Security access systems
Evolv Technologies Holdings, Inc., a foremost security technology company pioneering AI-based solutions designed to create safer experiences, today announced its partnership with Stern Grove Festival, the oldest nonprofit music festival in the country, providing free performances in San Francisco for over 88 years. Evolv Express® weapons detection systems have been installed and were operational in time for the festival’s opening weekend on June 15, 2025. The systems are placed a...
Traditional security models protected a perimeter like a castle moat, assuming anyone inside was safe. Zero trust removes that implicit trust entirely, recognizing that threats can exist both outside and inside a facility. Zero trust is a routine and accepted concept in cybersecurity. Given the importance of information technology and the increasing convergence of physical and logical security, the tenet is becoming a dominant principle in physical security, too. We asked our Expert Panel Roundt...
By delivering digital keys directly into Apple Wallet, guests can lock or unlock room doors via iPhone and Apple Watch, elevating the access experience for the hospitality industry. Salto hospitality smart access solutions now support room key in Apple Wallet for iPhone and Apple Watch users. This represents the next evolution in room key convenience, security, and operational efficiency for hotels and guests alike. Smart access management platform This solution integrates seamlessly into a h...
iDenfy, a global provider of identity verification, fraud prevention, and various compliance-focused solutions, has launched a major update to its Know Your Business (KYB), or Business Verification, platform by introducing a Dynamic KYB Workflow feature. This new functionality will help companies automatically direct other company representatives who need to complete the onboarding into the most suitable KYB workflow based on their responses, and in this way, help businesses scale the KYB onboa...
NEXCOM will participate in the National Restaurant Association Show 2026 (NRA Show), held at McCormick Place in Chicago, where it will present smart application solutions for the restaurant and foodservice industry. By integrating edge computing and odor-sensing technology, NEXCOM aims to help foodservice operators enhance food safety, operational efficiency, and customer experience. NRA Show 2026 As a globally recognized benchmark exhibition for commercial technologies and foodservice...
Zimperium, the world pioneer in mobile security, outlined its new AI-empowered mobile security vision, including the availability of two new AI-powered agents that provide a force multiplier in the battle to harden the mobile attack surface. Globally, cybercriminals have moved to a mobile-first attack strategy, weaponizing AI coupled with highly sophisticated social engineering campaigns. The result is that mobile apps and devices now represent the most vulnerable attack surface in most organiz...
News
Organizations of every size and type have already discovered the security and convenience benefits of a CLIQ digital key access management system. Now, new CLIQ Readers and Updaters for indoor and outdoor use make extending the scope and reach of a CLIQ solution even simpler, including to third-party digital access devices. It takes CLIQ to new openings more easily than ever before. New additions These new additions to the CLIQ family are compatible with fully electronic eCLIQ and electromechanical PROTEC2 CLIQ solutions. They simplify both secure unlocking and the transfer of access updates to CLIQ keys. With new CLIQ Readers, all the keyholder needs to do is insert their key and wait for visual confirmation from its inbuilt LED – they do not even turn it, which minimizes key wear-and-tear. The Updater incorporates the same intuitive LEDs as CLIQ Wall Programming Devices (PDs) – informing the keyholder about update and key battery status. Fully integrated “The new CLIQ Readers are the first readers which are fully integrated with the CLIQ system,” explains Ralf Stange, Product Manager at ASSA ABLOY. “Managing access is simple because the software treats a Reader just like a cylinder. The new Updater makes it easier and more cost-efficient to add secure credential updating protocols to outside spaces.” A fast, reliable new Reader, inside or outdoors The CLIQ Reader is compatible with everything an organization needs to manage access more flexibly: with CLIQ Web Manager and Local Manager; with the CLIQ Go mobile solution for small businesses; and with the full range of CLIQ programmable keys. The Reader itself offers customized setup options to suit individual needs. Switch delay may be set between 1 and 10 seconds, with a choice of activation on key insertion or on removal. An optional remote relay unit can add an extra layer of security. Installing and connecting a Reader can put a CLIQ system in control of user access to doors with electric strikes or motorized locks, automatic revolving doors or sliding glass doors, lift priority and more. In addition, the Outdoor Reader model packs all this convenient functionality into a durable stainless-steel housing designed for exterior use. With certified protection against water, dust (IP65), and vandalism (IK09), it extends CLIQ’s use-cases reliably to external barriers, gates, turnstiles and other entrances. Secure outdoor credential management with a new Updater Another new addition to the device range, the CLIQ Updater provides a secure way to add CLIQ key updates outside a building. Because connecting the Updater does not require a network cable, the device is fast and secure to install even on retrofit projects. The Updater is simply linked via RS485 cable to an existing CLIQ Wall PD (Gen 2), up to 200 metres away, with no need for network configuration. All security-related elements remain in the building interior. When connected to a Wall PD featuring a free output switch function (FO1), the Updater can activate third-party devices such as electric strikes. For installation convenience, all CLIQ Readers and Updaters come in a choice of flush and surface-mounted configurations to suit the specific application. The Outdoor Reader and Updater are also available as e-modules for seamless, integration with steles, tableaus, and outdoor intercom systems, including ASSA ABLOY’s DoorBird solution. Secuting homes and businesses “With these new additions to the CLIQ device range, facility managers can implement even more comprehensive and flexible access protocols,” adds Ralf Stange. “And like every CLIQ product, they are backed by decades of ASSA ABLOY investment and innovations in lock and key technologies to secure homes and businesses.”
ULTRALOQ, a best-selling smart lock brand under Xthings, a global pioneer in AIoT solutions, announced that several of its smart lock models have achieved certification for Aliro, a new open industry standard developed under the Connectivity Standards Alliance (CSA) that enables secure digital keys stored directly in smartphone wallets. The certification spans a variety of deadbolt and latch style smart locks, offering intelligent and convenient access control solutions for homeowners, property managers, and hospitality operators. These locks enable a consistent tap-to-unlock experience across supported smartphone platforms. Different platforms, different approach For homeowners, Aliro means unlocking a front door with the same tap used for payments or transit passes, with no separate app required. For property managers, facility operators, and hospitality companies, it means digital keys can be issued, updated, and revoked centrally across multiple doors and properties, using credential infrastructure already built into the smartphones residents and guests carry every day. With Aliro-enabled smart locks, users can unlock doors using compatible mobile wallet experiences, including those supported by platforms like Samsung Wallet, eliminating the need for separate lock applications or physical keys. Access control "Samsung Wallet is designed to act as a digital hub for users' belongings (payment cards, IDs, car keys, etc.). The integration with Samsung Wallet through Aliro-certified ULTRALOQ smart locks is part of this customer experience. Now, Samsung Wallet customers can activate the easy tap-to-unlock feature for convenient home access control," said Junho Hyun, Head of Wallet BD2 Group, Samsung Electronics. Features and functions Unlike proprietary smart lock ecosystems that require residents, hospitality guests, or staff to download and manage dedicated apps, Aliro-certified locks from ULTRALOQ integrate directly with wallet platforms users already have on their phones, reducing friction for operators and end users alike. In addition to Aliro certification, upcoming ULTRALOQ smart locks are also Matter-certified, enabling seamless integration across leading smart home ecosystems. Together, Matter and Aliro represent complementary layers of the connected experience. Matter ensures devices work across platforms, while Aliro enables a consistent, convenient and secure way to access them using digital keys. A universal key "With Aliro, the smartphone is becoming the universal key to the physical world," said Raj Sundar, Sr. Director of Product Management at Xthings. "What makes this shift meaningful is not just the technology, but the experience - a simple tap to unlock that works the same way across mobile devices from many different brands, while also making it easy to share and manage access." With Aliro certification, ULTRALOQ joins the first wave of smart lock manufacturers helping bring this next generation of digital access to homes and buildings worldwide. Availability Aliro-enabled ULTRALOQ smart locks will be available through ultraloq.com, select retail partners and authorized security and smart home integrators. Commercial and multifamily property operators interested in deploying Aliro-certified access control at scale should contact Xthings directly.
