Volume 110
Volume 110 | August 26, 2025
Click on the above image and use code sxst3gkbkn to hear the audio version.

As I write this on the plane ride home, summer is officially over. Or at least mine has. Like many of you, my kids head back to school Monday, my calendar is stacked with meetings, the out-of-office replies are gone, events are filling the horizon, and it’s time to kick Q3 into gear (or Q1 for some of you on a different fiscal clock).
Before we know it, the year will be over. I know, I know…I’ll stop. Still, I always feel this moment marks the start of the slide toward year’s end, and it comes with a flood of emotions: excitement for what’s ahead, a bit of sadness that summer is over, gratitude for the opportunities, and happiness for the time with family. Overall, it was another epic season of globetrotting across the access control industry.
This summer took me to Turkey, San Francisco, Australia, New Zealand, Pittsburgh, Ft Lauderdale, Singapore, and Indonesia. At every stop, I was welcomed warmly, engaged in fascinating discussions, shaped by new insights, immersed in culture, and spoiled by incredible food and drink. I left each place with a full mind, heart, and stomach.
And with that, I also walked away with a few clear confirmations:
What we’re doing matters. It’s appreciated and carries a sense of ownership among everyone involved. It’s a grind, but the global security community is large, growing, and committed to forging change.
Every place has a story. Countries, cities, companies, and people all have something worth telling.
Markets are more alike than they are different. There are nuances, but the similarities outweigh them. Sydney is not so different from Minneapolis. Bali is not so different from London.
We can elevate all of us if we reframe competition, opportunity, and value.
There has never been a better time to be in this industry. I know you hear this from me a lot, but I find it important to help remind you. We stand on a strong history with an unobstructed runway ahead. Whether you choose incremental progress or exponential innovation, both paths are available and valid. What matters is the desire to act and the willingness to partner along the way.
Trips like these also give me perspective on what Hilary and I are building with The Access Control Executive Brief and our other initiatives. Every summer, we reset and refocus: What’s working? What’s not? What do we want to build? What do we stop doing? Coming out of this season, we’re clearer than ever. Our opportunity is to build a global community with the resources to support it, not just for access control, but for all security. To do that, we will be more open, specific, and intentional about what we’re delivering.
For a while, it worked to be a bit of a mystery about how we operate, but it’s time to change that. You should expect clarity from us on what we’re doing, how we’re doing it, and what’s coming next. Whether that’s bringing more end users and channel partners onto the platform, building an industry demo site, or tackling education, training, and recruiting head-on, you should expect more from us. And we’ll deliver.
Which brings me to this Brief. It’s one of those issues where I have a million things running in my head, and I’m putting them down for you. Think of it as more musings than a single thread. Like a hit list of ideas and observations, I believe, will help you make sense of what you’re seeing, or spark something new that pushes you toward innovation rather than just progress.
Here’s to a strong second half of 2025. And if you need anything, reach out.
Before we dive into this week’s Brief, I’d love your input. I’ve put together a quick one-question survey: What would you like to see, read, or hear more of from me and The Access Control Executive Brief?
Your feedback helps shape what we do, and I’d love to hear directly from you. Please let me know your thoughts here: https://mqt7vln1m2y.typeform.com/to/N1XYy3uw.
Alright, back to the Brief and first up I want to tell you about what I hope becomes a movement that reframes the conversation around biometrics from dystopia to utopia.
A new white paper from The Access Control Collective and RealSense
We’ve been talking about biometrics in access control for years, but only now is the ethical conversation starting to catch up…getting louder and louder. The dystopian narrative is organized, loud, and actionable, driving the debate. The utopian view, while often correct, has been fragmented, overly technical, and ultimately ineffective. I like to say “right but not productive.”
This white paper is our effort, together with RealSense, to reset the conversation. Our goal is to provide a foundation the industry can build on and to make the case that facial authentication isn’t just “ready,” it’s already here. The real question is no longer if adoption happens, but how responsibly we implement it.
There’s a lot in the white paper (and I’m proud of it), but here are three points I want to highlight:
First, security and convenience are no longer in conflict. Facial authentication removes friction at the door, eliminates lost or stolen credentials, and outperforms PINs, cards, and fobs in speed and assurance. One-to-one matching has smoothed early adoption, while one-to-many enables true enterprise scale. When applied correctly, biometrics deliver both high levels of throughput and increased assurance. It’s hard to beat.
Second, the barriers are ethics and perception, not technology. Privacy, consent, transparency, and bias remain the real hurdles. Too many still equate facial authentication with surveillance. In reality, encryption, liveness detection, and edge processing can be deployed to protect individuals and earn trust. But that only happens if enterprises lead with fairness, choice, and openness.
And third, regulation is the next frontier for biometrics. The U.S. patchwork of state laws, the EU’s GDPR, and frameworks in Canada and Mexico make compliance complex. Enterprises that succeed will embrace that complexity and prove to users that protecting rights and data is non-negotiable.
In the end, facial authentication could become the default credential in enterprise access control, but only if we shift from a technology conversation to a responsibility conversation.
Download the full white paper here, and let me know if you’d like to join the discussion. RealSense and I are just getting started.
The Secret to Enterprise Systems Scaling is…Badging?

