Volume 128
Volume 128 | January 20, 2026
Click on the above image and use code sxst3gkbkn to hear the audio version.
Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.

From doors to identity: in just 12 months, the structural shift in the region is now visible.
Unlike Intersec Dubai's past events, the 2026 Access Control Theatredidn't feel like typical access control programming. It felt like a status update on an industry mid-transformation in a region that has as much substance as it does hype. It is rare to feel something in 12 months, but I felt something different. And I'm not being dramatic for the sake of a story.
For this Brief, I will speak specifically to what was discussed on Monday at the Access Control Theatre. We will roll out a podcast series soon featuring 21 companies I talked to at the show, diving even deeper into the nuances of the market.
The Access Control Theatre was a perfect show setter for what was to unfold. This year, the Theatre was one full day and had a mix of 6 company spotlights and 1:1 moderated discussions with me. The participating companies were CoreWillSoft, Elatec, HID, Iris ID, LEGIC, Spintly, and Wavelynx. The format was a success and has built on what we did in 2024 and 2025. I couldn't be happier with it, and from the feedback, neither were the speakers nor the audience.
Across the Access Control Theatre sessions, one idea kept resurfacing in different languages, from all the companies on stage, in other contexts: access control is no longer a product category. It is becoming an identity-driven, software-defined, interoperable layer of critical infrastructure.
No single speaker “broke” this news. Instead, the collective message was unmistakable. I have written before that “the center” has moved, including the market, the narrative, and customer expectations. The industry is now being forced to reconcile legacy architectures with modern operating realities.
Below is a synthesis of the day’s talks, framed as takeaways, shared beliefs, and productive tensions for you. My goal was to give you the 2x speed version as though you were there. Let me know how I did.

The new center of gravity is identity, not credentials
One of the clearest shifts in the Theatre was the industry’s growing agreement that identity is becoming the organizing principle.
The implication hits wide and far. In the past, access control systems were built around “cardholders” and “credentials” (at least since the 80’s. In the 70s, it was about identity, but we lost that with the introduction of the controller. At that point, we shifted to being about the door. In the emerging model, people are identified with attributes, permissions, policies, and lifecycle events. Credentials are simply delivery mechanisms, not the core entity.
This surfaced most strongly in the convergence discussion: as physical security and IT collide, identity becomes the bridge. It doesn’t stop there as HR also owns parts of identity, and on and on. IT owns authentication policies. Physical security owns door permissions. Historically, these were siloed. Increasingly, they are being pulled into a unified identity journey for employees, contractors, visitors, and even machines.
A key point of agreement emerged: systems positioned as identity management systems are increasingly positioned to become the integrator of record. Not because PACS can’t evolve, but because IT identity platforms are already architected to normalize data, enforce authentication policy, and orchestrate workflows across systems.
The conflict underneath this is obvious: everyone wants to “own identity,” but the future likely belongs to those who enable identity portability and governance, not those who attempt to contain it.

|
Software has taken the lead.
If identity is the center of gravity, software is the engine.
A consistent message came through: buyers are no longer purchasing devices; they are buying outcomes. Incident management, workflow automation, compliance reporting, onboarding and offboarding, credential lifecycle operations. These are software-defined problems.
That shift is changing buying behavior.
Hardware selection increasingly follows software platform requirements, not the other way around. It is also changing the channel. Integrators are being pulled up the stack toward SaaS, managed services, recurring revenue models, and customer success.
The most important nuance here is that “software” does not mean “a UI.” It means the ability to define and orchestrate use cases across systems, which leads directly to the next theme.

|
|
Interoperability is now procurement, not marketing. |
Interoperability was not discussed as an aspiration. It was discussed as a market condition.
RFPs are increasingly written around required integrations: access, video, BMS, SOC tooling, HR, ERP, identity systems, Workday, ServiceNow, Salesforce, and booking systems. The modern enterprise does not want security islands. It wants interconnected operational systems that create business value beyond “open a door.”
But the industry is still structurally behind.
Closed APIs, cosplay integration platforms, NDA-protected SDKs, long certification cycles, brittle integrations that break on upgrades, and unclear ownership of integration maintenance all surfaced as real friction points.
This created one of the day’s sharper contrasts:
-
Customers expect plug-and-play behavior when standards are in place.
-
Vendors still operate as if closed ecosystems are a form of strategic differentiation.
The emerging truth is that standards are becoming the “language of love” in access control. Not because standards are perfect, but because they reduce time-to-value and customer dependency.

