Institute security
Observation Without Limits (O.W.L.), a U.S.-based manufacturer of 2D and 3D radars for ground and low-altitude airspace surveillance applications, is proud to announce it will exhibit at the 2026 Global Security Exchange (GSX), taking place Sept. 14-16 at the Georgia World Congress Center in Atlanta, booth 3550. “During GSX 2026, O.W.L. will focus on the importance of effective, less costly drone and perimeter detection solutions for airports, data centers, utilities, water treatment plan...
Gallagher Security has been named Outstanding Security Equipment Manufacturer at the 2026 Outstanding Security Performance Awards (OSPAs), presented at GSX in Atlanta. Gallagher's third win since 2023, the award recognizes the company's vertically integrated approach to designing and manufacturing access control, perimeter, and intruder alarm security solutions. Intruder alarm security solutions "With Gallagher, you're dealing with one manufacturer end-to-end that makes upgrades simpler, supp...
As artificial intelligence, geopolitical tensions and emerging quantum computing capabilities reshape the global cyber threat landscape, organizations are rethinking how they protect critical infrastructure, safeguard digital assets and prepare for the emerging cyber risks. GISEC Global 2026, the biggest and most influential cybersecurity event in the MENA, organized by inD, will bring together governments, critical infrastructure operators, technology innovators and cybersecurity leaders at Du...
Allied Universal®, the world’s pioneer security and facility services provider, announces that Charles Orgbon, Jr. has joined the company as vice president of corporate security. Orgbon will support the company’s sales and growth initiatives leveraging his law enforcement experience, industry expertise and professional relationships to identify opportunities and strengthen client engagement. He joins Allied Universal following a distinguished career with the Federal Bureau of In...
Johnson Controls, a global pioneer in thermal management, mission-critical building systems, energy efficiency, and decarbonisation, is returning to exhibit at Global Security Exchange (GSX) 2026 in Atlanta from Sept. 14-16. At Booth 1633, Johnson Controls will showcase new innovations and Managed Services designed to help organizations improve visibility across facilities, accelerate incident response, strengthen operational resilience and maintain continuity across increasingly connected and m...
Gallagher Security is strengthening its leadership bench across the Americas as the business continues a clear growth trajectory, with more than 30 percent growth forecast for the current financial year across the region. “Planning for strategic expansion has been a key focus for our team this year. We are incredibly excited about the opportunity ahead, and it is crucial that we set our teams up for success - not just in capability, but in the culture we build along the way," says Matt Bu...
News
The pace of technological progress is best described as relentless. Cyber attacks have evolved from opportunistic strikes into highly automated, intelligent campaigns that move at faster than ever. Traditional security operations centres, built for a slower and more predictable threat landscape, are struggling to keep up. This is where the AI-native Security Operations Centre (SOC) enters the scene, not as a luxury, but as a necessity. An AI-native SOC reimagines security operations from the ground up, placing artificial intelligence at the crux rather than treating it as an add-on. It shifts the burden from human analysts, trudging through alerts to intelligent systems that can reason, prioritise, and respond in real time. Reimagining security operations In this article, users will learn how an AI-native SOC works, how AI-driven SOCs use large language models to deliver stronger protection, the step-by-step process behind modern AI security operations, and the best practices for building one. Along the way, consider this: if attackers are already using AI to scale their operations, can the SOC afford to remain manual? At the heart of an AI-native SOC lies a powerful combination of machine learning, automation, and large language models. These technologies do more than accelerate workflows. They fundamentally change how security decisions are made. Simply flagging anomalies Large language models act as the cognitive layer of the SOC. They ingest vast amounts of structured and unstructured data, including logs, alerts, threat intelligence, and even analyst notes. Instead of simply flagging anomalies, they interpret context. They can correlate seemingly unrelated events, explain why something is suspicious, and recommend actions in plain language. It’s helpful to imagine an analyst reviewing hundreds of alerts across endpoints, networks, and cloud environments. Now imagine an AI system that not only filters out noise but also explains that a sequence of login attempts, file access patterns, and outbound connections resembles a known attack chain. The system is not simply creating alerts, but entire narratives. This capability transforms the SOC from reactive monitoring to proactive defense. AI is complementary to analysts, working to amplify them, turning them into decision-makers rather than data processors. An AI-native SOC operates like a finely tuned orchestra, where each component plays its part in harmony. Let us walk through how this system functions in practice. Standardising data formats Step 1: Data Ingestion and Normalisation Everything begins with data. Logs from endpoints, network devices, cloud services, identity systems, and applications flow into the SOC continuously. In traditional environments, this data often remains fragmented. In an AI-native SOC, it is centralized and normalised. AI models help standardize data formats and enrich them with context. For instance, an IP address is not just an address. It becomes a known entity with reputation, geolocation, and behavioral history. This leads one to question how many critical signals are currently buried in their data, simply because they cannot be connected. Large language models Step 2: Intelligent Detection and Correlation Once the data is prepared, AI-driven detection engines analyze it in real time. Instead of relying solely on static rules or signatures, these systems use behavioral analytics and anomaly detection. Large language models enhance this layer by correlating events across multiple domains. A failed login attempt might seem harmless. Combine it with unusual file access and privilege escalation, and a more sinister picture emerges. Step 2 is where the SOC begins to think rather than just see. Step 3: Contextual Investigation In a traditional SOC, investigation can take hours or even days. Analysts must manually gather evidence, cross-reference logs, and build a timeline of events. An AI-native SOC compresses this process dramatically. LLMs can automatically generate incident summaries, map attack paths, and highlight affected assets. They provide a narrative that explains what happened, how it happened, and what it means. This capability is akin to having a seasoned analyst who never tires, never misses a detail, and works at extraordinary speed. Multi-factor authentication challenges Step 4: Automated Response and Orchestration Detection without response is like spotting a fire but refusing to act. AI-native SOCs integrate with orchestration tools to automate responses. When a threat is confirmed, the system can isolate endpoints, revoke access, block malicious IPs, or trigger multi-factor authentication challenges. These actions occur within seconds, not hours. Crucially, AI ensures that responses are proportionate and context-aware. It avoids the blunt-force approach of shutting down systems unnecessarily. Step 5: Continuous Learning and Adaptation Cyber threats evolve constantly, and so must the SOC. AI-native systems learn from every incident, every alert, and every response. Machine learning models refine their detection capabilities over time. LLMs improve their understanding of organizational context, making future analyses more accurate and relevant. This creates a feedback loop where the SOC becomes more effective with each passing day; growing, adapting, and maturing. Event management systems Behind the scenes, several technologies work together to enable this intelligent ecosystem. Security information and event management systems still play a role, but they are no longer the centre piece. Instead, they act as data pipelines feeding into more advanced platforms. Extended detection and response tools provide visibility across endpoints, networks, and cloud environments. Security orchestration, automation, and response platforms handle automated actions. Overlaying all of this are AI and machine learning engines, with large language models acting as the interpretive layer. Threat intelligence platforms enrich data with external insights, ensuring that the SOC is not operating in isolation. Effective security operations Think of it as a living system rather than a collection of tools. Each component contributes to a unified objective: faster, smarter, and more effective security operations. Creating an AI-native SOC requires a shift in mindset, strategy, and operations. Start with data quality. AI systems are only as good as the data they consume. Ensure that your telemetry is comprehensive, accurate, and well-structured. Next, prioritise integration. Disconnected tools create blind spots. An AI-native SOC thrives on interconnected systems that share data seamlessly. Invest in explainability. AI decisions must be transparent and understandable. Analysts need to trust the system, and that trust comes from clear reasoning and visibility into how conclusions are reached. Critical decisions and strategic direction Balance automation with oversight. While AI can handle many tasks autonomously, human expertise remains essential for critical decisions and strategic direction. Finally, focus on continuous improvement. Treat the SOC as an evolving capability. Regularly assess performance, update models, and refine processes. Consider and evaluate whether users are building a SOC for today’s threats, or for the threats that will emerge tomorrow. The modern threat landscape demands more than incremental improvements. It calls for a fundamental transformation in how security operations are designed and executed. An AI-native SOC delivers this transformation by combining automation, intelligence, and adaptability. It reduces noise, accelerates response, and empowers analysts to focus on what truly matters. Future of security operations In this article, they explored how AI-driven SOCs use large language models to interpret and act on data, the step-by-step process that underpins their operation, the tools that make them possible, and the best practices for building one effectively. The question now is not whether AI will shape the future of security operations. It already is. The real question is whether the organization is ready to embrace it. If users are looking to elevate the SOC capabilities and stay ahead of increasingly sophisticated threats, now is the time to act. Explore how Rewterz experts can help users design and implement an AI-native SOC tailored to your organization’s needs. The future of security is intelligent, adaptive, and already within reach.
Security operations centres of the past were pictured as quiet control room filled with blinking dashboards with constant surveillance from human analysts. Today, cyber security teams utilize high-speed decision engines; constantly interpreting signals, filtering noise, and responding to threats that evolve by the minute. In this environment, terms like AI SOC, SIEM, and SOAR are often used interchangeably, yet each plays a distinct role. In this article, users will learn what sets these three pillars apart, how they complement one another, and why organizations are increasingly weaving them together into a unified security fabric. Users will also explore how large language models are quietly reshaping each of these technologies, turning static tools into adaptive, intelligent systems. Central repository of security data To appreciate the differences, it helps to imagine a security operation as a living organism. SIEM is the memory. SOAR is the nervous system. AI SOC is the brain that learns reasons, and acts. Each has its own purpose, but none reaches its full potential in isolation. What is a SIEM? A Security Information and Event Management system, or SIEM, is the central repository of security data. It collects logs and telemetry from across an organization’s digital environment, including endpoints, servers, applications, and network devices. Traditionally, SIEM platforms were designed to answer a fundamental question: What is happening across my infrastructure? They aggregate data, correlate events, and generate alerts based on predefined rules. For example, if multiple failed login attempts occur across different systems, a SIEM can flag this as suspicious. Often overwhelming analysts However, SIEMs have historically struggled with scale and context. As data volumes grow, alerts multiply, often overwhelming analysts. The signal gets buried under a mountain of noise. This is where large language models are beginning to change the game. By layering LLM capabilities onto SIEM platforms, organizations can now interpret logs in natural language, summarise incidents, and even prioritise alerts based on contextual understanding. Instead of simply reporting that something happened, the system can explain why it matters. If a SIEM generates thousands of alerts per day, it must be able to identify which are genuinely actionable. Manually investigate alerts What is SOAR? Security Orchestration, Automation, and Response, or SOAR, takes things a step further. If SIEM identifies potential threats, SOAR is responsible for deciding what to do about them. SOAR platforms connect different security tools and automate workflows. They can trigger actions such as isolating a compromised endpoint, blocking an IP address, or initiating an investigation process. Think of SOAR as the conductor of an orchestra, ensuring that each instrument plays at the right time. Before automation, analysts had to manually investigate alerts, gather data, and execute responses. SOAR reduces this burden by codifying response playbooks. When a known type of alert appears, the system follows a predefined sequence of actions. Predefined sequence of actions With the integration of LLMs, SOAR platforms are becoming more dynamic. Instead of rigid playbooks, they can adapt workflows based on context, suggest next steps, and even generate new response strategies on the fly. Analysts can interact with the system conversationally, asking questions like, “What is the likely impact of this alert?” or “What should we do next?” An important factor to consider emerges from these capabilities. If automation handles most responses, how can a security team ensure it makes the right decisions in unfamiliar scenarios? Embeds artificial intelligence What is an AI SOC? An AI-native Security Operations Centre represents the evolution of both SIEM and SOAR. It is not just a tool, but an architecture that embeds artificial intelligence across the entire security lifecycle. An AI SOC ingests data like a SIEM, orchestrates actions like a SOAR platform, and then goes further by continuously learning from patterns, behaviours, and outcomes. Rather than relying solely on predefined rules or static playbooks, it uses machine learning and LLMs to detect anomalies, predict threats, and recommend or execute responses in real time. In practical terms, an AI SOC can identify subtle indicators of compromise that would be invisible to rule-based systems. It can correlate events across time and systems, understanding not just what is happening, but how different activities are connected. Complex security data Large language models play a particularly powerful role here. They act as interpreters between humans and machines, translating complex security data into clear narratives. Analysts no longer need to sift through raw logs. Instead, they can receive concise, contextual insights or query the system directly in plain language. Comparing AI SOC, SIEM, and SOAR - While these technologies overlap, their core functions remain distinct. The differences become clearer when considering their limitations. A SIEM is primarily focused on visibility. It gathers and analyses data to detect potential threats. Without it, organizations lack a unified view of their security landscape. SOAR is focused on action. It automates and coordinates responses, ensuring that threats are addressed quickly and consistently. Introducing adaptive learning An AI SOC integrates both capabilities while adding intelligence. It enhances detection, accelerates response, and introduces adaptive learning. A standalone SIEM can identify issues but often leaves analysts overwhelmed with alerts. A standalone SOAR can automate responses but depends heavily on the quality of the inputs it receives. An AI SOC, by contrast, reduces noise, enriches context, and continuously refines both detection and response. In a modern security environment, SIEM, SOAR, and AI SOC are not competitors but collaborators. The SIEM acts as the data foundation, collecting and correlating events. SOAR builds on this by automating workflows and responses. The AI SOC overlays intelligence across both layers, enhancing detection accuracy and decision-making. Isolating affected systems In a scenario where unusual network activity is detected, the SIEM flags it based on correlation rules. The AI SOC analyses the behavior, recognizing it as part of a broader attack pattern. It then prioritises the alert and provides context. SOAR executes a response, isolating affected systems and initiating an investigation. This integrated approach transforms security operations from reactive to proactive. It also invites a strategic question. Are your current tools working together as a cohesive system, or are they operating in silos? Enabling adaptive playbooks Large language models are the quiet force reshaping all three technologies. In SIEM, they enhance data interpretation and reduce alert fatigue by summarising and contextualising events. In SOAR, they introduce flexibility, enabling adaptive playbooks and conversational interaction. In AI SOC environments, they act as cognitive engines, supporting reasoning, investigation, and continuous learning. The result is a shift from tool-centric operations to intelligence-driven security. Instead of asking analysts to adapt to tools, the tools adapt to analysts. AI SOC, SIEM, and SOAR each serve a unique purpose in modern security operations. SIEM provides visibility, SOAR enables action, and AI SOC delivers intelligence and adaptability. Together, they form a powerful ecosystem capable of detecting, understanding, and responding to threats at scale. Intelligence-driven security As cyber threats grow more sophisticated, relying on isolated tools is no longer sufficient. Organizations must think in terms of integrated systems that combine data, automation, and intelligence. It is important to consider that if the current security operations model is struggling to keep pace with evolving threats, what would it look like to reimagine it with AI at the core? To explore how you can elevate the security capabilities, connect with Rewterz experts and discover how their AI-powered solutions can help users build a smarter, faster, and more resilient defences.
