Volume 100
Volume 100 | May 7, 2025
Welcome to Brief 100!
In celebration of our 100th Access Control Executive Brief (saying it blows my mind)—and as a thank you—we want to give YOU the ability to share it with anyone in your network who would benefit from it, add to the community, and join us. Rather than offering a simple discount, we're giving away 100 free professional monthly memberships! Here's how it works: We created a code. Only existing members can share the code. If you know someone who would benefit from or contribute to this community, you can send them the code. They simply need to sign up here (under Professional Access and monthly) and use the code BRIEF100&THANKYOU. That's it! The first 100 people who sign up get free access for 12 months. Thank you all for being part of it!
ACS25 Update: As you've probably heard from me and the team, ACS25 is right around the corner. The major details are finalized, and we're working on the finishing touches. For those attending and joining us on Slack, there's a dedicated channel under #acs25. We encourage you to connect, network, share ideas, and ask questions. Our new My Views sessions are shaping up beautifully. These 5-minute segments are designed to mirror TED Talks, and I'm delighted to report that after our prep calls with speakers, they're exceeding expectations. Each speaker brings unique point-of-view while delivering well-thought-out, thought-provoking presentations with compelling calls to action. We'll also be announcing two new products and services there. If you can't attend, don't worry—all sessions will be recorded and available on a password-protected webpage to watch as if you were there. If you're still undecided about joining, I want to emphasize the invaluable in-person networking opportunity. While we strive to replicate this in Slack, nothing compares to being in the room with 170 other industry peers. You can review the agenda and speaker list here. Please reach out with any questions about the event, and we look forward to seeing you in San Sebastian at the end of the month!
So here is the plan for Brief 100. After 99 Access Control Executive Briefs, I thought I would look back on our discussion over the years. Reviewing all the Briefs, titles, paragraphs, sentences, and words is pretty amazing. I am not shy to say I am proud of what we've done. I am. It has been a ton of work. It has also been a personal journey, but it's all been worth it in the end, and we are just getting started. I can't thank you all enough for your patronage and support. Without you, none of this can happen. So, if there is one summary for me to share after 99 Briefs, it is A BIG THANK YOU!
There are some themes and insights that we can take a look at since Volume 1 of the Access Control Executive Brief published on 11.8.22. After introducing what you could expect from me, the original topic was "the birth of a new channel called System Integrators." The sentiment and thoughts in that Brief are as true then as they are now. From there, we have written 236,108 words, with an average of 2,434 words per Brief (this one is roughly 2100). At a typical adult reading speed of 200-250 words per minute, it would take 16-20 hours to read all Briefs in one sitting! That is a ton of content. The length of our Briefs has varied considerably - our shortest Brief (#20) contained just 110 words, while our longest (#25) reached 9,002 words.
But before we get into some of the insights and reflections, I wanted to quickly share why I started writing, how it began, and what I've learned. I think it is essential to share this as it underpins what we do today and will continue to do tomorrow.
Let us start with where this all began. The Access Control Executive Brief was a reboot (a better one, in my opinion) of what we did at Group337 with Inside Access Control in March 2020. The two reasons why we started then persist today. First was a business reason—I was reading newsletters and paying for access to interesting content, and I felt our industry needed one for the same reasons. So, I saw a business opportunity and went for it. Second, and much more importantly, writing became an unexpected love that allowed me to express myself and release the thoughts, feelings, and frustrations that consumed me. It's been a wonderful accidental outcome. I didn't set out to find relief, but I found it. I felt that with Inside Access Control and wanted to continue with The Access Control Executive Brief.
