (U series) now have AI – fulfilling their promise to democratize AI. Another approach is to connect non-AI-equipped cameras to the network by way of an AI-equipped camera, a process known as “AI-relay.” For instance, i-PRO can incorporate non-AI cameras into a system by routing/connecting them through an X-series camera to provide AI functionality. Bosch is also embracing AI throughout its video camera line and enabling customers to choose application-specific analytics for each use case, in effect, tailoring each camera to the application, and providing AI to everyone. Context Cloud system also enables users to ask open-ended queries that involve context, in addition to detection Context refers to an AI system that can understand the “why” of a situation. For example, if someone stops in an area and triggers a video “loitering” analytic, the event might trigger an alarm involving an operator. However, if an AI system can provide “context” (e.g., he stopped to tie his shoe), then the event can be easily dismissed by the automated system without involving an operator. Bosch’s IVA-Pro Context product is a service-based model that adds context to edge detection. The cloud system also enables users to ask open-ended questions that involve context in addition to detection. For example, rather than asking "do you see a gas can?" you can ask "do you see any safety hazards in this scene?" The pre-trained model understands most common objects, and understands correlations, such as "a gas can could be a safety hazard.” A scaled-down on-premise version of the IVA Context product will be available in 2026. Bosch showed a prototype at ISC West. Most video data is never viewed by an operator. Context allows a system to look at all the video with "almost human eyes." Cameras are essentially watching themselves, and understanding why something happened and what we can do. All that previously unwatched video is now being watched by the system itself, boosted by the ability to add “context” to the system. Any meaningful information based on context can trigger a response by an operator. Data lake A data lake is a centralized repository that allows one to store vast amounts of structured, semi-structured, and unstructured data in its native format. In the case of the physical security marketplace, a data lake includes data generated by systems outside the physical security infrastructure, from inventory and logistics systems, for example. A data lake is where an enterprise can accumulate all their data, from the weather to Point-of-Sale information to logistics, to whatever they can gather. Putting the data in one place (a “data lake”) enables them to mine that data and parse it in different ways using AI to provide information and insights into their business. Notably, a data lake contains all a company’s data, not just security or video data, which opens up new opportunities to leverage the value of data beyond security and safety applications. Crunching the various information in a data lake, therefore, security technology can be used to maximize business operations.
The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel. The shocking event raised awareness in board rooms around the world about the need for, and challenges of, executive protection. Questions followed immediately, including why was the high-level executive not protected? Combination of risk and reward UnitedHealthcare’s stock price has gone down more than 20% since the shooting The event also highlighted what is at stake for companies, extending beyond the safety of executives and impacting many factors, even including a company’s stock price. UnitedHealthcare’s stock price has gone down more than 20% since the shooting, equating to tens of billions of dollars. “Companies are considering the combination of risk and reward like never before when it comes to executive protection,” says Glen Kucera, President of Allied Universal Enhanced Protection Services. “What are the chances this could happen? Before Dec. 4 many thought it was zero. And what are the financial implications for a company if it happens? Executive protection is a small investment to protect against a worst-case scenario.” Evaluation of an executive protection Before the UnitedHealthcare shooting raised awareness, fewer than 50% of executives had protection. But concerns that previously fell on deaf ears now have the full attention of companies, says Kucera. “Boards of directors are having to figure this out,” he adds. “They may not have executive protection, but now they have to do it.” A threat assessment, conducted by a company such as Allied Universal, provides an independent evaluation of a company’s executive protection needs. The assessment evaluates factors such as an executive’s travel habits, the safety of their home, etc. Does the executive need protection 24/7, or just when they travel into more dangerous areas? Risks increase related to corporate earnings Sometimes, cases increase the need for executive protection, such as an internal threat In assessing threats, security professionals also look beyond the individual to consider the safety of a corporate facility, for example. “Is there a visual deterrent, controlling who comes and goes?” asks Kucera. “If there is good security, it all ties together. We do home assessment, facility assessment, route