Security devices
Kaseya, the global provider of AI-powered cybersecurity and IT management software, welcomes thousands of managed service providers (MSPs) and IT professionals to Kaseya Connect Edge, the company’s virtual innovation summit. The event focused on the technologies and strategies shaping the future of IT, from AI and cyber resilience to compliance, automation and operational efficiency. Among the announcements unveiled at Connect Edge were two significant enhancements to Datto RMM designed t...
IQSIGHT announces the appointment of Michael J. Schulte as Chief Executive Officer, effective September 1, 2026. Michael will lead the global IQSIGHT business and report to Steve Shine, Chairman of IQSIGHT. Michael joins IQSIGHT with more than 30 years of leadership experience across technology, industrial and private equity-backed businesses. Most recently, he served as EVP and President of the Safety Solutions Group at Clarience Technologies and previously as President of Safe Fleet, where he...
Allied Universal®, the world’s security and facility services company, has been named to Forbes list of America’s Best Employers by State 2026 in Maryland, Nevada, New Jersey and Washington. The recognition reflects the strength of the company’s workplace culture and the meaningful impact its people have in shaping it every day. “Being named to Forbes list of America’s Best Employers By State is an honor and a reflection of the extraordinary people who make All...
HackerOne, a pioneer in Continuous Threat Exposure Management (CTEM), announces the appointment of Naveen Bhateja as Chief People Officer. Bhateja joins the executive leadership team to lead the company's people strategy, leadership development and culture. Bhateja brings more than 25 years of experience building leadership and talent in global technology companies through periods of fast growth and change. At HackerOne, he will focus on developing the company's leaders, deepening its bench and...
IDScan.net, a provider of identity verification and ID scanning technology, announces a new partnership with ScrapWare, a provider of software solutions for the scrap metal and recycling industry. Through the partnership, ScrapWare has integrated IDScan.net's ParseLink technology into its point-of-sale platform, giving recycling facilities a faster and more reliable way to capture and process customer identification during transactions. Scrap and recycling companies operate in a highly regulate...
ConnectWise, the software and services company dedicated to the success of IT solution providers, announces the appointment of Craig Rones as Chief Marketing Officer. Rones will lead Global marketing strategy, brand, and demand generation, reporting to Chief Executive Officer Manny Rivelo. Rones joins ConnectWise at a category-defining moment as Managed Service Providers (MSPs) and IT teams navigate AI adoption, escalating cyber risk, and growing customer expectations. Building on the recent la...
News
CREST, the international non-profit representing the global cybersecurity industry, announces the launch of its Security Testing of AI standard and accreditation. The new standard for cybersecurity service providers establishes independently assessable requirements for testing Generative AI and Large Language Model (LLM)-enabled systems. AI systems are moving rapidly from experimentation into real-world deployment, with AI becoming embedded within organizations’ applications, workflows, products and business processes. But up until now, buyers have had no way to know whether the cybersecurity providers testing their AI systems actually have the capability to do so. Providing independent assurance The CREST Security Testing of AI accreditation has been introduced to address that. It is designed to provide independent assurance that cybersecurity service providers have the demonstrable specialist capability to securely and effectively test AI systems. It assesses whether providers have appropriate: Technical expertise and practitioner competence. Testing methodologies. Governance and quality controls. Technical approaches and tooling. Processes for identifying and evaluating AI-specific security risks. Evidence to support the conclusions reached during testing. AI security expertise Once accredited, providers offer buyers independent assurance of their AI testing capabilities. This helps guide procurement, streamline supplier due diligence, and eliminate reliance on unsupported claims about AI security expertise. Nick Benson, CEO of CREST, said: “This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need. Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials. Offering " Security testing of AI systems" and demonstrating the ability to deliver it effectively are two different things. Buyers need to know that the providers assessing their AI have the right expertise and methodologies. Providers now have a way to develop their policies in line with our standard, demonstrate their technical capabilities through independent assessment, giving buyers that all-important confidence to proceed.” Entire attack surface The Security Testing of AI standard has been created under the principle that AI security testing needs to consider the whole system. To recognize the broader system-level security challenge, the new standard does not just treat the underlying model itself as the entire attack surface. It recognises that testing needs to also consider applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems influenced by AI outputs. AI assurance program The Security Testing of AI standard and accreditation marks the latest stage of CREST's growing AI assurance program. Recent CREST research highlights the magnitude of this evolution across cybersecurity: 69% of penetration testing providers already use AI, and 76% have increased their usage over the past year. Responding to this rapid rate of adoption, CREST announced its AI-Enabled Penetration Testing standard in July. This focused on how a penetration testing provider uses AI within the delivery of its services, while this latest standard assures their capability to test AI systems. Tim Reed, Technical Director, Sentrium Security Limited, a UK-based CREST member, said: "CREST’s standards turn responsible AI from a promise into something that can be evidenced and assessed. We believe this will strengthen buyer confidence, reward credible providers and set a higher bar for the profession, which is why we intend to pursue accreditation.” AI-enabled cybersecurity services Yann Chalençon, Head of Cyber Security Services, wizlynx group, a Switzerland-based CREST member, said: "CREST’s new standard provides a clear, independently verified framework that will help create consistency, strengthen assurance and build trust in both the testing process and the wider use of AI-enabled cybersecurity services.” CREST developed these standards in collaboration with the industry and will continue to refine them through its AI Working Group. The standards follow the launch of CREST’s industry-backed AI Charter and AI Principles in June. A global cohort of more than 100 founding signatory cybersecurity organizations - including more than 10% of CREST’s worldwide membership - publicly committed to supporting the responsible use of AI across industry services. Existing CREST Members and cybersecurity service providers are now invited to apply for this new accreditation. The Security Testing of AI accreditation builds on CREST’s Penetration Testing Accreditation, which organizations must hold or apply for alongside this one.
F5, the global pioneer in delivering and securing every app and API, introduces significant enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are accessed and used, while optimising the economics of AI at scale. Enterprises have moved past AI experimentation, but governance has not kept pace. AI traffic still moves through a patchwork of standalone proxies and monitoring tools that were never built for AI, with no guardrails in between. Unified control plane According to F5’s 2026 State of Application Strategy Report, 77% of organizations say inference, rather than model training or tuning, is now their dominant AI activity, and organizations are managing an average of seven AI models. As inference scales, tokenomics is becoming an increasingly important consideration, with every model request carrying implications for cost, performance, and security. Yet the piecemeal approach to standalone tools to secure AI traffic leaves enterprises without consistent control over how models and agents are accessed and used. Customers accelerate innovation "We're watching enterprises race to deploy AI while struggling to control it," said Kunal Anand, Chief Product Officer at F5. "Every AI request carries economic, security, and governance implications, yet most organizations are relying on fragmented tools that address only part of the problem. The result is rising costs, increased risk, and operational complexity. F5 AI Gateway, integrated into the F5 AI Security Platform, provides a single control point for managing AI across models, clouds, agents, and applications. We believe every enterprise will need an intelligent control layer for AI. F5 is building that foundation, helping customers accelerate innovation while maintaining visibility, security, and control." F5 AI Gateway brings three critical functions together in a single integrated solution: Model Gateway for model access and cost optimization MCP Gateway for agent-to-tool governance AI Guardrails for prompt and response protection Single integrated solution Budgets, model routing policies and agent access controls are set once centrally and enforced across distributed environments wherever the models, agents and AI apps run, providing a single operations pane for AI platform ops, AI Security ops and finance teams. Rapid adoption of AI is fueling the need for AI gateways. According to a recent Gartner® report, "AI gateways have emerged as a critical part of AI infrastructure, as enterprises need tools to support safe, efficient and controlled access to AI models and MCP servers. Adoption of AI gateways will continue to accelerate among large enterprises." Fine-grained access controls Organizations that cannot see which teams, models, and providers are consuming tokens cannot assess the value and costs of using AI. F5 AI Gateway puts tokenomics under control: the Model Gateway function attributes every token by provider, model, team, and user, per-team budgets enforce limits as spend occurs rather than after the invoice arrives; and automated optimization — smart routing and model tiering, semantic caching, and GPU-aware load balancing — routes each request to the right model at the right cost. The solution is designed to reduce token spend by up to 60 percent, with no application changes. As agents multiply, so do the MCP servers they call, usually with no central registry, no per-tool authorization, and no record of what agents are doing. The MCP Gateway function of F5 AI Gateway provides fine-grained access controls that limit agents to the resources they are explicitly authorized to use, including APIs, data sources, and RAG systems. Redacting sensitive data A complete audit trail captures what was accessed, when, by which agent, and on whose behalf. MCP server registry gives teams a single source of truth for approved MCP servers, thereby removing friction for developers who would otherwise find it challenging to discover which servers and tools exist. Personal data, health records, and intellectual property move through AI applications every day, and that data usually reaches external models uninspected while injection and jailbreak attempts go undetected. F5 AI Guardrails inspect every prompt and response, redacting sensitive data before it reaches the model, blocking injection and jailbreak attempts, and failing closed when a request cannot be evaluated. Full audit trails, SIEM export, data residency controls, and alignment with SOC 2, ISO, and HIPAA frameworks give regulated industries the evidence they need before putting AI into production. Hybrid multicloud environments F5 introduced the F5 AI Security Platform earlier this year to give teams continuous visibility, governance, and protection across enterprise AI applications, models, agents, and the APIs connecting them. Four integrated pillars — AI governance, AI usage control, AI security testing, and AI runtime protection — plus an overarching observability layer, create a persistent security lifecycle rather than a one-time compliance exercise. F5 AI Gateway is where those pillars meet live traffic, putting policy into force at the point of interaction and controlling what AI can access, what it can expose, and, crucially, what it can cost the business. F5 AI Gateway is deployable across SaaS, hybrid SaaS, and hybrid multicloud environments, with air-gapped support planned for regulated and sovereign use cases.