As the pace of progress quickens, organizations face a growing volume of alerts and increasingly sophisticated attacks. Security teams are expected to detect and respond to threats quickly, often with limited resources. This is where an AI-native Security Operations Centre (SOC) becomes essential to improve visibility, detection accuracy, and response times. Alerts rain down, attackers adapt in real time, and defenders are expected to see patterns in the chaos. A SOC is fueled not just by algorithms but by something far more fundamental: data. In this article, users will learn what kinds of data power an AI-driven SOC, including telemetry, security signals, and contextual intelligence. They will explore how these data streams are processed and enriched, how large language models elevate detection and response, and why the quality of the data can determine whether the SOC hums like a precision engine or sputters under pressure. We will also walk through best practices for building strong data foundations and conclude with how organizations can take the next step. Endpoint detection tools An AI SOC does not rely on a single stream of information. Instead, it thrives on a layered ecosystem of data that, when combined, creates clarity out of noise. Telemetry is the raw pulse of your environment. It includes logs, network flows, endpoint activity, cloud events, and user behavior data. Every login, file access, process execution, and API call leaves a trace. Telemetry is abundant, continuous, and often overwhelming in its volume. Security signals are what emerge when telemetry is analyzed. These include alerts from intrusion detection systems, endpoint detection tools, SIEM correlations, and anomaly detections. Signals are essentially telemetry that has been interpreted through a security lens. Human-readable explanations Contextual data adds meaning to both telemetry and signals. It answers critical questions: Who is the user? What is the asset’s value? Is this behavior normal for this system? Context includes asset inventories, identity and access information, threat intelligence feeds, vulnerability data, and even business risk profiles. Individually, each layer tells a partial story. Together, they form a narrative that AI can understand, reason about, and act upon. If telemetry is the raw orchestra and signals are the sheet music, large language models are the conductor bringing it all together. AI-driven SOCs increasingly use LLMs to interpret complex, multi-source data in ways that traditional rule-based systems cannot. Instead of relying solely on predefined signatures or rigid correlations, LLMs can understand relationships between events, infer intent, and even generate human-readable explanations. Accessing sensitive data For example, rather than flagging three separate alerts for unusual login activity, file access, and privilege escalation, an AI SOC can stitch these together into a single, coherent incident narrative. It can explain that a compromised account was used to move laterally and access sensitive data, reducing both noise and response time. LLMs also enhance threat hunting by allowing analysts to query systems in natural language. A question like “Show me unusual login patterns for privileged users in the last 24 hours” becomes actionable without complex query syntax. This bridges the gap between human intuition and machine precision. Perhaps most importantly, LLMs enable adaptive learning. They continuously refine detection logic based on new data, emerging threats, and organizational context. This transforms the SOC from a reactive function into a proactive, learning system. Isolated data points The journey from raw data to actionable defense is not magic. It is a carefully orchestrated pipeline where each step adds clarity and value. It begins with data collection, where telemetry is ingested from across endpoints, networks, cloud platforms, and applications. Modern AI SOCs rely on scalable data lakes and streaming architectures to handle this volume without bottlenecks. Next comes normalisation and enrichment. Data from different sources is standardized into a common format and enriched with contextual information such as user roles, asset criticality, and threat intelligence. This step transforms isolated data points into something meaningful. Then comes analysis and correlation. Machine learning models and LLMs analyze patterns, identify anomalies, and correlate events across time and systems. This is where signals are refined and prioritised. Effectiveness of automation Following this is decision-making and automation. AI systems assess the severity and likelihood of threats, triggering automated responses where appropriate. This could include isolating an endpoint, revoking access, or escalating to an analyst with a detailed incident summary. Finally, there is feedback and learning. Every incident, whether a true positive or false alarm, feeds back into the system. This continuous loop improves detection accuracy over time. At every stage, the quality and completeness of data determine the effectiveness of the outcome. An AI SOC is only as intelligent as the data it consumes. Poor data is like feeding distorted notes into that orchestral performance. The result is confusion rather than clarity. Incomplete telemetry can create blind spots where attackers move undetected. Noisy or unfiltered data can overwhelm models, leading to false positives and alert fatigue. Inconsistent data formats can break correlations and reduce the effectiveness of automation. More accurate prioritisation On the other hand, high-quality data enables precision. It allows AI systems to distinguish between benign anomalies and genuine threats. It supports faster investigations, more accurate prioritisation, and more confident decision-making. Consider this question: if your SOC had perfect visibility but imperfect context, would it truly understand what it is seeing? Building strong data foundations is not a one-time task. It is an ongoing discipline that requires both technical and organizational commitment. Start by ensuring comprehensive visibility across the environment. This means integrating telemetry from endpoints, networks, cloud services, and identity systems. Gaps in visibility often become entry points for attackers. Improving model performance Focus on data normalisation and standardization. Use consistent schemas and formats so that data from different sources can be easily correlated. This reduces friction in analysis and improves model performance. Invest in context enrichment. Maintain accurate asset inventories, classify data sensitivity, and integrate threat intelligence feeds. Context turns raw data into actionable insight. Prioritise data quality management. Regularly audit your data sources for accuracy, completeness, and relevance. Remove redundant or low-value data that adds noise without insight. Implement feedback loops between analysts and AI systems. Human expertise remains essential for refining models, validating detections, and improving outcomes over time. Finally, ensure governance and security of data itself. Sensitive telemetry and contextual information must be protected, with clear policies for access, retention, and compliance. Large language models An AI SOC is not just a security function. It is a data-driven capability that reflects the maturity of an organization’s digital ecosystem. When data is treated as a strategic asset, security becomes more than defense. It becomes intelligence. Organizations that invest in high-quality data pipelines, contextual enrichment, and AI-driven analysis gain a significant advantage. They move faster, see clearer, and respond smarter. AI-native SOCs are reshaping how organizations defend against cyber threats, but their effectiveness depends on the data that powers them. Telemetry provides the raw inputs, security signals highlight potential issues, and contextual data adds meaning and direction. Together, they enable AI systems, particularly those powered by large language models, to detect, understand, and respond to threats with unprecedented speed and accuracy. Modern security powerhouse The journey from data to defense involves careful collection, enrichment, analysis, and continuous learning. Along the way, the importance of high-quality data cannot be overstated. Without it, even the most advanced AI will struggle to deliver value. If users are looking to transform their SOC into an intelligent, adaptive defense system, the question is not whether to adopt AI, but whether the data is ready. To explore how expert-led, AI-driven approaches can elevate the security operations, consider partnering with Rewterz. Their specialists can help you build the data foundations, integrate advanced AI capabilities, and turn the SOC into a truly modern security powerhouse.
