Security policy
FireMon, a pioneer in network security policy management and the firewall policy control plane for the hybrid enterprise, announced it has completed its product integration with Palo Alto Networks Strata Cloud Manager to deliver intelligent and interoperable solutions that enable joint customers to innovate faster and solve their most complex cybersecurity challenges. The integration combines the FireMon platform with Palo Alto Networks Strata Cloud Manager to help security teams bring policy a...
Across the enterprise, the “office” is no longer a fixed location—it’s wherever an employee happens to be. For chief information security officers (CISOs) and chief technology officers (CTOs), this creates a growing challenge: how to secure mobile access without compromising user experience or adding complexity for IT teams. Samsung and Cisco are addressing this challenge with the next advancement in Zero Trust Access for Samsung Galaxy mobile devices. By bringing more i...
Zimperium, the world pioneer in mobile security, outlined its new AI-empowered mobile security vision, including the availability of two new AI-powered agents that provide a force multiplier in the battle to harden the mobile attack surface. Globally, cybercriminals have moved to a mobile-first attack strategy, weaponizing AI coupled with highly sophisticated social engineering campaigns. The result is that mobile apps and devices now represent the most vulnerable attack surface in most organiz...
The security industry is positioning itself: months ahead of the event, Security Essen 2026 is already seeing strong demand from companies and a correspondingly high level of exhibitor participation. From 22 to 25 September at Messe Essen, trade visitors can look forward to a comprehensive market overview, a wealth of innovation and excellent opportunities for networking and business development. The ticket shop is now open; tickets for the trade fair are available at the Security Essen website...
Axon, the global public safety technology pioneer, announced a new standard in real-time intelligence during Axon Week 2026, its annual user conference. New AI-powered capabilities enable agencies to detect incidents earlier, access critical information faster, and coordinate responses more effectively while maintaining security and data control across the full incident lifecycle. Incident occurence In the United States alone, more than 240 million 911 calls are placed each year, increasingly...
F5, the global pioneer in delivering and securing every app and API, and Forcepoint, a global pioneer in data security, announce a new alliance to help enterprises secure AI across its lifecycle—from foundational data discovery and classification through runtime protection and continuous assurance. As organizations rapidly deploy AI across copilots, assistants, and automated workflows, security practices are struggling to keep pace. Many enterprises face complex challenges in identifying...
News
Genetec Inc., the pioneer in enterprise physical security software, announces new access control enhancements to Security Center SaaS. The updates simplify day-to-day operations for security teams and give organizations more flexibility and control as they modernise. They include a new front desk experience, faster access to core security tasks, expanded intrusion panel support, and optional biometric capabilities—without requiring disruptive infrastructure changes. Optional biometric capabilities “Security teams shouldn’t be constrained by legacy infrastructure or forced into all or nothing cloud decisions,” said Francis Lachance, Senior Director, Product at Genetec Inc. “Security Center SaaS removes the friction of traditional upgrade cycles while preserving the architectural choice enterprises depend on. We’re delivering enterprise grade access control through the cloud in a way that lets organizations scale, adapt, and modernise without disrupting existing systems or compromising control.” Critical control point For many organizations, the front desk is a critical control point, yet visitor check in and cardholder access are often managed in separate systems. Security Center SaaS brings visitor check in and access workflows into a single cloud-based experience, allowing front desk staff to process visitors quickly while security teams retain clear oversight. Front desk personnel can manage scheduled and walk in visits from a unified interface, while access policies govern how visitors are granted access. Visitor screening rules can be applied during check in to verify individuals against external databases and registries. When a match or exception is detected, predefined actions—such as notifying security staff—can be triggered immediately. Security policy enforcement This approach supports environments such as schools, healthcare facilities, and corporate offices that need consistent visitor controls without adding complexity at reception. By separating front desk tasks from security policy enforcement, organizations can reduce manual steps, maintain situational awareness, and manage visitor access more consistently across sites. Cloud migration should not dictate hardware strategy. Security Center SaaS is engineered to modernise operations without a “rip and replace” mandate. Its open architecture and Genetec Cloudlink appliances allow organizations to bring existing access control and intrusion hardware into the cloud while retaining full control over their infrastructure and modernisation pace. Broader intrusion support The Genetec ecosystem is expanding to ensure security teams can manage disparate systems through a single, unified interface. This includes broader intrusion support for Radionix (formerly Bosch) and Honeywell, with DMP support arriving shortly. Furthermore, a new integration with SAFR SCAN allows organizations to deploy high-assurance facial authentication as needed. This capability provides a faster, more secure authentication method while reducing the operational burden and security risks associated with physical credentials such as cards or badges. The new front desk experience is available immediately to all Security Center SaaS users. Expanded intrusion support is available now for Honeywell Galaxy intrusion panels, with DMP support ready by June 2026. The SAFR biometrics integration will also be available by June 2026. Genetec will showcase the latest version of Security Center SaaS at ISC West in booth 13062.
Global security manufacturer, Gallagher Security, has announced NPSA compliance for the High Security Controller 7000, the most recent addition to their award-winning controller product range. The High Security C7000 has been awarded Automatic Access Control Systems (AACS) and Cyber Assurance of Physical Security Systems (CAPSS) compliance by the UK’s National Protective Security Authority (NPSA). High Security C7000 features Providing customers with the confidence that Gallagher will continue to meet the highest standards of countries in the Five Eyes Alliance and ensure they’re meeting compliances with future-proofed confidence, the High Security C7000 incorporates all the core functions of the award-winning C7000 Standard variant and expands cybersecurity capabilities in key areas to deliver enhanced reliability, resilience, and redundancy. With a Federal Information Processing Standard (FIPS)-approved micro and cybersecurity at the heart, the High Security Controller 7000 enforces security policy set in Command Centre and reports on local security events, with authenticated and encrypted communications to connected sensors, alarm terminals, and readers. Evolving as per the cybercsecurity needs Jason Hunter, High Security Manager UKI, says the new controller has been designed not just for traditional high security sites, but to meet the changing cybersecurity needs of today’s economy. “We’re increasingly seeing an appetite from enterprise organizations who need solutions that are certified to be used on critical national infrastructure,” he says. “These are not necessarily for government sites, but also commercial enterprises seeking to mitigate risk to ensure business continuity. These customers are wanting devices that are designed with that extra level of security – they want to get ahead of emerging threats.” Cyber assurance Gallagher Security’s Value Stream Lead – High Security, Daniel McVeagh, says the High Security C7000 speaks to the high degree of cyber assurance the new controller variant delivers. “While the Controller 7000 Standard already has excellent cybersecurity functionality, the High Security C7000 goes a step further, with bolder government and commercial applications firmly in mind. Specifically, this controller is tested and complies to many stringent government cyber and physical security standards and is built with the latest FIPS 140-3 compliant components for advanced cryptographic security.” Functions and operations Providing End Users with industry-foremost protection against attacks on firmware in the supply chain and a platform ready for the future, Gallagher’s C7000 product range are IP based controllers that can manage all localised access control, intruder alarms, perimeter security, business automation, and logic needs for an organization. Able to operate independently from the Command Centre server, the C7000 product range ensures predefined responses to monitored events, site safety, and continuity, and features a highly scalable system design, able to scale from single door systems to global systems with up to 10,000 controllers per server.