The irony is thick, given I was a terrible student who fought against everyone trying to make me do this type of "work" - writing. My parents still laugh and tease me that this is what I do for a living, as it's so contrary to who I was growing up, or at least who I and others thought I was. But in many ways, writing saved my life. It's made my life more better. It's made me a better husband, father, and friend. I'm less agitated than I was early in my career. Sure, my work still consumes me, but not negatively. Somehow, I feel more "heard"—or at minimum, expressing myself in writing, where I must think through my thoughts, combined with that vulnerable feeling of hitting "send" and exposing myself to critique, has been transformative. Again, it's made me just, better. I wish I had found it earlier. For those of you searching for yours, I hope you find it as well. Writing means so much to me now, and I'm grateful some people see enough value in it to subscribe, pay for it, and engage with it daily. It's wild.
Here is to another 100 for me and maybe your 1. If you are thinking about writing or want to try it, feel free to use The Security Breakdownas your safe space to express yourself. It goes out weekly, so grab a pen (or your computer) and write down/type your thoughts. Don't worry about length and format. Just go. Then share. You will be surprised by the response you get. And who knows, maybe you'll find your voice, that next customer, the job you always wanted, or more. You won't know till you try.
Thank you,

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
A Brief Look Back at the Last 99 Access Control Executive Briefs
Since 2022, several recurring themes surface and define our narrative through thought leadership. Let's take a look at a few of them.
The consumer at the center transformation
We've witnessed a fundamental paradigm shift in how our industry creates its purpose. What was once about securing "doors" has evolved into empowering "people." This isn't merely semantic wordplay—it represents a complete reorientation of our value proposition. We no longer just keep bad people out, we are letting the right people in and delivering operational efficiencies and revenue opportunities. By reframing the term "end user" to "consumer," we're advocating for human-centered design principles in access control experiences.
This transformation means acknowledging that behind every credential, every access point, and every authentication event stands a human with expectations shaped by their digital experiences across all aspects of life. The friction-free, intuitive interactions people have come to expect from their consumer technology must now be mirrored in our commercial solutions. Access control is no longer just about security—it's about delivering seamless experiences, user experience, that respect people's time, done ethically, and enhance their daily interactions with the built environment.
Software first access control industry
I've hammered this transition, and its importance has become more evident. Our industry's pivot from hardware-centric offerings to software-driven platforms represents the most consequential shift in how we create and deliver value. This is what differentiates the winners and losers.
This manifests through prioritizing APIs that enable extensibility, ensuring data accessibility that powers intelligence, promoting mobile credentials that meet users where they are, and establishing integration layers that break down silos. The proprietary control systems of yesterday are giving way to open(er?) ecosystems that foster innovation and collaboration. We aren’t there yet, but I believe we will get there.
Companies that cling to hardware-first thinking increasingly compete on diminishing margins and struggle to articulate their unique value. The market is only going to eat so many 6% price increases. Meanwhile, software-led organizations capture outsized market value by creating platforms that scale beyond physical limitations and enable nimble responses to changing market demands. Its the dawn of the $100B market opportunity.
Access Control as Infrastructure (ACaI)
Perhaps my favorite theme is that access Control is Part of a larger digital ecosystem with a vastly expanded value proposition. Rather than existing as an isolated security function, access control has become intertwined with identity management, cybersecurity frameworks, operational workflows, mobile experiences, and cloud architectures. It’s table-stakes.
This positioning elevates access control from purchasing a product to an infrastructure or a platform to being leveraged. We've become a "Utility+" - delivering a utility's essential security functions while enabling business intelligence, operational efficiency, and enhanced experiences that drive tangible ROI across the organization. No longer just TCO.
When access control is properly positioned as infrastructure or as a platform, it transforms from a cost center to a strategic asset. Its data becomes fuel for organizational intelligence, its touchpoints become opportunities for brand expression, and its integrations become catalysts for operational transformation.
Industry narrative and self identity
From early editions through the latest, there's ann undercurrent about our collective storytelling deficiencies, significant marketing gaps, and the unresolved identity crisis plaguing the physical security industry. We've consistently called for improvements in external perception, talent attraction strategies, and messaging alignment.
