Header Logo
Log In
← Back to all posts

Volume 102

Aug 03, 2026

Volume 102 | May 23, 2025

Welcome to Brief 102! I needed to get you this Brief for two reasons.

First, there are a good number of new members after the response from our 100th edition and I wanted you all to get a Brief right after. Thank you to all of you who shared your love and to all who have joined.

Second, next week will be ACS25 in San Sebastian, and I wanted to clear my deck to focus on the room. These Briefs are words on paper that typically start from mental tension in my head. And like a good flush, writing these Briefs allows me to exhale. This topic has been grinding on me for a while now, and I am excited to bring it to you. So what is it?

I have said this a lot, but I am ok repeating it: The access control industry is experiencing a transformation. A large group of incumbents who once enjoyed market dominance are facing unprecedented challenges (some don't even realize it due to bad data, or they do, but they are playing hot potato with whoever comes after them and choosing to ignore it) while another smaller group of incumbents and newer players are gaining significant traction or at least the opportunity to win.

This shift raises two questions for me:

First, why are certain brands winning now when cloud-based, mobile-first, and soon-to-be AI solutions have become ubiquitous?

Second, what drives the buying decisions, and why are some companies getting a shot?

I find myself making that "Wait, what?" 🤔 face often. 

For decades, the access control business operated on a predictable model. Customer relationships were remarkably stable - if a vendor secured a client in 1980, they likely retained them through 2019. The industry functioned as an annuity business; we even bragged about it, prioritizing low-risk iteration over innovation, focusing primarily on basic functionality: lock, unlock, and keep bad people out equals safety and security. Everyone was on board, and we did business. But over time, the product requests, business model changes, insecure modern enterprise functionality, and old truths have escalated from "ok, fine" to "I've had enough." 

Here is a little background that has shaped me a bit. The introduction of cloud-based access control systems marked the first significant disruption (it just took time). Companies like Brivo pioneered this transformation, introducing cloud solutions in 2002, followed by cellular technology (2005) and APIs (2007). I was there from 2012 to 2015 and ran marketing along with initiatives like Brivo Labs. The initial value proposition was easy: cloud-based versus on-premises systems. Early adopters fell in love with benefits like "always-on, anywhere access," browser-based interfaces, and recurring revenue models. Integrators bought into "the alarm industry did it, why not you?" End users who adopted early could see the future and want to take a bite out of it early.

However, cloud capabilities are no longer a differentiator. Companies without cloud solutions in their portfolio are now the outliers (good luck with that). This commoditization of cloud technology has forced the industry to seek new ways to stand out.

But who is and how? And if no one is, why is anyone getting a serious look?

Through my observations and conversations with end users and integrators, I have identified some key reasons that weave throughout all the conversations and drive purchasing decisions in today's market. By no means is this an exhaustive list, and for the simplicity of telling this story, I'm telling it through an enterprise lens. But don't be fooled. You can extrapolate from the enterprise examples to whatever vertical you target. The other thing to note is that this is global. It's not just North America. I've talked to people in almost every region, and these stories resonate. Sure, they are ahead in some points, but in others, they are not, so it evens out when you do the math.

Oh, and if you see "quotes" used, that is from notes I took of words used during my conversation with end users and integrators. 

What I found is in the Brief below.

For those of you coming to San Sebastián, see you soon. For those of you who aren't able to make it, don't worry. All that great content will be coming to you in full soon. You will receive a Brief with links to it all (behind a password-protected website).

¡Gracias y hablamos pronto!

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!


Why Some Brands Are Winning in 2025?

The market is frustrated, have resources, and are grouping.

Just flat out, they've had enough. There's growing frustration with the lack of meaningful innovation, outdated user interfaces reminiscent of the 1980s, unfulfilled promises of future improvements, poor value proposition relative to cost, and lack of support for open source and perceived defense of business. 

What's new is interesting. The frustrated and vocal group has a ton of resources. They don't have to eat it anymore. 

Also, other areas of the industry are evolving, giving them opportunities they did not have just a few years ago, and they are doing something about it. Two examples of the evolving market that are giving them comfort in leaning more toward the new are: 

  • More solutions adopt hardware that feels like a standard and turns them into a commodity. It feels like they don't care much about some of the parts they used to care about and are saying, "Give me the one that just works and supports what I want." 

  • Since APIs have opened up to support software solutions like tenant engagement applications (for example, Sharry), identity platforms (for example, RightCrowd), or mobile wallets (for example, Apple or Google Wallet), more software solutions can act as modern access control systems or be a middleware (example SwiftConnect) to bridge into other systems that gives the look and feel of a more modern access control solution.