|
|
Legacy is a reality, not an excuse. |
A mature industry with 15–25-year system lifecycles faces a simple constraint: modernization must occur without a rip-and-replace approach.
Speakers repeatedly returned to this, directly or indirectly: Legacy hardware is expensive. Legacy systems are entrenched. And organizations do not have the budget, appetite, or regulatory permission to replace everything.
That pushes the market toward software-led modernization strategies:
-
modular add-ons that extend capabilities
-
middleware that introduces modern authentication and identity integration
-
phased transitions that preserve installed hardware while upgrading the stack
The takeaway was consistent: the winners will be those who make the installed base more valuable, not those who punish customers for having one.
Cloud adoption is inevitable, but not uniform.
Cloud emerged as a major enabler of faster integration and simpler operations, with a more grounded tone than the typical“everything will be SaaS” narrative.
Customers want options: on-prem, private cloud, hybrid, SaaS. They want resilience. They want systems that operate through connectivity failure and power events. And in the GCC, they want data sovereignty by design. “The Middle East” is not a single policy environment. The UAE, Saudi Arabia, and Qatar each have distinct requirements regarding data residency and hosting.
The implication is strategic: cloud is not a destination. It is an architecture decision constrained by trust, regulation, and resilience.
Mobile is table stakes, lifecycle is the product.
Mobile credentialing is no longer treated as a novelty. (Side note: I think it will be huge here. Practicality meets cool factor, meets high visitor volume, meets operational efficiency, meets hospitality. Mix and watch exploration. Wallet integrations and smartphone credentials are accelerating, but the deeper insight was more important:
The door interaction is not the real story. The lifecycle is.
Issuance, provisioning, permission changes, re-credentialing, revocation, and offboarding. The value is in how elegantly and securely an organization can manage identity and credential lifecycle across systems and stakeholders.
And there’s a commercial reality emerging: wallet ecosystems are introducing pricing and margin complexity, especially as credential costs can inflate through the channel. That friction will matter, and the market is still working out who captures value where.

|
|
Biometrics are expanding, but context matters. |
Biometrics were discussed as an increasingly important modality, especially for critical infrastructure and high-security sites.
But the tone was pragmatic. Biometrics are not replacing cards and mobiles. They are joining them. Multi-factor authentication models, frictionless access experiences, and hands-free identity interactions are all accelerating, but privacy, storage models, and regulatory constraints remain decisive.
The emerging consensus was simple: biometrics are a factor, not a silver bullet.
And they should thank mobile for the reinvigorated life, energy, and awareness.

|
|
AI will augment, not replace, access decisions. |
AI showed up in two distinct ways:
-
As a strategic force expanding the security surface area
-
As a practical tool for pattern recognition and operational efficiency
There was also a clear warning: access control is still a high-consequence domain. In many jurisdictions, especially in Europe, AI-enabled security functions are legally constrained by requirements for human oversight. You can imagine the Middle East following some of this formation.
The more realistic near-term future looks like:
-
AI upstream: anomaly detection, policy violations, risk signals
-
AI downstream: reporting, investigation assistance, automated support
-
Human in the loop at the decision moment
The productive framing: AI doesn’t replace access logic. It improves the quality and speed of the information that surrounds access decisions. Keep in mind that in the Middle East, there isn’t a resource problem. AI is likely more of a tool than a replacement here.
Resilience and risk have become board-level issues.
Perhaps the most important shift is that access control is no longer viewed as a facilities tool. It is being pulled into the category of strategic operational technology.
Geopolitical tension, cyber-physical attacks, and regulatory oversight are raising the bar. Customers want clear documentation of failure modes, containment behavior, and recovery procedures across credential authorities, controllers, networks, and cloud dependencies.
Post-quantum cryptography and asymmetric credential standards were positioned as near-term necessities rather than distant research topics. The message was: the industry must prepare now, because upgrades later will be more complicated than investments today.

|
|
Wireless architectures are challenging old assumptions. |
Wireless, mesh-based access control was positioned not as “nice for SMB,” but as a legitimate architectural alternative with major advantages in retrofit and deployment speed.
The narrative is shifting:
-
Reliability can be engineered through distributed design
-
decisions can happen at the door to avoid lockout scenarios
-
Cost and deployment timelines can be reduced dramatically
This challenges the default “wired equals secure and reliable” assumption that has shaped the industry for decades.
Smells like enterprise.

|
|
My takeaway |
From what I saw, Intersec Dubai 2026 didn’t introduce breakthrough technology. It confirmed a structural shift, and sometimes that is more important.
Access control is becoming identity-driven, where user identity takes precedence over physical credentials. Platforms and integrations are now driving decisions, with hardware choices following software requirements. The industry is moving toward interoperability by default, as customers demand seamless integrations across their technology stack. Solutions must be adaptable across regions to meet diverse regulatory and cultural requirements. And finally, the focus is shifting to a lifecycle-oriented approach, managing the entire journey of credentials and permissions rather than just the moment of door access.
The implication for leaders is not subtle: stop selling products as endpoints. Start building and enabling trust across people, spaces, machines, and systems.
Those who are acting now will shape the next 30 years of access control.
Those who don’t will inherit someone else’s platform.

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
