Header Logo
Log In
← Back to all posts

Volume 123

Aug 03, 2026

Volume 123 | December 5, 2025

Click on the above image and use code sxst3gkbkn to hear the audio version.


Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.


Yes, I've heard about the "HID source code hack." (It is wild how many companies and institutions - Entrust, Schneider Electric, Washington Post, and Harvard University- were impacted by the Oracle 0-Day EBS Hack. I wrote about that on Slack for those who missed it.) No, I don't have extra details, and no, I'm not interested in doomsday speculation. What matters isn't the headline that matters to me. What matters to me is the business's secondary effects. And one question stands out:

Does this give HID leadership and other companies in our industry the permission to finally address long-avoided but inevitable changes?

I believe it does.

Other major shifts are already coming for the industry. Two examples are Aliro and Post-Quantum. Most companies are either waiting for them or ignoring them, knowing they (or someone after them) will have to deal with it at some point (and not the technical side of Aliro and Post-Quantum, but the business impacts). There are third-, fourth-, fifth-, etc., inevitabilities, like a major incident, that will continue to surface across our interconnected businesses, supply chains, ecosystem. We're now operating in the same world cloud, and SaaS industries have lived in for years: breaches, disclosures, controls, cadence.

Expected, not exceptional.

The interesting part isn't whether the breach happened. It's how leadership uses the moment.

The unpredictability of what companies do next that have motivation and permission to change should worry many.

In a legacy-heavy industry, a breach is rarely just technical. It usually becomes a catalyst. It exposes deferred decisions by past leadership teams, inherited architectures, and long-standing vulnerabilities that everyone quietly knew existed (note: to be clear, I'm not saying the HID Oracle 0-Day EBS hack was a known vulnerability; I am talking about others in the industry). It compresses timelines. It gives leaders something rare: political capital and a mandate to change what was previously untouchable.

Budgets open. Product lines get reconsidered. Roadmaps move. Risk rises to the surface. Leaders can finally point to something concrete and say, "This is why we must move now."

Sometimes a bad event is precisely what's needed to make overdue change possible.

Industries that have been online for years already know this rhythm. Our sector is only now experiencing what happens when legacy, offline assumptions collide with modern connectivity. The question isn't "How could this happen?" It's "What do we fix, accelerate, or retire because of it?"

By all visible signs, HID is following the standard disciplined playbook: controlled communication, accuracy over speculation, and stakeholder-focused updates. That's what mature companies do.

But the bigger story is what they and others choose to do next.

Let's be honest: our industry has "bodies buried everywhere." Prox where it shouldn't be. Weigand is still alive. Keys that can be copied at grocery stores. Legacy deployments running on assumptions built 20+ years ago. Business models built off of the last 30 years that do not support the next 30 years. Everyone knows change is coming; they just don't know when the forcing function will appear.

Well, one just did.

Visibility accelerates inevitability. A breach doesn't only expose weaknesses, it reveals possibilities.

The headlines will fade, but the decisions made right now won't. Leaders who use this moment to modernize architectures, reorganize teams, redirect investment, and rethink customer experience will shape the next decade of physical security.

Because ultimately:

A breach becomes a lever, a mandate, and the world's biggest excuse to do the things everyone already knew needed doing.

Aliro will force this.

Post-Quantum will force this.

This incident simply arrived first.

It's not about what happened.

It's about what's now possible.

It's about going from our heels to our toes.

My bet is on strong leadership that acts boldly, and I'm not just talking to HID. 


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!

Volume 150
Volume 150 | July 29, 2026 Reminder to JOIN the The Secured Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Welcome to the Access Control Executive Brief Volume 150! As Semisonic sang in "Closing Time"… "Every new beginning comes from some other beginning's end."And here we are.One. Hundred. Fifty. I have written that number (more ...
Volume 149
Volume 149 | July 8, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. iLOQ published its 2025 Annual Report last week, and with my trip to Oulu, Finland canceled due to weather, I figured I'd cover their report instead. Inside the ESG appendices and IFRS statements is a cleaner test of my three c...
Volume 148
Volume 148 | June 29, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. It was a treat to spend the day with ALOA Security Professionals Association. I'm grateful to Dave O'Toole for spearheading the opportunity to be there. Dave is an absolute legend in this industry, and if the locksmith trade c...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.