Allied Universal®, the world’s pioneer security and facility services provider, announces the appointment of Jordan Avnaim as Global Chief Information Security Officer. Avnaim will be responsible for the company’s global cybersecurity strategy and operations. Avnaim brings more than 20 years of experience to this role and will lead the development and implementation of a comprehensive, risk-based cybersecurity program designed to help protect Allied Universal employees, systems, data and technology platforms against evolving cyber threats. Reporting to Loretta Cecil, global general counsel, he will also oversee and manage the company’s cybersecurity resources and teams, working closely with our technology, legal, operations and business teams across more than 100 countries and territories. Complex global organizations “Protecting our people, systems and data is fundamental to our ability to serve customers and operate effectively around the world,” said Steve Jones, global chairman and CEO of Allied Universal. “Jordan is an accomplished cybersecurity leader who combines deep technical expertise with a clear understanding of business operations and enterprise risk. His leadership will help us continue to strengthen our cyber resilience while supporting the innovation and responsible growth of our company.” Experienced in developing and pioneer cybersecurity, technology risk and regulatory compliance programs for large, complex global organizations, Avnaim has advised boards and executive leadership teams, strengthened enterprise security capabilities and built high-performing teams focused on protecting critical infrastructure, sensitive information and business operations. Enterprise risk management “Jordan brings an exceptional combination of cybersecurity leadership, enterprise risk management experience and sound business judgment,” said Loretta Cecil, global general counsel of Allied Universal. “He has demonstrated an ability to translate complex technical risks into clear business priorities, respond effectively when incidents occur and establish accountability across large global organizations. Jordan will provide independent oversight and transparency while enabling close collaboration with our technology and operational leadership.” Previously, Avnaim served as chief information security officer at Hyundai AutoEver America and at Entrust Corp. where he was responsible for the company’s global information security program across more than 150 countries, 40 offices, and 20 data centers. He also held several senior technology risk and information security leadership positions at the Capital Group Companies. Operational readiness and collaboration Avnaim holds a Master of Engineering in management of technology, with an emphasis in information security and risk management, and a Bachelor of Engineering in computer engineering and mathematics from Vanderbilt University. He is a Certified Information Systems Security Professional, Certified Information Systems Auditor and a member of InfraGard, ISACA and ISC2. “I am honored to join Allied Universal and support an organization whose mission is centered on helping keep people and businesses safe,” Avnaim said. “Cybersecurity is a shared responsibility that requires strong governance, operational readiness and collaboration across every part of an organization. I look forward to working with colleagues around the world to further strengthen Allied Universal’s cybersecurity capabilities, protect its critical assets and support the company’s long-term growth.”
Brinqa, the pioneer in exposure management for enterprise security teams, announces it has acquired PlexTrac, the trusted platform for offensive security validation, workflow, and reporting. The acquisition adds the ability to verify that remediation has actually worked, uniquely positioning Brinqa to identify and prioritise the exposures that matter most, drive remediation, and prove the fix held, closing the CTEM loop. The acquisition also makes Brinqa the largest standalone vendor in Unified Exposure Management, with over 3,000 customers across 57 countries, including more than 25% of the Fortune 500. Solving exposure management challenges “We've spent over a decade building the platform enterprise security teams trust to prioritise what to fix first,” said Dan Pagel, CEO at Brinqa. “PlexTrac brings real offensive security depth, from practitioners who have spent years proving exactly how attackers get in. Pairing that expertise with our exposure assessment platform gives customers proof they can defend to a board, an auditor, or any AI system acting on that data.” Brinqa has spent more than a decade solving exposure management challenges for the world's largest and most complex organizations, including Nestlé, PhonePe, Cambia Health Solutions, Guidewire, and SAP. That focus paid off in 2025 with 164% year-over-year growth in new bookings, a 32% increase in new-logo average selling price, and inclusion in the inaugural Gartner® Magic Quadrant™ for Exposure Assessment Platforms. Momentum accelerated further in 2026, with new logo bookings more than doubling year-over-year and existing customers expanding their deployments as Brinqa shipped new AI capabilities, including new MCP interfaces, the AI Attribution Agent, and the AI Deduplication Agent. Robust data foundation The PlexTrac acquisition builds directly on that trajectory, adding the capability enterprise security teams kept asking for: proof that a fix actually worked. Combined with a robust data foundation, MCP, and Bring Your Own AI, customers can connect that same validated exposure data to the AI models and tools they already use, making high-value exposure intelligence available across teams. "Exposure management only matters if teams can prove the fix worked, and that's the gap Brinqa now closes. We've watched this team build category-defining technology, and this acquisition sharpens their lead at a moment when security organizations are demanding validated, AI-ready data," said Thomas Krane, Managing Director at Insight Partners and member of Brinqa's board of directors. Acquisition highlights Brinqa now serves 3,000+ customers across 57 countries, giving PlexTrac's offensive security community direct access to Brinqa's data foundation and AI agents. Brinqa now fully closes the CTEM loop, from discovery and prioritisation through validated proof that a fix worked. The combined company is now the largest standalone vendor in Unified Exposure Management, bringing together two companies independently recognized in the Gartner® Magic Quadrant™ for Exposure Assessment Platforms. Every confirmed exploit and fix from PlexTrac flows into Brinqa's data layer, strengthening the Cyber Risk Graph and sharpening every AI agent, whether Brinqa's own or one a customer runs via Brinqa’s Bring Your Own AI program. Dan DeCloss, founder and Chief Customer Brand Officer of PlexTrac, joins Brinqa's executive leadership team and board of directors to lead the combined offensive security practice. Pre-remediation testing For Brinqa's customers, it means faster confirmation that a fix worked, and evidence to back up what security teams report to auditors, insurers, and the board. A vulnerability marked “closed” in a ticketing system is a status update. A vulnerability confirmed closed through validated retesting is proof. For PlexTrac's customers, it means pentest teams and workflows now plug directly into a CTEM program instead of sitting next to one. Brinqa's prioritisation engine focuses pentest resources on the exposures that matter most to the business, and validation now covers both ends of remediation: pre-remediation testing to confirm an exposure is exploitable, and post-remediation retesting to confirm the fix held. Security, IT, and offensive security teams work from one prioritised list. Offensive security practitioners The PlexTrac solutions will continue operating as standalone offerings, giving existing customers the same experience they have today, with the option to extend into Brinqa's broader platform as their programs evolve. “PlexTrac was built by offensive security practitioners, for offensive security practitioners, and that's not changing. Joining Brinqa gives our team a bigger platform to prove that hands-on offensive security expertise still matters, even as more of this work gets automated,” said DeCloss. With PlexTrac, Brinqa becomes the operating system for enterprise exposure management: the layer where every decision, every fix, and every proof point comes together. Brinqa was represented by Covington & Burling in the transaction.
OpenAI has announced a series of enhanced safety measures designed for under 18’s using ChatGPT to introduce controls that limit how “human” the chatbot can appear amid growing concerns about the use of AI among children. Those with the new teen account can disable voice responses to ensure the tool is understood as AI rather than a person. OpenAI is also introducing reminders for young people to take a break when using the tool to prompt healthier usage patterns. Reinforcing real-world relationships OpenAI has said the update was not triggered by any single incident but the update comes following a wider concern about people believing AI systems to be sentient with the company reinforcing protections that should ‘reflect developmental stage, reinforce real-world relationships and support healthier use over time.’ Teen accounts will become a default for anyone who identifies as under 18 during sign up, as well as for users OpenAI determines to be minors. Children under 13 remain unable to use the product. Heather Barnhart, Senior Digital Forensic Expert at Cellebrite and SANS DFIR Curriculum lead commented: “Technology policy makers are up against what could be the greatest generation in tech. AI adoption is being introduced across all sectors and the children who understand how AI works and how to use it responsibly will be at an advantage as AI increasingly becomes a life skill. With this in mind, regulation should prioritise educating children on how to use it safely and what potential red flags to look out for.” Providing direct answers “Parents, educators and social media companies need to take an active role in guiding children on use. This gets at the larger issue, which is parents having open conversations about the dangers that lurk online - and having concrete guardrails on what their kids are doing and how they’re interacting with technology that is having an active role in shaping every sector. With education and healthy engagement, families can help their children navigate the online world, responsibly and safely.” As part of this, OpenAI is also expanding its Study Mode which was launched last year to help students work through problems without providing direct answers and set specific hours where Study Mode will automatically activate. OpenAI has reported nine out of 10 of its younger users use it to help them with learning.