assessment, and travel assessment as needed.” Sometimes, circumstances increase the need for executive protection, such as an internal threat. Timing is a factor, and risks increase related to corporate earnings releases, new product announcements, and corporate layoffs or consolidation. Monitoring social media tracks shifting threats that impact the need for executive protection. UnitedHealthcare shooting “He didn’t have it and probably didn’t think he needed it,” comments Kucera about the UnitedHealthcare executive who was gunned down in the streets of New York City. “He was staying at the hotel across the street and was used to walking down the street every day.” “Sometimes executives want to preserve their privacy and be able to walk down the street,” says Kucera. “Getting protection can be seen as a sign of weakness. Some CEOs in the past have said they just didn’t want it.” However, the UnitedHealthcare shooting raised the stakes of the need for more vigilance. “The bottom line is you have to yet beyond objections and make the investment to protect against a worst-case scenario,” says Kucera. Anti-capitalist sentiment in the general population An internal police bulletin warned of an online hit list naming eight executives and their salaries Threats to executives sometimes arise from anti-capitalist sentiment in the general population about perceived inequalities in wealth and power. Executives provide symbolic targets for anyone who fights the system, and social media has amplified the voices of those who oppose capitalism. For example, a "Most Wanted CEO” card deck seeks to shine a spotlight on "titans of greed." Also, in the aftermath of the UnitedHealthcare shooting, CEO "wanted" posters appeared across New York City, threatening various executives of large companies. An internal police bulletin warned of an online hit list naming eight executives and their salaries. Careful monitoring of social media posts Careful monitoring of social media posts and other sources enables executive protection professionals to analyze data and separate the dangerous threats from the merely negative ones. Sadly, positive support of the UnitedHealthcare shooting was expressed by the 300,000 or so followers of the shooter, who became a celebrity of sorts. A huge outcry of negative sentiment toward the insurance industry led to fear that copycat incidents might occur. “There has been an unprecedented amount of positive support for committing murder,” commented Kucera. Executive protection requests HR executives can be at risk, especially at a time of layoffs or consolidation “Let’s face it, there has been a lot of controversy, from COVID to the Middle East crisis, to the political campaign, and there is negativity on both sides,” says Kucera. “People have opportunities to pick sides, and there is a lot of sentiment going both ways, and there is a small percentage of people who will act aggressively.” Executive protection requests now extend beyond the CEO to include others in the management ranks of companies. Basically, any public-facing executive is at risk, including anyone who makes statements to the press. Human resource (HR) executives can be at risk, especially at a time of layoffs or consolidation. Private information on the Internet Typically, an executive is assigned a single armed operative for protection. The firearm serves primarily as a visual deterrent that hopefully makes a potential perpetrator think twice. “When they plan an event like this, their expectation is that it will be a soft target,” says Kucera. “If there is an officer, it gives them pause.” Controversial or high-profile CEOs are typically protected 24/7, including when they travel with their family. Adding risks is the fact that private information is now posted on the Internet, including where an executive lives and where their children go to school. Internet monitoring Internet monitoring also includes the “dark web,” which includes sometimes dangerous information “We offer social media monitoring, and we advise them to be more careful with what they post,” says Kucera. “We monitor reactions to posts including any that might be threatening. We watch social media carefully if a company announces earnings or a change in their service or product offering.” Internet monitoring also includes the “dark web,” which includes sometimes dangerous information that is intentionally hidden and requires specific software, configurations, or authorization to access. Own layer of protection Public and government officials can also come under fire in a variety of scenarios. FEMA officials faced threats after the recent floods in the Southeast, for example, among other situations where perceived unfair treatment promotes thoughts of retribution. Although government agencies have their own layer of protection, there are instances when they call on companies such as Allied Universal for additional help. Ad hoc protection for various executives In the aftermath of the UnitedHealthcare shooting, calls to Allied Universal’s Command Center increased by 600%, reflecting requests for ad hoc protection for various executives. These requests are in addition to the company’s business providing “embedded” operatives that travel with executives all or some of the time. On that side of the business, requests for services are up probably 300%, says Kucera.