Our industry has historically defined itself by what it prevents rather than what it enables. This defensive posture has limited our ability to attract diverse talent, secure appropriate investment, and earn a seat at strategic decision-making tables (and make more money). We must articulate a forward-looking vision that positions us not as guardians of the status quo but as enablers of safe, productive, seamless experiences in an increasingly complex world.
This narrative shift isn't superficial—it's existential and it’s real. It will determine whether our industry leads in defining the future of secure spaces or becomes increasingly marginalized as adjacent industries encroach on our territory with more compelling visions.
None of these themes appear likely to fade in relevance over the next 25 briefs or beyond. While progress continues, there remains significant ground to cover. I remain confident that a substantial portion of our industry will awaken to these realities and accelerate their transformation - I call them the “transformed.” This includes all stakeholders—end users, integrators, specifiers, distributors, manufacturers, and service providers—spanning functions from product development to engineering, marketing, and sales. The imperative is clear: we must embody the industry we need to become, not remain tethered to the industry we've historically been.

The Briefs are a nice time capsule as current events help shape the conversation and thought that goes into the writing. Here's how industry trends evolved over time across the Briefs:
Early (#1–#25)
In these early issues, my “getting my legs” Briefs, we explored the foundational shifts reshaping our industry:
-
Unbundling and re-bundling: I really liked this one. We tracked how the traditional access control integrated stack was deconstructed and reconstituted in more flexible configurations, allowing specialized players to emerge while creating new partnership opportunities.
-
Cloud and mobile emergence: We documented the transition from cloud and mobile as novelties to fundamental differentiators that separated forward-looking providers from legacy players.
-
COVID-19 as catalyst: We analyzed how the pandemic didn't simply create temporary disruptions but permanently accelerated digital-first mindsets, contactless, and remote management requirements.
These early Briefs established the vocabulary and frameworks for understanding subsequent evolutions, setting the stage for deeper exploration.
Mid-series (#26–#60)
As my message matured, we delved into more nuanced developments:
-
Hybrid architectures: We unpacked how organizations balanced cloud benefits with on-premises requirements, creating sophisticated deployment models that delivered the best of both worlds. We should just get here. It’s inevitable.
-
Mobile wallets and experience: We expanded beyond basic mobile credentials to examine access integration into broader digital wallet ecosystems and the user experience implications of this convergence.
-
Interoperability imperatives: We highlighted how the increasing complexity of technology stacks drove demand for standards and interoperability that transcended traditional industry boundaries. I still feel as though I’ll be dead or retired by the time we get here but I’m confident we will.
-
Consumer experience focus: We documented how leading organizations applied consumer-grade design thinking to previously single tone security functions.
-
Inclusion and accessibility: We emphasized the growing recognition that security solutions must serve diverse populations with varying abilities and needs. We need to be the industry of enablement not control.
-
Data strategy emergence: We tracked how forward-thinking organizations were beginning to view access data not as a byproduct but as a strategic asset requiring intentional governance. We are a data industry applied in security.
-
Software-led identity infrastructure: We articulated how access control was increasingly positioned as an essential layer in broader identity frameworks spanning physical and digital domains. We are also an identity industry.
Recent (#61–#99)
Our most current analysis has focused on acceleration and convergence across multiple dimensions:
-
Generative AI impact: We've mapped how artificial intelligence transforms everything from installation design to operational analytics, creating opportunities and ethical considerations.
-
Biometric ethics and governance: We've examined the tension between biometric authentication's convenience and the growing regulatory and ethical frameworks governing its use.
-
Regulatory pressures: We've analyzed how data privacy regulations, security standards, and industry certifications create compliance challenges and market differentiation opportunities.
-
Sustainability imperatives: We've highlighted how environmental considerations influence the security industry's product design, deployment approaches, and lifecycle management.
-
Cyber-physical convergence: We've discussed how the once-novel concept of bridging physical and digital security has become standard operating procedure rather than a forward-looking trend.