Teleport, the AI Infrastructure Identity Company, announces support for Linux Desktop as a protected resource within the Teleport Infrastructure Identity Platform. Engineering teams can now apply the same cryptographic identity, least-privilege access controls, and session auditability to Linux desktops that they rely on for servers, Kubernetes clusters, databases, GitHub, and cloud environments. The result: Their developer workstation will reside within the same unified identity layer as the rest of their infrastructure. Professional development environments The announcement reflects the accelerating shift in how engineering teams work. According to the Stack Overflow 2025 Developer Survey of more than 49,000 respondents, Ubuntu alone accounts for 27.7% of professional development environments, with many other Linux distros including Debian, Red Hat, and Arch showing the distinct migration to Linux desktops. Because the infrastructure that engineers build and operate largely runs on Linux, working on a Linux desktop creates parity between development and production environments. This trend is further fueled by the end-of-life of support in 2025 of widely distributed Windows 10 platforms and the broad migration of core business software and developer tooling to SaaS. Live session monitoring "With this release, we're extending the infrastructure identity layer to Linux, making Linux on the desktop the first class citizen in your computing infrastructure. This eliminates yet another identity silo, yet another attack surface, and yet another vendor to manage," said Ev Kontsevoy, CEO of Teleport. "When the developer’s Linux box is governed by the same unified identity layer as the rest of your infrastructure, you remove risk and harden resiliency. This is becoming more critical as frontier AI models emerge that can rapidly identify vulnerabilities for exploitation." With Linux Desktop support, Teleport customers can access Linux hosts across cloud, on-premises, and edge environments without opening ports or managing SSH keys, with all sessions subject to the same just-in-time access request workflows, live session monitoring, and audit logs applied to other supported protected resources in the platform. Modern engineering organizations This also enables companies to apply device trust, which ensures that resources are only accessed from registered and cryptographically verified machines, to this asset class. Linux Desktop, available in August, joins servers, Kubernetes, databases, web applications, Windows desktops, cloud consoles (AWS, GCP, Azure), GitHub, and MCP servers as a Teleport-protected resource type, extending the unified identity layer to one of the fastest-growing and most operationally critical surfaces in modern engineering organizations.


Expert commentary
For years, innovation in physical security has focused on what systems can do: higher-resolution cameras, AI-driven analytics, smarter access control, and cloud-based management. But across deployments, from residential systems to enterprise campuses, a more fundamental issue continues to undermine performance: Connectivity. It is increasingly clear that the effectiveness of modern security systems is not limited by sensors or software, but by the reliability, reach, and architecture of the networks that connect them. As security systems evolve toward real-time detection, automated response, and distributed intelligence, connectivity is no longer a supporting layer. It is the foundation and, too often, the weakest link. When security design is constrained by connectivity In theory, security systems are designed to maximize visibility, coverage, and response time. In practice, they are often designed around the limitations of network infrastructure. Nowhere is this more visible than in video surveillance. Cameras are frequently positioned not where risk is highest, but where connectivity is available. Dead zones in garages, basements, or perimeter edges force compromises in placement, reducing the effectiveness of the system. In some real-world deployments, traditional Wi-Fi has been shown to fail at a meaningful percentage of intended installation points, particularly in challenging environments or at the edges of coverage. This creates a disconnect between security intent and system reality. Instead of enabling proactive deterrence, such as detecting activity at the perimeter, systems are often relegated to recording events after they occur. The same pattern appears in access control. Many deployments rely on fragmented connectivity stacks, combinations of wired links, proprietary wireless protocols, and gateways, each optimized for a specific constraint such as range or power. While functional, these architectures introduce complexity, increase deployment costs, and create additional points of failure. Over time, these workarounds have become normalized. But as systems scale and expectations rise, their limitations are becoming harder to ignore. The hidden cost of fragmentation The consequences of unreliable or overly complex connectivity extend beyond performance. They impact the entire lifecycle of a security system. Advanced security features need consistent, reliable connectivity—not just bandwidthFor integrators, poor connectivity can mean longer installation times, more troubleshooting, and increased reliance on workarounds such as mesh networks or additional infrastructure. For vendors, it can translate into higher product return rates, increased support costs, and reduced customer satisfaction. For end users, the impact is more direct: systems that fail to connect reliably are systems that fail to deliver security. This is particularly critical as security solutions move toward more advanced use cases, including real-time alerts, remote management, and edge-based analytics. These capabilities depend not just on bandwidth, but on consistent, predictable connectivity across the entire deployment environment. Why traditional approaches are reaching their limits The industry has historically relied on a mix of connectivity options, each with its own strengths and tradeoffs. Wired infrastructure, such as Ethernet and PoE, offers reliability and performance but comes with higher installation costs and limited flexibility, particularly in large or distributed environments. Conventional Wi-Fi provides high throughput and seamless integration with IP networks but is optimized for short-range indoor use, where walls, distance, and interference can quickly degrade performance. Low-Power Wide-Area Networks (LPWAN) and cellular solutions extend range and coverage but often sacrifice throughput, increase latency, or introduce recurring operational costs. To compensate, many systems combine multiple technologies—layering gateways, protocol translation, and mesh architectures to bridge gaps. While effective in the short term, this approach increases system complexity and reduces long-term scalability. A shift toward simpler, more unified architectures In response, the industry is beginning to rethink connectivity, not as a patchwork of solutions, but as a unified foundation for modern security systems. The goal is straightforward: deliver long-range, reliable, and secure connectivity without adding architectural complexity. An example of this shift: Extending Wi-Fi beyond traditional limits One example of this shift can be seen in emerging Wi-Fi technologies designed specifically for long-range, low-power environments. Rather than replacing existing wireless approaches, these solutions aim to extend the familiar Wi-Fi model into new deployment scenarios where traditional networks struggle. Wi-Fi HaLow, based on the IEEE 802.11ah standard, is one such approach. Operating in sub-GHz spectrum, it enables significantly greater range and signal penetration compared to conventional 2.4 GHz and 5 GHz Wi-Fi, while maintaining native IP networking and established security frameworks. Wi-Fi trends reduce fragmentation and support data-heavy security systemsIn practical terms, this allows security devices, such as cameras and access control systems, to connect reliably across large properties, multi-building campuses, and outdoor environments without requiring dense access-point deployments or complex mesh configurations. It also supports higher data rates than many low-power wide-area technologies, enabling capabilities such as over-the-air updates, diagnostics, and increasingly, edge-based intelligence. At the same time, no single connectivity approach is universally optimal. Cellular remains essential for mobility, while LPWAN technologies continue to serve ultra-low-power sensing applications. Emerging Wi-Fi-based approaches highlight a broader industry direction: reducing fragmentation while supporting more demanding, data-rich security systems. From coverage to deterrence: A new security model One of the most significant implications of improved connectivity is the ability to rethink how security systems are deployed in the first place. Historically, limitations in wireless performance have pushed devices inward, closer to access points, inside buildings, and away from the perimeter. As a result, many systems are optimized for detection after the fact, rather than prevention at the edge. With more reliable long-range connectivity, this model begins to shift. Cameras and sensors can be placed where they are most effective—at entry points, along property boundaries, and in previously hard-to-reach areas. Combined with edge-based analytics, this enables earlier detection, faster response, and more effective deterrence. In this context, connectivity is not just an enabler of performance, it is a driver of fundamentally different security outcomes. Designing for the next generation of security systems As the industry moves forward, organizations deploying security systems should reassess how connectivity is factored into system design. Several principles are emerging: Prioritize reliability over peak performance Design for the perimeter, not just the interior Reduce architectural complexity Validate real-world performance, not just lab specifications The next wave of innovation in security will not be defined solely by smarter devices or more advanced analytics. It will be defined by whether those systems can connect, reliably, consistently, and at scale. Connectivity has long been treated as an invisible layer in security architecture. Today, it is becoming clear that it deserves far greater attention. As the industry rethinks its approach, one thing is certain: solving the connectivity challenge is not just a technical upgrade. It is a prerequisite for delivering on the full promise of modern security systems.