The contract was signed, live at the SPS in Nuremberg, Germany: CADENAS is now the newest member of the Eplan Partner Network. CADENAS Managing Director Terry Jonen and Eplan Managing Director Haluk Menderes signed the new technology partnership agreement on 26 November 2025. The stated goal of the cooperation is the expanded provision of technical device data via the Eplan Data Portal, which will be implemented using a direct interface between the Data Portal and the CADENAS platform 3Dfindit. Connectivity to the CADENAS device During the SPS, Eplan and CADENAS signed a groundbreaking technology partnership that will make it easier for Eplan users to find the right device data. “CADENAS is a strong partner who will help us considerably extend the range of device data available on the Eplan Data Portal with additional, validated content,” says Eplan Managing Director Haluk Menderes. “For our customers, this cooperation is significant. The connectivity to the CADENAS device database expands our quite comprehensive selection of device data with completely new, sometimes very complex configuration data – for instance for the energy sector.” Speaking about the newly sealed deal, CADENAS Managing Director Terry Jonen says, “With the planned connection of 3Dfindit to the Eplan Data Portal, we’re making it easier for engineers to access precise, up-to-date product data and are thereby increasing the added value for our common customers.” Focusing on added value for designers Comprehensive digital device data is indispensable for design engineers. It accelerates project planning and increases efficiency in engineering, making invaluable contributions to greater data consistency. To achieve this, the companies will be developing an interface to the CADENAS portal that users will be able to access via the Eplan Data Portal, meaning directly via the Eplan cloud. Eplan and CADENAS will be working closely together to design the interface, and both companies will be engaging in continued dialog with component manufacturers. The advantages for users at a glance Eplan users benefit from a significantly expanded range of data on offer, for instance, for complex designs Design engineers will have additional options when selecting device data Data consistency throughout the entire engineering process also increases Depth of data and data consistency Now that the agreement has been signed, the technical implementation is getting started. In the coming months, both partners will set up technical working groups to define the specific measures with a view to gradually expanding the cooperation. The goal is to validate added value for common customers along the value chain. This involves various topics and industries, for instance, the energy sector. For Eplan users, this will mean increased depth of data and data consistency.
Smeup, a key partner for companies engaged in digital transformation, now announced the expansion of its adoption of Cubbit, the first geo-distributed cloud storage enabler, as part of a Business Alliance Partnership that increases capacity to 3.2 petabytes, up from the initial 1.6 petabytes. The agreement has a dual objective: to enhance data management and resilience for smeup, and to accelerate the adoption of cloud storage services across the region through the launch of a fully Italian, secure, and cost-competitive offering. In 2023, smeup successfully adopted Cubbit DS3 Cloud, a fully-managed cloud object storage solution, achieving a 30% reduction in Total Cost of Ownership (TCO) compared to equivalent configurations previously run with US-based providers. Digital transformation of SMEs Smeup supports the digital transformation of SMEs and large organizations in the manufacturing, wholesale distribution, and services sectors. As part of an industrial plan aimed at exceeding €100 million in turnover, the company is seeking to expand and consolidate its presence in the cloud market. The traditional on-premises storage solutions previously used, while providing control, proved costly, inflexible, and complex to manage, creating geographically fragmented data silos. At the same time, public cloud services raised concerns related to data sovereignty, geopolitical risk, and unpredictable costs. Internal adoption of Cubbit’s technology In line with its new corporate strategy, smeup has chosen to both expand its internal adoption of Cubbit’s technology and to become a provider of it, launching its own geo-distributed S3 storage offering for enterprises. To do so, the company has integrated Cubbit DS3 Composer — software-defined object storage — into its three data centers located in the Italian regions of Emilia-Romagna and Lombardy. Cloud object storage solutions With Cubbit DS3 Composer, smeup can deliver multiple service tiers from a single intuitive platform, simplifying operations. This strengthens a fully Italian market offering that combines maximum resilience — as data is encrypted, fragmented, and distributed across multiple nodes, ensuring files remain accessible at all times yet never exposed in full — with data sovereignty, flexibility, cost control, and S3 compatibility. This enables smeup to benefit from cloud object storage solutions aligned with the highest security standards, such as NIS2, while expanding into new markets with tailored solutions for specific sectors. Key use cases Key use cases range from immutable backup repositories to cloud NAS for file sharing, application automation, and file and document archiving, through to hierarchical storage management (HSM). As part of the partnership, Cubbit supports smeup via close technical and commercial collaboration — including training, sales support, and joint go-to-market initiatives — enabling customers to benefit from solutions with high SLA standards, expertise, and service quality. Data sovereignty and strict GDPR compliance Gianluca Pellegrini, General Manager at smeup ICS, commented: “The smeup offering has been strengthened by integrating Cubbit cloud storage into our portfolio. This entirely Made in Italy solution plays a fundamental role in enhancing our services. Cubbit’s technology is synonymous with data sovereignty and strict GDPR compliance, ensuring an unparalleled level of security and resilience for our customers, with critical assets hosted on geo-distributed infrastructure." "We are not simply acquiring technology; we are actively investing in the country’s digital future by providing a scalable, secure, and reliable cloud platform. Thanks to Cubbit, we have achieved our goal of having a flexible, distributed architecture and service, enabling us to offer our customers prices 15% lower than with our previous solutions.” Data management strategy Alessandro Cillario, co-CEO and co-founder of Cubbit, said: “We are proud to see smeup double its adoption of Cubbit’s technology, consolidating its data management strategy and extending the benefits already measured internally to its end customers." "With DS3 Composer, European service providers can regain competitiveness in the global storage market without being forced into a price race to the bottom. This is exactly what smeup is doing by integrating Cubbit’s technology into its data centers to create its own geo-distributed, sovereign, and competitive cloud storage service.”
Wachter, Inc., a premier technology solutions integrator and innovator, proudly announces the appointment of James Stark as Business Development and Strategic Innovation Lead. With over 30 years of distinguished experience across various sectors, James is set to spearhead transformative initiatives that will enhance Wachter’s offerings for clients nationwide. A thought leader and respected speaker, Stark has graced national media platforms and industry conferences, sharing insights shaped by a broad career that includes executive roles at major organizations such as Neiman Marcus and Pier 1 Imports. Major cloud hyperscalers His recent experience engaging with major cloud hyperscalers and AI companies, including Google, coupled with his deep technical expertise spanning the software and hardware platforms that enable AI and advanced analytics, provides invaluable market insights that will guide Wachter's innovative national strategies. “Wachter is the industry’s best-kept secret,” Stark states, emphasising the company's unparalleled approach to end-to-end solutions. “They excel beyond basic integration by seamlessly incorporating IoT, AI, and connected technologies at scale. My goal here is to bridge gaps for businesses, driving performance across the enterprise by leveraging business intelligence not just for security, but for optimizing operations and elevating the customer experience with intelligent, connected solutions that truly work in the real world.” Wachter’s vision for the future Matt Tyler, Vice President of Innovation & Business Development at Wachter, highlights the significance of Stark’s appointment: “James embodies an exceptional blend of business acumen, loss prevention expertise, and technological insight. His notable background with industry giants like Google and Meta enhances his capability to align strategy with client needs and significantly elevates how we serve our customers. His deep-rooted industry connections and passion for innovation make him an invaluable asset to our leadership team.” In his new role, James will drive Wachter’s innovation strategy, ensuring that cutting-edge solutions remain at the forefront while strengthening partnerships and enhancing client support across various sectors. Complex security solutions His key responsibilities include: Designing integrated solutions that address loss prevention, IoT, AI/analytics, networking, and system modernization challenges. Collaborating closely with engineering and deployment teams to bring complex security solutions to fruition. Evolving Wachter’s business development to focus on ecosystem-driven solutions tailored to the needs of diverse industries. Fostering collaborative ideation with clients to overcome operational, security, and experiential challenges. As organizations increasingly invest in AI-driven analytics, connectivity, and operational efficiency, Stark’s extensive experience positions Wachter as a key player in the dynamic transformation of technology integration. His leadership reinforces Wachter’s unwavering commitment to delivering smart, scalable, and future-ready solutions that meet evolving market demands.