The information age is changing. Today, we are at the center of addressing one of the most critical issues in the digital age: the misinformation age. While most awareness of this problem has emerged in the consumer and political worlds, the issue cannot be ignored when it comes to the authenticity and protection of video and security data. Video surveillance data SWEAR is a company with the mission to ensure the integrity of video surveillance data by mapping video data and writing it into the blockchain, providing real-time, immutable proof of authenticity. Blockchain, which is the underlying technology that enables cryptocurrencies, is a decentralized digital ledger that securely stores records across a network of computers in a way that is transparent, immutable, and resistant to tampering. SWEAR solution The SWEAR solution is based on proactive, foundational protection that validates data at the source The SWEAR solution is based on proactive, foundational protection that validates data at the source before any opportunity for manipulation can occur. “Our technology is about proving what’s real and our goal is to ensure that security content and video surveillance data remain untampered with and reliable when needed,” says Jason Crawforth, Founder and CEO of SWEAR. Real-time authentication Security leaders need to ensure that the content they are relying on to make mission-critical decisions is authentic. Once verified, organizations can be sure that their investment in video can be trusted for critical use cases, including intelligence operations, legal investigations, and enterprise-scale security strategies. SWEAR seeks to embed trust and authenticity directly into video surveillance content at the point of creation. This ensures real-time authentication while proactively preventing tampering or manipulation before it can happen. AI-generated content The rise of AI-generated content, such as deepfakes, introduces significant challenges As AI transforms the landscape of video surveillance by enhancing threat detection and predictive analysis, it also introduces the very real risk of manipulation through AI-generated content. This presents a significant challenge in protecting critical security data, especially in mission-critical applications. The rise of AI-generated content, such as deepfakes, introduces significant challenges when it comes to ensuring the protection of digital media like video surveillance. Recent study findings It is a fact that digital media content is being questioned more regularly, which puts businesses, legal systems, and public trust at risk. A recent study from the Pew Research Center found that 63 percent of Americans believe altered videos and images create significant confusion about the facts of current issues. Last month, California Governor Gavin Newsom signed three bills aimed at curbing the use of AI to create fake images or videos in political ads ahead of the 2024 election. Footage authenticity “While most of the news cycle has centered on the use of fake content in politics, we need to think about how manipulated videos could affect security,” says Crawforth. “In video surveillance, ensuring the authenticity of footage is critical for keeping operations secure and safe around the world. That means verifying and protecting video data is a must.” Organizations must be capable of performing thorough digital investigations, which involve retrieving and analyzing video and security data from devices and networks through a chain of evidence. Digital forensic capabilities Strong digital forensic capabilities also enhance incident response, risk management, and proactive security An in-depth understanding of who has handled video data, how it was handled, and where it has been is an important step in responding to security incidents, safeguarding assets, and protecting critical infrastructure. Strong digital forensic capabilities also enhance incident response, risk management, and proactive security measures, all essential for risk management, regulatory compliance, and cost control, says Crawforth. An unbroken chain of custody “By using tools to identify, preserve, and analyze digital evidence, organizations can ensure swift and accurate responses to security incidents,” he adds. “Using the latest tools and techniques is vital for maintaining a strong security posture." "But you must ensure your digital content isn’t manipulated.” SWEAR’s technology provides an unbroken chain of custody, ensuring that video evidence can be trusted and admissible in court and forensic applications. Authenticating content Authenticating content also strengthens accountability and trust, protecting organizations By verifying video content is protected from tampering, manipulation, or forgery, organizations can be sure that they have reliable evidence that produces actionable results. Authenticating content also strengthens accountability and trust, protecting organizations from legal disputes or compliance violations. Safeguarding digital content “With an increasing amount of disinformation in today’s world, we sought to develop an innovative solution to safeguard the integrity of digital content,” says Crawforth. SWEAR safeguards security content using real-time “digital DNA” encoding. It integrates directly at the