The healthcare infrastructure is ever evolving. Facilities are no longer single entities for one, they are sprawling ecosystems that serve a wide range of users, from medical staff and administrators to vulnerable patients, visitors and maintenance personnel. Safeguarding their safety and security, while providing seamless operation is a complex challenge - one frequently solved by access control. Use of access control Today’s security solutions play a central role in protecting people and mitigating risk across much of our built environment. An appropriately specified system is effective at regulating, monitoring and restricting entry and exits, and allows users to navigate an integrated network and its hardware to ensure the right access is provided to the right person at the right time. In healthcare buildings, the use of access control expands further, whereby a system can tackle a host of unique operational challenges - significantly contributing to fire safety, ease of movement and the theft prevention of equipment, medicine and sensitive patient data, and all while protecting human life and preserving privacy and dignity. In healthcare buildings, the use of access control expands. In doing so, access control can become the cornerstone of functionality, compliance and organization in any healthcare environment. Though, as the complexity of projects deepen, decision makers are reminded that coordination is key. Preparing and empowering users Between January and March 2025, there were over 832,000 patient safety events recorded in the NHS. While each of these events may not be directly linked to building security specifically, the healthcare industry is faced with a considerable number of safety incidents, which suggests greater monitoring and mitigation is needed across the board. Access control often provides staff with the vital means of retaining control without impeding care Patient well-being and security will always remain paramount in the sector, and access control often provides staff with the necessary means of retaining control without impeding care. Hospitals for example, sustain a high level of footfall across large campuses with multiple points of entry and on-site patient record systems, presenting a number of simultaneous security tests as a result. Though, unlike other public buildings, where rigid security measures are active at all times, many healthcare environments must strike a balance throughout their security framework to meet a host of one-of-a-kind demands. Use of access credentials With a continuous influx of patients, staff and visitors, healthcare groups are habitually required to remain accessible and inviting around the clock. At the same time, they must also be prepared to deter unwanted visitors in areas of restricted access and lock down intensive wards to ensure patients remain safe and secure under periods of monitoring. For this, the use of access credentials is critical and provides a regulated system for sensitive staff-controlled areas such as pharmacies, wards, and server rooms. By applying role, zone, or schedule-based access, decision makers can authorize personnel seamlessly, empowering facilities to manage patient care without compromising security in the process. Use of access credentials is critical and provides a regulated system for staff. Implementation of AI-powered tools and devices Modern systems may incorporate the use of keycards, biometric scanners, and mobile credentials When it comes to the operation of these systems, training gaps are a concern, however. Over the five years up to February 2025, numbers of NHS doctors rose by 26%, with nurses also up 25%, and this influx of new staff requires education towards the usage of access control. Modern systems may incorporate the use of keycards, biometric scanners, mobile credentials and in some cases, voice-activation, with the implementation of AI-powered tools and devices set to play a more prevalent role in the future. Each system presents its own benefits and may be better suited to certain projects and areas, but without consultation and proper user education, they can instead become a barrier. Strategy, scalability, performance To alleviate these operational threats, early-stage planning is fundamental. Just as end-user education and training should be built into project timelines, it’s important to consider the growing need for cooperation throughout the entire supply chain of an access control project. A collaborative approach becomes even more critical when innovative solutions enter the market All too often, a lack of evidence-based decision making can hinder the specification of a scheme and its accompanying hardware, whereby choices are made without understanding long-term performance or compliance requirements. Whether approaching a new or retrofit development, ongoing communication allows experts to come together and ensure that product decisions are aligned with the buildings intended use and user base. This collaborative approach becomes even more critical when innovative solutions enter the market and new sector challenges arise. Latest access control products With this in mind, trusted manufacturers will no longer simply deliver the latest access control products, but will aim to work alongside the architects, specifiers, contractors, and facility managers at each stage of the building’s lifecycle to ensure touchpoints are addressed. This is crucial in modern healthcare environments, where the added layer of complexity requires tailored security measures. One area that is often neglected is scalability, for example. As healthcare facilities manage fluctuating patient numbers and a growing level of patient data, along with new regulations, systems must be adaptable and allow for ongoing improvements and updates to the security infrastructure without the need for a complete overhaul. By adopting a scalable system that combines technology integration with ease of use, decision makers can future-proof their building’s security. Manufacturers will no longer simply deliver the latest access control products Complexity of the healthcare industry In truth, access control has become more than a means of restricting access. Modern systems are more equipped than ever before to deliver environments that support care, safety, and operational excellence. Nonetheless, the complexity of the healthcare industry and its buildings demands more than product innovation - it requires an industry-wide commitment to collaboration, from project conception to product installation and beyond.
In today’s world, almost any electronic security system holds the potential to become a gateway for cybercriminals. With physical security and cybersecurity increasingly entwined, security professionals aren’t doing their job unless they take all possible precautions to lock down unauthorized access to camera systems, access control platforms, intercoms, and other network-based security devices and solutions. Let’s explore the many steps companies should take throughout their security technologies’ lifecycle – from choosing a vendor all the way through device decommissioning – to avoid making the common mistakes that leave systems, and the networks they reside on, vulnerable to attack and sabotage. Prepurchase Phase: Laying the Groundwork for Cybersecurity 1. Conduct a Vendor Risk Assessment IT departments often rely on the same Vendor Risk Assessment criteria they use for evaluating IT equipment manufacturers when considering the suitability of physical security vendors. While commonalities exist between how to assess these disparate solutions, there are also differences that require distinct scrutiny. For example, device endpoints within physical security systems run on custom Linux Kernels and therefore do not utilize standard Linux distributions like Red Hat, Ubuntu, or Debian. IT divisions often rely on the same Vendor Risk Assessment criteria they use for evaluating IT kit A comprehensive evaluation should examine how each security solutions manufacturer handles its software development life cycles. Ideally, vendors should adhere to a recognized framework when developing both their platform management and device-specific software. In 2021, Executive Order 14028 made it a bit easier for companies to evaluate vendors by providing guidelines for evaluating software security, the practices of the software developer, and methods to demonstrate conformance with secure practices, specifically referencing the NIST SP 800-218 Secure Software Development Framework. In short, a good vendor should have documentation that explains everything it’s doing to address cybersecurity from development, through releases and ongoing maintenance. 2. Obtain Software Update Schedules The frequency with which manufacturers update their software varies. Each company is different. If you’re their customer, it shouldn't matter whether the vendor schedules updates every six months, three months, or more often than that. What does matter is that you know what to expect and have a plan for how to deal with that reality. For example, if updates only occur every six months, under what conditions are patches released to address vulnerabilities that emerge between updates? Customers must understand how often they'll be updating the software on their devices and ensure they have the resources to make it happen. Make sure stakeholders agree, upfront, who will be performing the software updates. Will it be the integrator who installed the system, the physical security system staff, the IT team, or the end user? Keeping an entire system current is a huge challenge, but a non-negotiable responsibility. Manufacturers who don't issue frequent releases and patches put the onus on customers to handle mitigation efforts on their own. In these instances, IT departments must be prepared to employ network segmentation, firewalls, security whitelists/blacklists, and other methods to protect their systems until a patch is released. If a company's security team has typically updated firmware only when something breaks, these additional responsibilities most likely require greater collaboration with IT departments and a shift in how security systems are managed. 3. Know the Warranty Terms and Duration of Software Support Organizations should understand the warranty policies for the devices they purchase Organizations should understand the warranty policies for the devices they purchase. Even more important is knowing when a device's software support will expire. Software support should extend well beyond hardware coverage. For example, if a camera has a five-year hardware warranty, customers should reasonably expect an additional five years of software support. When that period ends, companies must plan on replacing the device – even if it still works well. Without software updates, the device lacks vulnerability support and becomes too risky to remain on the network. Manufacturers should be transparent about their warranty and software support policies, helping organizations plan for device replacements that align with cybersecurity needs. 4. Request a Software Bill of Materials (SBOM) During the pre-discovery process, customers should request a Software Bill of Materials (SBOM) that provides a detailed inventory of the software running on each device, including open-source components. By revealing what software is "under the hood," the SBOM allows IT departments to be vigilant in protecting the company's systems from exposed vulnerabilities. For example, a customer should understand how Transport Layer Security (TLS) is being handled to secure a security solution's web server if it’s an open-source component like OpenSSL. 5. Assess Vulnerability Disclosure Practices CNA manufacturers represent the gold standard in cybersecurity practices Understanding how a manufacturer handles vulnerabilities is essential. Ideally, they should be a Certified Naming Authority (CAN) and report common vulnerabilities and exposures (CVEs) to national vulnerability databases such as NIST and MITRE. Doing so automatically includes any disclosed vulnerabilities associated with their devices in vulnerability scanners' databases. CNA manufacturers represent the gold standard in cybersecurity practices, but most security manufacturers do not reach this level. At a minimum, the vendors you choose to work with should have an email notification system in place to alert customers to new vulnerabilities. Remember – email notifications are only as reliable as the employees managing them, so investigate whether the manufacturer has a strong track record of keeping up with such communications. Ask to speak with customer references who have been using the solution for an extended period to ensure the vendor is diligent in its communications. Configuration Phase: Ensuring a Secure Setup 1. Use Hardening Guides Once a device is purchased, configuring it securely is the next critical step. Manufacturers should publish hardening guides that detail the security controls available for their products and recommended practices for implementation. Between the features offered by the vendor and your company's own cybersecurity policies, make sure all possible encryption options are activated. Using HTTPS is vital for ensuring secure communication with devices. Many physical security devices default to HTTP to accommodate customer-specific network topologies and certificate management. Failing to implement HTTPS can leave sensitive metadata unencrypted and vulnerable to interception. 2. Consider Advanced Encryption Protocols Protocols are necessary to protect video data in transit from cameras to the VMS Some solutions offer built-in encryption protocols, like MACsec, which makes it impossible for data to be compromised as it is transmitted over the network. HTTPS is still necessary to secure the connection to the devices’ webservice, but while customers set up and configure their devices, MACsec will keep network data safe. Additionally, if you want to encrypt video streams, consider protocols such as Secure Real-Time Transport Protocol (SRTP), which secures the transmission of audio and video data over the Internet, or tunneling methods like Secure Socket Tunneling Protocol (SSTP), which encapsulate data packets for safe transmission between two points, even if the network is insecure. Such protocols are necessary to protect video data in transit from cameras to the Video Management System (VMS). Encryption should also extend to the VMS hard drive where video is stored. There are different methodologies to do that, but ultimately the goal is to encrypt data in transit and in storage. 3. Implement Remote Syslog In the case of a breach, each device maintains a set of logs that are useful for forensic investigations. However, if a device gets hacked, its log may not be accessible. Best practices dictate that companies should set up a remote Syslog server that maintains a copy of all device logs within a central repository. In addition to providing redundant data for investigations, a Syslog offers IT systems an efficient way to look for anomalies. Cybersecurity teams will receive immediate notification for events like unsuccessful login attempts so they can quickly figure out what's happening. Who is trying to log in? Why on that particular device? 4. Practice Healthy Password Hygiene Ideally, organizations should move towards using Active Directory or Single Sign-On (SSO) solutions One of the most basic and yet overlooked aspects of cybersecurity is the failure to manage user accounts meticulously. Many organizations use the same username and password for all security devices because it's simply too cumbersome to manage a network of devices in which each requires a separate, unique login. It's assumed that the system's primary administrators are the only ones who know the universal password. However, the system becomes vulnerable if anyone within this select group leaves the company and the password isn't changed or deleted right away. Ideally, organizations should move towards using Active Directory or Single Sign-On (SSO) solutions. This approach ensures that employees throughout a company are each assigned a unique login credential that they use for any systems they use throughout the organization. When they leave, their passwords and access are universally terminated along with their accounts. If SSO is not an option, regular password changes and prompt account deactivation are critical. Decommissioning Phase: Securely Retiring Devices At some point, physical security devices will reach the end of their useful life. When that time comes, companies must take care in how they dispose of their devices. A good vendor will provide guidance on how to clear memory chipsets and restore factory defaults. Improper decommissioning can lead to severe risks. For example, if an improperly decommissioned device is sold on the secondary market or retrieved from a dumpster, an attacker could gain access to sensitive network configurations and use this information for malicious purposes. Conclusion Deploying physical security solutions involves more than just securing buildings and assets; it also requires robust measures to protect against cybersecurity threats. From assessing vendors and understanding update policies to configuring devices securely and managing decommissioning processes, each step presents potential pitfalls that, if overlooked, could expose organizations to significant risks. By incorporating the techniques discussed into their deployment protocols, organizations can ensure their physical security solutions provide comprehensive physical and digital protection.