This summer I had the chance to tag along with my wife to one of her work events. As many of you know, she works at large enterprise software provider. I don’t talk about it much, and I’ve intentionally kept a wall between her world and mine, even though it’s becoming increasingly clear that enterprise software and physical security are on a collision course. (If you follow Brian Tuskan on LinkedIn, you know he’s been one of the loudest voices showing where these worlds are intersecting.)
Over the course of a week, I found myself at dinners and social gatherings surrounded by the top enterprise software system integrators in the APAC region. Naturally, I asked a lot of questions. I wanted to test my own hypotheses and see if what I’ve been writing about and saying holds up in their world. I’m happy to report it does. Not only do they see physical security as a form of business value creation, but many of them are actively building it into their client offerings. They just didn’t realize it and call it “access control.”
Where are they starting? Two very specific places: Badging and rebadging workflows and employee workflows to access secondary offices and spaces.
Interestingly, they didn’t initially describe this as “access control.” To them, it was simply workflow and user experience. When pressed, they defined access control narrowly as locks and card readers. Hardware. We are always viewed as hardware.
Hearing this was both eye-opening and validating. Eye-opening because it shows how outsiders frame our industry’s value and where they are subconsciously drawing the lines. Validating because it confirms what many of us already sense: the convergence is upon us, the opportunity is enormous as it hits a new gear, but it is only ours if we claim it. If we don’t, this group will reframe our work as hardware and the software, above system configuration, will become just another workflow feature inside a broader enterprise value proposition that they deliver. They will eat our industry exponential value one badging workflow at a time and leave us with the incremental opportunities as we have it today. Make no mistake: large, capable enterprise software integrators are already creeping into our customers’ worlds. It’s time we collectively do more about it. Including me.
One other observation struck me. Many of these large global integrators with scaling capabilities actually build their own cloud infrastructure in each country where they operate, then run services on top of it. They don’t rely solely on the software or in our case a manufacturer’s cloud. This approach drives high adoption, reduces friction, and lets them adapt more fluidly to varying laws and regulations across regions.
It got me thinking: what if our industry’s large global integrators with scaling capabilities, say MC Dean or SECOM, took the same approach? What if they and others built country-by-country cloud infrastructure to accelerate adoption and growth? How would that reshape access control’s role and pace of adoption globally? Would it?
The Difference Between Progress & Innovation

The idea of progress versus innovation isn’t new, but I was reminded of it while reading Boom: Bubbles and the End of Stagnation by Byrne Hobart and Tobias Huber over the summer. The book explores why technological and scientific advancement has slowed. They call it “the Great Stagnation” and argue that speculative bubbles can drive transformative breakthroughs. Case studies from the Manhattan Project to Bitcoin show how periods of collective “irrational exuberance” can, if directed well, fuel exponential leaps forward.
That framing made me think about where our industry sits today. Plus, I like the word exponential. For the most part, we’ve been stuck in incremental progress, filled with being risk-averse, cautious, and predictable. Don’t get me wrong, it’s been fruitful and we have seen progress. Yet we still label these steps “innovation.” With all respect, mobile is rolling out incrementally. Cloud is progress, but it’s rarely deployed in truly innovative ways. Most integrators follow suit. Specifiers are the same. Programs are tweaked, not reborn. All of this holds the potential for genuine innovation, but only a small fraction of the industry is pushing it that way. Most aren’t. We know who they are; they break through the noise and are built to last. But we need more. You need more. I need to do more.
What we need is something bolder. Innovation that feels wild, exponential, even “bat shit crazy.” Progress is valuable, no doubt, but too often our industry hides behind progress as a safe substitute for real disruption. Typically, because we are afraid we will disrupt ourselves.
And when actual innovation does appear, we often reject it or make excuses for why it isn’t good or won't work. Take Verkada’s go-to-market strategy of building demand directly at the end-user. Controversies aside, it was disruptive and innovative for our industry and forced the rest of the industry to rethink. Instead of learning from it, many dismissed or outright hated it. Ironically, I suspect most of the same critics are or will eventually adopt parts of the same model. They will just do it later, once it feels familiar enough to be relabeled as progress.
Another example? Cloud adoption.
So ask yourself: what’s the last truly innovative thing you’ve seen in this industry that wasn’t just a marginal build on what already exists?
What can we do that is the bat shit innovation in security that we need?
I can tell you this: you won’t find it in New Orleans.
Persona Journeys vs. Vertical or Products