Cyber threats are evolving at a pace that bewilder even seasoned security analysts. Attackers used to be easy to detect; with their reliance on phishing emails riddled with spelling mistakes or predictable malware signatures. Today’s threat actors are harnessing artificial intelligence to automate reconnaissance, generate convincing social engineering campaigns, evade detection, and adapt their attacks in real time. Against this backdrop, many traditional Security Operations Centre, or SOC, are struggling to keep up. Legacy SOC models were designed for a very different threat landscape. They were built around manual investigations, siloed tools, and reactive workflows. While these models once provided a strong defensive foundation, they now resemble medieval castle walls facing a swarm of autonomous drones. Endpoint protection systems In this article, readers will learn how traditional SOCs are structured, why they fall short against AI-driven threats, and how AI-powered SOCs are reshaping modern cyber defense. We will also explore why high-quality data is essential for effective AI security operations and outline best practices for building the kind of data environment that allows AI-driven SOCs to thrive. Traditional SOC is typically built around a layered operational model designed to monitor, detect, investigate, and respond to security incidents. Analysts are often divided into tiers based on skill level and responsibilities. Tier 1 analysts monitor alerts generated by security tools such as SIEM platforms, firewalls, endpoint protection systems, and intrusion detection systems. Their role is to triage alerts, dismiss false positives, and escalate suspicious activity. Tier 2 analysts conduct deeper investigations into escalated incidents, while Tier 3 analysts handle threat hunting, advanced investigations, and incident response. AI-powered cyber threats At first glance, this structure appears logical and organized. However, it has several structural weaknesses that become obvious when facing AI-powered cyber threats. One of the biggest limitations of legacy SOCs is their dependence on manual processes. Human analysts are expected to sift through thousands, sometimes millions, of alerts each day. This creates a dangerous environment where alert fatigue becomes inevitable. Imagine a smoke alarm that goes off every few minutes, but for a non-critical fire. Eventually, people stop reacting with urgency. The same phenomenon occurs in SOC environments. Analysts become overwhelmed by false positives, causing genuine threats to slip through unnoticed. AI-generated phishing campaigns AI-driven attackers exploit this weakness masterfully. Modern malware can generate behavior that blends into normal activity, avoiding traditional detection methods that rely on static rules or known indicators of compromise. AI-generated phishing campaigns can create highly personalized messages that mimic writing styles, business terminology, and communication patterns with uncanny accuracy. Traditional SOCs also struggle with response speed. Many legacy environments still depend on analysts manually correlating events across multiple disconnected systems. By the time an investigation begins, the attacker may already have escalated privileges, exfiltrated sensitive data, or moved laterally across the network. Probing cloud infrastructure The problem becomes even more severe when attackers use AI to automate their operations. AI-powered threats can rapidly test defences, adapt their behavior, and exploit vulnerabilities faster than human-led teams can respond. Consider this hypothetical scenario: what happens when an AI-driven attack can rewrite its own malware behavior every few minutes while simultaneously launching personalized phishing campaigns against employees and probing cloud infrastructure for weaknesses? A traditional SOC would likely spend more time chasing alerts than stopping the actual intrusion. Legacy SOCs also lack contextual awareness. Most conventional detection systems focus on isolated events rather than broader behavioral patterns. An employee logging in from a new location may trigger an alert, but the system may fail to connect that event with unusual data access patterns, suspicious endpoint activity, and abnormal cloud API requests occurring simultaneously. Without context, security teams are left trying to assemble a jigsaw puzzle while pieces keep changing shape. Suspicious activity patterns To defend against AI-driven threats, organizations need to match an attacker’s arsenal and turn to AI. Modern AI-native SOC do not simply bolt machine learning onto existing workflows. They fundamentally transform security operations. AI-powered SOC ingest enormous volumes of telemetry data from endpoints, networks, cloud environments, identity systems, applications, and threat intelligence feeds. Instead of relying solely on predefined rules, they use machine learning models and behavioral analytics to identify anomalies and suspicious activity patterns. These systems continuously learn from the environment, improving their ability to distinguish normal behavior from malicious activity. This dramatically reduces false positives and allows analysts to focus on genuine threats rather than drowning in alert noise. Threat hunting capabilities Automation also plays a major role. AI-driven SOC can automatically investigate alerts, enrich incidents with contextual data, prioritise risks, and even initiate containment actions without waiting for human intervention. For example, if an endpoint begins exhibiting ransomware-like behavior, an AI-powered SOC can isolate the device, block malicious processes, revoke compromised credentials, and alert analysts within seconds. Traditional SOC workflows might require multiple manual approvals before taking action. AI-powered SOC also improve threat hunting capabilities. Large Language Models and advanced analytics tools can analyze vast datasets to identify subtle attack patterns that human analysts might overlook. These systems can detect low-and-slow attacks, insider threats, and novel attack techniques that do not match known signatures. Importantly, AI-powered SOC still require skilled analysts. AI is not replacing security professionals. Instead, it acts like an extraordinarily caffeinated research assistant that never sleeps, never blinks, and can process millions of events simultaneously. Abnormal behavior patterns Modern AI-powered SOC combine several technologies to deliver stronger protection against advanced attackers. SIEM platforms remain important, but they are increasingly enhanced with AI-driven analytics and orchestration capabilities. Security Orchestration, Automation, and Response, or SOAR, platforms automate repetitive tasks and coordinate responses across security tools. Extended Detection and Response, or XDR, platforms unify telemetry from endpoints, networks, email systems, cloud environments, and identity providers to provide broader visibility into threats. Threat intelligence platforms feed AI systems with up-to-date indicators, adversary tactics, and contextual threat information. User and Entity Behavior Analytics, or UEBA, tools help detect abnormal behavior patterns that may indicate compromised accounts or insider threats. Generating investigation recommendations Large Language Models are also becoming valuable SOC assistants. They can summarise incidents, generate investigation recommendations, correlate threat intelligence, and assist analysts with faster decision-making. However, even the most advanced AI security tools are only as effective as the data they receive. Data is the oxygen of AI-powered security operations. Poor-quality data leads to inaccurate detections, ineffective models, and dangerous blind spots. AI systems depend on clean, complete, and well-structured telemetry to identify threats accurately. If logs are inconsistent, incomplete, duplicated, or missing key contextual information, the AI models may struggle to distinguish malicious activity from legitimate behavior. For example, if endpoint telemetry is missing process execution details or cloud logs lack identity context, the SOC may fail to identify lateral movement or credential abuse. Disconnected business systems High-quality data also improves model training. AI systems learn from historical patterns, meaning that inaccurate or poorly labelled data can create biased or unreliable detections. In many organizations, data fragmentation is a major challenge. Security data is often scattered across legacy infrastructure, cloud services, third-party tools, and disconnected business systems. This fragmentation creates visibility gaps that attackers can exploit. Building a strong data foundation requires careful planning and governance. Organizations should begin by centralizing telemetry from across the environment into unified data platforms wherever possible. Standardising log formats and ensuring consistent timestamp synchronization helps improve correlation accuracy. Normalised data allows AI systems to analyze events more effectively across multiple systems. Data enrichment is equally important. Adding contextual information such as asset criticality, user roles, geolocation data, and threat intelligence helps AI models make more informed decisions. Relatively predictable techniques Organizations should also continuously validate data quality. Missing logs, duplicate entries, and ingestion failures can quietly undermine detection capabilities if left unchecked. Retention policies matter as well. AI-powered threat hunting often relies on historical behavioral analysis, meaning organizations need sufficient long-term data storage to identify patterns over time. Finally, collaboration between security, IT, cloud, and data teams is essential. Building an effective AI-driven SOC is not simply a technology upgrade. It is an operational transformation that requires alignment across the organization. Traditional SOC models were built for an era when cyber threats moved more slowly and attackers relied on relatively predictable techniques. Today’s AI-driven threat landscape is vastly different. Attackers can automate reconnaissance, personalize phishing campaigns, evade traditional detection methods, and adapt attacks in real time. Reducing operational risk Legacy SOC struggle under the weight of manual investigations, alert fatigue, fragmented visibility, and slow response times. In contrast, AI-powered SOC use automation, behavioral analytics, machine learning, and contextual intelligence to detect and respond to threats at machine speed. Yet technology alone is not enough. The effectiveness of an AI-driven SOC depends heavily on the quality of the underlying data. Clean, enriched, and well-governed telemetry enables AI systems to deliver meaningful security insights and reduce operational risk. As cyber threats continue evolving, organizations must rethink how their SOC operate. The future of cyber defense belongs to security operations that can learn, adapt, and respond as quickly as the threats they face. To discover how Rewterz experts can help modernise the SOC capabilities, strengthen the data foundations, and prepare the organization for AI-driven cyber threats, explore our advanced security operations solutions today.
Cybersecurity teams face a difficult reality. Organizations are collecting more security data than ever before, yet many still struggle to detect threats quickly, respond efficiently, or keep pace with increasingly sophisticated attacks. Traditional Security Operations Centre (SOC), once considered the backbone of enterprise defense, are under pressure from alert overload, analyst burnout, and attackers who now use automation and artificial intelligence themselves. As a result, AI-driven SOC is rapidly shifting from emerging technology to operational necessity. Businesses are no longer debating whether AI belongs in cybersecurity. Instead, they are asking a more practical question: is investing in an AI SOC actually worth it? Modern security operations This article explores what AI-powered SOC are, why organizations are adopting them, the costs involved, and the measurable returns businesses can expect. It also examines the long-term operational and strategic value AI can bring to modern security operations. Traditional SOC were built for a different era of cybersecurity. Analysts manually reviewed alerts, correlation rules were largely static, and attacks were often slower and less complex. Today’s threat landscape moves at machine speed. AI-assisted phishing campaigns Modern organizations generate enormous volumes of telemetry from cloud environments, endpoints, SaaS applications, networks, identity systems, and third-party integrations. Security teams are expected to monitor all of this continuously while defending against ransomware, insider threats, supply chain attacks, and AI-assisted phishing campaigns. Many analysts spend large portions of their time investigating false positives, enriching alerts manually, or repeating low-value workflows. This slows response times and increases the likelihood that genuine threats will be missed. Introducing intelligent automation AI-driven SOC address these challenges by introducing intelligent automation and machine learning into security operations. Rather than relying entirely on static detection rules, AI systems can analyze behavioral patterns, correlate large datasets, prioritise high-risk incidents, and automate repetitive investigations in real time. For many organizations, this transition is becoming essential. If attackers can launch AI-assisted campaigns that adapt in seconds, organizations can no longer rely solely on manual security operations to defend themselves effectively. Existing security maturity One of the main reasons organizations hesitate to adopt AI-driven SOC models is the perception that implementation requires enormous investment. While costs can be significant, the reality is more nuanced. The overall expense depends on factors such as organizational size, infrastructure complexity, existing security maturity, and operational goals. Initial investments often include: AI-powered SIEM or XDR platforms Security automation and orchestration tools Cloud infrastructure and storage Integration services Staff training and onboarding AI-enhanced operations Some businesses also partner with managed detection and response (MDR) providers that already incorporate AI capabilities into their SOC offerings. Additional costs may involve improving data visibility and integration. AI systems depend heavily on quality telemetry and accessible data. Organizations with fragmented security ecosystems may need to modernise data pipelines before they can fully benefit from AI-enhanced operations. However, comparing AI SOC costs only against traditional SOC spending can be misleading. Conventional SOC often require continuous growth in analyst headcount to keep up with increasing alert volumes. At the same time, experienced cybersecurity professionals remain difficult and expensive to hire. Burnout and staff turnover further increase operational costs. Scaling security operations AI changes the economics of scaling security operations. Instead of increasing staffing proportionally with data growth, organizations can use automation and intelligent correlation to manage larger workloads more efficiently. In many cases, businesses discover they were already paying heavily for inefficiency long before AI entered the equation. Cybersecurity ROI can sometimes feel difficult to measure because success often means preventing incidents that never occur. However, AI-driven SOC provide several measurable indicators that demonstrate both operational and financial value. One of the most important metrics is dwell time, which refers to how long attackers remain undetected inside an environment. Reducing reputational damage The longer a threat actor operates unnoticed, the greater the potential damage. AI-powered SOC improve detection speed by analyzing behavioral anomalies and correlating indicators across multiple systems simultaneously. Reducing dwell time can significantly lower breach costs, minimize disruption, and reduce reputational damage. AI SOC improve both Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Automated workflows rapidly enrich alerts with contextual intelligence, allowing analysts to make faster and more informed decisions. Instead of spending valuable time gathering information manually, analysts can focus on containment and remediation. Strategic security tasks Operational efficiency is another major driver of ROI. Rather than manually triaging thousands of alerts, analysts can concentrate on high-priority threats and strategic security tasks. AI systems eliminate much of the repetitive work that traditionally consumes analyst time. This not only improves productivity but can also reduce burnout and staff turnover, both of which carry significant operational costs. The financial impact of a major cyber incident can include: Regulatory fines Legal costs Customer loss Operational downtime Recovery expenses Reputational damage AI-driven SOC help reduce both the likelihood and severity of successful attacks through faster detection and more consistent response capabilities. Improving compliance operations For regulated industries, AI SOC can also improve compliance operations. Automated reporting, continuous monitoring, and enhanced visibility simplify audit preparation and reduce administrative overhead. This creates both operational savings and reduced regulatory risk. The benefits of AI SOC extend beyond cybersecurity alone. Security operations now directly influence customer trust, operational resilience, digital transformation, and organizational agility. As businesses expand cloud adoption and hybrid work environments, security operations must scale without slowing the business down. Growing telemetry volumes AI SOC support this scalability by managing growing telemetry volumes and operational complexity more efficiently than traditional models. This becomes especially important during periods of rapid growth, mergers, acquisitions, or international expansion. AI-enhanced SOC also improve executive visibility. Advanced analytics and automated reporting provide leadership teams with clearer insights into risk exposure and operational performance. Security discussions become more strategic and data-driven rather than purely reactive. Another major advantage is consistency. AI-driven security operations Some organizations focus heavily on immediate implementation costs while overlooking the long-term value AI-driven security operations create. In the short term, adopting an AI SOC may require: Infrastructure modernisation Workflow redesign Staff onboarding System integrations These investments can appear substantial, particularly for organizations transitioning from legacy systems. However, the long-term value often compounds over time. As AI systems analyze more operational data, detection quality improves. Automation workflows become more refined. Security teams become more efficient. Incident response becomes faster and more predictable. Traditional SOC models Meanwhile, the costs of maintaining outdated SOC models continue to rise. Manual operations struggle to scale with expanding attack surfaces. Analyst fatigue contributes to turnover. Delayed detection increases breach risk. Compliance management becomes more difficult and resource-intensive. Over time, these inefficiencies can become more expensive than modernising security operations altogether. Organizations should therefore evaluate AI SOC investment not simply as a technology purchase, but as a long-term operational transformation. AI-driven SOC are reshaping how organizations approach cybersecurity operations. As threats become faster, more automated, and increasingly complex, traditional SOC models often struggle to keep pace. Meaningful business outcomes While implementing an AI SOC requires investment, the long-term value can be substantial. Faster detection, improved operational efficiency, enhanced scalability, stronger compliance readiness, and reduced long-term risk all contribute to meaningful business outcomes. Most importantly, AI allows security teams to move beyond endless alert firefighting and toward more strategic, intelligence-led defense operations. Businesses adopting AI-enhanced security operations today are not simply purchasing new tools. They are building more resilient, scalable, and adaptive cybersecurity capabilities for the future. If the organization is evaluating how to modernise its SOC capabilities, Rewterz can help assess your current security posture, identify operational gaps, and implement AI-driven solutions that strengthen detection, response, and resilience across the environment.