Security beat
Companies at GSX 2023 emphasized new ways that technologies such as artificial intelligence (AI) and the cloud can address long-standing issues in the security market. Among the exhibitors at the event in Dallas were companies seeking creative ways to apply technology, lower costs, and make the world a safer place. Reflecting on the exhibition, here are some additional takeaways. Expanding AI at the edge i-PRO is a company reflecting the continued expansion of edge AI capability in the security market. Today, more than half of the company’s lineup supports AI at the edge so the customer has a wide choice of form factors when seeking to leverage the feature set. AI processing relay, extended warranty i-PRO is increasing their warranty period from 5 to 7 years, which could be a lifetime warranty in some cases I-PRO also has an “AI processing relay” device that accepts non-AI video streams and applies edge analytics. AI has progressed from a high-end technology to a feature available in a variety of cameras at different price points. i-PRO is also increasing its warranty period from 5 to 7 years, which could be a lifetime warranty in some cases depending on a customer’s refresh schedule and lifecycle management. Active Guard, MonitorCast The company’s video management system (Video Insight) is continuing to build new features including “Active Guard,” an integrated metadata sorter. Their access control platform, MonitorCast, is a Mercury-based solution that is tightly integrated with Video Insight. Their embedded recorders now have PoE built in. “We can move at a faster pace to fill out our product line since leaving Panasonic,” says Adam Lowenstein, Director of Product Management. “We can focus our business on adapting to the market.” Emphasis on retail and other verticals Shoplifting is a timely issue, and retail is a vertical market that got a lot of attention at GSX 2023. “We see a lot of retailers who are primarily interested in protecting employee safety, but also assets,” says Brandon Davito, Verkada’s SVP of Product and Operations. “Shrinkage is a CEO-level priority.” “Retailers are getting more engaged with security posture, instead of letting perpetrators walk,” Davito adds. Intrusion detection Verkada has an intrusion product that will notify a central station if there is an alarm On the alarm side, Verkada has an intrusion product that will notify a central station if there is an alarm, and operators can review videos to confirm the alarm. Other capabilities seeking to discourage trespassers include sirens, strobes, and “talkdown” capabilities. International expansion Verkada continues to expand internationally with 16 offices in all, including Sydney, Tokyo, and London. The core value proposition is to enable customers to manage their onsite infrastructure more simply, including new elements such as PTZ cameras, intercoms, and visitor management. Verkada emphasizes ease of use, including a mobile application to allow access to be managed across the user base. Forging partnerships “We are committed to the channel and industry, and we continue to build relationships and expand our reach,” says Davito. Among the industry relationships is a new partnership with Convergint, which was hinted at during the show and announced later the same day. They are also expanding their partnerships with Schlage, Allegion, and ASSA ABLOY. Working with other verticals They offer new features for K -12 schools, and a new alarm platform is easier to deploy and manage Verkada has also found success across multiple other verticals, notably healthcare, where they integrate with an electronic medical records system. They offer new features for K-12 schools, and a new alarm platform is easier to deploy and manage. They are integrating wireless locks to secure interior doors in schools, looking to secure the perimeter, and installing guest management systems. Transitioning the Mid-Market to the Cloud Salient is squarely focused on the “mid-market,” a large swath of systems somewhere between small businesses and enterprise-level systems. Pure cloud systems are not as attractive to this market, which has a built-out infrastructure of on-premise systems. Adding a camera to an existing system is easier and less expensive than tying it to the cloud. Benefits of cloud It’s a market that may not be ready for pure cloud, but there are benefits to be realized from adding a cloud element to existing systems. “We are continuing to augment our premise-based solutions with added cloud capabilities and flexibility,” says Sanjay Challa, Salient’s Chief Product Officer. The feedback Salient hears from their customers is “I want to own my data.” The hybrid cloud approach offers the right mix of control, flexibility, and unit economics. Cloud add-on capabilities We want to provide the flexibility for customers to go full-cloud as it becomes more economically attractive" Cloud add-on capabilities include bringing more intelligence about system operation to the user via the cloud. Over time, Salient expects to sell more cloud-centric offerings based on feedback from integrators and customers. “We want to provide the flexibility for customers to go full-cloud as it becomes more economically attractive over time,” says Challa. Vaidio AI technology Salient seeks to be a transition pioneer to help customers realize the path to the cloud. Their approach is “crawl, walk, run,” and helping customers make the transition at each stage. Salient has added AI to its product offering, incorporating Vaidio AI technology from IronYun into a powerful suite and broad array of on-premise analytics, which are gaining traction. The seamless approach makes it easy for customers to embrace AI analytics, although Salient remains broadly committed to open systems. Addressing ‘Soft’ Features for Integrators AMAG is in the process of enhancing its product line with the next generation of access control panels. However, “product” is just part of the new developments at AMAG. In addition to “hard” features (such as products), the company is looking to improve its “soft” features, too; that is, how they work with the integrator channel. Integrator channel Rebuilding a process to make your organization more efficient, is relatively easy; it just takes a lot of persistence" “We have the depth of our legacy customer base we can learn from, we just need to close the feedback loop quicker,” says Kyle Gordon, AMAG’s Executive Vice President of Global Sales, Marketing, and commercial Excellence, who acknowledges the value of reinstating face-to-face meetings after COVID. “We are laser-focused on nurturing our integrator channel,” he says. “Developing new features takes time, but rebuilding a process to make your organization more efficient, that’s relatively easy; it just takes a lot of persistence,” says Gordon. More cohesive internal communication is another useful tool, he says. Disrupting the cloud based on price Wasabi is working to make cloud applications less expensive by offering a “disruptive” price on cloud storage, $6.99 per terabyte per month (80% less than hyperscalers). Contending “hyperscalers” like AWS are charging too much for cloud storage, Wasabi is using its own intellectual property and server equipment co-located in data centers around the world. Wasabi sells “hot cloud storage,” which refers to the fact that they only have one tier of storage and data is always accessible. In contrast, a company such as AWS might charge an “egress fee” for access to data stored in a “colder” tier. Cloud storage “We saw that several video surveillance companies had not yet adopted cloud storage, and we saw an opportunity to make it easy to use,” said Drew Schlussel, Wasabi’s Senior Director of Product Marketing. “We just install a little bit of software that allows them to store data in the cloud and bring it back from the cloud.” Performance, protection (cybersecurity), and price Wasabi works with integrators, resellers, and distributors and also integrates with VMS companies Wasabi works with integrators, resellers, and distributors and also integrates with VMS companies such as Genetec and Milestone. Emphasizing performance, protection (cybersecurity), and price, their data centers are certified to SOC 2 and ISO 27001 standards. Faster throughput for weapons detection Xtract One is a young company focusing on weapons detection in a time of accelerated concern about gun issues post-COVID. Founded in Canada and based on technology developed at McMaster University, Xtract One has found a niche in providing weapons detection at stadiums and arenas. These customers already have budgets, and it is easy to shift the money to a newer, faster technology. Madison Square Garden in New York City is among its customers. Cost savings solution Xtract One can increase throughput to 30 to 50 people per entrance per minute (compared to 5 to 6 people per minute when using metal detectors). The solution doesn’t require anyone to empty their pockets and the system alarms on items beyond guns and knives. Using Xtract One allows customers to reduce the number of screening lanes and security staff, providing additional cost savings, all while getting fans through the screening process in half the time. Purpose-built sensors The system uses purpose-built sensors looking for specific characteristics, such as reflective and density properties In addition to stadiums and arenas, Xtract One, formerly Patriot One, is also getting “inbound” interest from schools, hospitals, manufacturers, and other verticals that makeup 50% of their business. “We’re on a rocket ride, mainly because the weapons issues are not going away,” says Peter Evans, CEO and Director at Xtract One. The system uses purpose-built sensors looking for specific characteristics, such as reflective and density properties, all correlated by an AI engine. Providing early warning of violence ZeroEyes is another company focused on weapons detection. Their AI gun detection system works with video images to identify if someone is “brandishing” (carrying) a weapon. In other words, the system does not detect concealed weapons. Identifying someone carrying a weapon provides early warning of a possible violent act. Increased response with AI-enables images Images are identified by AI and sent to a monitoring center where a human confirms the image before contacting first responders. Knowing the location of a shooter enables staff to lock entry points, move people to safety, and direct first responders. The company was founded to leverage existing camera views to stop mass shootings and gun violence by reducing response times.
