Header Logo
Log In
← Back to all posts

Volume 117

Aug 03, 2026

Volume 117 | October 9, 2025

Click on the above image and use code sxst3gkbkn to hear the audio version.


Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.


Reflections on Steve Van Till’s “Software Eats Security” article.

When Steve Van Till writes, I read, and I know many of you do the same. His latest article, “Software Eats Security. AI Eats Software. Man Bites Dog,” hit a nerve in the best way (great title btw). Not because it was done for the sake of attention, but because it captured what many of us in access control and the global security industry have been living with every day. What Steve wrote is exactly what’s happening today and forward. The changes and real-life experiences are not some far-fetched future discussion. And that’s why it’s important to discuss what he wrote and put it into context with what’s happening now.

Steve is right. Software has eaten security. AI is eating software. And if you look around, both meals are happening at once. His piece triggered me, connecting to ideas I have written in past Briefs and to what has been “eating me.”

Important note: Yes, there are pockets where what we are discussing is not happening, and that is valid. However, that by no means should explain away the reality of what we are describing and highlighting. It ultimately comes down to where and with whom you spend your time. One is an example of the $10 billion market of yesterday that grows at 8-12%, and the other is the $100 billion market. If what you read sounds unfamiliar, maybe it’s time to put down the $10B kaleidoscope and pick up the $100B one. I’ll offer you this - if you aren’t working on the $100B version of what we are discussing, set up a time with me to discuss exactly that. Within 15 minutes, I am confident we can discuss how to redirect your efforts to be part of the new era in electronic physical security, specifically the new era of electronic access control. Grab a time here: https://calendly.com/leeodess/15-minute-meeting.

Chart from Steve’s article showing software growth in the security industry.

Let’s start with “Software Eats Security,” but context matters.

Software has transformed physical security, but it has done more than consume it. Security became software.

This is more than “digitization.” It is a full behavioral shift. Our industry now mirrors the SaaS model, characterized by subscription revenue, continuous updates, faster iteration, and tighter feedback loops. Our systems and businesses continue to improve over time. They don’t degrade. Access control no longer lives on a wall in a black box that goes beep. It lives onsite, in the cloud, and is connected to HR, visitor management, and identity systems.

As I have written before, our industry has shifted from protecting doors to managing digital identities in motion. The companies that thrive will not treat software as an add-on. They will treat it as the connective tissue that turns protection into performance. Think about that. Our systems are designed to perform, and their performance is not just a single dance.

Then there is AI Eats Software, but security gets digested differently

In most industries, AI either replaces people or augments them. In ours, it repurposes them.

In my HiveWatch AI Operator brief, conversations with Bearing, and most recently, live from acre security’s partner event, I described “agentic AI” as changing how security operations centers function and the way our systems are being configured and managed. The software does not just record, alert, or run reports. You don’t just sit on it and go. It interprets, recommends, and acts. AI does not replace the operator or integrator. It redefines their purpose.

That is what makes Steve’s point so timely. AI is not eating software whole. It is metabolizing it into something contextually aware. In security, awareness saves time, resources, and often far more. Awareness even allows a great experience.

If you believe that your competitive advantage is sitting in a basement and configuring systems, you’re in trouble. If your systems are designed for someone to sit in a basement and configure it, you are in trouble.

Let’s move to hardware’s revenge: why software still needs a door

Software dominates the conversation, but the physical layer remains the foundation, if we choose to accept the mission.

In access control, hardware is not obsolete. Maybe one day, but not anytime soon. Readers, sensors, controllers, and locks are still where trust meets action. Software may have eaten security, but hardware still serves the meal for a large portion of our industry’s opportunity. The future belongs to companies that bring physical reliability with digital agility. I see and hear way too many companies allowing software-centric firms to suck the oxygen out of the room that many of you who have expertise in hardware could command and occupy. There is almost a defeatist attitude, like “we are going to be relegated to low-margin grunt work.” Well, yeah, if you let it. If our industry spent as much time embracing and implementing change as it did moaning about it, we’d see the change. GSX might as well be reclassified as “where the security industry goes to moan collectively and talk at a high level about change, but does nothing about it after Day 3 when they go home.” We need the places and spaces, as well as the people who see change, want change, and are willing to make change, do change. Now’s the time. Leverage your expertise. Leverage your currency.