SwiftConnect, the provider of the connected access network for places and spaces, announced that JLL, a foremost global commercial real estate services firm, has standardized on SwiftConnect's connected access network platform to deliver mobile wallet access across its corporate offices and the assets it manages, enabling employees and building occupiers to use mobile credentials in NFC wallets in place of physical badges. Challenges faced by JLL led to SwiftConnect The successful pilot at its 20 Water Street headquarters in London solved core challenges faced by JLL: managing disparate access control systems across its global corporate footprint and integrating its own access control with base building landlord systems, a common complexity in multi-tenanted buildings. The SwiftConnect platform unified JLL's different access control systems into a single pass stored in employees digital NFC wallet, using HID Signo™ readers and HID Seos® credential technology, so that employees can access both base building entrances and JLL office spaces with one credential on their smartphone or wearable device. As a result, the rollout kicked off a phased expansion at JLL’s new flagship UK headquarters and prompted JLL to use SwiftConnect’s connected access network to automate its global security approach around integrating multiple systems into a single digital access pass. Delivering physical security "JLL Spark recognized early on how fragmented the access control landscape was and how traditional access methods were ill-equipped to meet the growing need for frictionless, and on-demand office access, whether at a single location or a portfolio of buildings,” said Daniel Correa, Growth Principal at JLL Spark. “Our investment in SwiftConnect years ago was driven by this clear gap between how enterprises manage physical identity and access. Fast forward to today, our decision to deploy the company’s platform across JLL offices and managed assets is a natural expression of our confidence in what SwiftConnect delivers." Areas of deployment The SwiftConnect mobile access deployment delivers across three areas: Unified mobile credentials and systems enable a single digital pass in NFC wallets on mobile devices, spanning two access control systems for effortless Street-to-Seat® access. Automated, self-service badge provisioning reduces administrative time and accelerated onboarding for new employees. Centralized access management connects JLL’s global offices, delivering operational efficiencies, cost savings, and a best-in-class experience for tenants and guests. Growing momentum "JLL's decision to deploy our connected access network across their own portfolio is the kind of validation that speaks for itself,” said Chip Kruger, Co-CEO at SwiftConnect. “It reflects the growing momentum SwiftConnect is experiencing across the UK and European market for a truly unified approach to access, irrespective of the existing physical security infrastructure." Mobile access deployments Moving ahead, SwiftConnect is also scaling mobile access deployments for JLL as asset manager for its property owner clients. JLL currently manages a number of other buildings where SwiftConnect has implemented mobile access, including an ongoing deployment to 10,000 users this year.
Award-winning global security manufacturer, Gallagher Security is preparing for a strong return to The Security Event (TSE) 2026 in Birmingham later this month, bringing a wave of new solutions, an expanded European presence, and a continued focus on meaningful industry connection. Taking place at the NEC from 28-30 April (stand 5/F90), the event will provide a platform for Gallagher to demonstrate how its latest innovations are helping organizations unlock more while navigating an increasingly complex and connected security landscape. Key opportunity Executive Vice President – Europe, Spencer Marshall, says TSE remains a key opportunity to engage directly with the people shaping the industry. “TSE is a significant moment for us each year. It’s where we come together with our Channel Partners and End Users to share ideas, showcase innovation, and better understand the challenges organizations are facing on the ground. With new solutions ready to be unveiled, we’re excited to lead the conversation again in 2026.” Increasing connections Notably, Gallagher Security Chief Executive Mark Junge will attend The Security Event joining the team on the ground across the three days. Mark says the event represents an important opportunity to connect directly with the European market and wider industry. “This will be my first time attending TSE, and I’m looking forward to experiencing firsthand the energy and innovation that defines this event,” he says. “We have experienced significant growth in Europe over the past year, including opening a dedicated office in Stockholm, so opportunities like this to connect with our growing network of Channel Partners, End Users, and industry peers are incredibly valuable.” Mark also shares a glimpse of what can be expected on the Gallagher stand. “A key highlight of the event will be the European debut of AccessNow, our latest innovation that streamlines and automates access requests,” he says. Products on showcase A cloud-native platform, AccessNow is designed to automate how access is requested, approved, and provisioned; freeing security teams from administrative burden and giving End Users instant, self-serve access to the spaces they need. Also on the stand will be Gallagher’s OneLink, a cloud-based solution that makes it faster, easier and more cost-effective to deploy powerful security anywhere in the world, alongside QuickSwitch, Gallagher’s disruptive, cost-effective migration solution that simplifies the transition from legacy systems to Gallagher’s advanced access control technology. Bringing innovations to life The Gallagher booth will feature five solution pods designed to bring its innovations to life. Visitors can explore its cloud solutions, AccessNow and OneLink, discover Gallagher’s perimeter security offering, and see its QuickSwitch migration capabilities in action. A dedicated integration space will showcase how Gallagher solutions connect with leading technology partners, including Kenai, Hanwha, Milestone, Barox, and Idemia, highlighting the strength and flexibility of its broader security ecosystem. Panel sessions Gallagher Security European Marketing Manager, Bethan Thompson, shares Gallagher will be taking part in a panel session alongside Channel Partner Advancis, contributing to discussions on integrated incident management for real-world security challenges. “We also look forward to hosting our 2025 Channel Partner award winners for a celebratory dinner during the event. TSE is an excellent opportunity to show appreciation to our partners which is incredibly important to us,” she says. Gallagher Security will be exhibiting at The Security Event, 28–30 April at stand 5/F90 at the NEC Birmingham.
Reflecting on two decades of leadership and impact, Mark Junge, Chief Executive at Gallagher Security, says it was the company’s culture and people that first drew him in and what has kept him there ever since. “Our strong culture naturally flows through to performance,” he says. “And today, the caliber of people we’re continuing to attract into the business is incredibly high, it’s something I’m really proud of.” Leadership experience Since joining Gallagher in 2006, Mark has held a range of leadership roles spanning procurement, supply chain, global operations, and general management before being appointed Chief Executive of Security in 2023. During this time, he has played a key role in driving the company’s global growth. "We’ve more than doubled the size of the business since 2021 and five times since 2015, and we continue to invest heavily back into product and R&D to support long-term growth." Impact on the industry Reflecting on Gallagher’s impact on the industry, Mark points out that “The credibility that we’ve built around high security, particularly through innovations like PIV in the United States and our Type 1A solutions, has elevated our reputation globally. We have a strong reputation in high-security and high-compliance environments, but we’re also seeing great success across a wide range of verticals including government, health, education, manufacturing, distribution, and data centers." Mark also highlights the deeper purpose behind the security industry. “It’s an incredibly rewarding industry to be part of,” he says. “The human impact of keeping people safe, knowing they’ll get home to their families safely, that their assets are protected, that’s huge. When our solutions are part of mitigating serious incidents, it reinforces the responsibility we carry and makes me incredibly proud of what we do.” Global expansion As Gallagher continues its rapid global expansion, Mark says it’s the combination of growth, innovation, and people that excites him most about the future. “We’re growing quickly, bringing on incredible talent, andexpanding into new regions. That diversity of thought and skillset is making a real difference,” he says. “At the same time, preserving the culture that comes with family ownership allows us to take a long-term view, which is which is incredibly important to me - and to the ongoing success of the business.” He adds that his connection to the business remains as strong as ever. “When we talk about our growth and what we’re achieving as a team, I still get that proud feeling in my chest. It’s something I’ve genuinely enjoyed being part of, and I’m looking forward to continuing that journey well into the future.” Tribute towards the contribution Kahl Betham, Chief Executive Officer & Executive Director of Gallagher Group, paid tribute to Mark’s contribution. “Mark’s leadership has been instrumental in shaping the success of our security business. His commitment to our people, our partners, and our long-term vision has helped drive Gallagher’s growth globally. We are incredibly proud to celebrate this milestone with him and look forward to what the future holds under his leadership.” Throughout his career, Mark has remained committed to a customer-centric philosophy. "Strong, steady growth and long-term investment have always been our model,” Mark says. That’s what best supports our customers and gives them the confidence to partner with us in the long term."
dormakaba announces strong order intake in the healthcare sector in fiscal year 2025/26. In line with dormakaba’s go-to-market strategy, the company has secured several projects across Norway, Germany, and the US, allowing the company to strengthen its healthcare vertical. dormakaba delivers solutions for doors, including locks, door hardware, door automation, access control, and mechanical locking systems. The combined total order volume is in the low double-digit million range (CHF). Multiple project details In Norway, the South-Eastern Norway Regional Health Authority has awarded dormakaba a contract with a scope that includes more than 5,500 doors. The contract is part of the New Aker hospital project, one of the largest construction projects in the Norwegian healthcare sector, with completion scheduled for 2031. Also, in Germany, dormakaba has secured a multi-site order with the m&i-Klinikgruppe Enzensberg. The project includes more than 4,500 doors to support advanced access control across several rehabilitation centers. In addition, the tender requires the system to align with the European Union’s NIS2 cybersecurity requirements. In the US, dormakaba’s New York Entrance Systems team has secured strategic partnerships with two major healthcare systems in New York. The agreements include service and refurbishment of entrance systems and expand into a broader collaboration around security, access control, and ongoing support. This strengthens dormakaba’s position as a trusted partner to the US healthcare sector. Growing demand for innovative access solutions Till Reuter, CEO of dormakaba, says: “Demand for our solutions in the healthcare sector is high, and our business is gaining momentum. These recent project wins demonstrate the growing demand for secure, efficient, and innovative access solutions. We are proud to support leading healthcare providers as their trusted partner. These orders further reinforce our position in the healthcare market and support our ongoing growth in this sector.”