Google Cloud announced a significant, multi-million-dollar contract with the NATO Communication and Information Agency (NCIA) to deliver highly secure, sovereign cloud capabilities. This strategic partnership is a major step in bolstering NATO's digital infrastructure, strengthening its data governance, and enabling it to securely leverage cutting-edge cloud and AI capabilities. NCIA selected Google Distributed Cloud (GDC) to support the Joint Analysis, Training and Education Centre (JATEC). JATEC will leverage this infrastructure to modernize its operational capabilities and handle classified workloads. Cloud services and cutting-edge AI capabilities GDC air-gapped, a key component of Google's Sovereign Cloud solutions, brings Google's powerful cloud services and cutting-edge AI capabilities into completely disconnected, highly secure environments. This empowers organizations to run modern AI and analytics workloads on their most important data, unlocking valuable insights while maintaining absolute operational control and meeting the strictest digital sovereignty requirements. Leveraging this technology ensures that NATO maintains uncompromised data residency and operational controls, providing the highest degree of security and autonomy, regardless of scale or complexity. This contract underscores Google Cloud's dedication to supporting partners who protect and empower the most valuable data across NATO's allies. Robust and resilient infrastructure "Google Cloud is dedicated to supporting NATO's critical mission to develop a robust and resilient infrastructure and harness the latest technology innovations," said Tara Brady, President of Google Cloud EMEA, adding "This partnership will enable NATO to decisively accelerate its digital modernization efforts while maintaining the highest levels of security and digital sovereignty." "NCIA is committed to leveraging next-generation technology, including AI, to enhance NATO’s operational capabilities and safeguard the Alliance’s digital environment," said Antonio Calderon, Chief Technology Officer, NCIA, adding "Partnership with industry is a critical component of our digital transformation strategy. Through this collaboration, we will deliver a secure, resilient and scalable cloud environment for JATEC that meets the highest standards required to protect highly sensitive data.”


Expert commentary
Physical security isn’t a one-time project or a static system. It’s a dynamic, ongoing process and program that requires constant attention and management to remain effective. While the initial implementation of a security system — what we often call Day 1 — is critical, the ongoing maintenance, service, and adjustments made after systems are operational, or Day 2, are equally essential. Security program long-term Organizations that fail to focus on post-occupancy security operations risk falling victim Organizations that fail to focus on post-occupancy security operations risk falling victim to a phenomenon known as "program drift," where systems and policies gradually deviate from their intended standards over time. To manage your security program long-term, you often need an outside perspective. By engaging a security partner to provide managed services, organizations can achieve a strategic solution for maintaining their security programs' integrity, effectiveness, and efficiency over the long term. Let’s look at the reasons why. Moving beyond Day 1 Day 1 is the milestone moment when a security system is launched — whether it’s a new system, an upgraded access control platform, or a transition to advanced surveillance technology. On this day, all components align with established policies and standards. Yet, Day 1 is only the beginning of a security program's lifecycle. What happens on Day 2 and beyond is often where the real work begins. Without a robust plan for ongoing service and maintenance, security systems can quickly fall out of compliance. Policies become outdated, configurations drift, and vulnerabilities emerge. This gradual degradation — program drift — occurs not due to neglect but as a natural result of decentralized management; competing operational priorities; and the lack of dedicated, knowledgeable resources to oversee the systems. Avoiding program drift Drift is particularly pronounced in physical security because, unlike other building systems Program drift occurs when a security program’s elements — such as access controls, camera placements, or intrusion detection settings — gradually become misaligned from their intended standards. Think of a straight line representing perfect compliance on Day 1. Over time, various factors push individual components off this line. Left unchecked, these deviations accumulate, leading to significant vulnerabilities and deferred remediation costs that would be much easier to manage and predict with a more proactive approach. Drift is particularly pronounced in physical security because, unlike other building systems such as lighting or HVAC, security measures are often viewed as inconveniences. Even when systems function as designed, features like turnstiles, visitor management, or additional access controls may face pushback for being "in the way" of daily operations. This resistance and the Day 2 problems that often result — along with the lack of centralized oversight — exacerbate the risk of misalignment and ongoing inefficiencies. Why centralized post-occupancy management matters Post-occupancy management is critical for maintaining the long-term health of a security program. Facility managers, who are often tasked with overseeing security systems, may lack the technical expertise or bandwidth to handle the complexity of modern security infrastructure. Partnering with dedicated professionals to help meet these responsibilities ensures systems are managed effectively and vulnerabilities are addressed proactively. It also helps improve system availability and uptime, accelerate break/fix response and resolution times, lower ownership costs by reducing unnecessary and repeat service dispatches, and achieve a more consistent end user experience. Moreover, centralized management provides a consistent framework for handling security systems across multiple sites. This consistency is vital in preventing Program Drift, ensuring that local variations or individual decisions do not undermine the organization’s overall security posture. The case for managed services Hiring outside consultants offers a proactive and professional approach to mitigating program drift Hiring outside consultants offers a proactive and professional approach to mitigating program drift. Specialized providers have the expertise, tools, and resources to manage complex security systems effectively and ensure those systems remain aligned with organizational policies and performance expectations. By acting as a dedicated external resource and interfacing regularly with your security team, your consultant can help you build, manage, and optimize a variety of services that help keep your program on track. These services range from system health and availability management (break fix); move, add change management; system configuration administration; and program/project management offices. Key benefits in the following areas Let’s look at how a managed services a partner can yield key benefits in the following areas: Standards compliance. Centralized management ensures that security systems and processes remain in compliance with established policies and standards, reducing vulnerabilities caused by ad hoc changes or decentralized management. Operational efficiency. Managed services streamline maintenance and support workflows, minimize downtime, and ensure quick issue resolution. Enhanced security resilience. Proactive monitoring and maintenance reduce the likelihood of system failures and improve overall system reliability. Standardized processes for move-add-change (MAC) activities ensure that security configurations remain consistent across locations. Cost savings. Outsourced providers help organizations optimize resources, avoid errors, and benefit from economies of scale in service delivery. Strategic focus. Outsourcing also allows internal teams to shift their focus from routine operational tasks to higher-value activities, such as strategic planning, threat analysis, and incident response. Long-term value of security investments While Day 1 success is the foundation of a comprehensive program, what happens on Day 2 determines your ability to realize the long-term value of your security investments. As the complexity of security challenges grows, leaders must prioritize sustained management and professionalized oversight to protect their organizations, making the conversation around post-occupancy security more critical than ever. By adopting innovative strategies, implementing mature toolsets and processes, and leveraging specialized expertise, organizations can ensure their programs remain robust, aligned, and prepared to meet the challenges of tomorrow.
March is Women in Security Month, a time dedicated to celebrating and promoting the contributions of women in the security field—particularly in cybersecurity. This observance aligns with Women’s History Month, providing an opportunity to reflect on the progress made and the work still needed to advance gender equity in security. evolving role of women in security The security industry has witnessed a steady increase in women's participation. According to ISC2 Research in its “Women’s Role in Filling the Workforce Gap” report, women make up an estimated 20 to 25 percent of the security industry. Promisingly, younger generations are entering the profession at higher rates, with 26 percent of working professionals under 30 identifying as women. The security industry has witnessed a steady increase in women's participation The research tells us that women are thriving in a variety of roles, from engineering and system administration to sales, marketing, and project leadership. Key factors driving this transformation include mentorship programs, male allies advocating for gender equality, and cultural shifts recognizing the unique perspectives and strengths women bring to security challenges. These efforts are fostering more inclusive environments and ultimately strengthening the industry. The value of diverse perspectives in security Security is not a one-size-fits-all industry—each organization and facility has unique needs that require varied perspectives. Greater representation of women has introduced fresh approaches to problem-solving, fostering collaboration and driving innovation. By integrating diverse viewpoints, security professionals can create more effective solutions that better address end-user needs. Industry support for women’s professional growth SIA's WISF offers subcommittees such as NavigateHER, SupportHER, and UpLiftHER Organizations like the Security Industry Association (SIA) and ASIS International have established networking platforms and initiatives to support women in security. Events such as the Security LeadHER Conference provide valuable professional development and networking opportunities. Companies are also investing in science, technology, engineering, and mathematics (STEM) initiatives, hands-on training, and recruitment programs to attract more women into the field. Additionally, SIA's Women in Security Forum (WISF) offers subcommittees such as NavigateHER, SupportHER, and UpLiftHER, which provide pathways for engagement and growth. Challenges women in security face Despite progress, challenges remain. Many women still feel it necessary to repeatedly prove their expertise, take on additional informal responsibilities, or carefully navigate workplace dynamics. Imposter syndrome can be another hurdle, even for accomplished professionals. However, women in security are addressing these challenges by setting boundaries, advocating for themselves, and supporting one another through mentorship. By excelling in leadership and technical roles, women are reshaping outdated perceptions and advocating for more inclusive workplace policies. Steps industry pioneers can take To further support women in security, industry pioneers could: Provide targeted professional development and career advancement opportunities. Foster strong, supportive communities that recognize and mentor women. Implement structured mentorship programs that connect experienced professionals with newcomers. Promote workplace flexibility to help employees balance personal and career commitments. Actively challenge biases and advocate for meaningful change within organizations. Advice for women entering the security field Here are key pieces of advice for women considering a career in security: Own Your Expertise – Have confidence in your knowledge and skills. Seek Out Mentors & Allies – Connect with supportive professionals who can guide your career. Build a Strong Network – Join organizations like ASIS Women in Security, SIA Women in Security Forum, or Women in CyberSecurity (WiCyS), and attend industry events to expand your connections. Speak Up & Take Space – Confidently share your ideas and challenge outdated norms. Develop Resilience & Advocate for Yourself – Push past biases, demand the respect you deserve, and negotiate for fair salaries and promotions. Keep Learning & Stay Ahead – Continually build your expertise to stay competitive in the evolving security industry. The future of women in security As the security industry evolves with technological advancements and global changes, opportunities for women will continue to expand. Women are not just participating in the industry’s growth—they are shaping its future. With growing mentorship programs, male allies advocating for gender equality, and ongoing cultural shifts, the focus is no longer just on breaking barriers but on building bridges to new opportunities.