Modern architecture, integrations, and things that sound like enterprise software (or at least the promise of it)

The enterprise technology landscape has reached an inflection point where the promise of modern architecture has become more compelling than the comfort of legacy systems. I am hearing it over and over again. 

Companies are no longer asking whether to modernize but rather how quickly they can transition to systems that embody the principles of contemporary enterprise software design. There seems to be a sea shift from waiting to doing.

These modern solutions of choice distinguish themselves through cloud-native architecture that treats "distributed computing, elasticity, and resilience" (words often used in my discussions) as foundational design principles rather than afterthoughts or add-ons. Unlike legacy systems retrofitted for the cloud, these platforms are conceived with "microservices architecture, containerization, and orchestration" (again, often words used) at their core. This translates into tangible business benefits: "automatic scaling during peak loads, geographic distribution without performance degradation, and the ability to update individual components without system-wide downtime." Some of them quoted and reported "40-60% reductions in infrastructure costs" when migrating from monolithic legacy systems to cloud-native architectures (I didn't check receipts, but I will take their word for it), primarily due to optimized resource utilization and elimination of over-provisioning safety margins that characterize traditional deployments.

Give me the API. Give me the freedom.

They want systems that operate in an ecosystem, not a silo, which is why the API-first design philosophy has become almost a default must-have. This approach ensures that every system component is designed with integration as a primary consideration. Companies can rapidly connect disparate systems, create custom workflows, and respond to changing business requirements without extensive custom development, just like they can do reports. The practical impact is clear: where legacy system integrations often require months of professional services and custom coding, modern API-first platforms enable business users to create sophisticated integrations through visual interfaces. This democratization of integration capabilities represents an enormous shift in how companies approach business process automation and digital transformation. This is the Utility+ that I talk about often.

Zero Trust

Zero trust came up a lot. I don't pretend to be an expert in it (at all), so here is my attempt to distill what was discussed. In essence, security architecture has evolved, with modern systems embracing "identity-centric access control as a core principle, moving beyond perimeter-based security models" that assume internal network traffic is inherently trustworthy. This approach aligns with zero-trust security frameworks that have become essential in an era of remote work, cloud computing, and sophisticated cyber threats, and they want their access control system to behave like this. Identity-centric systems provide granular access control, continuous authentication, and comprehensive audit trails that satisfy security and compliance requirements. Companies implementing these systems report significant improvements in security posture while simultaneously simplifying user experience through single sign-on and adaptive authentication mechanisms. It supports the transition from keeping bad people out only to also including letting the right person in.

Data to feed

The shift toward real-time event streaming capabilities reflects a fundamental change in business expectations around "data freshness" (I liked this description) and system responsiveness. This functionality also speaks to the IT shift. Modern platforms leverage "event-driven architecture to process" and respond to business events as they occur, rather than relying on "batch processing cycles" that characterize legacy systems. This architectural approach enables use cases previously impossible or expensive: real-time event detection, instantaneous updates across multiple channels, and dynamic adjustments based on the current situation. One person stated that organizations implementing "event-streaming architectures" typically see dramatic improvements in customer experience and operational efficiency.

IoT, but for what it does not for the sake of saying IOT

The promise of IoT seems to be upon us - particularly through protocols like MQTT, positioning modern platforms for the next wave of digital transformation. When most people explained how they saw systems function, I'd usually follow up with "Oh, like IoT" and get a smile and a "Yes, exactly." While full IoT implementation may still be aspirational for many organizations, and I am not sure we are even close to full-throat, the architectural foundation for handling millions of lightweight device connections and processing sensor data streams provides future-proofing that legacy systems cannot match. There is also a vibe around wanting "consumer-like functionality." This capability becomes increasingly valuable as organizations recognize that IoT integration will eventually become a competitive necessity rather than a nice-to-have feature. Modern platforms that support MQTT and other IoT protocols today will be ready to scale these capabilities tomorrow. At a minimum, we should give the trust and comfort that the going forward will continue in this manner.

Trust me, it's just different.

And this trust and comfort is no joke either. Companies mentioned that they are selecting systems based on current capabilities and the promise of what these architectures enable. This "promise" reflects a strategic understanding that today's technology decisions will impact organizations for years. And don't confuse this promise as a "roadmap" promise. This "the architecture decisions made" makes the promise real. Regardless of their current functionality, legacy systems carry technical debt that constrains future possibilities, and they are done waiting. Even when not fully built, modern architectures provide a foundation for innovation and adaptation that becomes increasingly valuable in rapidly changing business environments. Trust and comfort are forward-looking.