Expert commentary
The healthcare infrastructure is ever evolving. Facilities are no longer single entities for one, they are sprawling ecosystems that serve a wide range of users, from medical staff and administrators to vulnerable patients, visitors and maintenance personnel. Safeguarding their safety and security, while providing seamless operation is a complex challenge - one frequently solved by access control. Use of access control Today’s security solutions play a central role in protecting people and mitigating risk across much of our built environment. An appropriately specified system is effective at regulating, monitoring and restricting entry and exits, and allows users to navigate an integrated network and its hardware to ensure the right access is provided to the right person at the right time. In healthcare buildings, the use of access control expands further, whereby a system can tackle a host of unique operational challenges - significantly contributing to fire safety, ease of movement and the theft prevention of equipment, medicine and sensitive patient data, and all while protecting human life and preserving privacy and dignity. In healthcare buildings, the use of access control expands. In doing so, access control can become the cornerstone of functionality, compliance and organization in any healthcare environment. Though, as the complexity of projects deepen, decision makers are reminded that coordination is key. Preparing and empowering users Between January and March 2025, there were over 832,000 patient safety events recorded in the NHS. While each of these events may not be directly linked to building security specifically, the healthcare industry is faced with a considerable number of safety incidents, which suggests greater monitoring and mitigation is needed across the board. Access control often provides staff with the vital means of retaining control without impeding care Patient well-being and security will always remain paramount in the sector, and access control often provides staff with the necessary means of retaining control without impeding care. Hospitals for example, sustain a high level of footfall across large campuses with multiple points of entry and on-site patient record systems, presenting a number of simultaneous security tests as a result. Though, unlike other public buildings, where rigid security measures are active at all times, many healthcare environments must strike a balance throughout their security framework to meet a host of one-of-a-kind demands. Use of access credentials With a continuous influx of patients, staff and visitors, healthcare groups are habitually required to remain accessible and inviting around the clock. At the same time, they must also be prepared to deter unwanted visitors in areas of restricted access and lock down intensive wards to ensure patients remain safe and secure under periods of monitoring. For this, the use of access credentials is critical and provides a regulated system for sensitive staff-controlled areas such as pharmacies, wards, and server rooms. By applying role, zone, or schedule-based access, decision makers can authorize personnel seamlessly, empowering facilities to manage patient care without compromising security in the process. Use of access credentials is critical and provides a regulated system for staff. Implementation of AI-powered tools and devices Modern systems may incorporate the use of keycards, biometric scanners, and mobile credentials When it comes to the operation of these systems, training gaps are a concern, however. Over the five years up to February 2025, numbers of NHS doctors rose by 26%, with nurses also up 25%, and this influx of new staff requires education towards the usage of access control. Modern systems may incorporate the use of keycards, biometric scanners, mobile credentials and in some cases, voice-activation, with the implementation of AI-powered tools and devices set to play a more prevalent role in the future. Each system presents its own benefits and may be better suited to certain projects and areas, but without consultation and proper user education, they can instead become a barrier. Strategy, scalability, performance To alleviate these operational threats, early-stage planning is fundamental. Just as end-user education and training should be built into project timelines, it’s important to consider the growing need for cooperation throughout the entire supply chain of an access control project. A collaborative approach becomes even more critical when innovative solutions enter the market All too often, a lack of evidence-based decision making can hinder the specification of a scheme and its accompanying hardware, whereby choices are made without understanding long-term performance or compliance requirements. Whether approaching a new or retrofit development, ongoing communication allows experts to come together and ensure that product decisions are aligned with the buildings intended use and user base. This collaborative approach becomes even more critical when innovative solutions enter the market and new sector challenges arise. Latest access control products With this in mind, trusted manufacturers will no longer simply deliver the latest access control products, but will aim to work alongside the architects, specifiers, contractors, and facility managers at each stage of the building’s lifecycle to ensure touchpoints are addressed. This is crucial in modern healthcare environments, where the added layer of complexity requires tailored security measures. One area that is often neglected is scalability, for example. As healthcare facilities manage fluctuating patient numbers and a growing level of patient data, along with new regulations, systems must be adaptable and allow for ongoing improvements and updates to the security infrastructure without the need for a complete overhaul. By adopting a scalable system that combines technology integration with ease of use, decision makers can future-proof their building’s security. Manufacturers will no longer simply deliver the latest access control products Complexity of the healthcare industry In truth, access control has become more than a means of restricting access. Modern systems are more equipped than ever before to deliver environments that support care, safety, and operational excellence. Nonetheless, the complexity of the healthcare industry and its buildings demands more than product innovation - it requires an industry-wide commitment to collaboration, from project conception to product installation and beyond.
The sheer volume of smart locks, lock management systems, connected readers and an increasing array of Internet of Things (IoT) devices complicates the issuance and management of certificates that are foundational to establishing trust between a device and the credential used to access it. That’s why more companies are turning to PKIaaS for IoT devices. But there’s another reason to consider PKIaaS: the rise of quantum computing. Secure digital communications Gartner predicts that the pace of quantum computing will render asymmetric cryptography systems PKI certificates form the backbone of secure digital communications, but Gartner predicts that the pace of quantum computing will render asymmetric cryptography systems unsafe by 2029 and could render all current cryptography unsafe by 2034. As with any software implementation, there are pitfalls to avoid, including vendors that use proprietary technology that’s incompatible with other systems and “gotcha” pricing tactics where a slight increase in certificate usage triggers a massive increase in pricing. However, the time to implement PKIaaS is now. Physical security faces growing cyber threats Although ransomware attacks directly on computing infrastructure dominate business headlines, physical security systems are also under threat. An HID survey of over 1,200 security professionals, end-users and executives shows that 75% reported threats to their physical security systems in the past year, as these systems are more tightly integrated with company IT networks. Until recently, most physical access control systems (PACS) were proprietary and worked only on the specific systems they were designed to interact with. However, the movement toward open supervised device protocol (OSDP) revolutionized the field, allowing companies to integrate and control devices from different vendors while improving compatibility and security. PACS and IoT devices PKIaaS makes sense as the number of digital certificates needed to power PACS and IoT devices As a result, 40% of companies plan to either update or change access control systems in the next year, with 21% emphasizing the need for open standards like OSDP to both improve interoperability and future-proof their systems. When asked about reasons for a proposed upgrade, more than half cited convenience, while another 40% sought to improve their overall security posture. PKIaaS makes sense as the number of digital certificates needed to power PACS and IoT devices continues to increase, promoting security and reducing manual processes related to tracking certificates. Regulatory compliance demands automation and agility Companies also face increased regulatory pressures regarding technology in general — and certificates in particular. The European Union’s Cyber Resilience Act sets mandatory cybersecurity standards for manufacturers and retailers, covering the planning, design, development and maintenance of products throughout the entire value chain. Certain high-risk products must undergo third-party evaluation by an authorized body before being approved for sale in the EU. EU Cybersecurity Act shows a unified certificate framework for ICT products, services, and processes More specifically, the EU Cybersecurity Act establishes a unified certification framework for information and communications technology (ICT) products, services, and processes. Businesses operating in the EU will benefit from a “certify once, recognized everywhere” approach, meaning that approved ICT offerings will be accepted across all EU member states. Given the global nature of PACS, these regulations likely will impact companies well beyond the EU, much like the general data protection regulation on websites has. These changes, when considered together with rapid advancements in quantum computing, underscore the need for a unified certification solution such as PKIaaS to handle increased — and increasingly complex — certificate compliance. A path to PKI modernization Modernizing PKI through a PKIaaS model doesn’t have to be difficult. With a clear and phased approach, most organizations can transition smoothly while reducing risk and improving efficiency. It starts with a quick assessment of current certificate usage to understand where certificates are issued, how they’re renewed and any gaps in coverage. From there, it's about defining what you need and selecting a trusted partner. Look for a solution that integrates well with your existing systems, supports automation and scales as your needs grow. In terms of partners, not all PKIaaS vendors are the same. Look for one with a strong security track record and predictable pricing, which will simplify both onboarding and long-term management. When it comes to vetting vendors, ask the following questions: Is the solution scalable? The trend toward future-proof installations has never been greater. As the number of certificates increases, any PKIaaS solution must be able to grow in concert. How will pricing change as certificate volume grows? Some solutions are priced in tiers by the number of certificates. If a company exceeds that maximum by even a single certificate, it owes not only the price difference between tiers, but it will also be expected to pay for that tier the following year, which can bring a significant financial surprise. How are CAs accessed and stored? Look for companies that can provide long-term offline secure storage of certificates that can also track when CA keys are accessed. What support is included in the PKIaaS? Specifically ask vendors about up-front costs for implementation and onboarding to get a real apples-to-apples comparison among partners. Step-by-step replacement of manual processes A pragmatic approach allows corps to move quickly and confidently from legacy PKI to a scalable Once a vendor in place, start with a focused rollout, e.g., automating certificate renewals for internal systems or a specific business unit. Once the pilot is complete, expand automation with a step-by-step replacement of manual processes to limit operational disruptions. Finally, as PKIaaS becomes embedded in day-to-day operations, it’s important to align it with broader security governance. Establishing regular reporting and clear policies, as well as future-proofing for quantum-safe cryptography to ensure long-term resilience and compliance without adding complexity. This phased, pragmatic approach allows organizations to move quickly and confidently from legacy PKI to a scalable, secure and future-ready solution. A necessary upgrade According to an analyst report, manual certificate management can cost organizations up to $2.5 million annually in labor and outage-related expenses. While automation reduces these costs by up to 65%, the real challenge in IoT environments lies in managing scale. With device lifecycles often spanning decades and certificate volumes reaching millions — especially across distributed, resource-constrained endpoints — manual PKI processes and legacy infrastructure simply can't keep up. The convergence of regulatory mandates, quantum computing threats and rising cyber risks to connected physical systems makes scalable, cloud-based PKIaaS not just a strategic advantage, but a foundational requirement for secure IoT deployments.