Cybersecurity teams are experiencing a shift in their scope of work. Attack surfaces are expanding, threat actors are becoming more sophisticated, and the speed of modern attacks is outpacing traditional security operations. At the same time, organizations are facing off a spike in alerts, struggling with analyst burnout, and dealing with an ongoing shortage of skilled cybersecurity professionals. Against this backdrop, Artificial Intelligence has emerged as one of the most transformative technologies in the Security Operations Centre, or SOC. Reshaping security operations Yet one question continues to surface in boardrooms and security teams alike: can AI replace SOC analysts? The short answer is no. AI is reshaping security operations, but it is not eliminating the need for human expertise. Instead, the future of cybersecurity lies in collaboration between intelligent automation and skilled analysts. AI excels at speed, scale, and pattern recognition, while human analysts provide judgement, creativity, contextual understanding, and strategic decision-making. In this article, they will explore how AI-driven SOC are changing security operations, why businesses increasingly need both AI and human analysts, and how responsibilities are being divided between machines and people. They will also examine the critical human role in threat hunting, contextual analysis, oversight, and response orchestration in modern SOC environments. AI-assisted phishing campaigns Traditional SOC is designed for a very different era of cybersecurity. Analysts manually reviewed logs, investigated alerts, relying heavily on static rules and signatures to identify threats. While this model once worked reasonably well, modern cyber threats move far too quickly for purely manual operations. Attackers are now using automation, AI-assisted phishing campaigns, polymorphic malware, and sophisticated social engineering tactics that constantly evolve. A single organization may generate millions of security events every day, creating a tidal wave of telemetry that no human team can realistically process on its own. Interpreting complex threats This has created several operational challenges for SOC teams. Alert fatigue has become widespread, with analysts overwhelmed by false positives and repetitive tasks. Response times are often delayed because security teams cannot prioritise incidents efficiently. At the same time, cybersecurity talent shortages mean many organizations are operating with understaffed SOCs. AI-driven security operations emerged as a response to these growing pressures. By automating repetitive tasks and accelerating analysis, AI helps organizations detect and respond to threats at machine speed. However, this does not mean humans become irrelevant. Quite the opposite. As AI handles operational heavy lifting, human analysts become even more important in guiding strategy, validating decisions, and interpreting complex threats. Large-scale data analysis AI thrives in environments that involve large-scale data analysis, repetition, and pattern detection. Modern SOC platforms use machine learning and large language models to process telemetry from endpoints, networks, cloud infrastructure, applications, and identity systems in real time. One of AI’s greatest strengths is its ability to rapidly identify anomalies that might otherwise go unnoticed. Instead of relying solely on pre-defined rules, AI systems can learn behavioral baselines and flag suspicious deviations. This allows organizations to detect novel attacks, insider threats, and stealthy lateral movement more effectively. AI is also highly effective at triaging alerts. Rather than forcing analysts to manually sift through thousands of low-priority notifications, AI can correlate events, eliminate duplicates, enrich alerts with contextual data, and prioritise incidents based on risk. This dramatically reduces noise inside the SOC. Improving response times Automation also improves response times. AI-powered orchestration systems can isolate compromised endpoints, disable suspicious accounts, block malicious IP addresses, or trigger containment workflows within seconds. Tasks that once consumed valuable analyst hours can now happen almost instantly. In many ways, AI functions like a hyper-vigilant digital air traffic controller, constantly monitoring thousands of moving signals simultaneously without becoming tired or distracted. Despite AI’s impressive capabilities, cybersecurity is not purely a technical challenge. It is also a human problem involving intent, deception, business context, and strategic judgement. These are areas where human analysts remain indispensable. Critical business operations One of the most important responsibilities humans retain is decision-making during high-risk incidents. AI can recommend actions based on patterns and probabilities, but human analysts must evaluate the wider consequences of those decisions. A false containment action, for example, could disrupt critical business operations or impact customers. Human analysts are also essential for contextual analysis. AI may identify suspicious activity, but it often lacks a nuanced understanding of organizational priorities, geopolitical considerations, regulatory obligations, or industry-specific risk factors. Sensitive financial data Imagine an AI system flagging unusual access to sensitive financial data at 2am. Is it a malicious insider? A compromised account? Or simply a finance executive traveling internationally during an acquisition process? Human analysts provide the contextual reasoning needed to answer these questions accurately. Threat hunting is another area where human creativity remains critical. Skilled analysts think like adversaries. They form hypotheses, investigate subtle behavioral indicators, and connect seemingly unrelated clues across environments. While AI can assist by surfacing anomalies, human intuition and experience often uncover the deeper narrative behind an attack. There is also the issue of adversarial manipulation. Attackers are already experimenting with ways to deceive AI models through poisoned data, evasive malware behavior, and prompt manipulation techniques. Human oversight is essential to ensure AI systems are functioning correctly and are not being misled. Automate repetitive workflows Modern cybersecurity environments are simply too complex for either humans or AI to operate effectively in isolation. Businesses increasingly require a blended approach that combines machine efficiency with human expertise. AI dramatically improves scalability. It allows SOC teams to process vast volumes of data, accelerate detection, and automate repetitive workflows. This helps organizations manage growing attack surfaces without endlessly expanding headcount. However, AI alone cannot fully understand business priorities, ethical considerations, or nuanced attacker behavior. Human analysts provide governance, oversight, and strategic direction that machines cannot replicate. High-volume operational tasks Here is a thought-provoking question many organizations are beginning to ask themselves: If an AI system autonomously detects and contains a cyber attack in under thirty seconds, but mistakenly shuts down a hospital’s critical systems in the process, who should ultimately be accountable for that decision? The SOC of the future will almost certainly be AI-native, but it will not be human-free. Instead, we are moving towards a model where analysts and AI systems operate as collaborative partners. AI will continue handling high-volume operational tasks such as alert triage, telemetry analysis, workflow automation, and real-time response orchestration. Human analysts, meanwhile, will focus on strategic oversight, advanced investigations, adversarial thinking, and business-aligned decision-making. Accelerating threat detection This evolution can elevate the role of SOC analysts rather than eliminate it. As repetitive work decreases, analysts can dedicate more time to proactive defense, threat intelligence, and security innovation. AI is transforming security operations at an extraordinary pace, but it is not replacing SOC analysts. Instead, it is redefining their role. AI excels at analyzing massive datasets, automating repetitive tasks, and accelerating threat detection and response. Human analysts contribute critical thinking, contextual understanding, creativity, and strategic judgement that machines still cannot replicate. Organizations that embrace this AI-augmented model will be better positioned to reduce alert fatigue, improve detection accuracy, accelerate response times, and defend against increasingly advanced cyber threats.


Expert commentary
Across many sectors, AI is transitioning from an experimental process to a trusted tool, but how will construction - and architectural ironmongery specifically - balance this technological opportunity with traditional practice? Artificial intelligence was once considered the trend of tomorrow, but it’s now here, and already it’s impacting the design, specification and management of the built environment. Following a period of refined development, the technology is emerging as a valuable tool for architectural professionals, with its growing role signifying far more than a passing industry trend. Passing industry trend According to the Royal Institute of British Architects’ (RIBA) Artificial Intelligence Report 2025, 59% of architectural practices now use AI on at least some projects, an increase from 41% in 2024. Furthermore, a global survey led by the Royal Institution of Chartered Surveyors in 2025 found that 56% of investors planned to increase AI investment, suggesting that the rate of adoption will continue to accelerate over the coming years. However, whilst innovation typically creates opportunity, there are challenges to address These findings represent a cultural shift, one where AI is firmly embedding itself into workflows and influencing the decision making process. However, whilst innovation typically creates opportunity, there are challenges to address. As more professionals equip themselves with an arsenal of AI-driven tools, are we in danger of becoming overly reliant on technology? Or are those reluctant to adapt likely to be left behind? Daniel May, Director at Consort Architectural Hardware, shares insight: Repetitive administration tasks “The development of the built environment has always relied on technical precision. Specifications naturally contain large volumes of product information and technical data, with professionals managing document-heavy tasks in the form of specification writing, door scheduling and BIM coordination in order to meet project requirements and compliance obligations. All of this data must be analyzed and processed accurately - often in line with demanding timescales - and it is here where AI can offer the greatest value.” “Where time was once consumed by repetitive administration tasks and information processing, professionals are now embracing AI as a means of working more efficiently. For architectural ironmongery specifically, where specification accuracy is critical, AI has the potential to support architects and specification professionals as they navigate the product selection process. As a tool, AI can streamline documentation by rapidly processing performance data and certification requirements, whilst also identifying inconsistencies and absent compliance information within schedules.” Complex project requirements “AI systems are helping professionals navigate increasingly complex project requirements quickly, accurately and consistently. As machine learning and autonomous models continue to advance, these tools may further reduce the administrative burden associated with architectural work models whilst improving accuracy and minimizing the risk of human error in the process. With that said, the effectiveness of AI software is very much reliant on the quality of the information it receives.” “With the sector so deeply tied to fire safety, accessibility, security and regulatory standards, the caution around adopting AI as common practice is of course justified. Historically, much of the construction industry has been measured in its adoption of new technology, partly due to the critical nature of compliance and the significant consequences of error. Though, AI feels somewhat different because of its pace and potential, and as such, organizations must be measured in their approach to it, ensuring that professional knowledge remains central to delivering safe, efficient and compliant building projects.” The human element As industry standards and the legislation surrounding the built environment continues to evolve, so too will the methods used to achieve high level design and compliance. Seemingly, AI looks set to have an increasingly prominent role, but it should be viewed as a collaborative partner capable of enhancing professional expertise as opposed to a system that can, or should, do it all. Daniel continues: “At this stage, AI alone simply can’t understand the nuances of individual projects and that has implications for both design and compliance. This is particularly relevant in the post-Grenfell regulatory landscape, where accountability, traceability and evidence-based decision-making have become fundamental to product specification and delivery.” Building greater trust “Although AI can assist with information processing, the technology is not ultimately responsible for the decisions being made. Accountability has rightly become a major focus point in construction, and as AI continues to disrupt practices, the industry must ensure that responsibility remains clearly defined. AI-driven errors could lead to serious penalties in relation to compliance, safety and project delivery, proving human expertise remains critical.” “Moving forward, greater transparency within AI systems will be key. If professionals are able to understand how or why AI recommendations have been generated, they can assess them with confidence, building greater trust in the technology.” Architectural design solutions “When it comes to architectural design, the emotional intelligence, contextual understanding and creative balance offered by a team of professionals far outweighs the speed that AI can offer. Already, AI is being used to support visualization and concept development for multi-layered projects in hospitality, healthcare and commercial environments to name a few, helping teams to explore ideas and communicate concepts at a quicker rate.” “However, can AI effectively develop architectural design solutions based on the bespoke requirements of a project, the operational needs of its users or even the general character of the building? Most would argue that it’s not conceivable, because AI lacks the lived experience and contextual understanding that comes from being present in the project itself.” Architectural ironmongery products “For architectural ironmongery products, professionals must regularly assess how products will function in real environments. Human intuition is impossible to replace and those informed design decisions, made by human professionals, will always be essential. Whilst some question whether AI could one day plan and deliver a project from concept to completion, perhaps the more important question should be whether future generations of professionals could lose the critical design and specification skills that are needed, should the industry become too dependent on AI.” “There is a growing sense of inevitability surrounding AI’s influence on architectural ironmongery and the wider built environment. As the industry continues to embrace this new wave of technological development, it is important to remember that innovation must complement the knowledge, judgement and accountability of the professionals who create safe and functional buildings, not replace it.”