GSX 2023 has its share of new product announcements, although many of the new products are enhancements to technologies shown at last spring’s ISC West show in Las Vegas. Booth traffic on the first day seemed busy at the Kay Bailey Hutchison Convention Center in Dallas, although one exhibitor complained that it takes some time for the traffic to make its way to the farthest areas of the show floor. Apparent throughout the GSX show is an expanding idea of what constitutes security. Increasingly, ‘security’ technologies offer benefits throughout other parts of a company or institution. Security is also being broadened to encompass ‘safety,’ including emergency response and wider issues of keeping a company safe. Managing multiple systems People look at the systems they have, and they are looking for more information" Manufacturers at GSX are talking about more than new products. Rather, they are offering new approaches to turn products into ‘solutions’ for customers. Among the benefits of new systems is the availability of more data. “People look at the systems they have, and they are looking for more information and data and insights from their systems,” says Kyle Hurt, Genetec’s Area Vice-President of Sales for the US and Canada. “In the past, if I’m managing multiple systems and spending time and resources, I am making sure systems are operational. Today, it’s more like: How do I make my enterprise more efficient? I spend less time on making sure systems are working together but more time on how we can use the information.” Manufacturers at GSX are talking about more than new products Security control room Genetec is enhancing its Security Center 5.11 version with a newly redesigned web client that provides new capabilities related to system audio, including the ability to trigger a public address from a mobile device in an emergency, two-way audio to and from the security operations center, and the ability to record an incident. The new web client offers new levels of “Security on the go,” says Hurt. A mobile device becomes an extension of the security control room. “Customers want to have more remote capabilities and have their security personnel out and about, not tied to a desk,” says Hurt. The new web client works to unify the four pillars of the Security Center— video, access control, license plate recognition, and now audio. Single source manufacturer Audio can now be used to broadcast a message, respond to an incident, and notify people" “Audio has taken time to develop legs in our ecosystem,” says Hurt. “We have been developing partnerships and use cases beyond an intercom at the door. Audio can now be used to broadcast a message, respond to an incident, and notify people en mass of what’s going on.” Manufacturers are also fine-tuning how they work to meet customers’ needs. “Customers want one point of contact, a single source manufacturer, and a solution that reflects the manufacturer is listening to the voice of the customer,” says Jerry Burhans, Managing Director of ASSA ABLOY Global Solutions - Critical Infrastructure, which seeks to be a global partner to critical infrastructure industries. The Critical Infrastructure business works across the various product groups of the notoriously siloed company to bring together solutions aimed at meeting each customer’s need. Manufacturers are also fine-tuning how they work to meet customers’ needs Best-in-class technology “We try to have best-in-class technology and collaborate within ourselves to make sure we have what customers need,” says Burhans. Critical infrastructure industries such as water, power and energy, oil and gas are developing standards to help support preparedness of the nation’s infrastructure, and ASSA ABLOY Global Solutions is helping operators secure access and provide audit trails on locking hardware and keys within their security perimeters. Managing customer assets Johnson Controls’ new OpenBlue Service for the security device market seeks to proactively manage customer assets (equipment) as a service. The company’s software platform of connected solutions monitors and manages security devices across vendors and provides remote support services including skilled engineers who can work to ensure that a company’s assets, including cameras and access control readers, operate dependably. Working remotely, OpenBlue analyzes the performance of each system component Johnson Controls estimates that, unfortunately, up to 25% of a company’s security assets may not be working as intended, whether they lack the latest firmware update or are not connected. Working remotely, OpenBlue analyzes the performance of each system component and responds to ensure equipment operates as intended. “We believe we can close that gap with our solutions,” says Greg Parker, Vice President, Innovation & Portfolio Management for Johnson Controls. Physical security equipment A big advantage of OpenBlue for security customers is the ability to manage cybersecurity and threats at the edge, which may not currently be addressed by the IT department. The OpenBlue offering includes an embedded ‘air wall,’ which is a zero-trust architecture for physical security equipment. OpenBlue also helps customers manage the ever-changing lifecycles of various assets. Another concept prompting discussion at GSX 2023 is the gap between what a customer expects from a product and what the product can realistically deliver. With endless promotion in the last several years centering on concepts such as artificial intelligence (AI), is it any wonder that customers may sometimes have unrealistic expectations about what a technology can accomplish? The good news at GSX is that, as progress marches on, newer technologies are getting closer and closer to delivering on customers’ most ambitious expectations. The forward momentum of technology development is evident throughout the GSX 2023 show floor, reflecting the promise of even greater product capabilities in months and years to come.
A pioneer in the access control sector since 1971, AMAG Technology is looking to the future and the next generation of products that will expand its services to customers. “In our vision, we have advanced approaches that will not only provide our partners with advanced technologies but also ones that are easier to install with tools to expand their services,” says David Sullivan, who was appointed President of the venerable access control company in September 2022. New challenges at AMAG Sullivan brings a new outlook to the AMAG business, a part of Allied Universal, and a new vision to lead the company into the future. We caught up with David Sullivan to discuss his new challenges at AMAG and the journey ahead as the company looks to the future. Q: How does your background inform your approach to leading AMAG? I believe that it helps me to define a vision for AMAG that will be unique and on the leading edge of our industry David Sullivan: With the exception of only a few short years, my career has been in access control. I have experience with several systems and have had the privilege to manage several successful access control companies. As a result, I bring a great deal of experience into my role at AMAG. I believe that it helps me to define a vision for AMAG that will be unique and on the leading edge of our industry. Q: How would you describe AMAG’s journey over the last several years and how do you see the future? Sullivan: Prior presidents of AMAG always shared their leadership vision and direction with senior leaders located in the United Kingdom. This had an impact on the full direction of the business, sometimes limiting its ultimate success. Before I became a part of AMAG, these senior leaders that were located in the UK retired, placing for the first time the full management responsibilities of the president. This has allowed me to integrate the business into a single team, with single objectives, and a single vision. We expect to begin to reveal this new vision in the coming weeks. We are excited about the future of AMAG and believe we will surprise the industry with our new products and approach in the coming months and years. Q: How important is it that a manufacturer provides both hardware and software solutions? How does AMAG’s approach (in general) differentiate it in the market? We can design the complete solution, providing functionality that others may find more difficult to accomplish Sullivan: Regardless of the manufacturer, we all provide hardware and software. An access control solution is not complete without both. Some of us choose to make our panels, and others do not. Those who are dependent on third-party suppliers are restricted to the developments and direction of that company, and while it might be perceived to be an open technology, it still is proprietary to the hardware manufacturer. AMAG has controlled its manufacturing of panels from day one. The result means that we can design the complete solution, providing functionality that others may find more difficult to accomplish. Q: How does the breadth of AMAG’s product suite provide advantages to customers and/or integrators? Sullivan: AMAG’s product portfolio is unique and provides the end user with an end-to-end identity management solution from one company. Our Control Room PSIM, Symmetry CONNECT Identity Management Solution, Symmetry Access Control, and Symmetry GUEST solutions all integrate to provide the user with a broad set of features and capabilities from a single provider. There is no finger-pointing when we come to support your system. We hold full responsibility for making it work and can quickly provide a resolution to any application difficulties the user may be experiencing. Q: How does AMAG address the divide between on-prem and cloud systems? How do you help customers make the transition and/or plan for the future? We are in the early stages of developing our next generation of access control in which we intend to provide on-prem Sullivan: In our current product portfolio, we have three products that are cloud-based. Our mobile credential platform (Symmetry Mobile), our visitor management solution (Symmetry GUEST), and our physical identity and access management solution (Symmetry CONNECT) are all offerings that operate in the cloud. We are in the early stages of developing our next generation of access control in which we intend to provide on-prem, web client, and cloud-based offerings. One of the primary objectives is to ensure that the large installed base of systems that are out there today will be able to migrate not only to our next generation but as well to the cloud if the client so desires. Q: What is AMAG’s approach to mobile credentialing? Sullivan: As an access control provider, adding Symmetry Mobile credentialing to our portfolio just made sense. We want our customers to have a forward-thinking solution with the opportunity to save money not only on the physical badges but the cost of printing and distributing badges. Mobile credentials can be easily issued and revoked remotely, reducing administrative overhead, and eliminating the need for physical inventory management. Organizations can centrally configure what devices are used and the read range for each type of device and operating system, thus providing flexibility. Symmetry Mobile offers a customized questionnaire that controls access and reduces liabilities. Q: What has surprised you the most in your first year or so leading AMAG? Not many companies are blessed with such a broad portfolio that is supported by a resource-rich company Sullivan: I wouldn’t say I was surprised by this as much as happy to see, but I would say that the quality of our people was a pleasant surprise. As well, the AMAG product offering is broad and has some unique elements. When coupled with the depth of the resources that we have in AMAG, I know that we are second to none. Not many companies are blessed with such a broad portfolio that is supported by a resource-rich company that has so many talented people. Q: Please describe your dealer channel, and how you are seeking to expand it. Sullivan: The AMAG products are sophisticated and typically are installed for higher-end applications. With this sophistication comes a need to be well able to install such a solution. We have a strong group of certified and loyal partners who help us to deliver these enterprise solutions. We desire to provide our existing partners with updated and competitive systems to offer to their end users. Q: What is the security industry’s (and/or AMAG’s) biggest challenge in the next five years? We need to find ways to provide both our channel partners and the customers with solutions that are easily integrated Sullivan: I believe that the advancements that we are seeing in technology provide our industry with the opportunity to truly change how security is provided to our collective customers. As we advance these solutions, we will need to do so responsibly and in a way that helps the channel’s abilities. We need to find ways to train our partners to both install and support these more complex solutions. At the same time, we need to find ways to provide both our channel partners and the customers with solutions that are easily integrated, moving away from proprietary closed systems to open and cohesive solutions. This will ensure that the users get the best, and most complete solutions. Q: What does the industry as a whole misunderstand about AMAG -- time to set the record straight! Sullivan: Well, I am not ready to openly share where we are heading. We are in the process of putting together some advanced approaches to how we will do business with our partners. We are focused on providing tools that will enhance their services to their customers, and with products that are leading edge. I can only state that all should keep their eyes on AMAG, because over the next few years, we are going to surprise some people, and more importantly make our loyal partners quite powerful.