In today’s world, almost any electronic security system holds the potential to become a gateway for cybercriminals. With physical security and cybersecurity increasingly entwined, security professionals aren’t doing their job unless they take all possible precautions to lock down unauthorized access to camera systems, access control platforms, intercoms, and other network-based security devices and solutions. Let’s explore the many steps companies should take throughout their security technologies’ lifecycle – from choosing a vendor all the way through device decommissioning – to avoid making the common mistakes that leave systems, and the networks they reside on, vulnerable to attack and sabotage. Prepurchase Phase: Laying the Groundwork for Cybersecurity 1. Conduct a Vendor Risk Assessment IT departments often rely on the same Vendor Risk Assessment criteria they use for evaluating IT equipment manufacturers when considering the suitability of physical security vendors. While commonalities exist between how to assess these disparate solutions, there are also differences that require distinct scrutiny. For example, device endpoints within physical security systems run on custom Linux Kernels and therefore do not utilize standard Linux distributions like Red Hat, Ubuntu, or Debian. IT divisions often rely on the same Vendor Risk Assessment criteria they use for evaluating IT kit A comprehensive evaluation should examine how each security solutions manufacturer handles its software development life cycles. Ideally, vendors should adhere to a recognized framework when developing both their platform management and device-specific software. In 2021, Executive Order 14028 made it a bit easier for companies to evaluate vendors by providing guidelines for evaluating software security, the practices of the software developer, and methods to demonstrate conformance with secure practices, specifically referencing the NIST SP 800-218 Secure Software Development Framework. In short, a good vendor should have documentation that explains everything it’s doing to address cybersecurity from development, through releases and ongoing maintenance. 2. Obtain Software Update Schedules The frequency with which manufacturers update their software varies. Each company is different. If you’re their customer, it shouldn't matter whether the vendor schedules updates every six months, three months, or more often than that. What does matter is that you know what to expect and have a plan for how to deal with that reality. For example, if updates only occur every six months, under what conditions are patches released to address vulnerabilities that emerge between updates? Customers must understand how often they'll be updating the software on their devices and ensure they have the resources to make it happen. Make sure stakeholders agree, upfront, who will be performing the software updates. Will it be the integrator who installed the system, the physical security system staff, the IT team, or the end user? Keeping an entire system current is a huge challenge, but a non-negotiable responsibility. Manufacturers who don't issue frequent releases and patches put the onus on customers to handle mitigation efforts on their own. In these instances, IT departments must be prepared to employ network segmentation, firewalls, security whitelists/blacklists, and other methods to protect their systems until a patch is released. If a company's security team has typically updated firmware only when something breaks, these additional responsibilities most likely require greater collaboration with IT departments and a shift in how security systems are managed. 3. Know the Warranty Terms and Duration of Software Support Organizations should understand the warranty policies for the devices they purchase Organizations should understand the warranty policies for the devices they purchase. Even more important is knowing when a device's software support will expire. Software support should extend well beyond hardware coverage. For example, if a camera has a five-year hardware warranty, customers should reasonably expect an additional five years of software support. When that period ends, companies must plan on replacing the device – even if it still works well. Without software updates, the device lacks vulnerability support and becomes too risky to remain on the network. Manufacturers should be transparent about their warranty and software support policies, helping organizations plan for device replacements that align with cybersecurity needs. 4. Request a Software Bill of Materials (SBOM) During the pre-discovery process, customers should request a Software Bill of Materials (SBOM) that provides a detailed inventory of the software running on each device, including open-source components. By revealing what software is "under the hood," the SBOM allows IT departments to be vigilant in protecting the company's systems from exposed vulnerabilities. For example, a customer should understand how Transport Layer Security (TLS) is being handled to secure a security solution's web server if it’s an open-source component like OpenSSL. 5. Assess Vulnerability Disclosure Practices CNA manufacturers represent the gold standard in cybersecurity practices Understanding how a manufacturer handles vulnerabilities is essential. Ideally, they should be a Certified Naming Authority (CAN) and report common vulnerabilities and exposures (CVEs) to national vulnerability databases such as NIST and MITRE. Doing so automatically includes any disclosed vulnerabilities associated with their devices in vulnerability scanners' databases. CNA manufacturers represent the gold standard in cybersecurity practices, but most security manufacturers do not reach this level. At a minimum, the vendors you choose to work with should have an email notification system in place to alert customers to new vulnerabilities. Remember – email notifications are only as reliable as the employees managing them, so investigate whether the manufacturer has a strong track record of keeping up with such communications. Ask to speak with customer references who have been using the solution for an extended period to ensure the vendor is diligent in its communications. Configuration Phase: Ensuring a Secure Setup 1. Use Hardening Guides Once a device is purchased, configuring it securely is the next critical step. Manufacturers should publish hardening guides that detail the security controls available for their products and recommended practices for implementation. Between the features offered by the vendor and your company's own cybersecurity policies, make sure all possible encryption options are activated. Using HTTPS is vital for ensuring secure communication with devices. Many physical security devices default to HTTP to accommodate customer-specific network topologies and certificate management. Failing to implement HTTPS can leave sensitive metadata unencrypted and vulnerable to interception. 2. Consider Advanced Encryption Protocols Protocols are necessary to protect video data in transit from cameras to the VMS Some solutions offer built-in encryption protocols, like MACsec, which makes it impossible for data to be compromised as it is transmitted over the network. HTTPS is still necessary to secure the connection to the devices’ webservice, but while customers set up and configure their devices, MACsec will keep network data safe. Additionally, if you want to encrypt video streams, consider protocols such as Secure Real-Time Transport Protocol (SRTP), which secures the transmission of audio and video data over the Internet, or tunneling methods like Secure Socket Tunneling Protocol (SSTP), which encapsulate data packets for safe transmission between two points, even if the network is insecure. Such protocols are necessary to protect video data in transit from cameras to the Video Management System (VMS). Encryption should also extend to the VMS hard drive where video is stored. There are different methodologies to do that, but ultimately the goal is to encrypt data in transit and in storage. 3. Implement Remote Syslog In the case of a breach, each device maintains a set of logs that are useful for forensic investigations. However, if a device gets hacked, its log may not be accessible. Best practices dictate that companies should set up a remote Syslog server that maintains a copy of all device logs within a central repository. In addition to providing redundant data for investigations, a Syslog offers IT systems an efficient way to look for anomalies. Cybersecurity teams will receive immediate notification for events like unsuccessful login attempts so they can quickly figure out what's happening. Who is trying to log in? Why on that particular device? 4. Practice Healthy Password Hygiene Ideally, organizations should move towards using Active Directory or Single Sign-On (SSO) solutions One of the most basic and yet overlooked aspects of cybersecurity is the failure to manage user accounts meticulously. Many organizations use the same username and password for all security devices because it's simply too cumbersome to manage a network of devices in which each requires a separate, unique login. It's assumed that the system's primary administrators are the only ones who know the universal password. However, the system becomes vulnerable if anyone within this select group leaves the company and the password isn't changed or deleted right away. Ideally, organizations should move towards using Active Directory or Single Sign-On (SSO) solutions. This approach ensures that employees throughout a company are each assigned a unique login credential that they use for any systems they use throughout the organization. When they leave, their passwords and access are universally terminated along with their accounts. If SSO is not an option, regular password changes and prompt account deactivation are critical. Decommissioning Phase: Securely Retiring Devices At some point, physical security devices will reach the end of their useful life. When that time comes, companies must take care in how they dispose of their devices. A good vendor will provide guidance on how to clear memory chipsets and restore factory defaults. Improper decommissioning can lead to severe risks. For example, if an improperly decommissioned device is sold on the secondary market or retrieved from a dumpster, an attacker could gain access to sensitive network configurations and use this information for malicious purposes. Conclusion Deploying physical security solutions involves more than just securing buildings and assets; it also requires robust measures to protect against cybersecurity threats. From assessing vendors and understanding update policies to configuring devices securely and managing decommissioning processes, each step presents potential pitfalls that, if overlooked, could expose organizations to significant risks. By incorporating the techniques discussed into their deployment protocols, organizations can ensure their physical security solutions provide comprehensive physical and digital protection.