Security technology has witnessed huge advancements in recent years, particularly for those protecting critical assets or information. Facial and fingerprint recognition, ANPR and even 'mac addresses' or a person of interest's gait, now all make up the technology toolbox of forward-thinking organizations' security policy. However, humans remain the weakest link in any security chain, and the only way to correct this is to eliminate the human burden, argues Richard Hilson, head of sales for security access management specialist, Parking Facilities. Here, he examines the pitfalls in relying upon human intervention in critical national infrastructure (CNI) settings, and the future of biometrics to keep assets, information and personnel safe. Recent Verizon report 74 percent of corps are saying that insider threats are becoming more of a concern for them As with any workplace initiative, be it a simple recycling policy or a corporate password protection directive, technology is only as good as those who implement or operate it. While technology can be fallible and gremlins do arise, it’s never as flawed as us mere humans with our unreliable ‘on/off’ switch. Likewise, we carry the ability to reason, to override procedures, or ignore policy, should we wish. Or as it happens, just make mistakes. In fact, according to a recent Verizon report, two out of three insider attacks happen as a result of negligence, and 74 percent of organizations are saying that insider threats are becoming more of a concern for them. Fundamental security practices Security breaches aren’t limited to external threats either, whether intentionally or not, they can come from within. Humans can, and do, ‘go rogue’, whether that’s pre-meditated criminal or malicious intent, or just by taking shortcuts. While data breaches court most news headlines in this digital era, some of the most significant security risks are those posed when employees neglect fundamental security practices such as sharing passwords or access cards. Employee negligence and insider threats Insider negligence remains one of the pioneering causes of security breaches Insider negligence remains one of the pioneering causes of security breaches. Employees who share passwords or access cards may do so out of convenience, ignorance, or a misplaced sense of trust. Unfortunately, this creates vulnerabilities that are left open to exploitation. When multiple employees share credentials, it becomes difficult to trace actions to a single individual. This lack of accountability can complicate incident investigations and allows malicious activities to go undetected. Emergency services resources Furthermore, the sharing of passwords or access cards means inaccurate accounting of personnel, and in the event of an evacuation or major incident, central IT systems will hold misleading information of employees’ locations which could have a huge impact upon safety and potentially emergency services resources. Employees with malicious intent can exploit shared credentials to carry out unauthorized activities while shifting blame to others, increasing the risk of deliberate sabotage or theft of sensitive data. Even when there is no malicious intent, employees who share access credentials risk unintentionally exposing them to unauthorized individuals, such as contractors, visitors, or external attackers. What happens when employees compromise security? Access cards are designed to limit entry to restricted physical locations. When shared, unauthorized personnel could enter secure areas such as control rooms, rail lines, large construction sites, data centers, power plants or indeed any site meant to be kept secure. This creates opportunities for sabotage, theft, or corporate espionage. Sensitive data held within critical sites, such as blueprints, system controls, and customer records Likewise, shared passwords can lead to unauthorized entry into IT systems, allowing hackers to install malware, ransomware, or spyware. For example, a cybercriminal gaining access to an energy grid system could shut down power to entire regions, causing chaos to millions of people, and disrupting essential services. And not all data breaches are caused by online hackers gaining entry through unsecure firewalls. Sensitive information held within critical sites, such as blueprints, system controls, and customer records, becomes vulnerable when access credentials are shared too, and the disclosure of such information can have a serious impact upon a company’s bottom line, operations, and ultimately its reputation. Eliminating the human burden One way to prevent human error, or to thwart malpractice is to reduce the burden upon employees to be compliant, and eliminate our flaws by using technology that requires no intervention, decision-making or reason. Facial recognition is widely used in the civil world now, despite the concerns of various lobbyists. Used correctly it is not a ‘catch all’, but an instant recognition of persons of interest cross referenced against a database of known suspects. Our car parks are governed by automatic number plate recognition (ANPR) to gain access in and out, while border controls are using advanced biometrics for everything from facial and fingerprint recognition, through to recognition of human characteristics and gait, for both entry and to apprehend. The UK Home Office is even accelerating its transition to digital border management, using biometric technology to improve efficiencies, safety, and to track and capture known or illegal persons. What of the CNI sites? But what of the corporate world? What of the CNI sites, our airports, our national construction developments such as HS2 or our high-rise office spaces? We always ask this very question, and also ‘can you afford a security breach’ in whatever environment you’re in? Because the smart, cloud-based technology being used by governments, law enforcement authorities and Border Force have cascaded down through the civil and corporate worlds. Immediate safety and security Security-conscious corps are diligently removing human error, by eliminating the human burden Security-conscious organizations are now diligently removing human error, by eliminating the human burden. With cloud-managed software not only are access points managed through biometric integration, but it also overcomes the issues mentioned earlier around accountability - in that the cloud will always register who has passed through an access point, or out of it. This is critical for both immediate safety and security but also for matters arising from a crisis, or emergency situation. It’s also less admin-heavy, more cost-effective and can manage and store employee records, including background checks. Employee or contractor data is encrypted, their information is safe, their interactions are secure, and businesses are protected. Implement robust access management systems Simple acts of negligence, such as sharing passwords or access cards, can open the door to catastrophic consequences, operational disruption, financial loss, and even, in the case of CNI, national security risks. To mitigate this, organizations can do worse than to implement robust access management systems, and in doing so, release employees from having to be accountable for ensuring the security of the sites in which they work. As artificial intelligence evolves, I see even more robust biometrics coming to the fore, until such time we work and live in environments that are controlled without us even knowing security checkpoints are all around us, and access management happening at every step. It will become as ‘every day’ as an automatic door allowing entry into our local supermarket - but we’re not quite there yet.