-
Capital markets activity: Through great pieces written by Tony Dong, we've tracked investment patterns, merger and acquisition dynamics, and valuation models as the industry attracts increased attention from financial players.
-
Global expansion strategies: We've analyzed how leading companies navigate geopolitical complexities, regional regulations, and cultural differences to pursue international growth.
-
Vertical-specific innovation: We've highlighted specialized solutions emerging for commercial real estate, hospitality, healthcare, education, and other sectors with unique security challenges.

Throughout our Briefs, we've identified and often anticipated major digital inflection points that have reshaped our industry. Sometimes, you don't have to look far out. Just pick your head up, look across the room to other sectors and mainstream trends, historically and in current affairs, and you start to see what is happening to our industry. For instance:
Cloud-to-hybrid architecture
We've consistently promoted the inevitability of hybrid deployment models, urging companies to plan for this reality rather than resist it proactively. I’d even go a step further…we have stated, you should already be doing it. This wasn't simply about technological attitudes—it recognized the complex regulatory, operational, and legacy system environments that characterize enterprise security.
The most successful organizations will be those that embrace what is already here: the hybrid future: building architectures that maintain centralized management while accommodating diverse deployment requirements. They recognize that the question isn't "cloud or on-premises?" but rather "what belongs where, and how do we maintain cohesion across the ecosystem?" Solution based selling.
Mobile credentials and wallets
We've (obnoxiously?) promoted the narrative that mobile credentials represent far more than a convenience feature or “card in phone”—a modality of choice and they're the gateway to platform thinking and ecosystem integration. By meeting users on the devices they already carry and value, mobile credentials create daily touchpoints that traditional access cards never could.
Organizations that view mobile merely as a card replacement are missing the strategic opportunity to reimagine the entire access journey.
API-first ecosystems
We've consistently encouraged openness, more integrated, and cultivated developer ecosystems, repeatedly warning against closed systems that resist integration. This advocacy wasn't about technical architecture alone—it recognized that value increasingly emerges from connections rather than standalone capabilities. Plus it is what the customer wants.
Although new to our industry, organizations embracing API-first approaches have discovered that they don't need to build every feature themselves. Instead, they can focus on core competencies while leveraging an ecosystem of partners that extend their value proposition. Plus they can deliver what the customer needs and want by, more or less, getting out of the way and enabling others. This shift from product to platform thinking has coincided with the rise of developer experience as a competitive differentiator. We have only just begun.
AI and computer vision
We forecasted AI's role in transforming access control from a reactive system to a proactive intelligence layer. This transition accelerates across multiple domains—from anomaly detection to predictive maintenance, from natural language interfaces to computer vision integration. To be fair, that just scratches the surface.
The most forward-thinking organizations are either thinking bout leveraging AI or using AI to automate processes and identify patterns, especially the mundane, and opportunities invisible to human analysis. They're using these insights to move from security as a cost center to security as a source of business intelligence that informs decisions across the organization.

I've always believed in pairing critique with solutions. Those who just complain or throw stones but don't come up with solutions either can't think critically or don't understand the business enough to form a complete analysis (if you think I am talking about someone…trust your instincts). We've highlighted structural challenges throughout the Briefs while offering practical paths forward. Here are some examples grouped.
Challenges identified:
-
Resistance to change: Cultural inertia, outdated mental models, and technical debt block innovation across the industry. Organizations struggle to overcome the "that's how we've always done it" mindset, even when they intellectually recognize the need for transformation. The next 30 years has nothing to do with the past 30 years.
-
Fragmentation: Hardware defined moats. Lack of interoperability across hardware and software vendors creates complexity, increases costs, and limits the ability to deliver cohesive experiences. End users face the burden of integration challenges that should be solved at the industry level.