Security beat
AI has the potential to enhance the usability of traditionally complex access control and physical security systems. The application of AI (artificial intelligence) within access control is still relatively new, but rapid advancements in generative AI are already transforming how security systems operate. acre security is driving the deployment of generative AI in access control through its acquisition of REKS earlier this year. REKS is a purpose-built generative AI solution designed specifically for acre’s access control platform. Unlike generic AI tools, REKS understands both system and security-specific terminology, allowing users to ask natural-language questions like, “Show me all access denied events at a specific location,” and receive instant results. AI workflows and AI agents “We're starting to see how AI workflows and AI agents, that leverage language models, can potentially be used in conjunction with access control to create new, automated processes around false alarm reduction, system configuration, report generation, data analysis, threat detection, and in-system customer support,” says Adam Groom, Director of Business Development, AI Development Team, acre security. “We expect AI-driven capabilities to evolve rapidly, but the full range of benefits will depend on continued development and real-world application,” he adds. Integrate AI-driven capabilities acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions The best way to think of REKS is as an acre access control expert you can talk to, says Groom. “As AI adoption grows in security, REKS will expand its capabilities, making access control more usable and more efficient.” Groom says acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions the company as a pioneer in next-generation physical security. “These features will add long-term value by enhancing usability and operational insights across various segments,” says Groom. “Work is already under way to incorporate REKS into acre access control, and we’ll evaluate other integration opportunities in the future.” REKS' AI capabilities According to acre, REKS simplifies daily operations, automating routine tasks, and delivering real-time, actionable intelligence. With REKS' AI capabilities, users can interact with the system to retrieve more detailed insights and actionable information from their acre access control system. “This eliminates the need for complex reports, navigating drop-down menus, or manually reviewing logs,” says Groom. “It significantly enhances efficiency and usability for security professionals.” Enhancing productivity and customer satisfaction Key concern is ensuring that system configuration, enactment, and servicing remain within their scope For integrators, the key concern is ensuring that system configuration, implementation, and servicing remain within their scope of expertise. With REKS, that doesn’t change — but the process becomes significantly faster and more efficient. Instead of manually configuring every panel, input, and output — a traditionally time-consuming task — REKS enables integrators to use natural language commands to streamline setup and adjustments, says Groom. This eliminates tedious steps and dramatically improves operational efficiency, allowing integrators to deploy and fine-tune systems with greater speed and accuracy, ultimately enhancing both productivity and customer satisfaction, he adds. Cloud-enabled ecosystems “We are committed to helping organizations modernize their security infrastructure by transitioning from legacy systems to cloud-enabled ecosystems at their own pace — ensuring minimal disruption while maximizing value,” says Groom. “By integrating AI-driven capabilities, we enhance usability and deliver deeper operational insights across all segments.” “Security’s future isn’t about forcing change — it’s about empowering choice,” adds Groom. “Whether staying on-prem, migrating to the cloud, or adopting a hybrid model, we plan to provide a seamless, zero-disruption transition, prioritizing interoperability, automation, and security at every stage.” Generic AI tools AI must be purpose-built for security applications because security demands precision, reliability, and context-aware decision-making, which only focused AI offerings like REKS bring to the table, says Groom. In contrast, generic AI tools, like ChatGPT, are designed to perform a wide variety of tasks, like how humans can learn and do many different things. Instead, purpose-built AI is built to do just one specific function. “REKS adds specially designed artificial intelligence to our access control solutions to enhance both intelligence gathering and the user experience,” says Groom. New applications in access control The integration of generative AI into acre's access control platforms and their broader portfolio A new AI development team will lead AI initiatives at acre, driving the integration of generative AI into acre's access control platforms and their broader portfolio. This team will seek to push boundaries in applying AI to new applications in access control, intrusion detection, and beyond, empowering security professionals to interact with their systems in a smarter, more intuitive way. But don’t worry, AI will not take the human element out of security entirely. AI human capabilities “The reality is that AI will improve upon human capabilities because it is a versatile tool that supports and strengthens security operations, not a replacement for human decision-making,” comments Groom. “It helps operators process large amounts of data quickly and detect patterns that might be missed otherwise.” Rather than removing the human element, AI allows security teams to work more efficiently by automating repetitive tasks and providing actionable data, enabling professionals to focus on critical responsibilities.
Active shooter situations grab the most attention, but there is a long list of other threats facing schools, including bullying, vandalism and emergency medical situations. Broadly speaking, a comprehensive approach to school security should prioritize prevention, preparedness and response to all threats. Holistic security approach “Fostering a culture of safety within a school, which involves strong relationships, trust, and communication, is highly effective and does not require significant costs,” says Christin Kinman, End User Sales Consultant with Allegion, a security manufacturer. “It is crucial to educate stakeholders about the unintended consequences of quick fixes, like barricade devices, to ensure informed decision-making and a holistic security approach. The goal should be to promote safety and security for all, every day, in every situation.” Integrated and successful security plans While this might solve a particular challenge, it can also create unintentional conflicts" "Creating an integrated security plan requires a multi-faceted approach," says Kinman. "Too often, security measures are implemented as a reaction to either an event or a specific vulnerability. While this might solve a particular challenge, it can also create unintentional conflicts," adds Kinman. “Creating a successful security plan involves a comprehensive approach,” she says. “An effective, systematic approach begins with assessing, identifying, and valuing assets, identifying threats and vulnerabilities, quantifying the impact of a loss, analysis, and prioritization, and finally, development of mitigation measures.” Safety and Security An effective resource is the Partner Alliance for Safer Schools (PASS), which provides a framework to help with school assessments, including identifying and valuing assets, identifying external threats and internal vulnerabilities, assessing the impact of loss, and analyzing and prioritizing mitigation measures. Safety and security are words used seemingly interchangeably when it comes to schools, but they mean different things. “How we define these terms influences planning and addressing challenges,” says Kinman. “It is easiest to think of these terms as being either external or internal to the individual.” Coordinated security Safety is internal to the individual and relates to the individual’s perception of being free from harm Security is external to the individual and encompasses the protective physical, emotional, and environmental measures implemented in conjunction with policies, procedures, and training, as well as mental health measures and social and emotional learning. Safety is internal to the individual and relates to the individual’s perception of being free from harm or danger. Coordinated security measures create an environment of safety. Four main elements of physical security Kinman lists four main elements of physical security, often referred to as the 4D’s. These elements are deter, detect, delay, and deny: Deter refers to measures implemented to prevent an attack or threat from happening. These are usually visual deterrents that communicate legitimate use. Detect refers to measures that can detect the presence of a threat, such as video surveillance and monitoring. Delay refers to measures that slow down an attack or increase the level of effort needed for an incident to occur. Finally, deny refers to measures that prevent or restrict access to valued assets. Four layers of ground perimeter A layered approach to school security creates “layers” that must be defeated for an event to occur, says Kinman. Typically, the four layers are the ground perimeter, the private grounds around the building, the building perimeter, and the building interior. The ground perimeter layer demarcates public vs private space, and deterrence is the primary objective. The grounds layer allows for identification of legitimate vs illegitimate users and detection is the primary objective. The building perimeter layer prevents illicit users’ intent on harm from gaining access. The primary objectives at this layer are delay/deny. The building interior protects the most valuable assets, and the denial of an unauthorized individual is the primary objective. Report on Indicators of School Crime and Safety The second element is impact, also rated on a scale of 1-5 and ranging from negligible to catastrophic “Quantifying loss and assessing risk is one of the most important steps in creating an integrated security plan,” says Kinman, who explains that the two elements that guide this step are probability and impact. Probability is the likelihood that an event will occur, typically rated on a scale of 1-5 ranging from rare to almost certain. The second element is impact, also rated on a scale of 1-5 and ranging from negligible to catastrophic. “Probability multiplied by impact equals risk, which has a score ranging from 1-25,” says Kinman. “The higher the score, the higher the risk.” An analysis of vulnerabilities and threats using a matrix yields a systematic approach to prioritize improvements and identify mitigation measures. For statistics on crime and safety in schools, visit the Report on Indicators of School Crime and Safety: 2022. Security improvements “The costs of school security encompass various aspects, including physical measures, personnel, training and policy enforcement,” says Kinman. “While there is no fixed amount, it often involves investments in technology, such as access control and emergency response systems. Many security improvements do not require additional funding, like training staff and students on security protocols and implementing policies to create a culture of safety.” Generally, funding for public school security is a shared responsibility among federal, state, and local governments; communities also contribute. “Striking a balance between shared responsibility and ensuring adequate resources is crucial for effective school security,” says Kinman. K-12 school security Community members and parents can donate by being vigilant and noting any suspect activities Various stakeholders play crucial roles in enhancing K-12 school security in addition to schools and communities. Stakeholders include community members, parents, local government, local law enforcement, first responders, and non-profit organizations. “Engaging these stakeholders fosters a comprehensive approach to school security,” says Kinman. Community members and parents can contribute by being vigilant and reporting any suspicious activities. Local government can support schools with funding and resources, while local law enforcement and first responders can provide expertise, conduct drills, and establish emergency response protocols. Safe and secure learning environment In addition, non-profit organizations can offer valuable resources, training, and support programs to address specific security concerns. “By involving all these stakeholders, schools can tap into a diverse range of expertise, resources and perspectives, pioneering to a more effective and comprehensive approach to school security,” says Kinman. “Collaboration and communication among these entities are vital to ensure a safe and secure learning environment for students and staff.”