video management system level, ensuring it is preserved with a secure chain of custody and maintains integrity for evidentiary purposes. Real-time “digital DNA” encoding The digital DNA is then stored on a blockchain, creating an immutable record The solution integrates with cameras and other recording devices to map this digital DNA of the video data, all in real-time. The digital DNA is then stored on a blockchain, creating an immutable record that tracks the content’s history and integrity. Any attempt to manipulate the media can be instantly detected by comparing the current state of the media to its original, authenticated version. SWEAR is actively collaborating with video management solution providers to integrate the technology into their platforms. Video and security data benefits “We’re still in the early stages of our collaboration in this space, but it is clear that the industry recognizes that we have to work together to mitigate this risk proactively before it becomes a significant issue,” says Crawforth. “The feedback we have received from the industry to date has been beyond our expectations, and we expect to have more integration partners to highlight shortly.” “We should approach this as a collaborative effort across the industry, as ensuring the authenticity of video and security data benefits everyone involved,” says Crawforth.
Case studies
Working in the heavily regulated and frequently targeted financial services industry, the client (a global financial services group) needed to ensure its cybersecurity posture was extremely robust to protect its infrastructure and customer data from threats. The previous threat detection solution posed challenges, notably with a high volume of false positives. Without a robust SIEM tool and relying on less effective UEBA processes, the team recognized the need to fortify its security framework to align with their stringent standards. Another key area of focus was enhancing visibility within their security infrastructure. The existing setup presented an opportunity for improvement in consolidating monitoring capabilities into a unified interface. Additionally, the team wanted to enhance oversight of active directory actions, specifically addressing enumeration attacks, and monitoring the controlled export of company data by internal users. The solution Brought in to increase visibility and reduce overall risk, RiverSafe suggested they implement Exabeam, which would provide the company with all the best-in-class UEBA tools needed. RiverSafe suggested Exabeam due to the platform’s efficient data processing, simple architecture, scalability, and ease of deployment. The off-the-shelf content within Exabeam’s UEBA dashboards and reporting tools offered another key benefit, giving the security team access to data pre-built models and statistics that would allow them to start monitoring and flagging events immediately. Finally, Exabeam’s smart timeline feature that merges all user activity into one stream would address the visibility issue. Security and monitoring purposes With the client ready to implement, RiverSafe deployed Exabeam on their AWS Environment following best practice guidelines. The team mapped out relevant log sources for the system, and onboarded all data streams, filtering and fine-tuning everything to ensure any information being ingested was relevant for security and monitoring purposes. RiverSafe then developed and deployed use cases scoped out in partnership with the client, helping them to get maximum value from their Exabeam implementation. This documentation included custom roles, models and parses, as well as other quality of life improvements, additional search filters, and guidance on maintenance and monitoring techniques. The outcome The client now has an established monitoring workflow for its security team that’s baked into their day-to-day tasks. The team can monitor the entire environment quickly, and has significantly reduced the time it takes to assess threats like phishing and brute force attacks, and investigate unusual internal behaviours. Following RiverSafe’s advice, the client has been able to scale its Exabeam solution by accessing the right hardware required to run the product efficiently. Data loss and maintaining data integrity Noise from the SIEM has been reduced thanks to the optimization work conducted on log source onboarding. This has resulted in less complexity, fewer false positives, and easier access to the precise information that the team really needs. The security team now has visibility into email, endpoint, active directory, and web activity, and is able to monitor these frequently targeted areas for suspicious events and behavior. This visibility now also extends to file activity, protecting the company from potential data loss and maintaining data integrity. Managing security data and identifying trigger points Siloes have been eliminated, with security insights now located in a single repository for maximum perceptibility. From server performance to traffic flows, whatever’s happening across its pan-global regions, the security team know about it. Exabeam has equipped the team with a simpler, more effective way of managing security data and identifying trigger points—resulting in a 30% reduction in time spent on threat hunting.