Security beat
AI has the potential to enhance the usability of traditionally complex access control and physical security systems. The application of AI (artificial intelligence) within access control is still relatively new, but rapid advancements in generative AI are already transforming how security systems operate. acre security is driving the deployment of generative AI in access control through its acquisition of REKS earlier this year. REKS is a purpose-built generative AI solution designed specifically for acre’s access control platform. Unlike generic AI tools, REKS understands both system and security-specific terminology, allowing users to ask natural-language questions like, “Show me all access denied events at a specific location,” and receive instant results. AI workflows and AI agents “We're starting to see how AI workflows and AI agents, that leverage language models, can potentially be used in conjunction with access control to create new, automated processes around false alarm reduction, system configuration, report generation, data analysis, threat detection, and in-system customer support,” says Adam Groom, Director of Business Development, AI Development Team, acre security. “We expect AI-driven capabilities to evolve rapidly, but the full range of benefits will depend on continued development and real-world application,” he adds. Integrate AI-driven capabilities acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions The best way to think of REKS is as an acre access control expert you can talk to, says Groom. “As AI adoption grows in security, REKS will expand its capabilities, making access control more usable and more efficient.” Groom says acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions the company as a pioneer in next-generation physical security. “These features will add long-term value by enhancing usability and operational insights across various segments,” says Groom. “Work is already under way to incorporate REKS into acre access control, and we’ll evaluate other integration opportunities in the future.” REKS' AI capabilities According to acre, REKS simplifies daily operations, automating routine tasks, and delivering real-time, actionable intelligence. With REKS' AI capabilities, users can interact with the system to retrieve more detailed insights and actionable information from their acre access control system. “This eliminates the need for complex reports, navigating drop-down menus, or manually reviewing logs,” says Groom. “It significantly enhances efficiency and usability for security professionals.” Enhancing productivity and customer satisfaction Key concern is ensuring that system configuration, enactment, and servicing remain within their scope For integrators, the key concern is ensuring that system configuration, implementation, and servicing remain within their scope of expertise. With REKS, that doesn’t change — but the process becomes significantly faster and more efficient. Instead of manually configuring every panel, input, and output — a traditionally time-consuming task — REKS enables integrators to use natural language commands to streamline setup and adjustments, says Groom. This eliminates tedious steps and dramatically improves operational efficiency, allowing integrators to deploy and fine-tune systems with greater speed and accuracy, ultimately enhancing both productivity and customer satisfaction, he adds. Cloud-enabled ecosystems “We are committed to helping organizations modernize their security infrastructure by transitioning from legacy systems to cloud-enabled ecosystems at their own pace — ensuring minimal disruption while maximizing value,” says Groom. “By integrating AI-driven capabilities, we enhance usability and deliver deeper operational insights across all segments.” “Security’s future isn’t about forcing change — it’s about empowering choice,” adds Groom. “Whether staying on-prem, migrating to the cloud, or adopting a hybrid model, we plan to provide a seamless, zero-disruption transition, prioritizing interoperability, automation, and security at every stage.” Generic AI tools AI must be purpose-built for security applications because security demands precision, reliability, and context-aware decision-making, which only focused AI offerings like REKS bring to the table, says Groom. In contrast, generic AI tools, like ChatGPT, are designed to perform a wide variety of tasks, like how humans can learn and do many different things. Instead, purpose-built AI is built to do just one specific function. “REKS adds specially designed artificial intelligence to our access control solutions to enhance both intelligence gathering and the user experience,” says Groom. New applications in access control The integration of generative AI into acre's access control platforms and their broader portfolio A new AI development team will lead AI initiatives at acre, driving the integration of generative AI into acre's access control platforms and their broader portfolio. This team will seek to push boundaries in applying AI to new applications in access control, intrusion detection, and beyond, empowering security professionals to interact with their systems in a smarter, more intuitive way. But don’t worry, AI will not take the human element out of security entirely. AI human capabilities “The reality is that AI will improve upon human capabilities because it is a versatile tool that supports and strengthens security operations, not a replacement for human decision-making,” comments Groom. “It helps operators process large amounts of data quickly and detect patterns that might be missed otherwise.” Rather than removing the human element, AI allows security teams to work more efficiently by automating repetitive tasks and providing actionable data, enabling professionals to focus on critical responsibilities.
In today's complex security landscape, ensuring the safety of building occupants and assets requires more than just cutting-edge technology. Holistic approach The SHIELD certification, introduced by the Secure Buildings Council, is designed to help building owners, tenants, and security professionals navigate this challenge effectively. SHIELD offers a holistic approach to physical security that emphasizes not just the systems in place, but the collaboration among all stakeholders. With practical, actionable guidance, SHIELD certification seeks to become a benchmark for secure building environments. What is SHIELD? Its primary goal is that buildings are equipped with security systems and protocols that protect against threats SHIELD is a comprehensive certification program developed by the Secure Buildings Council to establish and maintain a standard of excellence in building security. Its primary goal is to ensure that buildings are equipped with security systems and protocols that not only protect against threats but also enhance the overall safety and operational efficiency of the facility. Forward-thinking design It encourages a multi-disciplinary approach, bringing together building owners, managers, security professionals, architects, and engineers to foster an integrated security strategy. By adhering to SHIELD's standards, facilities can assure tenants, visitors, and investors that the building is designed to be a secure and resilient environment. The intent is to create safer spaces through collaboration, forward-thinking design, and stringent security measures. Enhancing security and building resilience SHIELD certification helps to ensure that buildings are not only secure from external threats but are also resilient in the face of internal vulnerabilities. This includes everything from access control systems and surveillance infrastructure to cybersecurity measures and emergency response protocols. Detailed framework SHIELD acts as a roadmap to assess and improve the effectiveness of a building's security architecture The certification process provides a detailed framework for identifying potential risks, implementing best practices, and continuously monitoring security measures. For security professionals, SHIELD acts as a roadmap to assess and improve the effectiveness of a building's security architecture. The program emphasizes the importance of both physical and digital security, recognizing that modern threats often cross over from one realm to the other. Benefits for tenants, investors, and facility managers One of the standout benefits of SHIELD certification is the assurance it provides to tenants and investors. Certified buildings demonstrate a commitment to security that can attract higher-quality tenants and increase the building’s market value. For investors, a SHIELD-certified building represents a lower-risk investment, as the facility is better protected against both physical threats and operational disruptions. Standardized procedures Additionally, facility managers benefit from SHIELD's emphasis on clear, standardized procedures for maintaining and upgrading security measures. The certification helps streamline operations by ensuring that all security protocols are applied consistently and reviewed regularly. This results in a safer, more efficient building environment for everyone involved. Promoting collaboration and industry integration Architects, engineers, and security professionals are encouraged to work together from the earliest stages SHIELD certification is not just about the implementation of security technologies—it is also about fostering collaboration among various stakeholders. Building owners, architects, engineers, and security professionals are encouraged to work together from the earliest stages of design and planning. This collaborative approach helps ensure that security measures are integrated into the fabric of the building, rather than being tacked on as an afterthought. Multi-disciplinary synergy Furthermore, SHIELD works in alignment with other industry standards, such as LEED for environmental sustainability and WELL for health and well-being. This multi-disciplinary synergy allows building owners to pursue multiple certifications concurrently, enhancing the building's overall value and appeal. Achieving SHIELD certification: The process The process to become SHIELD certified involves a comprehensive assessment of a building’s security features and protocols. This begins with a gap analysis, where security professionals evaluate the building's current state against SHIELD's stringent standards. From there, a detailed action plan is developed to address any deficiencies. Once the necessary upgrades and protocols are in place, the building undergoes a final audit before the certification is awarded. Incorporating multiple elements SHIELD takes a holistic approach that encompasses not just physical security but also digital and procedural elements A common misconception about SHIELD is that it is solely focused on physical security systems. In reality, SHIELD takes a holistic approach that encompasses not just physical security but also digital and procedural elements. Another misconception is that SHIELD is only applicable to large-scale commercial properties, when in fact it can be adapted for buildings of various sizes and functions. Global adoption of SHIELD certification SHIELD certification is seeing increased adoption across North America, Europe, and parts of Asia. Its focus on a comprehensive, collaborative approach to security has made it particularly attractive in high-risk industries such as finance, healthcare, and data centers. While it is still gaining traction in some regions, SHIELD is poised to become a global standard for building security in the coming years. SHIELD certification represents a significant step forward for building security. By fostering collaboration and emphasizing a holistic approach, SHIELD helps create safer, more resilient buildings that protect both the physical structure and the people and assets inside.