What can really move people in security?
It’s not specs, features, products, or vertical solutions.
It’s the journey of the person we’re protecting.
For too long, the industry has defaulted to categories like “K-12,” “stadiums,” or “airports.”
These terms may help us organize sales decks and make progress on products of the past, but they don’t inspire action or make the value of security tangible.
Categories are abstract.
Journeys are personal.
The story isn’t “K-12.” The story is “the 3rd grader walking safely into school and thriving in a secure learning environment.”
It’s not “stadiums.” It’s “the fan enjoying a game without worry” or “the owner seeing profitability rise because people feel safe and stay engaged.”
That shift, from categories to journeys, is where the true value of what we do comes alive.
This came back to me after a recent conversation with Travis Willis. He and I discussed how powerful it is when we frame security around human outcomes. When we do this, we create emotion, which drives adoption. Emotion is what attracts talent. Emotion is what can justify higher pricing. And, maybe most importantly, emotion reinforces that security isn’t just about doors, devices, or policies, it’s about people. And who knows, maybe we will deliver a safer environment for that 3rd grader to excel.
Think about how other industries have evolved. The insurance sector stopped selling “policies” a long time ago. They realized no one gets excited about deductibles or coverage details. What resonates is the peace of mind of knowing your family is protected, your home is safe, and your future is secure. They sell reassurance. They sell trust. They sell an emotional promise. We have the same opportunity in security, but we’ve been slow to tell the story that way. We’re focused on tech specs.
And let’s not stop at marketing. This mindset can be embedded into how we structure companies, build products, and organize teams. Imagine shifting from roles like “Director of Product Management for Mechanical Locks” to “Director of Safe and Productive Schools.” Or from “Cloud Sales Director” to “Director of Secure, Revenue-Generating, and Efficient Commercial Real Estate.” That kind of reframing changes what success looks like. It pulls people out of thinking in terms of hardware SKUs or software modules and puts them in the mindset of delivering human-centered outcomes.
If we consistently lead with journeys and highlight the student, the traveler, the fan, the employee, the family, we increase the relevance of our work beyond what it is today. We create more value for customers, we can attract stronger talent into the industry, and we can align ourselves with the broader desires of safety, productivity, revenue generation, and trust.

If you're a marketer in security or proptech, you already know: most industry events aren't really built for you.
𝐓𝐡𝐢𝐬 𝐨𝐧𝐞 𝐢𝐬.
Hilary and I have talked about this since day one.
We wanted to create an event for marketers. We've both felt the gap, not just in content, but in community, and we believed we could help fill it, because we’ve lived it.
So we teamed up with the crew at Bloxspring (Adam Malik PJ Appleton) to make it happen.
The first event is this fall in NYC. The next one will be on Bloxspring’s home court in London.
𝐓𝐡𝐞 𝐂𝐨𝐧𝐟𝐞𝐫𝐞𝐧𝐜𝐞 𝐟𝐨𝐫 𝐌𝐚𝐫𝐤𝐞𝐭𝐢𝐧𝐠 𝐋𝐞𝐚𝐝𝐞𝐫𝐬 𝐢𝐧 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 & 𝐏𝐫𝐨𝐩𝐭𝐞𝐜𝐡
Thursday, October 16
8:00 AM – 4:00 PM
New York City
𝐑𝐞𝐠𝐢𝐬𝐭𝐫𝐚𝐭𝐢𝐨𝐧 𝐢𝐬 𝐧𝐨𝐰 𝐨𝐩𝐞𝐧. Register here and select the member discount.
If you’re a marketer in this space, we made this for you. Hope to see you there.
LATAM at the Center of Access Innovation
ACS LATAM 2025 is an exclusive (and free) regional edition of the Access Control Summit, co-hosted with Google and supported by HIDand ASSA ABLOY. This special gathering brings together 150 industry leaders from across Latin America to explore the future of access control.
Held at Google’s LATAM HQ in São Paulo, the summit offers a curated platform for strategic dialogue, cross-sector insights, and high-impact networking. From mobile credentials to AI-driven infrastructure, ACS LATAM highlights the technologies and partnerships shaping the region, fast emerging as a global hub for innovation and collaboration.
Find out more information and register here.
Here are some of the 20+ speakers scheduled to be at ACS LATAM:
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!