The client, a large telecommunications provider, had teams working across multiple time zones and operated a sprawling and complex IT system. The scale and density of this system made gaining visibility into IT services extremely difficult, leaving the security team blind to what was happening with its IT environment. With little-to-no operations monitoring tools in place to proactively monitor these systems, the team had no visibility on the availability of its IT services or KPIs such as failure rates, send request times, and response times. This lack of oversight made it difficult for the team to prioritise issues — and nearly impossible for them to find the root cause of any problem. Proactive measures Without the ability to investigate the source of issues, the team was unable to take proactive measures to prevent them from reoccurring, severely impacting service performance. This was not only a problem for IT teams, but also for executives, who lacked the insight into IT business operations that would help them make decisions. The solution The company needed a solution that would map KPIs to critical service components, enabling the operations team to effectively drill down into issues in real time and conduct in-depth investigations to find resolutions. RiverSafe had previously implemented Splunk Enterprise Security for the customer and given the success of the implementation and the positive client feedback on the platform, RiverSafe was again engaged to deploy Splunk’s IT Service Intelligence (ITSI) tool to help it tackle its visibility problem. Data collection metrics Splunk ITSI uses machine learning to analyse existing data and predict future issues. As well as forecasting potential services bottlenecks, it can also troubleshoot problems and help users resolve issues fast. Delivering comprehensive monitoring across the entire IT environment, Splunk ITSI would also give the team full observability of their IT infrastructure. In particular, the engineering team wanted to gather metric data relating to the Kubernetes platform. RiverSafe reconfigured and implemented data collection metrics used elsewhere in the IT environment in Splunk to allow engineers to collate and access this information from different data sources in one place. The outcome: Actionable insights in days, not weeks In less than a week, the RiverSafe team implemented Splunk ITSI and began running monitoring services. With data from existing KPIs already indexed by the Splunk platform, the team are now able to access service insights even faster. These KPIs allow the operations team to identify trends, detect patterns, and proactively address any anomalies that occur before issues arise. Instant visibility with glass table visualisations To enable rapid and proactive issue resolution, RiverSafe implemented custom glass table visualisations in Splunk ITSI. This enables the team to navigate large volumes of data and reduce the time needed to identify and resolve problems. This simple and accessible dashboard gives the team an instant, digestible overview of its web portal performance metrics. These KPIs included the number of open tickets and failed login attempts, memory usage, API call success rates, average response times, and overall health of container services. Event analytics in Splunk ITSI As a result of RiverSafe’s work, the team has been able to centralize events from all its previously siloed solutions into a single interface with Splunk ITSI. The event analytics in Splunk ITSI help to prioritise responses and react more quickly to customers’ infrastructure events, empowering them to provide a better service. This is thanks in part to Splunk ITSI’s ability to identify and filter out false positives from the event management process. Excluding these invalid events reduced the total event volume by 40%, helping operators focus on the events that really matter. With fewer events to process, a single interface to work from, and a streamlined event analytics framework in Splunk ITSI, operators now process events eight minutes faster on average. This boost in efficiency has led to a major improvement in the company’s SLA performance. Best practices for using Splunk ITSI Overall, Splunk ITSI has delivered enhanced operational visibility, meaning the team can locate bottlenecks in workflows quickly and deliver fast recovery and troubleshooting solutions. Along the way, RiverSafe also provided best practices for using Splunk ITSI and recommended the most effective ways to collect data, including proposing an alternative metric type that would save on storage space when collecting logs.
In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organization. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimize operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialized expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organization. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimize the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.