ISC West 2024 mirrored a vibrant industry on the precipice of accelerated change. Factors such as the cloud, artificial intelligence (AI), edge computing, and biometrics are shaping the future of the security marketplace, and they were front-and-center at the industry’s biggest U.S. show in Las Vegas. Foot traffic was steady and impressive, including more than 29,000 security industry professionals viewing 750 exhibitors. A torrent of eager attendees crowded the lobby on the first day and could not wait for the doors to open. When they were admitted, the wealth of technological innovation and business opportunity did not disappoint. Focus on cloud systems Cloud systems were high-profile at ISC West. Camera manufacturer Axis, for example, introduced their Axis Cloud Connect at a press conference. Meanwhile, Genetec officially launched their Security Center SaaS platform, which aims at eliminating points of friction to enable integrators to easily embrace cloud systems from quoting and ordering to provisioning and installing. Camera manufacturer Axis, for example, introduced their Axis Cloud Connect at a press conference Cloud provider Eagle Eye Networks promoted their new “Eagle Eye 911 Camera Sharing” technology under which both non-Eagle Eye Cloud VMS customers (via Eagle Eye 911 Public Safety Camera Sharing) and Eagle Eye customers can opt to share their video feeds for use by 911 operators in case of emergency. If users opt-in, 911 operators can have access to live video as an emergency unfolds. Eagle Eye Networks provides the feature by integrating with RapidSOS call center software. Camera locations are based on geolocation coordinates, and customers can choose if they want to participate and which cameras they want to share. Biometrics in the mainstream Biometrics were well represented at ISC West, including Alcatraz AI, which introduced an outdoor version of their biometric face recognition product. The Rock X works well despite harsh lighting. Alcatraz’s products do not have to be integrated, they communicate just like a card reader using OSDP or Wiegand protocol. “At the show, customers are excited about moving to a frictionless environment and getting rid of existing credentialing,” said Tina D’Agostin, CEO and co-founder of Alcatraz. “We are making access control frictionless, secure and private. The experience can be as passive as possible – people can just walk in.” Multiple types of authentication, and the ability to detect tailgating and stream video SAFR from Real Networks also featured biometric face recognition, emphasizing feature sets, convenience, and price/performance. They offer multiple types of authentication, and the ability to detect tailgating and stream video. A new device is a small mullion mount that is “approaching the price of a card reader, factoring in the need to purchase cards,” said Brad Donaldson, Vice President and General Manager. SAFR focuses on convenience: You don’t have to take out your phone to pass through a door. Enrollment is easy by incorporating existing databases, and costs are lower than competitors, said Donaldson. The system analyses multiple points on the face, turns it into data and then encrypts it, providing a “unique signature for each person.” Credentials in Apple Wallet and Google Wallet AMAG Technology announced the compatibility of credentials with the Apple Wallet and Google Wallet. The company is also embracing a new strategic direction under President David Sullivan. They launched a new website in January, are developing dynamic resources and a partner page, and they now integrate with 120 tech partners. AMAG Technology Financial Services now enables their channel partners to offer leasing and financing options to customers. The big new booth at ISC West reflected an effort to “market different and look different,” according to the company. The big new booth at ISC West reflected an effort to “market different and look different" The new Symmetry Control Room, a command-and-control system, is a relaunch of an earlier AMAG product with enhanced features. Suitable for large enterprise customers, the software enables a big video wall to display all the various systems and incorporates all the data into a single “pane of glass.” Operators can “draw a lasso” around cameras they want to display on the video wall and can follow action across multiple camera feeds. Navigating megatrends A breakfast meeting for integrators, sponsored by Assa Abloy Opening Solutions, was built around the theme “Navigating Megatrends for Sustainable Growth." The megatrends are artificial intelligence, sustainability and cybersecurity. Related to cybersecurity, there are 350 common vulnerabilities and exposures (CVE) published per week, reflecting the continuing threat to cybersecurity. Physical security has a “data lake” of information from various physical security systems that can be an attractive target for cybersecurity breaches. Data sets can be exploited and/or poisoned. The security industry needs to apply “defense in depth” to the challenges of protecting data. “The threat landscape is always changing, and security technology is an iterative process,” said Antoinette King, i-PRO’s head of cyber convergence, one of the panelists. Natural language systems Natural language systems are a newer approach making an early appearance at ISC West Natural language systems are a newer approach making an early appearance at ISC West. Brivo, for example, has an early prototype of its “natural language search capabilities” that can answer questions such as “Who is in the office?” or “Where is Bob and what has he done?” Brivo also promoted its all-in-one door station device that combines a card reader and a camera (for facial authentication) and serves as a video intercom, thus eliminating the need for multiple devices at the door. Brivo is also emphasizing tailgate prevention, facial authentication, and people counting using AI at the edge. Also promoting natural language systems was Verkada, which unveiled a beta version of its AI Search feature that embraces national language capabilities. With AI Search, users will soon be able to use natural language to search for people or items. For example, a search could be “person climbing over a fence” or “person making phone call” or “person wearing football jersey.” Verkada wants to be thoughtful with the rollout and make sure effective guardrails are implemented to prevent abuse and bias. The release should happen in the coming months. Multi-family applications Allegion is promoting the XE360 hardware lock platform in various formats, including cylindrical lock, mortise lock, deadbolt, and exit trim. At the show, Allegion noted an enthusiasm for multi-family applications. “We have been surprised by the people who want to add electronics and to retrofit existing multi-family facilities to compete with newer facilities,” said Henry “Butch” Holland, Allegion’s Regional Director, Channel Sales East Region. Allegion works with 60 different physical access control software providers, including familiar players such as LenelS2 and Genetec Allegion also offers an “indicator” display on its locks, showing at a glance whether a door is locked or unlocked. The “indicator” might also display “occupied” or “vacant.” Allegion works with 60 different physical access control software providers, including familiar players such as LenelS2 and Genetec. Integrator M&A trends Everon looks for acquisitions in areas where they do not currently have support for national accounts A conversation with Everon at ISC West provided insights into the accelerating trend of mergers and acquisitions among the integrator community. Everon, formerly ADT Commercial, has done six acquisitions of local integrators since they changed their name last year. In targeting companies to acquire, they look for a good company with a good reputation, and they consider how the new company’s competencies complement their own. Some M&A strategy is geographic, as Everon looks for acquisitions in areas where they do not currently have support for national accounts. They also consider density, seeking to add new acquisitions in larger markets where they don’t currently have a big market share. “A lot of investment is coming into security because it is seen by investors as recession-proof,” said Michael Kennedy, VP, Mergers and Acquisitions, for Everon. Kennedy met with 95 businesses last year for possible acquisition, and the company only finalized a handful – reflecting that Everon is selective and careful that corporate cultures are aligned. “With an acquisition, the goal is to keep every customer and every employee,” said Kennedy. Voice of the customer ISC West provides an opportunity for manufacturers to listen to the “voice of the customer;” in person, no less. “We have every kind of problem come to the booth,” commented Heather Torrey, Honeywell’s General Manager, Commercial Security, Americas. “People are passionate, interested and very specific with their questions and comments,” she said. “We are driving a complete system, but we are flexible, helping our customers to meet their needs and not try to fit every foot into the same shoe. Sometimes meeting customer needs involves working with competitors," Torrey commented. “It truly comes back to listening to the customer, not just ‘this is what we have to offer,’” she adds. ISC West provides an opportunity for manufacturers to listen to the “voice of the customer;” in person, no less. Edge applications are everywhere at ISC West, and one company is promoting a new approach to expand functionality at the edge. Camera company i-PRO advocates the use of the “Docker” platform for app development, an option they offer on their cameras. Docker “containers” package deep-learning algorithms to make it easier to embed software into edge devices. Anyone can run Docker apps on i-PRO cameras that use the powerful Ambarella chip. A Docker “swarm” can combine multiple edge devices to work together and share resources. For example, the approach can increase computing power at the edge to increase the capabilities of instant analytics. It’s faster and provides better redundancies. A “distributed computing platform” ensures less latency than communicating analytics to a central server. Unification of capabilities Johnson Controls (JCI) also promotes the trend of combining multiple systems into a single pane of glass. Their “Open Blue” platform, with a security version unveiled at the show, integrates various security systems into one, combining data and monitoring device health. Basically, the system manages all resources holistically. JCI also notes a trend toward “unification of capabilities,” e.g., combining access control and video. “The scope of security is evolving from a focus on protection to a broader focus on operations,” commented Julie M. Brandt, JCI’s President, Building Solutions North America.