Companies at GSX 2023 emphasized new ways that technologies such as artificial intelligence (AI) and the cloud can address long-standing issues in the security market. Among the exhibitors at the event in Dallas were companies seeking creative ways to apply technology, lower costs, and make the world a safer place. Reflecting on the exhibition, here are some additional takeaways. Expanding AI at the edge i-PRO is a company reflecting the continued expansion of edge AI capability in the security market. Today, more than half of the company’s lineup supports AI at the edge so the customer has a wide choice of form factors when seeking to leverage the feature set. AI processing relay, extended warranty i-PRO is increasing their warranty period from 5 to 7 years, which could be a lifetime warranty in some cases I-PRO also has an “AI processing relay” device that accepts non-AI video streams and applies edge analytics. AI has progressed from a high-end technology to a feature available in a variety of cameras at different price points. i-PRO is also increasing its warranty period from 5 to 7 years, which could be a lifetime warranty in some cases depending on a customer’s refresh schedule and lifecycle management. Active Guard, MonitorCast The company’s video management system (Video Insight) is continuing to build new features including “Active Guard,” an integrated metadata sorter. Their access control platform, MonitorCast, is a Mercury-based solution that is tightly integrated with Video Insight. Their embedded recorders now have PoE built in. “We can move at a faster pace to fill out our product line since leaving Panasonic,” says Adam Lowenstein, Director of Product Management. “We can focus our business on adapting to the market.” Emphasis on retail and other verticals Shoplifting is a timely issue, and retail is a vertical market that got a lot of attention at GSX 2023. “We see a lot of retailers who are primarily interested in protecting employee safety, but also assets,” says Brandon Davito, Verkada’s SVP of Product and Operations. “Shrinkage is a CEO-level priority.” “Retailers are getting more engaged with security posture, instead of letting perpetrators walk,” Davito adds. Intrusion detection Verkada has an intrusion product that will notify a central station if there is an alarm On the alarm side, Verkada has an intrusion product that will notify a central station if there is an alarm, and operators can review videos to confirm the alarm. Other capabilities seeking to discourage trespassers include sirens, strobes, and “talkdown” capabilities. International expansion Verkada continues to expand internationally with 16 offices in all, including Sydney, Tokyo, and London. The core value proposition is to enable customers to manage their onsite infrastructure more simply, including new elements such as PTZ cameras, intercoms, and visitor management. Verkada emphasizes ease of use, including a mobile application to allow access to be managed across the user base. Forging partnerships “We are committed to the channel and industry, and we continue to build relationships and expand our reach,” says Davito. Among the industry relationships is a new partnership with Convergint, which was hinted at during the show and announced later the same day. They are also expanding their partnerships with Schlage, Allegion, and ASSA ABLOY. Working with other verticals They offer new features for K -12 schools, and a new alarm platform is easier to deploy and manage Verkada has also found success across multiple other verticals, notably healthcare, where they integrate with an electronic medical records system. They offer new features for K-12 schools, and a new alarm platform is easier to deploy and manage. They are integrating wireless locks to secure interior doors in schools, looking to secure the perimeter, and installing guest management systems. Transitioning the Mid-Market to the Cloud Salient is squarely focused on the “mid-market,” a large swath of systems somewhere between small businesses and enterprise-level systems. Pure cloud systems are not as attractive to this market, which has a built-out infrastructure of on-premise systems. Adding a camera to an existing system is easier and less expensive than tying it to the cloud. Benefits of cloud It’s a market that may not be ready for pure cloud, but there are benefits to be realized from adding a cloud element to existing systems. “We are continuing to augment our premise-based solutions with added cloud capabilities and flexibility,” says Sanjay Challa, Salient’s Chief Product Officer. The feedback Salient hears from their customers is “I want to own my data.” The hybrid cloud approach offers the right mix of control, flexibility, and unit economics. Cloud add-on capabilities We want to provide the flexibility for customers to go full-cloud as it becomes more economically attractive" Cloud add-on capabilities include bringing more intelligence about system operation to the user via the cloud. Over time, Salient expects to sell more cloud-centric offerings based on feedback from integrators and customers. “We want to provide the flexibility for customers to go full-cloud as it becomes more economically attractive over time,” says Challa. Vaidio AI technology Salient seeks to be a transition pioneer to help customers realize the path to the cloud. Their approach is “crawl, walk, run,” and helping customers make the transition at each stage. Salient has added AI to its product offering, incorporating Vaidio AI technology from IronYun into a powerful suite and broad array of on-premise analytics, which are gaining traction. The seamless approach makes it easy for customers to embrace AI analytics, although Salient remains broadly committed to open systems. Addressing ‘Soft’ Features for Integrators AMAG is in the process of enhancing its product line with the next generation of access control panels. However, “product” is just part of the new developments at AMAG. In addition to “hard” features (such as products), the company is looking to improve its “soft” features, too; that is, how they work with the integrator channel. Integrator channel Rebuilding a process to make your organization more efficient, is relatively easy; it just takes a lot of persistence" “We have the depth of our legacy customer base we can learn from, we just need to close the feedback loop quicker,” says Kyle Gordon, AMAG’s Executive Vice President of Global Sales, Marketing, and commercial Excellence, who acknowledges the value of reinstating face-to-face meetings after COVID. “We are laser-focused on nurturing our integrator channel,” he says. “Developing new features takes time, but rebuilding a process to make your organization more efficient, that’s relatively easy; it just takes a lot of persistence,” says Gordon. More cohesive internal communication is another useful tool, he says. Disrupting the cloud based on price Wasabi is working to make cloud applications less expensive by offering a “disruptive” price on cloud storage, $6.99 per terabyte per month (80% less than hyperscalers). Contending “hyperscalers” like AWS are charging too much for cloud storage, Wasabi is using its own intellectual property and server equipment co-located in data centers around the world. Wasabi sells “hot cloud storage,” which refers to the fact that they only have one tier of storage and data is always accessible. In contrast, a company such as AWS might charge an “egress fee” for access to data stored in a “colder” tier. Cloud storage “We saw that several video surveillance companies had not yet adopted cloud storage, and we saw an opportunity to make it easy to use,” said Drew Schlussel, Wasabi’s Senior Director of Product Marketing. “We just install a little bit of software that allows them to store data in the cloud and bring it back from the cloud.” Performance, protection (cybersecurity), and price Wasabi works with integrators, resellers, and distributors and also integrates with VMS companies Wasabi works with integrators, resellers, and distributors and also integrates with VMS companies such as Genetec and Milestone. Emphasizing performance, protection (cybersecurity), and price, their data centers are certified to SOC 2 and ISO 27001 standards. Faster throughput for weapons detection Xtract One is a young company focusing on weapons detection in a time of accelerated concern about gun issues post-COVID. Founded in Canada and based on technology developed at McMaster University, Xtract One has found a niche in providing weapons detection at stadiums and arenas. These customers already have budgets, and it is easy to shift the money to a newer, faster technology. Madison Square Garden in New York City is among its customers. Cost savings solution Xtract One can increase throughput to 30 to 50 people per entrance per minute (compared to 5 to 6 people per minute when using metal detectors). The solution doesn’t require anyone to empty their pockets and the system alarms on items beyond guns and knives. Using Xtract One allows customers to reduce the number of screening lanes and security staff, providing additional cost savings, all while getting fans through the screening process in half the time. Purpose-built sensors The system uses purpose-built sensors looking for specific characteristics, such as reflective and density properties In addition to stadiums and arenas, Xtract One, formerly Patriot One, is also getting “inbound” interest from schools, hospitals, manufacturers, and other verticals that makeup 50% of their business. “We’re on a rocket ride, mainly because the weapons issues are not going away,” says Peter Evans, CEO and Director at Xtract One. The system uses purpose-built sensors looking for specific characteristics, such as reflective and density properties, all correlated by an AI engine. Providing early warning of violence ZeroEyes is another company focused on weapons detection. Their AI gun detection system works with video images to identify if someone is “brandishing” (carrying) a weapon. In other words, the system does not detect concealed weapons. Identifying someone carrying a weapon provides early warning of a possible violent act. Increased response with AI-enables images Images are identified by AI and sent to a monitoring center where a human confirms the image before contacting first responders. Knowing the location of a shooter enables staff to lock entry points, move people to safety, and direct first responders. The company was founded to leverage existing camera views to stop mass shootings and gun violence by reducing response times.