With an extensive network of customers spanning the globe, cybersecurity is a primary concern for our client. Protecting extensive infrastructure and customer data requires a robust cybersecurity posture and effective tools, but the team found its SIEM solution lacking. Flooding its security team with an unmanageable number of false positives, the solution was diverting attention away from genuine threats and leaving them vulnerable. A substandard SIEM solution was not the only security issue. With no UEBA platform in place to help detect insider threats and data breaches, the company was faced with a number of gaps and weak spots in its security infrastructure that needed to be addressed. Three key issues The biggest concerns centred around three key issues: A lack of insider threat detection: Without a UEBA solution, the company had difficulty identifying insider threats and anomalous user behaviour within the network. Time spent on manual investigation: Security analysts spent significant amounts of time manually correlating events and investigating incidents, leading to delays in incident response and inefficient use of resources. Alert fatigue: The company’s existing SIEM solution generated a high volume of alerts, making it challenging for analysts to identify genuine threats among the many false positives. The solution The company engaged with RiverSafe to create a bespoke implementation plan that would address its primary issues and properly secure its digital infrastructure. Working in collaboration with the in-house security team, RiverSafe got to grips with existing infrastructure, gathered requirements and outlined the desired outcomes of the project. With all challenges and end goals collated, the RiverSafe team developed a solution that would meet all requirements and eliminate current security weaknesses. The team suggested Exabeam’s Fusion SIEM platform as it addressed the key concerns: Incident management: Delivering streamlined incident management processes by automating the correlation and enrichment of security events, Fusion SIEM equips analysts with actionable insights and real-time alerts. This improved visibility helps analysts hone in on genuine threats more quickly and reduce response times. Behaviour analytics: Tackling the company’s lack of UEBA issue, Exabeam’s advanced machine learning algorithms were configured to establish baseline behaviour for all users and systems. Any deviation from this baseline alerts analysts, enabling them to investigate anomalous activities and potential security issues, including insider threats. Data integration: The platform was integrated with various data sources, including logs from firewalls, servers, applications, and network devices to ensure comprehensive visibility across the organization’s infrastructure. The outcome The implementation of Exabeam’s Fusion SIEM solution has yielded significant benefits, including: Enhanced threat detection: Exabeam’s behavioural analytics (AA) and machine learning (ML) capabilities have improved the accuracy of threat detection, enabling analysts to identify and respond to security incidents more effectively. Faster incident response: Exabeam’s automated incident enrichment and real-time alerts are helping the security team to respond to incidents promptly, minimizing the impact of potential breaches. Reduced alert fatigue: The platform’s next-generation event analysis capabilities have reduced the number of false positives generated, reducing alert fatigue and giving analysts more time to focus on genuine threats. Improved insider threat detection: With its advanced behaviour analytics, Fusion SIEM is enabling the team to detect insider threats by identifying abnormal user activities and deviations from established behavioural patterns.