-
Talent and generational gaps: The industry struggles to attract new talent and facilitate knowledge transfer between generations. This challenge is compounded by rapidly evolving technology requirements, even among experienced professionals, creating skills gaps. Plus, lets be real, we haven’t made this industry seem cool.
-
Underinvestment in marketing and storytelling: Our industry consistently fails to articulate its value, evolution, and opportunities to external audiences. This storytelling deficit hurts recruiting, limits fundraising potential, and diminishes our influence in broader technology conversations. No better time than now.
Solutions proposed:
-
Collaboration over silos: We've advocated for breaking down traditional boundaries, particularly between IT and security departments. Organizations that establish cross-functional teams and shared objectives consistently outperform those that maintain rigid separations. We have also advocated for cooperating today with those you competed with over the years. It is called coopetition.
-
Training pipelines and upskilling: We've highlighted the need for systematic approaches to talent development, including partnerships with educational institutions, certification programs that reflect current technology realities, and continuous learning platforms that keep professionals current. It is time to invest in the industry we want and need. Do not carry the bag of yesterday forever.
-
Industry-led standards: We've promoted participation in standards bodies and technology coalitions like NFID, LEAF, and various open standards initiatives. These collaborative efforts can reduce fragmentation, improve interoperability, and simplify the end-user experience.
-
Integrated value beyond security: We've emphasized articulating how access control delivers value across multiple dimensions—enhancing safety, streamlining operations, elevating user experiences, and generating business intelligence that improves decision-making.
The organizations making the most progress on these fronts recognize that these aren't discrete challenges but interconnected issues requiring systematic approaches. They're investing in cultural transformation alongside technological evolution, recognizing that one without the other inevitably leads to diminished returns.

Let's break them down and see how we have dealt with some inevitable trends and predictions over the years. Throughout the Briefs, I've consistently looked for those who have pushed boundaries with forward-looking insights that subsequent developments have largely validated:
Cloud is inevitable, but the hybrid will dominate
-
Now, mainstream practice
-
Just get to the inevitable and stop promoting things in a way only because you didn’t have it already.
Access control will merge with video and identity
-
Still unfolding but gaining traction
-
Next year will be the year. End users and customers want it and the mainstream expects it.
Consumer-centric UX will win
-
Reflected in recent product roadmaps and acquisitions
-
Experience design capabilities have become essential, not optional, requiring new talent profiles and development methodologies within your company. Do you have the talent?
Mobile wallet > what we already have
-
Still unfolding but gaining traction
-
Strategic advantage awaits those positioned now for native wallet integration rather than offline approaches or treating it as a card.
Biometrics having a moment
-
Stuck a bit
-
Is mobile the best thing to happen to biometrics? I believe so, but the utopian voices need to band together and start telling the value creation story and at least compete with the collective dystopian mainstream movement.
AI will reshape marketing, operations, and security
-
Happening rapidly across the industry
-
AI literacy is becoming a core competency, with leading organizations establishing ethical guidelines alongside technical capabilities. Resist at your own peril.
As stated, these are more inevitable truths than predictions, and they reinforce the value of thinking beyond immediate market conditions to identify fundamental shifts that will reshape competitive dynamics and then act on them. This forward-thinking perspective becomes even more critical in navigating increasingly complex technology, regulatory, and market landscapes as we look to the future.
I know that some organizations have embraced these inevitable truths as strategic guideposts. The companies that do will consistently outperformed those that dismiss them as speculative. They've positioned themselves not merely to respond to change but to shape it—establishing thought leadership, influencing industry direction, and creating sustainable competitive advantages.
That is why I wanted us to look back over what we have discussed over the past 2 years. It validates what we're doing and the collective impact we're making. It also allows us to reflect and say, "We aren't crazy"—or at least not crazy with this.
It gives me great pride and even more energy to continue for the next 100 briefs as we work to tell the inevitable story of progress and highlight the people, companies, culture, and technology that are shaping it.
Thank you, and here's to getting to 200!