Case studies
Security requirements for critical infrastructure are changing rapidly. Recent events, such as the discovery of a drone at Leipzig Airport, have once again demonstrated how quickly modern technologies can become a security challenge. This makes dialog between industry, authorities and emergency services all the more important. Security Essen, which will take place at Messe Essen from 22 to 25 September 2026, is placing precisely this exchange at the heart of two key program highlights: the European Drone Conference and the Emergency Services Forum. Unmanned aerial systems open up a wide range of potential applications – from inspecting critical infrastructure to supporting security and emergency services. Protection of critical infrastructure At the same time, they present new challenges for operators of sensitive facilities. The European Drone Conference on 23 and 24 September will therefore bring together experts from the security industry, public authorities, academia and politics to discuss current developments, the regulatory framework and effective protection strategies. The conference is organized by the Drone Expert Committee of the German Security Industry Association (BDSW), together with Security Essen and the Confederation of European Security Services (CoESS). Experts discuss drone deployment, detection and countermeasures Around 20 specialist presentations will examine drone technology from various perspectives – ranging from regulatory issues and the protection of critical infrastructure to detection and counter-drone systems. Managing new risks In his statement, Cornelius Toussaint, Vice-President of the BDSW and Chair of the Drone Expert Committee, will focus on security and drone technology in Germany. Marcus Schermann (DB Sicherheit GmbH) will discuss the protection of critical infrastructure, using multicopter operations as an example. Drone management, with a particular focus on detection and countermeasures, is the main theme addressed by the two speakers, Ralf Holstein and André Danner (German Business Protection GmbH). The program is complemented by presentations on research and development, as well as international keynote speeches from the worlds of politics and the security industry. The central question is how to capitalize on the opportunities offered by the technology whilst effectively managing new risks. Public safety authorities Emergency Services Forum (Blaulichtforum) takes place for the first time In collaboration with Feuerwehr-Magazin (Fire & Rescue Magazine) and Rettungs-Magazin (Emergency Medical Services Magazine), the Emergency Services Forum 2026 will make its debut at Security Essen. On 22 September, the new forum will bring together public safety authorities and organizations (BOS), the security industry and public authorities, focusing on a key question: How are new threat scenarios and technologies changing security and emergency response? On stage, experts from the fire service, police, civil protection, the security industry and defense will discuss current challenges: What role will drones and autonomous systems play in future operations? Shared situational picture How well is Germany prepared for CBRNE incidents and hybrid threats? And how do control centres, communication technologies and networked systems ensure that a shared situational picture emerges in an emergency? The focus will also be on cooperation between civilian and military actors. Specialist conferences included in the trade fair admission ticket Both the European Drone Conference and the Emergency Services Forum will take place directly in Hall 5. Admission is already included in the Security Essen trade fair ticket. Tickets for Security Essen 2026 are available online. A day ticket costs €49. The trade fair is open from 9 am to 6 pm from Tuesday to Thursday and from 9 am to 4 pm on Friday.
iDenfy, the global RegTech solution provider that delivers identity verification and fraud prevention tools, has implemented Czech Bank iD into its electronic identity verification software. The addition of the new digital ID or non-document verification method for the Czech market gives businesses a native alternative for verifying Czech citizens through their existing bank login credentials, without asking for a physical document during the onboarding process. Czech Bank iD is a nationwide, bank-issued digital identification system introduced in the Czech Republic in 2021. It allows citizens to use their internet banking credentials to authenticate themselves for both e-government and private sector services. Separate identity document The system is currently used by over 5,000,000 internet banking users, which corresponds to an adoption rate of 57% across the Czech Republic with 9 million people. Czech Bank iD runs on the OIDC protocol and operates through a bank delegation model, meaning the verification is confirmed directly by the user’s bank rather than through a separate identity document. iDenfy’s non-document verification platform was built to operate alongside the platform’s standard document-based KYC flow. Businesses can configure the platform to automatically route users to the Czech Bank iD path when traditional document capture is unavailable or produces insufficient image quality, a scenario that iDenfy’s internal data consistently shows as a recurring source of session drop-off. The combined flow is available to all iDenfy clients at no additional cost and can be activated in the dashboard settings without any additional integration work. Additional integration work To perform a successful verification, Czech Bank iD checks the person’s given name, family name, middle name, full name, date of birth, nationality, sex, phone number, and full address details. Where available, it can also return document data, such as document type, number, issue date, expiration date, issuing country and authority. This gives businesses a verification result that is both broad in scope and consistent in structure, since the data is returned directly by the bank network rather than extracted from a scanned image. As defined by Regulation (EU) 2024/1183, each of the EU 27 will have to implement the EU Digital Identity Wallet for citizens and residents by the end of 2026. Every bank, payment, and electronic money institution will have to support wallet-based credentials as Strong Customer Authentication measures. Bypassing security controls The Czech Republic has the third-highest risk of cyber fraud globally, according to security firm Gen Digital, which conducted research from Avast, AVG, and Norton companies. Social engineering attacks, a form of psychological manipulation in which criminals trick people into giving up private data, downloading malware, or bypassing security controls, made up 86% of the threats that happened in the country. iDenfy states that for businesses that serve Czech market users, the ability to verify identity through a credential that more than five million adults already use for banking and government access can remove a document capture step that often contributes to onboarding drop-off. It still maintains a secure enough compliance procedure to keep the process trustworthy for both the user and the business so it can validate a real person behind it. Digital identity networks “Czech Bank iD has become one of the most widely trusted digital identity credentials in the Czech Republic. Our clients that serve that market can now meet Czech users on those terms and present a verification path that feels familiar and requires no additional physical document capture at the point of onboarding,” said Domantas Ciulde, the CEO of iDenfy. It is worth mentioning that iDenfy’s KYC software currently covers over 16,000+ government-issued documents across over 200+ countries and territories. If a case is not resolved automatically, it is reported to iDenfy’s internal compliance review team, which works 24/7 to review identities and fix any onboarding issues. “Czech Bank iD is deeply embedded in how Czech citizens already access banking, government, and private sector services. For our clients, adding Czech Bank iD is not just an onboarding improvement. It is a direct connection to one of Central Europe’s most established digital identity networks,” added Domantas Ciulde. Czech Bank iD support is available now across iDenfy’s identity verification platform.
Gunnebo Entrance Control has completed a major entrance control project for ByteDance’s new corporate offices in Dubai Media City and Business Centre, delivering secure and efficient access for one of the world’s pioneer technology companies. ByteDance, the global organization behind TikTok, Lark and Lemon8, selected Dubai as the base for its Corporate Services head office. The facility supports business functions including security, procurement, EHS and R&D and reflects the company’s long-term investment in the Middle East. Maintaining robust protection With a rapidly growing workforce and constant visitor traffic, ByteDance needed to maintain a secure workplace while ensuring smooth, welcoming operations. Managing access for hundreds of employees and contractors daily, alongside the onboarding of new staff, was critical to preventing unauthorized entry to sensitive areas and systems while maintaining a seamless day-to-day experience across the offices. Gunnebo Entrance Control worked closely with ByteDance’s internal teams to align with both security and operational requirements, ensuring employees and visitors could move efficiently throughout the building without disruption while maintaining robust protection across key areas. High-traffic corporate environments In total, twenty-four SpeedStile FLs MAX gates were installed across the two sites: seven in Media City and seventeen in the Business Centre. The SpeedStile FLs MAX is a premium speed gate designed for high-traffic corporate environments, combining advanced security functions with a sleek, professional appearance. Compact in footprint and highly adaptable, the solution integrates smoothly with third-party access control systems. Intelligent detection technology reduces the risk of tailgating and piggybacking, ensuring only authorized personnel gain entry while preserving a smooth flow for everyday movement. Entrance control solutions Delivering the project required close collaboration with ByteDance’s IT teams and civil contractors to align the solution with building design and operational requirements. The installation was completed in line with the timeline for the launch of ByteDance’s new headquarters and has become a central part of the company’s entrance control strategy in the region. Jacob Touma concluded: “ByteDance is a global brand with demanding requirements for workplace security and employee experience. Their new Dubai offices mark an important hub for the company’s Middle East future, and the SpeedStile FLs MAX delivers the right balance of safety, efficiency and aesthetics, ensuring smooth movement while maintaining robust protection. This project underlines our commitment to supporting world-leading businesses with reliable, effective entrance control solutions.”