A security camera installed today has more AI processing power than the systems that guided early autonomous vehicle prototypes. And yet the operator who mounts that camera on a wall will, in all likelihood, never use most of that capability. Industry surveys bear this out: a wide gap persists between the number of security professionals who believe AI can improve outcomes and the much smaller share who have adopted it operationally. The reason has nothing to do with the silicon and everything to do with how the industry has asked people to configure these systems. The problem is not that the industry lacks algorithms. The problem is that physical security has never found a scalable way to personalize systems for each site. The personalisation dilemma hiding in plain sight The problem is that physical security has never found a scalable way to personalize systems for each site A surveillance deployment at an airport, a retail chain, a school campus, and a logistics yard can look strikingly similar in hardware terms. Each installation uses image sensors, edge processors, network connectivity, and a management layer. What changes is what the operator cares about. At a school entrance, the priority might be perimeter approach after hours and controlled access during the day. At a loading dock, the concern is tailgating, vehicle dwell time, and safety incidents near forklifts. At an airport, the operator may need queue-flow analytics one moment, unattended-item detection the next, and then a search for a specific person of interest carrying a particular bag. At a retail store, loss prevention teams want to correlate customer flow patterns with point-of-sale data and identify suspicious behavior near high-value merchandise. This range of needs forces a reality that the industry has acknowledged in principle but never resolved in practice: the application pool across the market is vast, yet each individual site typically requires only a narrow set of outcomes. Each deployment needs personalisation once, at commissioning, and then again whenever the environment or the risk profile shifts. The app store that never became a market For the better part of a decade, the industry’s most visible answer to the personalisation problem was the “app store” model. The logic was straightforward: curate a marketplace of trained neural network algorithms, let integrators browse a catalog, and download the right analytic for each job. Queue counting for a passport control hall. License plate recognition for a parking structure. Occupancy monitoring for a conference room. The concept borrowed directly from the consumer smartphone approach. In practice, it never matched physical security’s purchasing and operating rhythm. A phone owner discovers and downloads new apps continuously. A physical security deployment selects one or two analytics functions at installation and rarely revisits them. Another maintenance burden A queue-counting algorithm trained on airport data is excellent at queue counting The economic incentive to maintain, curate, and update a broad catalog across a fragmented ecosystem of camera OEMs, VMS platforms, and system integrators never materialised when the average buyer drew from only a thin slice of it. And the question of who would operate such a marketplace across that fragmented landscape was never satisfactorily answered. The deeper issue is that distribution was not the hard part. Personalisation was. A queue-counting algorithm trained on airport data is excellent at queue counting. It does not naturally become a general-purpose security tool for whatever the operator needs next. Once a model is trained for a narrow task, adaptation requires another project, another integration cycle, and another maintenance burden. AI-enabled cameras The examples that do exist are instructive. Schiphol Airport in the Netherlands has used trained camera systems for over a decade to measure queue length at passport control and alert staff when additional counters should open. Rome trailed AI-enabled cameras to track pedestrian wait times at crosswalks, measure bus queue length, and monitor parking occupancy to support active transport and reduce vehicle emissions. These are effective, well-regarded deployments. They also illustrate the limitation: each required its own trained model, its own integration effort, and its own maintenance cycle. The queue-counting camera at Schiphol cannot be redeployed to detect an abandoned bag. That is a separate algorithm, a separate procurement, and a separate project. What changes with agentic AI Applied to physical security, this translates into a simpler commissioning experience Agentic AI points to a fundamentally different approach. An agentic system can receive goals expressed in natural language, determine the appropriate actions to fulfill those goals, execute those actions using available tools, and verify the results. Applied to physical security, this translates into a simpler commissioning experience: the operator expresses intent in plain language, and the system configures itself to achieve that intent. Consider the practical implications. An installer commissioning cameras at a retail location could type or speak a set of instructions: “Alert the manager if more than five people are waiting at checkout for longer than two minutes.” A facilities director could ask the system to “Track vehicles that enter the east parking lot after 9 p.m. and flag any that remain for more than 30 minutes.” A school security coordinator might specify: “Notify campus police if anyone approaches the perimeter fence between midnight and 5 a.m.” Appropriate perception capabilities None of these instructions require the operator to select a specific analytic from a catalog, configure a detection model, or define pixel-level zones in a complex VMS interface. The system interprets the intent, selects the appropriate perception capabilities, configures thresholds and context, and validates behavior over time. When the operator’s needs change, a new instruction replaces the old one. The camera hardware stays the same. The AI adapts. This is the core of the shift: minimal user input, maximum flexibility, and a security system that personalises itself without requiring the operator to navigate the traditional customize-certify-deploy cycle. Vision language models make it practical A conventional neural network trained for people counting can count people The enabling technology is the vision language model, or VLM. A VLM combines visual encoders with language reasoning, allowing it to interpret images or video in the context of natural language prompts. This is a qualitative leap beyond traditional convolutional neural networks, which classify or detect predefined objects and have no mechanism for open-ended interpretation. A conventional neural network trained for people counting can count people. It cannot distinguish between a crowd of commuters exiting a train station and a crowd assembling in protest. A VLM, by integrating contextual reasoning with visual analysis, can draw inferences that a task-specific model cannot. It can assess behavioral patterns, interpret spatial relationships, and respond to queries about scenes it has never been explicitly trained to analyze. Where a neural network might register two people carrying objects, a VLM could infer whether the scene suggests travellers with luggage or workers transporting equipment, provided the visual context supports that inference. Supporting multimodal input This matters in physical security because operational questions are rarely phrased as taxonomy labels. Operators want to express outcomes. They want to say “show me anything unusual near the loading bay after hours,” and the system should be able to reason about what “unusual” means given the site context. VLMs also support multimodal input. Audio cues such as a raised voice, a scream, an alarm, or breaking glass can contribute to scene interpretation when paired with video. In security applications, where events routinely unfold across both visual and auditory channels, this capability adds a meaningful layer of situational awareness. The edge constraint that forces discipline Large language models in the cloud use hundreds of billions of parameters and consume hundreds of watts None of this works if the architecture assumes data center conditions. Most surveillance cameras operate under strict power and thermal limits. Power over Ethernet (PoE), the standard delivery mechanism, typically provides between 15 and 30 watts depending on the PoE class, and only a fraction of that budget is available for AI processing after the sensor, ISP, video encoder, and network stack have taken their share. In many installations, the AI workload must fit within a few watts. Large language models in the cloud use hundreds of billions of parameters and consume hundreds of watts. That scale does not translate to a camera mounted on a pole or embedded in a ceiling tile. For agentic AI to work at the edge of a physical security network, the models must be compact, efficient, and designed for the purpose. Neural network acceleration This is where smaller, domain-specific VLMs become essential. Models trained on industry-relevant image and text datasets, combined with techniques such as pruning, quantisation, and parameter-efficient fine-tuning, can deliver meaningful visual reasoning within the compute and memory constraints of an edge processor. The result is a VLM that fits inside a camera’s power budget and still responds to natural language instructions with useful accuracy. Ambarella’s CVflow AI architecture, now in its third generation, was designed for this class of workload. The architecture integrates advanced neural network acceleration with high-resolution image signal processing and video encoding on a single system-on-chip, allowing cameras to run complex AI inference alongside their core imaging functions without exceeding the thermal and power boundaries that define edge deployments. The company's latest addition to its portfolio, the 4-nanometer CV7, runs CNNs and vision language models concurrently across multiple video streams while consuming 20 percent less power than its predecessor. For infrastructure and robotic applications requiring heavier models, the 5-nanometer N1 family supports multimodal LLMs in multi-camera configurations. Distributing intelligence across far edge, near edge, and cloud This tier must respond in milliseconds and operate within a fixed power envelope A workable agentic architecture for physical security distributes intelligence across three tiers, each matched to the processing demands and latency requirements of its role. At the far edge, inside the camera itself, the processor handles real-time perception: object detection, tracking, zone logic, and initial event classification. This tier must respond in milliseconds and operate within a fixed power envelope. At the near edge, on a local gateway or network video recorder, a more capable processor orchestrates across multiple cameras, maintains state, correlates events, retrieves site-specific policies and procedures, and classifies incidents requiring more context than any single camera provides. At the cloud/server tier, available when connectivity permits, the system accesses heavier models for forensic analysis, fleet-wide analytics, model updates, and long-horizon reporting. Periodic cloud access This tiered approach keeps the most time-sensitive decisions local, where latency is lowest and data privacy is strongest. It also means agentic capabilities can scale incrementally. A small installation might run entirely at the far edge with periodic cloud access. A large campus might employ all three tiers, with near-edge orchestration coordinating PTZ patrol patterns across dozens of cameras while the cloud generates shift summaries and updates models based on fleet-wide telemetry. In practice, a security workflow built on this pattern often combines real-time detection at the far edge, behavior-tree orchestration at the near edge for multi-camera coordination, local retrieval over site playbooks, and conservative safe-mode escalation when system confidence is low. The discipline of deterministic guardrails and structured verification loops is essential in security operations, where unpredictable system behavior is not acceptable. A hybrid future, with VLMs orchestrating specialist models The transition to agentic AI does not eliminate specialized neural networks The transition to agentic AI does not eliminate specialized neural networks. Purpose-trained models will continue to deliver superior accuracy for well-defined, high-frequency tasks such as license plate recognition, face matching, and fire and smoke detection. In a mature agentic system, the VLM acts as an orchestrator. It handles open-ended perception and natural language interaction while routing to specialized models when a task demands their precision. A PTZ camera at a transportation hub might receive the instruction “monitor the west concourse for unattended items.” The VLM interprets the request, manages the interface, and reasons over broader scene context. Real-time video processing When it identifies a candidate object, it routes to a dedicated abandoned-item classifier optimized for that specific validation step. The VLM orchestrates. The specialist model validates. The operator receives a refined, actionable alert. That hybrid pattern places specific demands on the silicon. The processor must support both traditional CNN inference and generative AI workloads simultaneously while maintaining real-time video processing within the same power envelope. The value of a tightly integrated SoC, one that combines an advanced ISP, a deep learning accelerator, and a video encoder on a single die, is that it eliminates the multi-chip complexity and power overhead that would otherwise make this approach impractical at the edge. Making agentic AI deployable for the ecosystem Ambarella’s Developer Zone, launched at CES 2026, provides a centralized portal of tools Physical security is built on a broad ecosystem of camera OEMs, VMS providers, independent software vendors, module builders, and system integrators. For agentic AI to reach the market at scale, these participants need model-ready tooling, reference workflows, and a practical path from prototype to production. This is where developer ecosystems become part of the story. Ambarella’s Developer Zone, launched at CES 2026, provides a centralized portal of tools, optimized AI models, agentic blueprints, low-code templates, and documentation aimed at accelerating edge AI application development on Ambarella’s SoCs. Common software stack ISVs and integrators can evaluate models, prototype applications, and deploy using a common software stack that spans the company’s CV7 and N1 SoC families through the Cooper development platform. That consistency across the product range reduces per-project engineering cost and accelerates time-to-market for partners building perception and analytics solutions. The point is broader than any single portal: agentic systems require components that have already been tested and optimized for edge deployment, so that integrators can focus on solving their customers' problems rather than rebuilding the AI pipeline from scratch. The ecosystem participants who lead the transition to agentic AI in physical security will be the ones with access to tooling that fits into their existing development and deployment processes. What comes next Physical security has searched for years for a scalable answer to personalisation Physical security has searched for years for a scalable answer to personalisation. The app store model did not provide it. Manual configuration, while functional on a per-site basis, scales poorly across large portfolios of cameras and changing operational requirements. Agentic AI offers a credible path forward because it aligns with how operators actually think. They express outcomes, not model specifications. They want systems that adapt to new requirements without repeated engineering cycles. Traditional neural networks With VLMs as the interface layer, smaller domain-specific models at the far edge, orchestration at the near edge, and disciplined verification loops throughout, personalisation can become a standard part of deployment rather than a custom project. The building blocks are now in place. Power-efficient edge AI processors can run VLMs and traditional neural networks simultaneously. Developer ecosystems are maturing to support rapid prototyping and deployment. Reference architectures for distributing intelligence across far-edge, near-edge, and cloud tiers are solidifying. For an industry that already installs vast numbers of AI-capable cameras each year, the opportunity is to make the intelligence already embedded in those endpoints genuinely usable for the people who rely on them every day.