Case studies
Working in the heavily regulated and frequently targeted financial services industry, the client (a global financial services group) needed to ensure its cybersecurity posture was extremely robust to protect its infrastructure and customer data from threats. The previous threat detection solution posed challenges, notably with a high volume of false positives. Without a robust SIEM tool and relying on less effective UEBA processes, the team recognized the need to fortify its security framework to align with their stringent standards. Another key area of focus was enhancing visibility within their security infrastructure. The existing setup presented an opportunity for improvement in consolidating monitoring capabilities into a unified interface. Additionally, the team wanted to enhance oversight of active directory actions, specifically addressing enumeration attacks, and monitoring the controlled export of company data by internal users. The solution Brought in to increase visibility and reduce overall risk, RiverSafe suggested they implement Exabeam, which would provide the company with all the best-in-class UEBA tools needed. RiverSafe suggested Exabeam due to the platform’s efficient data processing, simple architecture, scalability, and ease of deployment. The off-the-shelf content within Exabeam’s UEBA dashboards and reporting tools offered another key benefit, giving the security team access to data pre-built models and statistics that would allow them to start monitoring and flagging events immediately. Finally, Exabeam’s smart timeline feature that merges all user activity into one stream would address the visibility issue. Security and monitoring purposes With the client ready to implement, RiverSafe deployed Exabeam on their AWS Environment following best practice guidelines. The team mapped out relevant log sources for the system, and onboarded all data streams, filtering and fine-tuning everything to ensure any information being ingested was relevant for security and monitoring purposes. RiverSafe then developed and deployed use cases scoped out in partnership with the client, helping them to get maximum value from their Exabeam implementation. This documentation included custom roles, models and parses, as well as other quality of life improvements, additional search filters, and guidance on maintenance and monitoring techniques. The outcome The client now has an established monitoring workflow for its security team that’s baked into their day-to-day tasks. The team can monitor the entire environment quickly, and has significantly reduced the time it takes to assess threats like phishing and brute force attacks, and investigate unusual internal behaviours. Following RiverSafe’s advice, the client has been able to scale its Exabeam solution by accessing the right hardware required to run the product efficiently. Data loss and maintaining data integrity Noise from the SIEM has been reduced thanks to the optimization work conducted on log source onboarding. This has resulted in less complexity, fewer false positives, and easier access to the precise information that the team really needs. The security team now has visibility into email, endpoint, active directory, and web activity, and is able to monitor these frequently targeted areas for suspicious events and behavior. This visibility now also extends to file activity, protecting the company from potential data loss and maintaining data integrity. Managing security data and identifying trigger points Siloes have been eliminated, with security insights now located in a single repository for maximum perceptibility. From server performance to traffic flows, whatever’s happening across its pan-global regions, the security team know about it. Exabeam has equipped the team with a simpler, more effective way of managing security data and identifying trigger points—resulting in a 30% reduction in time spent on threat hunting.
In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organization. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimize operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialized expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organization. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimize the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.
The client, a British media and telecommunications company, was looking to increase operational efficiency, save time spent on identifying and addressing vulnerabilities and reduce risk by increasing visibility across their environment. With multiple security tools in different places, security data was siloed and needed to be accessed separately. This led to long periods of time spent jumping between tools to find data, and a lot of context switching when it came to looking at the results. Developers, security teams and senior directors were forced to search in multiple places for critical, often time-sensitive information about vulnerabilities. Risk of vulnerabilities Not only did this eat into their valuable time, but it also meant they had no overall visibility into the organization’s security posture. This lack of visibility significantly hampered the development process, as developers struggled to locate and address security issues. In addition, the organization did not have centralized CI/CDs, instead running different pipelines for individual developers or teams. Combined with poor visibility, this lack of efficiency was causing major frustration for the development team, slowing down development and increasing the risk of vulnerabilities in the code going undetected. The solution RiverSafe was initially brought on board to address the issue of decentralized security data, and help improve operational efficiency. The team’s goal was to allow for the results to be sent directly to the developers without them needing to access and search multiple security platforms to find the information they needed. The RiverSafe team created an integration script for the developers to execute when they were running their pipelines. Once triggered, the script would send a notification to a server that RiverSafe had specifically designed, which collated the identified vulnerabilities and relayed them back to the developers’ pull request. This ensured the development team got the information they needed to improve the security of their code. The next phase: Developing the data insights RiverSafe consultants worked alongside the client’s team to take all the security data that was being collected and, rather than sending it to individual developers’ pull requests, instead created and directed it to a pane-of-glass tool. This tool allows the developers to log in and see their repositories and projects in one place. For management, it allows them to have a complete picture of all the vulnerabilities and what they are impacting, on both individual repositories or a given product. The tool also allows them to build reports and includes a scoring model to give a visual rating so everyone can easily see if their repositories are secure or not. The scoring system, ranging from insecure to excellent sends alerts to let the developers know if their repositories fall below a certain level so they don’t need to continually monitor themselves. The RiverSafe team also provides advice on the steps that should be taken to remediate any identified vulnerabilities. Multiple security operations A key requirement of this tool was that it supported multiple security operations, including SAST (Static Application Security Testing), which would look at code smells and general quality of life, Source Code Analysis (SCA), which would look at which libraries are being used and also Secret Scanning to look for secrets in the code. RiverSafe also wanted to ensure that all of this is serverless on AWS to minimize the time spent on infrastructure maintenance. After launching, RiverSafe continued to work on improving this tool, making quality improvements, performing maintenance, and enhancing the integration via the shell scripts. The outcome The tool now brings together data from over 22,000 code repositories into one centralized place, allowing the client to see all of their security information, what libraries were most common, where the vulnerabilities were, and to start looking for trends. Developers and other stakeholders no longer need to scour multiple locations for vulnerability data, saving the company huge amounts of time and making its development process more efficient. With the bespoke script in place, the data comes to them. This increase in visibility has also led to improvements in response times to zero-day vulnerabilities. Previously, it could take weeks or even months to find all the affected repositories. However, since implementing RiverSafe’s custom tool, the team has been able to locate repositories featuring the vulnerable package immediately and remediate any issues quickly, massively improving their overall security posture. Thanks to this uplift in operational efficiency, the development team is now able to spend more time improving their code. RiverSafe and the client’s team are now working on expanding coverage throughout the organization, improving analytics and alerting, and centralizing CI/CD pipelines.
A major UK retailer known for its quality clothing, home products, and premium food offerings recently migrated their SIEM platform to Microsoft Sentinel, which was integrated with other Microsoft security tools, including Defender. Over the months, multiple configurations had been built up, creating complexity within the system. The alert overload problem After the migration, the SOC (Security Operations Center) team became overwhelmed by a flood of alerts—many of which were false positives. This not only drained their resources but also weakened their security posture, as the team couldn’t thoroughly investigate the flood of alerts. RiverSafe’s solution: Optimising configurations RiverSafe was brought in to address this issue and guide the leading UK retailer on reviewing Microsoft Defender configurations and fine-tuning the Microsoft Sentinel queries. The consultant conducted a thorough review of the existing configurations and provided actionable recommendations to the SOC team. Some changes were straightforward and implemented quickly, while others required collaboration with multiple teams across the organization—something the SOC team had issues in getting implemented over a few months. Facilitating communication for effective implementation The consultant facilitated communication between the SOC team and other departments, providing detailed documentation and clear explanations of why these changes were necessary. By bridging this gap, they ensured the required changes were finally actioned and documented with high standards. Key impacts Within a few weeks, they achieved the changes the SOC team had been pushing for over the few months, fostering better collaboration between the networking and security teams. Alerts were reduced by 62%, significantly improving team efficiency by cutting out noisy, recurring alerts. The improved configurations enhanced the company’s overall security posture, allowing the SOC team to focus on real threats and respond more effectively.