John Street, Newham, a high‑rise residential development comprising Blocks A and C, has been equipped with a comprehensive life safety solution from Advanced, incorporating SmokeGo smoke control and EvacGo evacuation alert systems to support a stay‑put fire strategy and enhance resident safety. The project, delivered as part of a wider life safety installation by Simple Life Safety Systems Limited, required a robust and compliant approach to smoke control and evacuation alert across two buildings with different heights and risk profiles. Block A is a 14‑storey, high‑rise residential block, while Block C is a smaller, four‑storey building. Each block was equipped with one SmokeGo panel and one EvacGo panel, providing dedicated control tailored to the specific needs of each structure. High‑rise residential block SmokeGo was specified to deliver active smoke control via the fire system, supporting the management of smoke in common escape routes and critical areas. Designed to comply with EN 54 Parts 2 and 4, as well as BS 7346‑8 and ISO 21927‑9, SmokeGo enables automatic and manual control of smoke control fans and dampers from a single, intuitive interface. Its simple matrix‑based configuration allowed the project team to clearly define smoke compartments and cause‑and‑effect relationships, helping ensure smoke is contained and extracted effectively in the event of a fire. EvacGo was installed as a fully independent BS 8629-compliant evacuation alert system, giving the fire and rescue service a reliable and secure means of alerting residents if evacuation beyond the affected flat is required. Each EvacGo panel is housed within a robust, tamper‑proof enclosure and is designed exclusively for use by the fire and rescue service, helping prevent misuse while ensuring clear, decisive control during an incident. Complex residential project John Newton, Director Life Safety at Simple Group, commented: “John Street was a complex residential project that required careful coordination between smoke control and evacuation alert systems. Using SmokeGo and EvacGo allowed us to deliver a fully compliant solution that aligns with the fire strategy while giving the fire and rescue service the tools they need to manage incidents safely and effectively.” The SmokeGo smoke control system and EvacGo evacuation alert system operate as separate, dedicated life safety systems, ensuring smoke movement can be actively controlled while evacuation decisions remain firmly in the hands of the fire and rescue service. This layered approach supports resident safety without undermining the stay‑put strategy that underpins the building’s fire design. Implementing smoke control Shaun Scott, Applications Engineer at Advanced, added: “Projects like John Street highlight the importance of implementing smoke control and evacuation alert systems correctly. SmokeGo makes complex smoke control logic far simpler to configure and manage, while EvacGo provides a clear, compliant evacuation alert solution. Together, they deliver confidence for installers, building managers, and emergency responders alike.” With one SmokeGo panel and one EvacGo panel installed in each block, the John Street development now benefits from a coordinated life safety solution that addresses both smoke management and evacuation alerting in line with current best practice and regulatory guidance. The project demonstrates how Advanced’s specialist systems can be combined to meet the evolving safety requirements of modern residential buildings, delivering compliant, practical solutions that prioritise both resident safety and operational simplicity.
In today’s hospitality environment, properties are expected to deliver exceptional guest experiences and airtight operational security. But juggling physical safety, digital privacy, vendor coordination, and staff accountability isn’t easy – especially when legacy systems like pegboards, logbooks, or unmanaged key drawers are still in use. Intelligent key control systems help users modernise their security while unlocking operational insights for better business decisions. Here are eight ways users can improve security and business intelligence at their facilities using key control: 4 Hospitality Security Enhancements Enforce Access Control: A networked key control system secures high-risk areas like storage, housekeeping, and back-of-house offices with real-time visibility and alerts. Reduce Risk of Internal Theft or Misuse: Automated key storage with audit trails deters misuse and helps quickly identify issues, lowering theft and liability exposure. Improve Accountability and Guest Protection: Detailed tracking holds staff accountable, highlights unusual behavior, and strengthens guest and personnel safety. Reduce Rekey Expenses: A networked key control system prevents lost keys and lets you trace usage instantly, reducing costly rekeying. 4 Business Intelligence Boosters Spot Trends with Key Usage Reports: Automated reports show which areas and tools are used most often, helping users plan staffing, prepare supplies, and detect anomalies. Streamline Vendor and Contractor Access: Grant time-limited, role-based permissions to contractors and deliveries, reducing the need for staff supervision and easing the front desk workload. Maximize Asset Utilization: Keys unlock more than rooms. They also access golf carts, radios, minibars, tools, and more. Tracking usage helps manage inventory, reduce loss, and improve availability. Update Access Instantly: With centralized software, users can revoke or adjust permissions across the property in seconds – safer and faster than manual updates.
Gunnebo Entrance Control has partnered with Queenstown Airport (ZQN) and Custom Technology Systems Ltd to elevate the domestic departure experience, providing greater convenience and security for passengers. Queenstown Airport, a key gateway to New Zealand’s South Island and the country’s fourth-busiest airport, has evolved continuously since opening in 1935. Now serving more than 2.6 million passengers each year, it connects major domestic destinations and east coast Australia, driving ongoing improvements to passenger facilities and operational efficiency. Entrance control solution As part of a dedicated program to enhance the domestic departures journey, ZQN reworked existing café space. A glass wall was installed to relocate the café airside, integrating it with the gate lounge. This provided direct food and beverage access for passengers and created additional seating, all within the same footprint. To support the new layout, Custom Technology Systems Ltd and Gunnebo Entrance Control worked closely with the on-site teams to deliver a tailored entrance control solution that balanced security and passenger flow while accommodating spatial limitations. Adapting to unexpected challenges “The success of this project was achieved by working together, adapting to unexpected challenges, and staying focused on delivering a secure, seamless journey for every passenger,” said Chris Walker, Project Manager at Queenstown Airport. “Every challenge we encountered was met together. Whether it was refining the design, resolving compliance issues, or adapting to the space, we relied on each other’s strengths to get it right.” Gunnebo Entrance Control’s PasSec solution To optimize style, security and passenger movement, the team installed Gunnebo Entrance Control’s PasSec solution, a sleek one-way corridor system designed to prevent backflow while maintaining compliance with strict local and international aviation regulations. Brett Copeland, Managing Director at Custom Technology Systems Ltd, added: “For this works programme, there was a genuine sense of problem-solving together. It wasn’t about one party leading and others following but instead a collaborative process from initial design and specification through to project completion. We each brought ideas, worked through constraints and stayed focused on making the solution fit.” Challenges together to deliver smarter Clive Dillen, Regional Manager at Gunnebo Entrance Control, concluded: “We’re proud of what we achieved here, and the result reflects the true essence of coordination, discussion and trust. That’s what true partnership looks like and marks a major step forward in Queenstown Airport’s continued development." "It stands as a clear example of what can be accomplished when organizations work through challenges together to deliver smarter, more effective outcomes for passengers and operators.”


Round table discussion
At mid-year 2026, the broader economy tells a story of resilience under pressure. Conflict in the Middle East has triggered a shock to the energy supply, driving oil prices up and reigniting global inflation. However, a total downturn has been averted. Exceptional, historic levels of business investment and data center construction are providing a firm floor for growth, offsetting cooler consumer spending and keeping labor markets fundamentally stable. But how are changing economics impacting the physical security market? We asked our Expert Panel Roundtable: How do changes in the broader economic climate impact physical security?
The Internet of Things (IoT) is having a profound impact on businesses across various industries, including security. In physical security as in other business environments, the IoT is changing how systems operate, interact, and create value. In the process, the IoT is driving efficiency, reducing costs, and opening up new avenues for innovation and growth. We asked our Expert Panel Roundtable: How is the Internet of Things (IoT) transforming how security systems are deployed?
In the past, security installers and integrators were used almost exclusively to install hardware. However, the role is changing and expanding along with the technologies used in the physical security industry. Nowadays, an installer or systems integrator is much more likely to use a strategic, IT-centric, and data-driven approach. To gain additional insights, we asked our Expert Panel Roundtable: How is the role of the security installer/integrator changing?
Products


White papers
Preventing Loss, Securing Assets
Download
Safeguard Students With New Techniques And Technology
Download
5 Ways To Strengthen Physical Security With An Integrated System
Download
The Benefits of Edge AI + Cloud For Security Systems
Download
Smart Security Cameras: Excellence in Retail
Download
Is Access Control In The Cloud More Cost Effective?
Download
Innovative Edge Storage Solutions For The Video Surveillance Industry
Download
Enhanced Ethernet Technology (ePoE)
Download
Do You Know The Weakest Link Of Your Access Control System?
Download

Videos
Security devices: Manufacturers & Suppliers
- Dahua Technology Security devices
- Vicon Security devices
- Seagate Security devices
- Aiphone Security devices
- Bolide Security devices
- Vanderbilt Security devices
- Bosch Security devices
- Hanwha Vision Security devices
- ABLOY Security devices
- LILIN Security devices
- Aritech Security devices
- Parabit Security devices
- VIVOTEK Security devices
- Hikvision Security devices
- BCDVideo Security devices
- Sony Security devices
- ComNet Security devices
- Videotec Security devices
- CEM Systems Security devices
- Pelco Security devices