Acquisitions are often billed as moments of bold opportunity. For senior executives and boards, these deals are about accelerating growth, unlocking synergies, and strengthening competitive advantage. But for the teams responsible for making operations run safely and smoothly — including physical security — acquisitions can feel like controlled chaos. Decisions happen without warning, details are opaque, and the ripple effects of choices made in the boardroom cascade down through every layer of the organization. Too often, physical security isn’t even in the room where those decisions happen. Beyond access control When security is treated as an afterthought — a cost center to be rationalised, rather than a strategic enabler — companies expose themselves to risks that go well beyond access control or surveillance coverage. Overlooked integration challenges can compromise the safety of people and property, slow down facility transitions, inflate budgets, and undermine everyone’s confidence in the acquisition deal itself. For seasoned physical security leaders, the imperative is clear: make your program visible, credible, and indispensable before and during acquisition conversations. That means ensuring your voice is represented. Why security visibility matters At first glance, it’s not obvious to some why physical security should rank alongside finance, IT, and legal in the M&A playbook. But consider what’s really at stake:͏ Budget accuracy: If no one accounts for system migrations, access credential re-issuance, or security subject matter expert (SME) travel during due diligence, financial forecasts will be miscalculated. Underestimating these costs by even a small percentage can throw off larger integration budgets. ͏ Technology fit: Acquirers frequently inherit access control, video, and monitoring platforms that don’t align with their standards. Without early planning, companies risk unsupported infrastructure, avoidable downtime, and duplicating expensive features. ͏ People and roles: Security staff redundancies and mismatched responsibilities are often decided hastily, surfacing operational gaps and challenges with morale. ͏ Cultural harmony: Employees at acquired companies can perceive new security measures as heavy-handed or intrusive, jeopardising adoption and compliance. Each of these factors is manageable — but only if you consider them early on in the acquisition and communicate clearly at the decision-making level. Securing a seat at the table Physical security leaders don’t need to wait passively for a seat at the M&A table — they can and should advocate for it. Take practical steps: Identify the M&A committee. This group may go by different names — corporate development team, integration steering group, or even a subcommittee of the board. Pinpoint who leads it and which executives have influence. Make the case for inclusion. Position security not as a compliance hurdle but as a value multiplier. Remind leadership that visibility into risks, costs, and integration timelines reduces surprises, accelerates business continuity, and protects reputation. Bring data, not anecdotes. Prepare a concise playbook: current-state inventories of systems and personnel, cost models for typical integration activities, and sample timelines for cutovers. When executives see that security has done its homework, they’re more likely to view the function as essential. Leverage allies. Partner with your security consultant, along with your facilities, IT, HR and risk management teams who share overlapping interests in safe, seamless operations. Unified advocacy is harder to dismiss than a single voice. By getting on the M&A committee, you ensure your concerns aren’t filtered secondhand or raised too late to influence outcomes. Leading with credibility during acquisitions Visibility is only the first step. Once in the room, security leaders must contribute with authority and clarity. Three practices stand out:͏ Translate security into business impact. Executives don’t respond to jargon about card readers or VMS licenses—they respond to risk, cost, and continuity. Frame every input in terms of: Financial implications, such as “Consolidating platforms will save $X annually, but requires $Y in upfront integration.” Operational implications, such as “Delays in credentialing will stall employee onboarding at three newly merged sites.” Cultural implications, such as “Without a clear change management plan, acquired employees may resist compliance, leading to increased insider risk.”͏ Provide scenarios, not surprises. Acquisitions move fast, but that doesn’t mean you can’t plan. Present modeled scenarios — small target vs. large target, regional vs. global integration — and their associated timelines and costs. This proactive approach demonstrates foresight and earns trust. ͏ Advocate for people, not just systems. In the scramble to integrate technology, companies often forget the human element. Use your platform to ensure that acquired security personnel are evaluated fairly, retrained where possible, and integrated into the new culture. Advocating for people strengthens morale and preserves institutional knowledge. Visibility beyond a single deal For some companies, acquisitions are rare, high-stakes events. For others, they’re a routine growth engine. In either case, physical security leaders should treat M&A as a recurring test of their strategic value. To do this, work with your security consultant to:͏ Document lessons learned from each acquisition, then institutionalise these lessons in playbooks and checklists. ͏ Develop clear security messaging that explains your team’s mission and impact, so executives understand why your presence is non-negotiable. ͏ Commit to realistic timelines for integration work, ensuring leadership sees the discipline and predictability of your function. The goal isn’t just to be consulted during one deal — it’s to become permanently visible in the company’s growth strategy. Don’t be an afterthought In the popular imagination, the “room where it happens” is a place where power dynamics shift and futures are decided. For physical security leaders, being absent from that room during an acquisition means watching others dictate the future of your program, your people, and your company’s security posture. But by proactively seeking visibility — by insisting on a voice in acquisition planning, by bringing data and credibility to the table, and by consistently framing security as a business enabler — you can transform physical security from an afterthought into a recognized pillar of successful acquisitions.
Security beat
The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel. The shocking event raised awareness in board rooms around the world about the need for, and challenges of, executive protection. Questions followed immediately, including why was the high-level executive not protected? Combination of risk and reward UnitedHealthcare’s stock price has gone down more than 20% since the shooting The event also highlighted what is at stake for companies, extending beyond the safety of executives and impacting many factors, even including a company’s stock price. UnitedHealthcare’s stock price has gone down more than 20% since the shooting, equating to tens of billions of dollars. “Companies are considering the combination of risk and reward like never before when it comes to executive protection,” says Glen Kucera, President of Allied Universal Enhanced Protection Services. “What are the chances this could happen? Before Dec. 4 many thought it was zero. And what are the financial implications for a company if it happens? Executive protection is a small investment to protect against a worst-case scenario.” Evaluation of an executive protection Before the UnitedHealthcare shooting raised awareness, fewer than 50% of executives had protection. But concerns that previously fell on deaf ears now have the full attention of companies, says Kucera. “Boards of directors are having to figure this out,” he adds. “They may not have executive protection, but now they have to do it.” A threat assessment, conducted by a company such as Allied Universal, provides an independent evaluation of a company’s executive protection needs. The assessment evaluates factors such as an executive’s travel habits, the safety of their home, etc. Does the executive need protection 24/7, or just when they travel into more dangerous areas? Risks increase related to corporate earnings Sometimes, cases increase the need for executive protection, such as an internal threat In assessing threats, security professionals also look beyond the individual to consider the safety of a corporate facility, for example. “Is there a visual deterrent, controlling who comes and goes?” asks Kucera. “If there is good security, it all ties together. We do home assessment, facility assessment, route assessment, and travel assessment as needed.” Sometimes, circumstances increase the need for executive protection, such as an internal threat. Timing is a factor, and risks increase related to corporate earnings releases, new product announcements, and corporate layoffs or consolidation. Monitoring social media tracks shifting threats that impact the need for executive protection. UnitedHealthcare shooting “He didn’t have it and probably didn’t think he needed it,” comments Kucera about the UnitedHealthcare executive who was gunned down in the streets of New York City. “He was staying at the hotel across the street and was used to walking down the street every day.” “Sometimes executives want to preserve their privacy and be able to walk down the street,” says Kucera. “Getting protection can be seen as a sign of weakness. Some CEOs in the past have said they just didn’t want it.” However, the UnitedHealthcare shooting raised the stakes of the need for more vigilance. “The bottom line is you have to yet beyond objections and make the investment to protect against a worst-case scenario,” says Kucera. Anti-capitalist sentiment in the general population An internal police bulletin warned of an online hit list naming eight executives and their salaries Threats to executives sometimes arise from anti-capitalist sentiment in the general population about perceived inequalities in wealth and power. Executives provide symbolic targets for anyone who fights the system, and social media has amplified the voices of those who oppose capitalism. For example, a "Most Wanted CEO” card deck seeks to shine a spotlight on "titans of greed." Also, in the aftermath of the UnitedHealthcare shooting, CEO "wanted" posters appeared across New York City, threatening various executives of large companies. An internal police bulletin warned of an online hit list naming eight executives and their salaries. Careful monitoring of social media posts Careful monitoring of social media posts and other sources enables executive protection professionals to analyze data and separate the dangerous threats from the merely negative ones. Sadly, positive support of the UnitedHealthcare shooting was expressed by the 300,000 or so followers of the shooter, who became a celebrity of sorts. A huge outcry of negative sentiment toward the insurance industry led to fear that copycat incidents might occur. “There has been an unprecedented amount of positive support for committing murder,” commented Kucera. Executive protection requests HR executives can be at risk, especially at a time of layoffs or consolidation “Let’s face it, there has been a lot of controversy, from COVID to the Middle East crisis, to the political campaign, and there is negativity on both sides,” says Kucera. “People have opportunities to pick sides, and there is a lot of sentiment going both ways, and there is a small percentage of people who will act aggressively.” Executive protection requests now extend beyond the CEO to include others in the management ranks of companies. Basically, any public-facing executive is at risk, including anyone who makes statements to the press. Human resource (HR) executives can be at risk, especially at a time of layoffs or consolidation. Private information on the Internet Typically, an executive is assigned a single armed operative for protection. The firearm serves primarily as a visual deterrent that hopefully makes a potential perpetrator think twice. “When they plan an event like this, their expectation is that it will be a soft target,” says Kucera. “If there is an officer, it gives them pause.” Controversial or high-profile CEOs are typically protected 24/7, including when they travel with their family. Adding risks is the fact that private information is now posted on the Internet, including where an executive lives and where their children go to school. Internet monitoring Internet monitoring also includes the “dark web,” which includes sometimes dangerous information “We offer social media monitoring, and we advise them to be more careful with what they post,” says Kucera. “We monitor reactions to posts including any that might be threatening. We watch social media carefully if a company announces earnings or a change in their service or product offering.” Internet monitoring also includes the “dark web,” which includes sometimes dangerous information that is intentionally hidden and requires specific software, configurations, or authorization to access. Own layer of protection Public and government officials can also come under fire in a variety of scenarios. FEMA officials faced threats after the recent floods in the Southeast, for example, among other situations where perceived unfair treatment promotes thoughts of retribution. Although government agencies have their own layer of protection, there are instances when they call on companies such as Allied Universal for additional help. Ad hoc protection for various executives In the aftermath of the UnitedHealthcare shooting, calls to Allied Universal’s Command Center increased by 600%, reflecting requests for ad hoc protection for various executives. These requests are in addition to the company’s business providing “embedded” operatives that travel with executives all or some of the time. On that side of the business, requests for services are up probably 300%, says Kucera.
GSX 2023 has its share of new product announcements, although many of the new products are enhancements to technologies shown at last spring’s ISC West show in Las Vegas. Booth traffic on the first day seemed busy at the Kay Bailey Hutchison Convention Center in Dallas, although one exhibitor complained that it takes some time for the traffic to make its way to the farthest areas of the show floor. Apparent throughout the GSX show is an expanding idea of what constitutes security. Increasingly, ‘security’ technologies offer benefits throughout other parts of a company or institution. Security is also being broadened to encompass ‘safety,’ including emergency response and wider issues of keeping a company safe. Managing multiple systems People look at the systems they have, and they are looking for more information" Manufacturers at GSX are talking about more than new products. Rather, they are offering new approaches to turn products into ‘solutions’ for customers. Among the benefits of new systems is the availability of more data. “People look at the systems they have, and they are looking for more information and data and insights from their systems,” says Kyle Hurt, Genetec’s Area Vice-President of Sales for the US and Canada. “In the past, if I’m managing multiple systems and spending time and resources, I am making sure systems are operational. Today, it’s more like: How do I make my enterprise more efficient? I spend less time on making sure systems are working together but more time on how we can use the information.” Manufacturers at GSX are talking about more than new products Security control room Genetec is enhancing its Security Center 5.11 version with a newly redesigned web client that provides new capabilities related to system audio, including the ability to trigger a public address from a mobile device in an emergency, two-way audio to and from the security operations center, and the ability to record an incident. The new web client offers new levels of “Security on the go,” says Hurt. A mobile device becomes an extension of the security control room. “Customers want to have more remote capabilities and have their security personnel out and about, not tied to a desk,” says Hurt. The new web client works to unify the four pillars of the Security Center— video, access control, license plate recognition, and now audio. Single source manufacturer Audio can now be used to broadcast a message, respond to an incident, and notify people" “Audio has taken time to develop legs in our ecosystem,” says Hurt. “We have been developing partnerships and use cases beyond an intercom at the door. Audio can now be used to broadcast a message, respond to an incident, and notify people en mass of what’s going on.” Manufacturers are also fine-tuning how they work to meet customers’ needs. “Customers want one point of contact, a single source manufacturer, and a solution that reflects the manufacturer is listening to the voice of the customer,” says Jerry Burhans, Managing Director of ASSA ABLOY Global Solutions - Critical Infrastructure, which seeks to be a global partner to critical infrastructure industries. The Critical Infrastructure business works across the various product groups of the notoriously siloed company to bring together solutions aimed at meeting each customer’s need. Manufacturers are also fine-tuning how they work to meet customers’ needs Best-in-class technology “We try to have best-in-class technology and collaborate within ourselves to make sure we have what customers need,” says Burhans. Critical infrastructure industries such as water, power and energy, oil and gas are developing standards to help support preparedness of the nation’s infrastructure, and ASSA ABLOY Global Solutions is helping operators secure access and provide audit trails on locking hardware and keys within their security perimeters. Managing customer assets Johnson Controls’ new OpenBlue Service for the security device market seeks to proactively manage customer assets (equipment) as a service. The company’s software platform of connected solutions monitors and manages security devices across vendors and provides remote support services including skilled engineers who can work to ensure that a company’s assets, including cameras and access control readers, operate dependably. Working remotely, OpenBlue analyzes the performance of each system component Johnson Controls estimates that, unfortunately, up to 25% of a company’s security assets may not be working as intended, whether they lack the latest firmware update or are not connected. Working remotely, OpenBlue analyzes the performance of each system component and responds to ensure equipment operates as intended. “We believe we can close that gap with our solutions,” says Greg Parker, Vice President, Innovation & Portfolio Management for Johnson Controls. Physical security equipment A big advantage of OpenBlue for security customers is the ability to manage cybersecurity and threats at the edge, which may not currently be addressed by the IT department. The OpenBlue offering includes an embedded ‘air wall,’ which is a zero-trust architecture for physical security equipment. OpenBlue also helps customers manage the ever-changing lifecycles of various assets. Another concept prompting discussion at GSX 2023 is the gap between what a customer expects from a product and what the product can realistically deliver. With endless promotion in the last several years centering on concepts such as artificial intelligence (AI), is it any wonder that customers may sometimes have unrealistic expectations about what a technology can accomplish? The good news at GSX is that, as progress marches on, newer technologies are getting closer and closer to delivering on customers’ most ambitious expectations. The forward momentum of technology development is evident throughout the GSX 2023 show floor, reflecting the promise of even greater product capabilities in months and years to come.