Case studies
The Community Builders (TCB) is a nonprofit organization whose mission is to build and sustain strong communities where all people can thrive. They work with businesses, institutions, and public officials to revitalize neighborhoods in ways where all people can live in healthy homes with equitable access to resources and opportunities to pursue their dreams. Their partnership with Salient Systems exemplifies the use of video technology in vulnerable neighborhoods to help achieve these goals. Challenge TCB operates and manages 150 sites and properties across the country, employing over 600 staff members. These locations range from campus environments to individual buildings, each presenting unique security challenges to ensure overall resident safety. The primary focus for implementing a video management system is not only to ensure safety and security but also prevent property maintenance issues. Under Joe Giggey’s leadership as senior director of Information Technology, TCB established enterprise- level security standards. These standards enabled access to video remotely through smartphones, iPads, and laptops for a central team of sites in 30 cities. Additionally, seamless integration with existing cameras and access control systems was required, considering TCB’s extensive network of 30+ access control systems and about 6,800 different camera models. Affordability was another crucial factor, as is often the case for nonprofit organizations. Having an easy-to-administer VMS, reliable search and video export functionalities, scalability for future property acquisitions, and centralized management in a distributed environment were also significant requirements. Solution Salient’s CompleteView VMS met all the specified criteria, marking the beginning of the partnership between TCB and Salient in 2016. The deployment of CompleteView has grown to 85 site recording servers and over 2,300 camera licenses. Given the widespread nature of TCB’s properties, certified regionalized integrators have been selected to install CompleteView across TCB locations. These integrators have been trained and received certification from Salient Systems professional trainers on installation, executing upgrades, expanding systems, and customizing the deployment ensuring effective implementation and ongoing support. In addition, manufacturer support by Salient’s own System Engineering team has been utilized and according to TCB personnel, “has been phenomenal.” Results TCB staff help address complaints, educate residents on lease rules, and avoid evictions. Salient’s CompleteView has assisted in resolving disputes, and investigating incidents. In addition, the ability to verify details of incidents in progress helps pinpoint the location and gives first responders details about the situation they may face on arrival. Video footage provided by Salient’s VMS, CompleteView has proven invaluable in multiple instances and according to Giggey “The VMS paid for itself immediately, highlighting the effectiveness and value of this partnership.” The collaboration between TCB and Salient Systems has become an exemplar of how technology can be harnessed for the greater good, building trust and effecting positive changes in vulnerable neighborhoods. With ongoing support from Salient Systems, TCB is committed to making a lasting impact and ensuring strong communities where all people can thrive.
A leading K-12 school district in the southeastern United States, recognized for its excellence in education, innovation, and community engagement, faced the growing challenge of keeping students and faculty safe while managing a complex video infrastructure. To maintain its high standards for safety and modernization, they turned to Arcules cloud-based Video Surveillance as a Service (VSaaS). The result is a flexible, scalable foundation that enhances visibility, strengthens cybersecurity, and simplifies daily operations. With hundreds of cameras deployed across multiple campuses, the district now manages its video infrastructure more efficiently than ever before. Challenge: Growing district, growing demands The district’s on-premises video systems were aging, difficult to maintain, and expensive to upgrade. The addition of planned new schools and expanding facilities created greater coverage requirements that their existing technology could not meet. Administrators needed a secure, cost-efficient solution that could scale quickly, reduce maintenance time, and improve access for security staff across multiple campuses. They wanted a platform that could evolve with their needs, provide reliable visibility during emergencies, and ensure consistent performance with limited local IT resources. The system also had to align with cybersecurity and data privacy requirements while supporting the schools’ long-term digital transformation strategy. By modernizing through the cloud, administrators saw an opportunity to standardize technology across campuses and free IT staff from constant system upkeep. Solution: Modernizing security through the cloud After evaluating several options, the district selected the Arcules cloud-based VSaaS platform to replace its legacy systems. Built on Google Cloud, Arcules provides centralized monitoring, automatic updates, and strong cybersecurity protections. The subscription-based model turned large capital investments into predictable operating costs, allowing the district to expand video coverage as new schools were added, without the expense of physical servers or extensive reconfiguration. The transition also simplified security management, turning what was once a patchwork of local systems into one cohesive, always-up-to-date network, accessible from anywhere. Results: Safer campuses, simplified management The new Arcules VSaaS system gives security teams the ability to monitor all campuses from a single, intuitive interface. Real-time video access improves situational awareness and speeds up investigations. Automated updates reduce IT workload, while the cloud-based structure ensures consistent performance and uptime. With improved accessibility and lower maintenance demands, the district has gained a more reliable and cost-effective solution that supports its goal of creating safer learning environments. This success demonstrates how modern, cloud-connected infrastructure can strengthen campus safety while reducing the IT burden — a vital combination for growing school districts.
The multi-national Retail and Consumer organization was concerned about their lack of awareness regarding potential threats. Securitas tailored solution significantly enhanced their confidence and decision-making capabilities, providing them with a competitive advantage and assurance in critical business decisions. The challenge The multi-national Retail and Consumer organization, with stores in major cities worldwide, including a diverse tenant and occupant environment, was concerned about their lack of awareness regarding potential threats to their people, properties, third parties and brand reputation. They had limited interaction with authorities, and the information they received was often outdated, irrelevant or lacking in analysis needed to guide security decisions effectively. The complex nature of their locations further complicated matters. Limited engagement with authorities meant they may have missed out on crucial information about emerging threats. As a result, decision-makers may have struggled to respond effectively to security challenges, potentially leading to disruptions in operations, safety incidents and other negative impacts. It was vital for thier client to address these challenges promptly and proactively to protect their people, assets and reputation. The solution In response to the challenge, Securitas implemented a tailored intelligence service for thier client, leveraging advanced technology and expert insights. This service included: Real-time monitoring of threats and incidents, operating 24/7 throughout the year. Instant alerting systems to promptly notify responders and decision-makers of early warning indicators and any unfolding incidents. Regular Daily Updates to provide ongoing assurance and maintain situational awareness. Monthly Intelligence Summaries (INTSUMs) offering management a strategic overview of incidents, threats and risks, coupled with in-depth analysis of the security landscape. Additionally, Securitas offered a Request For Intelligence (RFI) service, delivering specific intelligence outputs such as reports and investigations, along with intensified monitoring during major events to ensure comprehensive security coverage. The result This tailored solution has significantly enhanced thier client's confidence and decision-making capabilities, providing them with a competitive advantage and assurance in critical business decisions, while maximizing their security and resilience. Through Securitas Risk Intelligence Services, they received advance notification of potential threats, allowing them to proactively mitigate disruptions, safeguard staff and customers, and minimize reputational impact. In the event of an incident, Securitas facilitated effective incident and crisis management, enabling swift response and recovery. Moreover, understanding of their threats supported comprehensive security risk management, empowering them to address priority risks effectively. By integrating cutting-edge technology and intelligence expertise with Securitas’ six protective services, Securitas delivered an industry-leading intelligence-led security service. With improved security and reduced business interruptions, thier client could focus on core operations, enjoying added value and peace of mind.
