Volume 123
Volume 123 | December 5, 2025
Click on the above image and use code sxst3gkbkn to hear the audio version.
Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.

Yes, I've heard about the "HID source code hack." (It is wild how many companies and institutions - Entrust, Schneider Electric, Washington Post, and Harvard University- were impacted by the Oracle 0-Day EBS Hack. I wrote about that on Slack for those who missed it.) No, I don't have extra details, and no, I'm not interested in doomsday speculation. What matters isn't the headline that matters to me. What matters to me is the business's secondary effects. And one question stands out:
Does this give HID leadership and other companies in our industry the permission to finally address long-avoided but inevitable changes?
I believe it does.
Other major shifts are already coming for the industry. Two examples are Aliro and Post-Quantum. Most companies are either waiting for them or ignoring them, knowing they (or someone after them) will have to deal with it at some point (and not the technical side of Aliro and Post-Quantum, but the business impacts). There are third-, fourth-, fifth-, etc., inevitabilities, like a major incident, that will continue to surface across our interconnected businesses, supply chains, ecosystem. We're now operating in the same world cloud, and SaaS industries have lived in for years: breaches, disclosures, controls, cadence.
Expected, not exceptional.
The interesting part isn't whether the breach happened. It's how leadership uses the moment.
The unpredictability of what companies do next that have motivation and permission to change should worry many.
In a legacy-heavy industry, a breach is rarely just technical. It usually becomes a catalyst. It exposes deferred decisions by past leadership teams, inherited architectures, and long-standing vulnerabilities that everyone quietly knew existed (note: to be clear, I'm not saying the HID Oracle 0-Day EBS hack was a known vulnerability; I am talking about others in the industry). It compresses timelines. It gives leaders something rare: political capital and a mandate to change what was previously untouchable.
Budgets open. Product lines get reconsidered. Roadmaps move. Risk rises to the surface. Leaders can finally point to something concrete and say, "This is why we must move now."
Sometimes a bad event is precisely what's needed to make overdue change possible.
Industries that have been online for years already know this rhythm. Our sector is only now experiencing what happens when legacy, offline assumptions collide with modern connectivity. The question isn't "How could this happen?" It's "What do we fix, accelerate, or retire because of it?"
By all visible signs, HID is following the standard disciplined playbook: controlled communication, accuracy over speculation, and stakeholder-focused updates. That's what mature companies do.
But the bigger story is what they and others choose to do next.
Let's be honest: our industry has "bodies buried everywhere." Prox where it shouldn't be. Weigand is still alive. Keys that can be copied at grocery stores. Legacy deployments running on assumptions built 20+ years ago. Business models built off of the last 30 years that do not support the next 30 years. Everyone knows change is coming; they just don't know when the forcing function will appear.
Well, one just did.
Visibility accelerates inevitability. A breach doesn't only expose weaknesses, it reveals possibilities.
The headlines will fade, but the decisions made right now won't. Leaders who use this moment to modernize architectures, reorganize teams, redirect investment, and rethink customer experience will shape the next decade of physical security.
Because ultimately:
A breach becomes a lever, a mandate, and the world's biggest excuse to do the things everyone already knew needed doing.
Aliro will force this.
Post-Quantum will force this.
This incident simply arrived first.
It's not about what happened.
It's about what's now possible.
It's about going from our heels to our toes.
My bet is on strong leadership that acts boldly, and I'm not just talking to HID.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