Autonomous access control

There is a shift and desire from human-dependent systems in favor of autonomous platforms (there is that word again - platforms). This shift represents more than a technology upgrade—it's a complete reimagining of how security operations function in the modern enterprise. Traditional access control systems operate on a simple premise: a human in every loop - configure, maintain, detect, alert, and rely on human intervention. This approach creates operational overload, critical vulnerabilities through delayed response times, inconsistent human judgment, and the inability to process complex data patterns at scale. The desire for modern autonomous access control systems is seen to eliminate these gaps by creating self-managing ecosystems that configure, anticipate, prevent, and respond to threats without human bottlenecks.

There has to be a belief that the current system has the opportunity to support autonomy in the future. The goal is not to eliminate humans (but they also seem open to reducing the number of humans needed to operate a system) but to elevate them from mundane routines to strategic planning and complex systems. The companies see that those who embrace this transformation now will establish significant competitive advantages in operational efficiency, risk management, and regulatory compliance - and they don't want their system to be the reason they can't do this. They know that those who delay will find themselves increasingly vulnerable to sophisticated threats that outpace human response capabilities. The evolution from legacy to autonomous access control and broader security represents a fundamental shift from reactive protection to proactive risk management—a transformation they cannot postpone.

I'll put it like this: Legacy access control systems create operational friction and security gaps that modern businesses cannot afford anymore. Manual processes slow response times, increase human error rates and require significant staffing resources. Many of these companies are automating everything and carving off our industry as a special unicorn that can not be touched is no longer being allowed. Legacy access control systems typically operate in silos, unable to share intelligence or coordinate responses without major forklifts.

Business models too 

It was mentioned a couple of times that companies also differentiate themselves through their business approach, which includes simplified pricing models that avoid nickel-and-diming customers, comprehensive professional services and implementation support, vertical-specific solutions that address unique market needs, and a strong focus on customer success and support. I found this heartening as I hoped it was beyond technical and product, and it proved true. Every person had a story of how the rep, the pricing, or the service impacted their decision-making. I recognize that this is true even on the legacy side of the industry, but it was different as it was related to the overall shift to being more software-like. 

And you know, this one made me smile: A story.

Beyond technology and business models, the winning companies mentioned have compelling storytelling. They share several characteristics: a clear vision and commitment to advancing the industry, R&D, innovation, authentic brand narratives that connect experience with future potential, and a focus on solving customer problems rather than chasing buzzwords. Decision-makers want to believe in the complete picture and understand a clear story (and none of it seems to revolve around technical specifications). My analogy is that we have shifted from the wood behind the arrow, only mattering to the arrows, too. 

Looking ahead

It is clear to me that the feeling I was having was real. Yes, I know the access control industry is at a pivotal moment. And yes, while there's value in supporting existing installations, the real opportunity lies in embracing modern approaches that address current and future needs because that is where the customer is heading. But that feeling of something being different? Yeah, that's real, too. 

It is clear that success requires more than technical capability—it demands a comprehensive understanding of customer needs, a commitment to innovation, and the ability to execute a modern security vision with a good story—and a customer with an ear open enough to hear it and then to believe it.

Are there examples where all of this above is not true? Yes, of course. But that does not mean that what I explained above does not exist. Why? Because these are real stories and real examples of really large end users not just telling me but doing it.

Thank you to those who took the time to talk to me about this. What an awesome time to be in our industry.

Volume 150
Volume 150 | July 29, 2026 Reminder to JOIN the The Secured Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Welcome to the Access Control Executive Brief Volume 150! As Semisonic sang in "Closing Time"… "Every new beginning comes from some other beginning's end."And here we are.One. Hundred. Fifty. I have written that number (more ...
Volume 149
Volume 149 | July 8, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. iLOQ published its 2025 Annual Report last week, and with my trip to Oulu, Finland canceled due to weather, I figured I'd cover their report instead. Inside the ESG appendices and IFRS statements is a cleaner test of my three c...
Volume 148
Volume 148 | June 29, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. It was a treat to spend the day with ALOA Security Professionals Association. I'm grateful to Dave O'Toole for spearheading the opportunity to be there. Dave is an absolute legend in this industry, and if the locksmith trade c...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.