The client, a pioneering oil and gas corporation, faced significant challenges in knowledge management. The software engineering function struggled with locating the right documentation across multiple platforms such as ADO Repo, Confluence, SharePoint, and others. This fragmented system created delays and inefficiencies, with engineers spending valuable time searching for answers rather than focusing on delivery. Slow Access to Technical Information The sheer volume of documentation, continuously growing, compounded the problem. Onboarding tools for cloud services Onboarding tools for cloud services was also cumbersome, often dependent on a “hero culture” where finding the right person for help was the norm. This led to frequent meetings, wasted time, and a negative engineering experience, significantly slowing down workflows. RiverSafe was brought in to improve the engineer experience and increase velocity by enabling engineers to complete tasks more efficiently, reduce reliance on individual knowledge holders, and minimize time spent searching for outdated or misplaced documentation. The solution AI-enabled knowledge discovery They introduced an engineering portal powered by AI and natural language processing (NLP). Using a closed-domain RAG model, this portal introduced a ChatGPT-style interface where engineers could engage in natural language conversations to query documentation and receive consolidated answers, dramatically reducing the time spent locating information. The portal’s capabilities include rich content support such as diagrams, graphs, videos, and even in-platform automation for tasks like tool onboarding, further streamlining processes. The platform draws from multiple high-quality content repositories, creating a unified search experience across ADO Repo, Confluence, Internal document management systems, SharePoint, and more. Crucially, they implemented near-real-time monitoring for key model metrics, ensuring that each user’s question and answer interactions delivers unparalleled accuracy and relevance. This guarantees that the portal continuously provides genuine value through its responses. Recognizing the challenges posed by response degradation and hallucinations in AI-driven systems, they have developed a set of innovative solutions designed to optimize each interaction’s impact. The outcome Eliminating wasted time and accelerating software delivery The portal has transformed the way engineers work, saving significant time and boosting efficiency across the board. One engineer commented, “I’ve been here for 15 years, and this is the best product for software delivery in our organization. Previously, it could take me 2 weeks just to find out how to build a cloud environment. Now I get the answer straight away.” Key outcomes Time and Cost Savings: Engineers now save between 45 minutes and 10 days when searching for technical solutions. The portal has saved the organization 68,000 engineering hours annually, equating to over £4 million in cost savings within the first year. Improved Document Quality: The platform collects and analyses data on the usefulness and quality of documents. This feedback loop ensures that outdated or low-quality documents are flagged for improvement, keeping the knowledge base relevant and focused on high-value content. High-Fidelity Responses: Engineers receive immediate, detailed responses with links to relevant documentation, images, videos, and graphs. This reduces reliance on outdated information and significantly improves the quality of software delivery. Onboarding and Automation: Engineers can complete tasks directly within the platform, such as onboarding new tools, without needing to switch between systems, further streamlining workflows. User feedback and performance data The portal continues to gather user feedback and performance data, ensuring that it remains an invaluable tool for the organization, consistently improving the engineer experience and accelerating software delivery. The organization has also engaged NeuroLogik to build on these successes. NeuroLogik specialises in providing deep insights into entire codebases, ensuring that engineers can easily locate and reuse existing code across the organization, further enhancing efficiency and reducing duplication of effort.
The client, a British media and telecommunications company, was looking to increase operational efficiency, save time spent on identifying and addressing vulnerabilities and reduce risk by increasing visibility across their environment. With multiple security tools in different places, security data was siloed and needed to be accessed separately. This led to long periods of time spent jumping between tools to find data, and a lot of context switching when it came to looking at the results. Developers, security teams and senior directors were forced to search in multiple places for critical, often time-sensitive information about vulnerabilities. Risk of vulnerabilities Not only did this eat into their valuable time, but it also meant they had no overall visibility into the organization’s security posture. This lack of visibility significantly hampered the development process, as developers struggled to locate and address security issues. In addition, the organization did not have centralized CI/CDs, instead running different pipelines for individual developers or teams. Combined with poor visibility, this lack of efficiency was causing major frustration for the development team, slowing down development and increasing the risk of vulnerabilities in the code going undetected. The solution RiverSafe was initially brought on board to address the issue of decentralized security data, and help improve operational efficiency. The team’s goal was to allow for the results to be sent directly to the developers without them needing to access and search multiple security platforms to find the information they needed. The RiverSafe team