One of the world’s pioneering energy companies embarked on a transformative journey to modernise its development infrastructure with an Internal Developer Platform (IDP). This case study explores how the organization tackled key challenges to remove barriers, streamline workflows, and improve developer productivity. The challenge The company’s development environment presented several obstacles that impacted team efficiency and overall productivity: Lengthy Provisioning Times: Development resources often took excessive time to provision, leading to delays and bottlenecks. Cumbersome Processes: Resource allocation relied on complex, manual workflows, adding unnecessary friction to the development process. Extended Onboarding: New projects faced onboarding times of 4–6 weeks, delaying time-to-productivity for developers. Inconsistent Practices Across Teams: Varied development practices led to inconsistencies and technical drift from organizational standards. High Cognitive Load: Engineers were required to manage knowledge across multiple domains, increasing their cognitive load. Increased Support Overhead: Complex infrastructure needs led to elevated support requirements, which stretched engineering resources. The solution journey The company engaged RiverSafe to collaborate with its DevOps team on a multi-phased journey toward an automated, developer-friendly platform. Phase 1: OpenShift implementation The initial phase involved adopting OpenShift to simplify cloud operations and establish a unified framework: Pre-Configured Workspaces: Provided developers with pre-configured environments, reducing setup time and manual tasks. Automated Provisioning: Automated the allocation of resources, removing manual paperwork and streamlining workflows. Security and Observability Enhancements: Embedded platform-wide security guardrails and introduced tools for chaos engineering and observability. CI/CD Pipeline Automation: Established automated continuous integration and delivery (CI/CD) pipelines to accelerate deployment cycles. Phase 2: Building the full IDP Building on the OpenShift foundation, the organization worked on creating a comprehensive IDP designed to: Simplify Deployments: Introduced one-click deployment capabilities to enable rapid iteration and deployment. Enable GitOps and Monitoring: Integrated tools like ArgoCD and Crossplane for GitOps, and Grafana and Loki for real-time monitoring. Streamline Resilience and Testing: Added advanced testing tools, including ChaosMesh for resilience testing and PACT for contract testing. Standardize Development Workflows: Established standardized resource definitions and centralized operational management to ensure consistency. Results to date Quantitative improvements Deployment Time Reduction: Cut deployment times from 2 weeks to 2 minutes, dramatically speeding up the development cycle. Faster Onboarding: Reduced onboarding time from 4–6 weeks to just 30 minutes, enabling new projects to start quickly. Lower Support Overhead: Streamlined processes and automation have significantly reduced support requirements. Qualitative benefits Standardized Developer Experience: Created a more consistent, efficient environment for developers across teams. Reduced Cognitive Load: Engineers can now focus on core development tasks instead of juggling multiple domains. Enhanced Security and Compliance: Automated guardrails ensure compliance and improve security practices.
A major oil and gas organization faced a critical challenge in securing its applications at scale. With a vast, globally distributed technical organization, security and development teams operated in isolation, each focused on their own priorities. This siloed approach created significant bottlenecks, leading to slow vulnerability remediation, missed security risks, and frustrated developers. A common problem in large enterprises In large, complex organizations, security is often seen as a gatekeeper rather than an enabler. Security teams are tasked with identifying vulnerabilities but lack the mechanisms to ensure fixes are implemented effectively. Meanwhile, development teams are under pressure to deliver features rapidly, often seeing security as an external function rather than a core part of their workflow. This misalignment results in: Backlogs of Unresolved Security Issues: Security vulnerabilities piled up because developers had no direct accountability for remediation. Without embedded security expertise, fixes were delayed or deprioritised in favor of feature development. Slow, Inefficient Security Processes: Security was treated as an external checkpoint rather than an integrated function. Developers had to hand off security-related work, leading to long lead times between identifying and resolving vulnerabilities—sometimes spanning multiple sprints. Lack of Clear Ownership: Security was considered “someone else’s problem,” rather than a shared responsibility. Without direct security support within development teams, security best practices were inconsistently applied, increasing risk across the organization. Developer Resistance to Security Processes: Developers often saw security as a blocker rather than a partner. Security reviews felt like an extra burden, slowing down releases rather than enabling a more secure development process. These challenges are not unique to this organization—they are common across large enterprises where scale, complexity, and competing priorities make security integration difficult. The organization knew it needed a different approach—one that would embed security into the development lifecycle without slowing down innovation. The solution: Embedding security engineers into development teams To break down silos and improve security efficiency, the organization introduced Embedded Security Engineers within development teams. This approach ensured that security expertise was always available where it was needed, eliminating bottlenecks and enabling a proactive security culture. Key Changes Implemented: Security Engineers Became Part of Dev Teams Instead of working as an external function, security engineers were placed directly into development teams. This eliminated handoffs and competing priorities, ensuring security expertise was built into day-to-day development. Security Became Seamless and Developer-Friendly Security engineers worked alongside developers to automate security checks and integrate them into existing workflows. Hands-on support was provided to help developers understand why security fixes mattered and how to address them efficiently. Faster Vulnerability Remediation With security engineers embedded, vulnerabilities were now identified, triaged, and resolved within the same sprint. The organization moved from reactive, end-of-cycle security interventions to continuous security integration. Building Long-Term Security Capability Developers were trained to proactively manage security in their codebases, reducing dependency on external security teams. Teams created and maintained their own threat models within a few sprints, enabling self-sufficiency in secure development. Minimised Dependency on External Reviews Security was no longer an afterthought that required costly external audits or last-minute fixes. By shifting security “left” into development, teams could proactively manage risks before they became critical issues. The outcome: Security as an enabler, not a barrier By embedding security engineers within development teams, the organization achieved: Faster Security Fixes What once took multiple sprints to resolve was now often fixed within a single sprint. Security became an enabler of fast, secure development rather than a blocker. Stronger Collaboration Between Dev and Security Security was no longer a separate function—it was part of the team. Developers had immediate access to security guidance, leading to better, more secure coding practices. Reduced Bottlenecks and Handoffs Security was no longer a slow-moving external review process. Developers had real-time security support, eliminating delays in identifying and fixing vulnerabilities. A Scalable, Self-Sufficient Security Culture Developers took ownership of security, reducing reliance on a stretched central security team. Teams became security champions within their own projects, ensuring security was integrated into every stage of development. Conclusion: A model for large-scale security integration This transformation enabled the organization to scale its security practices without slowing down development. By embedding security engineers within development teams, they shifted from reactive security fixes to proactive security integration, ensuring a faster, more resilient approach to securing applications.


Round table discussion
In many cases, architectural design and layout dictate optimal placement of security devices like cameras, access control readers, and sensors. Poor design can lead to blind spots, reduced coverage, and ineffective surveillance. However, planning that involves all the various stakeholders can maximize both security and design elements. We asked this week’s Expert Panel Roundtable: When are building design and physical security systems complementary? When are they at odds?
There is no shortage of threats facing security professionals, including some that are new and emerging. Understanding various new threats allows individuals and organizations to take proactive steps to protect themselves, but the first step is to identify what those threats are. Early detection of threats can minimize the impact of a successful attack, whatever the vulnerability at issue. We asked this week’s Expert Panel Roundtable: What new and emerging threats will physical security professionals need to be prepared for in the future?
Manufacturers make things. That hasn’t changed. Manufacturers today still produce finished goods from raw materials using various tools, equipment, and processes. What is evolving is a greater emphasis among manufacturers on understanding and meeting customer needs. In the security industry and elsewhere, the role of a manufacturer is expanding from a purely production-focused function to one that embraces technology, prioritizes adaptability, expands service offerings, and caters to a more demanding customer base. We asked this week’s Expert Panel Roundtable: How is the role of the manufacturer changing in the security market? Is “manufacturer” still the best term to reflect the changing role?
Products


White papers
Safeguard Students With New Techniques And Technology
Download
How To Implement A Physical Security Strategy With Privacy In Mind
DownloadCybersecurity in Keyless Access Management
Download
Cybersecurity In The Physical Security World
Download
Preparing Your Organization With Quality Situational Awareness
Download
The Role Of IT In Physical Access Control
Download
Expanding Video Surveillance In The Enterprise Market
Download
9 Opportunities To Upgrade Your Access Control Technology
Download