Securitas discovered serious threats aimed at a top executive of a global corporation, both in their professional and personal life. Addressing these challenges requires urgent and proactive measures to safeguard both the executive and the organization from harm. The challenge Securitas discovered serious threats aimed at a top executive of a global corporation, both in their professional and personal life. These threats put their work and home life in jeopardy. What's more, Securitas found signs that the culprits were planning to take action during a crucial business period to cause maximum disruption. Adding to the complexity, Securitas uncovered an insider threat perspective, meaning the culprits could exploit someone with insider knowledge and access to harm the executive and the entire organization. The threats targeting the executive client posed serious risks - safety concerns for themselves and loved ones, damage to their reputation and that of the organization, and disruption of crucial business operations and a major announcement. Addressing these challenges requires urgent and proactive measures to safeguard both the executive and the organization from harm. The solution Securitas swiftly notified their client and promptly launched an extensive assessment into the threat. Additionally, Securitas provided Protective Intelligence services, conducting a comprehensive defensive screening assessment for the Executive, identifying potential vulnerabilities that could be exploited by threat actors. Utilizing the insights gleaned from these investigations, Securitas collaborated with their protective services to fortify the principal's safety and safeguard the organization from disruption. The measures included: Bolstering security protocols to safeguard the Executive's professional and personal information. Implementing continuous monitoring of the Executive's online presence and activities for any red flags. Strengthening executive protection measures, such as providing escorts and regular check-ins. Offering lone worker solutions equipped with alarm and tracking functionalities. Enhancing operational security by disseminating threat briefings, including indicators and warnings, to relevant personnel. Coordinating with authorities as necessary to address the threat effectively. Conducting awareness communications to educate key stakeholders on personal threats, workplace violence and insider threats and risks. The result Through the effective integration of intelligence-driven security measures and Securitas' renowned protective services, the collaborative efforts with this client yielded profound results, offering unparalleled protection to the Executive during a critical business phase. This approach not only ensured the safety and well-being of the principal but also instilled a sense of reassurance and confidence throughout the organization. By leveraging cutting-edge intelligence capabilities, Securitas proactively identified and mitigated potential threats, thereby safeguarding the Executive's interests and preserving operational continuity during a pivotal business period. This comprehensive strategy not only mitigated immediate threats and associated risks but also established a robust framework for ongoing security resilience. In essence, the successful implementation of their solution epitomizes the transformative impact of intelligence-led security, fostering a culture of proactive risk management and instilling a sense of confidence in their client's ability to navigate challenges effectively.
A valued Securitas client expressed concern about threatening and abusive behavior targeting their organization and staff members. They turned to Securitas for assistance in investigating and addressing the threat. The challenge A valued Securitas client expressed concern about threatening and abusive behavior targeting their organization and staff members. They recognized the significant potential risks involved: without prompt intervention, this behavior could escalate, endangering employees, customers and assets, causing physical harm, property damage and business disruptions. As they approached a peak business period, any security breach could lead to financial losses, reputational damage and missed opportunities. Moreover, the psychological impact on employees facing such threats could harm morale, productivity and company culture. Urgent action and effective security measures were essential to mitigate these risks. They turned to the us for assistance in investigating and addressing the threat. The solution To address the challenge, Securitas implemented a multifaceted approach: POI Investigation: Securitas conducted a thorough investigation into the intent, capability and opportunities of the individuals involved. Defensive Screening: Securitas analyzed the digital footprint and vulnerabilities of the company executives to fortify defenses against potential threats & provided one to one feedback to those individuals on how to remain safe both online and in public. Threat Assessment: Securitas also performed a comprehensive assessment of the threat landscape, providing actionable recommendations to mitigate risks. Ongoing Monitoring: Continuous monitoring was established to stay vigilant against evolving threats. Intelligence-led Executive Protection: Intelligence-driven strategies were applied to provide their client specialized protection for their Executives, tailored to their unique needs and circumstances. The result By leveraging cutting-edge intelligence capabilities, Securitas were able to assess the threat landscape of the individual executives within the organization. Delivering feedback and training the team not only provided them assurance and peace of mind but also assurance to their family members. Securitas ensured they were safe when traveling proactively identified and mitigated potential threats, thereby safeguarding the Executive's interests and preserving operational continuity during a pivotal business period. This comprehensive strategy not only mitigated immediate threats and associated risks but also established a robust framework for ongoing security resilience. In essence, the successful implementation of their solution epitomises the transformative impact of intelligence-led security, fostering a culture of proactive risk management and instilling a sense of confidence in the organization's ability to navigate challenges effectively.
Securitas client, a major player in the global Financial Services industry, faced challenges such as incidents impacting staff and resources and threats disrupting business operations. The challenge The client, a major player in the global Financial Services industry, faced challenges such as incidents impacting staff and resources and threats disrupting business operations. These included cyberattacks on financial data, compliance issues and geopolitical instability affecting worldwide operations. Despite these risks, they lacked a full understanding and found it tough to coordinate with local teams effectively. Their current incident reporting system fell short, lacking detailed analysis and practical insights for decision-makers. Given these risks, it was crucial for them to enhance risk management, improve global team collaboration and implement strong incident reporting. Failing to address these could jeopardize their competitiveness, financial stability and long-term success in Financial Services. The solution Securitas tailored a custom intelligence service, combining the expertise of dedicated analysts and technology to provide: Real-Time Monitoring: Securitas defined their client Critical Intelligence Requirements (CIRs) setting up live monitoring and 24/7 Alerting to incidents in close proximity to their chosen locations. This ensured the safety of their client’s global assets and colleagues. Crisis Support and Early Warnings: Invaluable assistance was provided during crises and incidents, along with early alerts about potential threats directly targeting their client, like protests. Regular Intelligence Updates: They stayed informed with daily, weekly and monthly intelligence summaries. These kept them abreast of the threat landscape and actionable insights, enabling them to gain decision making advantage within their security operations. Executive Protection Screening: Securitas ensured the safety of executives and colleagues facing targeted threats with the enhanced defensive screening solutions. Securitas were there to support their well-being & advise on how to improve the security of their online profiles to help keep them safe. Dedicated Request For Intelligence (RFI) Service: When they needed information on specific threats, Securitas’ dedicated specialists were there to assist promptly and effectively. The result Securitas customized solution empowered their client's intelligence-driven security approach, giving decision-makers from their client a competitive edge and the confidence to make critical business decisions while optimizing their security and resilience investments. By providing comprehensive situational awareness, Securitas not only offered peace of mind but also enhanced value, allowing them to protect their people, properties and assets worldwide. Through monitoring of new and emerging threats to the organization, Securitas helped them mitigate the potential costs of disruption, including protests targeting high-profile events, property damage plans and threats against personnel. With intelligence at the forefront of their security strategy, their client could focus on what mattered most: understanding pertinent intelligence and taking decisive action. This enabled their broader business to carry out global operations and achieve strategic goals efficiently and effectively.


Round table discussion
False alarms are the security industry's oldest and most persistent challenge. Industry estimates suggest that as many as 95% to 98% of security system activations are non-emergencies. The high rate stems from a combination of human behavior, environmental triggers, and technical limitations. However, newer technologies are finally addressing the challenge of false alarms. We asked our Expert Panel Roundtable: What are the new solutions to security's oldest challenge, reducing false alarms?
Emphasizing proactive rather than reactive security shifts the focus from dealing with crises and damage control to prevention. Advantages of a proactive approach include cost efficiency, better business continuity, and fewer crises that draw attention away from strategic improvements. Staying ahead of threats is a core mission of the security department, and technology has evolved to enable security professionals to deliver on that mission better than ever. We asked our Expert Panel Roundtable: How are security systems transitioning from reactive to proactive, and what is the benefit?
Future-proofing your skillset is about embracing continuous learning and developing a versatile set of competencies that remain valuable regardless of technological shifts or industry changes. In the security marketplace, it is not about predicting the exact jobs of the future, but rather equipping yourself to adapt and thrive in the uncertain security landscape. But where to begin? The emerging technology shifts in the security industry provide clues, such as the growing importance of cybersecurity and artificial intelligence (AI). We asked our Expert Panel Roundtable: How can physical security professionals “future-proof” their skillsets to prepare for emerging technologies?
Products


White papers
Technology's Role In Securing Banks And Financial Institutions
Download
Integrated Systems Enable Critical And Compliant Security For Transportation
Download
Modernizing Physical Access Control
Download
Access. Intrusion. One Estate.
Download
Securing The Modern Data Center
Download
Security Technologies Promote Real-Time Awareness In K-12 Schools
Download
An End User's Guide To Physical Security For Data Centers
Download
Hospital Safety In A High Risk World
Download
How Digital Transformation Is Delivering New Opportunity
Download
Where Do We Go From Prox?
Download
The User-Centric Security Revolution
Download
One System, One Card
Download
Aligning Physical And Cyber Defence For Total Protection
Download
Modernizing Access Control
Download
Enhancing Physical Access Control Using A Self-Service Model
Download

Videos
Security access systems: Manufacturers & Suppliers
- ABLOY Security access systems
- Vanderbilt Security access systems
- Aiphone Security access systems
- HID Security access systems
- CIVINTEC Security access systems
- CyberLock Security access systems
- Alpro Security access systems
- Briton Security access systems
- Bosch Security access systems
- Hikvision Security access systems
- CEM Systems Security access systems
- Software House Security access systems
- AMAG Security access systems
- Parabit Security access systems
- Honeywell Security Security access systems
- Delta Scientific Security access systems
- Aritech Security access systems
- TESA Security access systems
- Vicon Security access systems
- ASSA ABLOY - Aperio® Security access systems