created an integration script for the developers to execute when they were running their pipelines. Once triggered, the script would send a notification to a server that RiverSafe had specifically designed, which collated the identified vulnerabilities and relayed them back to the developers’ pull request. This ensured the development team got the information they needed to improve the security of their code. The next phase: Developing the data insights RiverSafe consultants worked alongside the client’s team to take all the security data that was being collected and, rather than sending it to individual developers’ pull requests, instead created and directed it to a pane-of-glass tool. This tool allows the developers to log in and see their repositories and projects in one place. For management, it allows them to have a complete picture of all the vulnerabilities and what they are impacting, on both individual repositories or a given product. The tool also allows them to build reports and includes a scoring model to give a visual rating so everyone can easily see if their repositories are secure or not. The scoring system, ranging from insecure to excellent sends alerts to let the developers know if their repositories fall below a certain level so they don’t need to continually monitor themselves. The RiverSafe team also provides advice on the steps that should be taken to remediate any identified vulnerabilities. Multiple security operations A key requirement of this tool was that it supported multiple security operations, including SAST (Static Application Security Testing), which would look at code smells and general quality of life, Source Code Analysis (SCA), which would look at which libraries are being used and also Secret Scanning to look for secrets in the code. RiverSafe also wanted to ensure that all of this is serverless on AWS to minimize the time spent on infrastructure maintenance. After launching, RiverSafe continued to work on improving this tool, making quality improvements, performing maintenance, and enhancing the integration via the shell scripts. The outcome The tool now brings together data from over 22,000 code repositories into one centralized place, allowing the client to see all of their security information, what libraries were most common, where the vulnerabilities were, and to start looking for trends. Developers and other stakeholders no longer need to scour multiple locations for vulnerability data, saving the company huge amounts of time and making its development process more efficient. With the bespoke script in place, the data comes to them. This increase in visibility has also led to improvements in response times to zero-day vulnerabilities. Previously, it could take weeks or even months to find all the affected repositories. However, since implementing RiverSafe’s custom tool, the team has been able to locate repositories featuring the vulnerable package immediately and remediate any issues quickly, massively improving their overall security posture. Thanks to this uplift in operational efficiency, the development team is now able to spend more time improving their code. RiverSafe and the client’s team are now working on expanding coverage throughout the organization, improving analytics and alerting, and centralizing CI/CD pipelines.


Round table discussion
Emphasizing proactive rather than reactive security shifts the focus from dealing with crises and damage control to prevention. Advantages of a proactive approach include cost efficiency, better business continuity, and fewer crises that draw attention away from strategic improvements. Staying ahead of threats is a core mission of the security department, and technology has evolved to enable security professionals to deliver on that mission better than ever. We asked our Expert Panel Roundtable: How are security systems transitioning from reactive to proactive, and what is the benefit?
Data overload is real. Sometimes it seems we are bombarded by the sheer volume, velocity, and variety of data available in our personal lives, and in our work lives. The solution is to figure out how to make sense of the data and transform it into real information we can use. In the case of physical security systems, new opportunities are emerging every day to utilize data to make our businesses safer and better managed. We asked our Expert Panel Roundtable: What is the expanding role of data in physical security systems? Why does it matter?
New technology advancements significantly increase efficiency and productivity in any industry, including physical security. Enhanced innovation both creates new products and services and improves existing products, all for the benefit of security manufacturers, integrators, and end users. Companies that embrace new technology stay ahead of the curve and gain a significant competitive advantage. In addition, they can differentiate themselves in the marketplace. We asked this week's Expert Panel Roundtable: What are the most promising new technologies in the physical security industry?
Products


White papers
Technology's Role In Securing Banks And Financial Institutions
Download
Securing The Modern Data Center
Download
An End User's Guide To Physical Security For Data Centers
Download
The User-Centric Security Revolution
Download
One System, One Card
Download
Aligning Physical And Cyber Defence For Total Protection
Download
Understanding AI-Powered Video Analytics
Download
The Power Of Integration In Physical Security Systems
Download
Using Artificial Intelligence (AI) To Automate Physical Security Systems
Download
A Modern Guide To Data Loss Prevention
Download
7 Proven Solutions For Law Enforcement Key Control And Asset Management
Download
Palm Vein Recognition
Download
Cybersecurity For Enterprise: The Essential Guide To Protecting Your Business
Download
The Security Challenges Of Data Centers
Download
Access Control System Planning Phase 2
Download