Chart from Steve’s article showing % of software vs hardware.

And then I loved, from innovator’s dilemma. To me, it is an Integrator’s Dilemma.

Steve referenced the Innovator’s Dilemma. In our world, it has evolved into what I call the Integrator’s Dilemma. And I’m not just talking security integrators.

Success no longer depends on who builds the best product. It depends on who places the most value. We have shifted from forced partnership to integration. Many legacy firms still struggle with this because they built monolithic systems, and the market has begun to reward modularity.

News flash: you don’t need to do it yourself anymore.

Consider what AMAG has done with SwiftConnect or what many are doing with Seam.

Tomorrow’s leaders will not just ship new products. They will orchestrate ecosystems that unify security, identity, and operations. They will be or play within platforms.

And they will not allow their engineers to get in the way of the build vs. buy decision.

Then Security as Software. To me, Software as Media

A less discussed reality is how communication drives adoption.

Software transforms the product, but content transforms the perception. The companies that tell clear, consistent stories about what their platforms enable will win the market. This is why The Access Control Collective evolved into a media company. And you should too.

Insight without storytelling does not scale.

Software eats security. AI eats software. But content still decides who gets fed. If you don’t have a CMO or a marketing team that moves beyond product marketing, this is the first bell to ring that you are already behind.

Everyone, including integrators and end users, should prioritize content.

Access control’s next appetite

Access control has lived this evolution more visibly than any other segment.

We have moved from mechanical to electronic, from on-premise to cloud, and now from software-defined to AI-assisted. The next 30 years are not about replacing cards with phones. It is about making access data strategic: understanding behavior, flow, and intent, while delivering an amazing and secure experience.

As I wrote in the Platform Evolution brief, access control is becoming the nervous system of the built world. It is the utility that matters. What was once a safety-only function is now operational and experiential. It’s why every tenant engagement app turns into an access control app. AI will not make it unrecognizable. It will finally make it unified. There is no better time to be in our industry than now.

And lastly, winners will build vertical

Every disruption wave creates a new class of winners. For this one, it’s important to go deep, not wide.

I have written about “inside-out vertical integration,” where security shifts from protecting perimeters only to also enabling what happens inside. Companies that build complete vertical ecosystems for industries like healthcare, retail, and education, combining hardware, software, and identity, with the ability to integrate them seamlessly with other systems, will own those markets.

Horizontal platforms scale faster. Vertical ecosystems last. That is where software’s next appetite is. Go deep.

My final thought.

Steve’s article is not only a reflection on the past. It is a mirror for where we are now with a map to tomorrow. It captures the shift from product to platform, from access control to identity, from competition to collaboration.

He is right that AI will disrupt the current order. I believe it is also our best opportunity to redefine ourselves as an industry that truly unites physical and digital worlds (beyond cyber).

Software ate security. AI is eating software. The question I’m already starting to think about is: what will eat identity?


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!

Volume 150
Volume 150 | July 29, 2026 Reminder to JOIN the The Secured Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Welcome to the Access Control Executive Brief Volume 150! As Semisonic sang in "Closing Time"… "Every new beginning comes from some other beginning's end."And here we are.One. Hundred. Fifty. I have written that number (more ...
Volume 149
Volume 149 | July 8, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. iLOQ published its 2025 Annual Report last week, and with my trip to Oulu, Finland canceled due to weather, I figured I'd cover their report instead. Inside the ESG appendices and IFRS statements is a cleaner test of my three c...
Volume 148
Volume 148 | June 29, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. It was a treat to spend the day with ALOA Security Professionals Association. I'm grateful to Dave O'Toole for spearheading the opportunity to be there. Dave is an absolute legend in this industry, and if the locksmith trade c...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.