A pioneer in the access control sector since 1971, AMAG Technology is looking to the future and the next generation of products that will expand its services to customers. “In our vision, we have advanced approaches that will not only provide our partners with advanced technologies but also ones that are easier to install with tools to expand their services,” says David Sullivan, who was appointed President of the venerable access control company in September 2022. New challenges at AMAG Sullivan brings a new outlook to the AMAG business, a part of Allied Universal, and a new vision to lead the company into the future. We caught up with David Sullivan to discuss his new challenges at AMAG and the journey ahead as the company looks to the future. Q: How does your background inform your approach to leading AMAG? I believe that it helps me to define a vision for AMAG that will be unique and on the leading edge of our industry David Sullivan: With the exception of only a few short years, my career has been in access control. I have experience with several systems and have had the privilege to manage several successful access control companies. As a result, I bring a great deal of experience into my role at AMAG. I believe that it helps me to define a vision for AMAG that will be unique and on the leading edge of our industry. Q: How would you describe AMAG’s journey over the last several years and how do you see the future? Sullivan: Prior presidents of AMAG always shared their leadership vision and direction with senior leaders located in the United Kingdom. This had an impact on the full direction of the business, sometimes limiting its ultimate success. Before I became a part of AMAG, these senior leaders that were located in the UK retired, placing for the first time the full management responsibilities of the president. This has allowed me to integrate the business into a single team, with single objectives, and a single vision. We expect to begin to reveal this new vision in the coming weeks. We are excited about the future of AMAG and believe we will surprise the industry with our new products and approach in the coming months and years. Q: How important is it that a manufacturer provides both hardware and software solutions? How does AMAG’s approach (in general) differentiate it in the market? We can design the complete solution, providing functionality that others may find more difficult to accomplish Sullivan: Regardless of the manufacturer, we all provide hardware and software. An access control solution is not complete without both. Some of us choose to make our panels, and others do not. Those who are dependent on third-party suppliers are restricted to the developments and direction of that company, and while it might be perceived to be an open technology, it still is proprietary to the hardware manufacturer. AMAG has controlled its manufacturing of panels from day one. The result means that we can design the complete solution, providing functionality that others may find more difficult to accomplish. Q: How does the breadth of AMAG’s product suite provide advantages to customers and/or integrators? Sullivan: AMAG’s product portfolio is unique and provides the end user with an end-to-end identity management solution from one company. Our Control Room PSIM, Symmetry CONNECT Identity Management Solution, Symmetry Access Control, and Symmetry GUEST solutions all integrate to provide the user with a broad set of features and capabilities from a single provider. There is no finger-pointing when we come to support your system. We hold full responsibility for making it work and can quickly provide a resolution to any application difficulties the user may be experiencing. Q: How does AMAG address the divide between on-prem and cloud systems? How do you help customers make the transition and/or plan for the future? We are in the early stages of developing our next generation of access control in which we intend to provide on-prem Sullivan: In our current product portfolio, we have three products that are cloud-based. Our mobile credential platform (Symmetry Mobile), our visitor management solution (Symmetry GUEST), and our physical identity and access management solution (Symmetry CONNECT) are all offerings that operate in the cloud. We are in the early stages of developing our next generation of access control in which we intend to provide on-prem, web client, and cloud-based offerings. One of the primary objectives is to ensure that the large installed base of systems that are out there today will be able to migrate not only to our next generation but as well to the cloud if the client so desires. Q: What is AMAG’s approach to mobile credentialing? Sullivan: As an access control provider, adding Symmetry Mobile credentialing to our portfolio just made sense. We want our customers to have a forward-thinking solution with the opportunity to save money not only on the physical badges but the cost of printing and distributing badges. Mobile credentials can be easily issued and revoked remotely, reducing administrative overhead, and eliminating the need for physical inventory management. Organizations can centrally configure what devices are used and the read range for each type of device and operating system, thus providing flexibility. Symmetry Mobile offers a customized questionnaire that controls access and reduces liabilities. Q: What has surprised you the most in your first year or so leading AMAG? Not many companies are blessed with such a broad portfolio that is supported by a resource-rich company Sullivan: I wouldn’t say I was surprised by this as much as happy to see, but I would say that the quality of our people was a pleasant surprise. As well, the AMAG product offering is broad and has some unique elements. When coupled with the depth of the resources that we have in AMAG, I know that we are second to none. Not many companies are blessed with such a broad portfolio that is supported by a resource-rich company that has so many talented people. Q: Please describe your dealer channel, and how you are seeking to expand it. Sullivan: The AMAG products are sophisticated and typically are installed for higher-end applications. With this sophistication comes a need to be well able to install such a solution. We have a strong group of certified and loyal partners who help us to deliver these enterprise solutions. We desire to provide our existing partners with updated and competitive systems to offer to their end users. Q: What is the security industry’s (and/or AMAG’s) biggest challenge in the next five years? We need to find ways to provide both our channel partners and the customers with solutions that are easily integrated Sullivan: I believe that the advancements that we are seeing in technology provide our industry with the opportunity to truly change how security is provided to our collective customers. As we advance these solutions, we will need to do so responsibly and in a way that helps the channel’s abilities. We need to find ways to train our partners to both install and support these more complex solutions. At the same time, we need to find ways to provide both our channel partners and the customers with solutions that are easily integrated, moving away from proprietary closed systems to open and cohesive solutions. This will ensure that the users get the best, and most complete solutions. Q: What does the industry as a whole misunderstand about AMAG -- time to set the record straight! Sullivan: Well, I am not ready to openly share where we are heading. We are in the process of putting together some advanced approaches to how we will do business with our partners. We are focused on providing tools that will enhance their services to their customers, and with products that are leading edge. I can only state that all should keep their eyes on AMAG, because over the next few years, we are going to surprise some people, and more importantly make our loyal partners quite powerful.
Case studies
In a sector where budgets are always a focus of attention, delivering concrete returns to every investment is crucial. By digitalising access, healthcare premises – whether large hospitals or small clinics – can benefit from day one. They can improve staff and patient safety; quickly implement more efficient, time-saving workflows; and painlessly meet compliance demands. Healthcare sites always present complex access challenges. They must be welcoming, accessible public spaces. They often occupy large, sprawling areas; unfamiliar faces and first-time visitors are around every single day. At the same time, these premises inevitably have valuable and/or sensitive assets, including confidential data and medicines, which must be secured. Patients, doctors, nurses and support staff must feel safe. In labs and treatment suites, restricted materials and valuable equipment need both security and a compliant system for logging every access event. This has always been healthcare’s ‘business-as-usual’: it is a complex environment for any security manager. Meeting compliance demands Modern hospitals and clinics, however, now face an extra level of challenges – and opportunities. Their access system may benefit from integration with fire detection, CCTV and other building solutions, for example. With so many temporary and contract workers employed on-site, access is in constant motion. It needs to be tailored to specific and very different needs and, equally, revoked when any time-limited tasks are complete. In case of a security breach, rapid investigation is essential. Tracing and logging access to specific areas may also be a legal requirement, especially with new NIS2 regulations introduced for critical infrastructure, which demand proactive “hybrid” cyber/physical security frameworks for many healthcare premises. Relying on manual or siloed systems to complete these tasks could eat up hours or even days for security and even medical staff. Happily, there is a better way to work. Digital access devices The solution is access digitalisation. Digital access devices and credentials help to keep every hospital user safe. Unauthorized access is minimised because unapproved key copies rarely circulate and lost credentials are canceled with a click. Employees and equipment are safer because more access points may be digitally secured. Issuing contractors and temporary staff with digital or even mobile credentials can further simplify the granting, amending and revoking of site access. Security teams waste less time handing out and collecting keys. Intelligent, intuitive software helps facilities managers stay in control even while they are off-site. Logging access to specific assets or areas becomes quick and simple: a few clicks rather than the laborious process of keeping manual logs up to date. “Access is such an important part of any holistic approach to safety,” says David Moser, SVP and Head of Digital Access Solutions at ASSA ABLOY Opening Solutions EMEIA. “Digitalising access immediately puts powerful tools in the hands of hospital management, delivering tangible daily benefits to meet security challenges head-on, improving efficiency and regulatory compliance at the same time.” Implementing digital access “There’s now a device to extend existing systems with digital control at almost any access point, whatever building solution is in place. Alternatively, we can equip customers with whole solutions to implement digital access from scratch, without invasive installation. So many efficiency and security benefits are within reach.” Below are three of many real-life examples which illustrate the ways healthcare premises have benefited from digital access beyond the most obvious security and safety aspects. By choosing ASSA ABLOY’s Aperio® wireless locks, integrated natively with an ARD access management solution, Centre Hospitalier Métropole Savoie (CHMS) could issue access rights tailored to individual staff and contractors and implement real-time control, helping to boost site safety. Because Aperio locks are wireless, the hospital introduced more layers of security without incurring excessive installation or operating costs, including for sensitive offices and drug stores. Access point functionality at CHMS now includes real-time management logs and remote door opening. Real-time management logs For convenience, staff now carry one credential programmed with their individual tailored permissions. “Having just a single badge, and not having to carry around heavy keys, has been a major advantage for us,” explains Béatrice Dequidt, Health Executive at CHMS. “We have implemented internal HR management procedures, creating badges that are automatically integrated into ARD's operating software,” adds Alain Gestin, CHMS’s IT Systems Architect. Aperio and ARD maintain compatibility of credentials with the French government’s electronic Health Professional Card (CPS), for added staff and management convenience. Personalized access permissions Hospital MAZ, in Zaragoza, also implemented a new ASSA ABLOY digital solution, SMARTair®, with real-time access functionality. Their online wireless access management system saves security managers’ time because they can implement all changes via the central system in real time, without needing to waste time walking through the hospital. Staff convenience is further enhanced: they now carry a smartcard programmed with their personalized access permissions. Custom-made cards double as employee IDs, so 625 staff and approximately 100 contractors only need to carry one. Their ASSA ABLOY system is also mobile access ready, making it easy for the hospital to issue and manage mobile keys in the future without hardware changes. “Digitalisation presents opportunities for healthcare organizations of every size and type to improve security while they also reduce costs ‘hidden’ in daily workflows,” explains David Moser. Convenient secure access Managing physical keys can impact nursing care, as pharmacy managers at Queen Elizabeth Hospital, Birmingham discovered. An older, mechanical system made it difficult for them to keep track of who held the right key. Searching for that person wasted time. They identified a better solution for convenient secure access to controlled medicines: programmable keys. With their CLIQ programmable key access solution, power to digital and electromechanical locks is supplied by a standard battery inside every key, so no wires are required – making it an ideal retrofit solution for hospital doors, cabinets and mobile drug trolleys. Audit trails for locks and padlocks are available on demand: nurse managers can quickly see who has accessed cabinets or drug trolleys. Key access solution “The message from all nursing staff is that patients are getting medicines much easier and in a more timely fashion,” says Inderjit Singh, Chief Pharmacist at QE Birmingham. “For us, the key return on investment is the quality of service we’re providing.” “Our expertise in access, established over decades, enables us to work with customers to get their access ready for what’s ahead,” adds David Moser. “With ASSA ABLOY, they digitalise with confidence.”
Bournemouth and Poole College, the largest provider of further education and apprenticeships in the Dorset area, has installed Hochiki's ESP addressable fire detection range across its four-storey site, protecting a diverse mix of teaching environments including IT suites, kitchens, workshops and engineering bays. The installation was specified and delivered by SFA Fire and Security, working closely with the college to design a system capable of handling the varied fire risks found across further education provision. Subjects such as catering, automotive maintenance, construction and engineering carry a higher risk of nuisance alarms from dust and fumes, while IT and digital media spaces rely heavily on electrical equipment. A tailored approach was needed to protect the site without interrupting learning. Protecting valuable teaching time ESP's common mounting base allowed SFA's installers to work through the site using a single standard base across most devices, reducing the range of parts held on site and helping installation stay on schedule despite the complexity of the building. In kitchens and workshops, LPCB and VdS approved heat sensors were used to distinguish genuine fire risk from cooking activity and dust, reducing false alarms and protecting valuable teaching time. ESP's textual identifier gives staff the exact location of an activated device, supporting fast and accurate evacuation decisions in a large site with high footfall. Wall-mounted VADs, certified to EN 54-23, added audio and visual alerts throughout the college, ensuring alarms reach staff and students regardless of location or impairment. Where cabling access was limited by drop beams, wireless technology was integrated onto the ESP loop, avoiding extensive drilling and preserving the building's original structure. Successful projects together Naomi Fell, Projects Director at SFA Fire and Security, said: "This project presented numerous challenges due to the complexity of each room and storey within the college. Our extensive experience with Hochiki's products, combined with the consistently positive feedback from our end-users, made Hochiki the clear choice for this project. We met the college's stringent deadlines with minimal disruption to teaching and learning." Ryan Baulcomb, Regional Sales Manager at Hochiki, added: "Hochiki and SFA have a strong, long-term partnership, built on years of successful projects together. This installation shows what that partnership can deliver on a genuinely complex site. We're proud that our products continue to give installers and end-users the reliability and support they expect." Bournemouth and Poole College now benefit from a fire detection system tailored to the specific demands of each corridor, room and storey across the site, with the flexibility to adapt as the college continues to grow.
ZeroEyes, creators of the multi-analytics weapons detection and threat intelligence platform, announces that its proactive AI gun detection and intelligent situational awareness software has been renewed by Central Valley School District in Beaver County, Pennsylvania after a successful first year of deployment. Serving four schools across Beaver County, Pennsylvania, including a primary center, elementary school, middle school, and high school, the district supports approximately 2,200 students and 200 faculty and staff. ZeroEyes has been integrated across all facilities as part of the district’s commitment to maintaining a safe, secure, and welcoming learning environment. Welcoming learning environment “The safety of our students and staff will always be our top priority,” said Brian Dolph, Safety & Security Director for the Central Valley School District. “By implementing ZeroEyes technology, Central Valley School District is taking a proactive step to enhance campus security and provide real-time detection of potential firearm threats, helping ensure that our schools remain safe places for teaching, learning, and growth. ZeroEyes has been a valued partner, delivering continuous monitoring and an added level of assurance in our campus security efforts.” Central Valley School District’s deployment is part of a broader, layered approach to safety that includes closed-circuit cameras, a visitor management system, ALICE-trained staff, regular district-wide safety drills, and school resource officers in all buildings. The district also conducts coordinated active shooter drills each summer in partnership with Beaver County Emergency Services and works closely with local communities, including Monaca Borough and Central Township, to support campus safety efforts. Situational awareness software ZeroEyes’ AI gun detection and intelligent situational awareness software layers onto existing digital security cameras. If a gun is identified, images are instantly shared with the ZeroEyes Operations Center (ZOC), the industry’s only U.S.-based, fully in-house operations centre staffed 24/7/365 by specially trained U.S. military and law enforcement veterans. If the threat is determined to be valid, alerts and actionable intelligence — including visual description, gun type, and last known location — are dispatched to law enforcement and school officials, often in a matter of seconds from the moment a gun is detected. “Central Valley School District has taken a thoughtful and proactive approach to campus safety,” said Mike Lahiff, CEO and co-founder of ZeroEyes. “By continuing to invest in real-time intelligence and working closely with trusted partners, the district is strengthening its ability to respond quickly to potential threats while maintaining a safe and supportive learning environment.”
Verkada, a pioneer in physical security and operations, announces that the Miami Dolphins and Hard Rock Stadium adopted its platform to enhance fan safety and security. Hard Rock Stadium's new Verkada deployment unifies video security, access control, guest management, intercoms and alarms into a single, cloud-based platform that enables its team to streamline security operations at the scale and speed that the 65,585-seat venue demands. "As a world-class venue hosting global events year-round, we prioritise solutions that align with the scale and pace of our operations," said Sameer Istafa, Chief Technology Officer for the Miami Dolphins and Hard Rock Stadium. "Verkada's unified platform provides a seamless, connected operating environment that supports our focus on delivering a consistent, elevated experience for our fans at every event." Resource-intensive maintenance costs Verkada's unified platform gives Hard Rock Stadium's team: Faster response during high-pressure moments. Activity-based detection and intelligent alerts provide teams with greater visibility into activity across Hard Rock Stadium, enabling faster, more informed responses when needed. Proactive perimeter coverage. Advanced detection tools enable Hard Rock Stadium to take a proactive approach to monitoring the stadium's exterior and surrounding areas, flagging unusual activity before it escalates. Streamlined access across a large campus. Verkada's cloud-managed access credentials replace physical keys and disconnected badge systems. With all door events logged, Verkada's platform can flag anomalies. Flexibility across a wide range of events. In addition to the Miami Dolphins, Hard Rock Stadium hosts college football games, concerts, and other global events – and each event has a different footprint and different security needs. Verkada enables the Hard Rock Stadium team to tailor protocols event-by-event without new infrastructure. Lower infrastructure costs. Moving onto Verkada's cloud-based platform is expected to save Hard Rock Stadium on time- and resource-intensive maintenance costs, with new features delivered automatically through software updates. Insight into operational efficiency. Visual intelligence from Verkada's platform provides insight into occupancy trends that can enable operations teams to reduce bottlenecks and adjust staffing in real-time. World-class experience "Hard Rock Stadium can swing from hundreds of employees and vendors on a weekday to more than 65,000 fans in a matter of hours," said Filip Kaliszan, co-founder and CEO of Verkada. "Verkada is built to handle this kind of complexity, with one unified platform that keeps pace with an operation that never stays still. We're proud to provide solutions that help keep fans, athletes and entertainers who visit Hard Rock Stadium safe – and to give the team behind these legendary events the tools they need to keep delivering a world-class experience." Video security infrastructure Hard Rock Stadium worked with Castaway Technology and Security (CTS) to support its Verkada deployment and implementation across the campus. CTS used Verkada's Command Connector to bring Hard Rock Stadium's existing video security infrastructure into the new platform during the migration period, ensuring a smooth transition and letting security teams work from Verkada's platform from day one. "Hard Rock Stadium is a marquee venue that demands a security infrastructure to match. Our goal was to help them transition to a more agile and integrated ecosystem. With Verkada, we were able to deliver a truly end-to-end solution that eliminates technical friction, allowing the security team to focus entirely on maintaining a safe, premier experience for every fan," said Craig Bruce, co-founder at CTS.
Evolv Technologies Holdings, Inc., a security technology company pioneering AI-based solutions designed to create safer experiences, announces that Evolv Express®, the company’s people-screening system, has been selected as a security partner in Northwestern University’s new Ryan Field following a rigorous evaluation process. As Ryan Sports Development prepares to open the first NFL-type stadium in college sports, they evaluated available screening solutions before selecting Evolv Express to help deliver an elevated fan security experience. Evolv Express uses advanced sensor technology and AI to detect concealed threats and identify the location of the potential threat while allowing people to move through checkpoints at their natural walking pace. Advanced sensor technology The New Ryan Field, in the final stages of construction, will have a capacity of 35,000 fans when it opens on October 2nd with a nationally televised game. In addition to Northwestern football games, New Ryan Field will also host other athletic and community events throughout the year. The project is designed to set a new standard for the college football experience and boasts several features and innovations fitting its ambitious vision, including the Evolv Express security systems. The multi-year agreement between Evolv and Ryan Sports Development includes a variety of marketing elements and designates Evolv as Northwestern University’s “Official Fan Screening Provider.” Exceptional arrival experience “Our goal for the New Ryan Field is simple: build the best place to watch football in America,” said Pat Ryan Jr., CEO of Ryan Sports Development. “That ambition covers not only the event itself, but also the entire time that a fan is on site. We built a stadium designed to represent the future of college athletics, and so much more, and we rigorously evaluated available screening technologies and selected Evolv Express because it aligned with our goals of delivering a secure, convenient, and exceptional arrival experience.” “When an institution invests in creating what it believes will be the premier college football venue in the country, every decision matters, including the first impression fans receive when they arrive,” said John Kedzierski, President and CEO of Evolv Technology. Ambitious stadium projects “Northwestern had the opportunity to evaluate the industry’s leading screening solutions as part of this landmark project, and we are honored that Evolv Express was selected to help deliver the elevated fan experience Ryan Field is designed to provide. It’s a testament to the strength of our technology that one of the most ambitious stadium projects in college sports chose Evolv to help welcome fans through its gates.” The New Ryan Field at Northwestern is another signature deployment on Evolv’s growing roster of higher education customers, as well as numerous stadiums, arenas, theme parks, schools, hospitals and other public spaces around the world.
ZeroEyes, creators of the multi-analytics weapons detection and threat intelligence platform, announces that its AI gun detection and intelligent situational awareness platform has been deployed by Kansas’ Bonner Springs–Edwardsville USD 204 to protect students and faculty against gun-related violence. USD 204 serves more than 2,400 PreK–12 students with 455 staff members across a network of schools in the suburban communities of Kansas City, Bonner Springs, and Edwardsville, including one high school, one middle school, three elementary schools, and two pre-K buildings. ZeroEyes complements the district’s multilayered security plan, which also includes school resource officers (SROs), secured entrances, and close, ongoing collaboration with local law enforcement agencies across all three communities. Situational awareness platform The district secured funding through the Kansas Safe and Secure Firearm Detection Grant Program, administered by the Office of the Kansas Attorney General, to purchase and implement ZeroEyes. “Ensuring the safety of our students and staff is at the core of everything we do,” said Lisa Terrell, Director of Education Foundation & Counseling Services. “The deployment of ZeroEyes is a natural extension of our district’s proactive, layered approach to security, enhancing the strong foundation we’ve built through trusted partnerships with local law enforcement, secure facilities, and dedicated personnel.” Digital security cameras ZeroEyes' AI gun detection and intelligent situational awareness software layers onto existing digital security cameras. If a gun is identified, images are instantly shared with the ZeroEyes Operations Center (ZOC), the industry's only U.S.-based, fully in-house operation centre, which is staffed 24/7/365 by specially trained U.S. military and law enforcement veterans. If these experts determine the threat is valid, they dispatch alerts and actionable intelligence — including visual description, gun type, and last known location — to law enforcement and local security teams, often in a matter of seconds from the moment a gun is detected. “Thanks to the Office of the Kansas Attorney General, we can provide an added level of confidence for USD 204’s families and community with ZeroEyes,” said Mike Lahiff, CEO and co-founder of ZeroEyes. “It's great to see the district reinforce its commitment to creating a safe, supportive environment where every student can thrive.”


Round table discussion
At mid-year 2026, the broader economy tells a story of resilience under pressure. Conflict in the Middle East has triggered a shock to the energy supply, driving oil prices up and reigniting global inflation. However, a total downturn has been averted. Exceptional, historic levels of business investment and data center construction are providing a firm floor for growth, offsetting cooler consumer spending and keeping labor markets fundamentally stable. But how are changing economics impacting the physical security market? We asked our Expert Panel Roundtable: How do changes in the broader economic climate impact physical security?
College campuses are meant to be places of learning, growth, and community. Fostering such an environment requires the deployment of policies and technologies that ensure safety and security. Considering the growing role of security technology in the higher education market, we asked this week’s Expert Panel Roundtable: What are the new applications for security technology in the college and university markets?
There is safety in numbers, or so the expression goes. Generally speaking, several employees working together tend to be safer than a single employee working alone. Even so, some environments require that workers complete their jobs alone, thus presenting a unique combination of security vulnerabilities. The U.S. Occupational Safety and Health Administration (OSHA) defines a lone worker as “an employee working alone, such as in a confined space or isolated location.” We asked this week’s Expert Panel Roundtable: How can security technologies help to protect "lone workers?"
Products


