Volume 135
Volume 135 | March 4, 2026

Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.
And we already deserve to be there.
They have positioned themselves as thinkers. We have positioned ourselves as vendors.
I wrote and spoke (Secured Podcast) recently about the need for our industry to be at The Munich Security Conference and how it's a missed opportunity that we are not. To recap: The Munich Security Conference happens every February, where heads of state, defense ministers, NATO leadership, intelligence chiefs… the type of people who make decisions that affect the safety of billions… show up, sit across from each other, and have the conversations that actually matter. There are also satellite meetings and conferences around the main event that add as much value and cross-pollinate between venues. Munich Cyber Security Conference is one. The International Security Management Association is there too, but it is only one part of the security ecosystem. Overall, it is a great opportunity to drive density, build bridges, learn, listen, inject your own ideas, and represent groups with a point of view, expertise, and a sense of belonging at the table.
Physical security was not there.
No seat, no voice, no presence.
That is not Munich's failing. That is ours.
But don't get lost in the example. Munich is an example, not the point. The point is a pattern.
Think about where the critical conversations on national infrastructure, identity, AI governance, workforce safety, urban planning, and public trust are happening right now (and this is an exhaustive list):
Think Tank convening from Brookings to CSIS to the Atlantic Council.
Corporate boardrooms
Legislative hearings
Policy working groups
Physical security isn't consistently in those conversations, and it should be. And when we are, as the Security Industry Association does with the work Jake Parker and his small team are doing on the US Capitol Hill, we don't fund it enough to have a loud enough voice.
We secure the buildings where those conversations take place. We protect the people who have them. We manage the credentials of the staff who support them. We do a ton, and we do it well. We sit at the literal threshold of every critical decision-making environment on the planet.
And we are talking to each other.
And that's not good enough. We deserve and should want more.
What is The Room?
The room is wherever decisions about safety, identity, infrastructure, AI, and policy are being made without our direct input.
It is the National Security Council briefing on physical threats to critical infrastructure. It is the Senate Commerce Committee hearing on data privacy that does not include a single physical access control perspective. It is the World Economic Forum panel on AI and trust where no one represents the people who actually deploy identity systems at scale. It is the corporate C-suite conversation about return-to-office where facilities and security get handed a memo instead of a seat at the table.
The room is any place where our expertise would change the outcome, and our absence changes it in the wrong direction.
We need to be there, and here is why.
Physical security is infrastructure. In many ways, it is identity infrastructure, and at a minimum, it is safety infrastructure. Full stop.
Every day, this industry manages access for billions of people across offices, hospitals, schools, data centers, government facilities, and critical infrastructure. The systems we build, sell, and install are the foundation for how the physical world decides who belongs where. That is not a niche function. That is a foundational social and economic system.
You can draw a direct line from what we do to people being safe, feeling safe, and a nation's GDP. And we play a huge role in that.
Here is what being in the room does for us and for the people we serve and for us:
The policy gets better.
Lawmakers and regulators making decisions about identity, data sovereignty, biometrics, and surveillance are doing so without one of the most important stakeholders: the people who actually make, install, service, and run these systems. The result is a policy that is either too restrictive to enable good outcomes or too permissive to prevent bad ones. Our direct input changes that.
The narrative gets reframed.
Right now, physical security gets dragged into the news when something goes wrong, or we are portrayed as a goofball mall cop in a joke. We hear about the school shooting, the data breach, the biometric scandal, but we are not actually talking. We show up in the story as the technology that failed, not the infrastructure that worked 99.9% of the time, and not with a voice from an expert point of view. We leave that to others to tell our story. Being in the room before the story happens means we help tell it, we help write it. We help.
The capital flows toward us.
Private equity, venture capital, and institutional investors are increasingly looking at identity, enterprise software, data, and, in turn, physical security as a critical infrastructure play. They are making those decisions in rooms filled with enterprise software people and cybersecurity executives. If we are not there to explain why physical is the original and most consequential layer of that stack, the investment thesis gets built without us. And it is.
The talent pipeline opens.
The best graduates from the best programs are choosing careers based on where they perceive the greatest impact and prestige. They are going to cyber, AI, and fintech. Being in more rooms and telling a bigger story signals that physical security is a serious and meaningful career. It is. We just have not said so in the right places. It is time we stop laughing about how we all fell into this industry and didn't run to it. It is time to start a generation that runs to physical security.
The market grows.
When physical security is part of the infrastructure conversation, the total addressable market expands. Smart cities need our input. Healthcare systems need our frameworks. Energy grids need our protocols. Staying in the same lanes and showing up in the same conversations keeps us competing for the same budget pool instead of opening new ones. We love our own bath water. Actually, we love holding the cup as we pour our own industry bath water into the mouths of others in our industry, only to have them do it to us and then applaud each other and give recognition awards for doing it (see any ISJ Magazine edition or conference they put on as a reference point).
Why people think we don’t belong.
The truth is, there are reasons people in those rooms do not look up when physical security professionals walk in, and some of them are worth taking seriously.
We have historically led with product, not expertise. When we do show up in broader conversations, we often show up selling. Hardware specs, boring integration announcements, and six-foot table product demos are our comfort zone. The other people in those rooms lead with frameworks, data, policy perspectives, and original research. They have positioned themselves as thinkers. We have positioned ourselves as vendors.
We cannot answer the basic questions. Ask someone from our industry about the size of the global physical security market. Go ahead. I’ll wait. You will get six different numbers, if you get any at all, and none of them will be confident. That is not a research problem.
That is a credibility problem.
Every other industry that sits at a serious policy table has authoritative data on its own size, economic contribution, employment footprint, and safety impact. Pharma, finance, and defense all have it. Technology has it. HVAC has it. We do not, and we accept that as normal.
It is not normal. It is a symptom of an industry that has not yet decided it wants to be taken seriously at scale.
The Munich moment is connected to this. You cannot claim a seat at a table where global security strategy is being discussed if you cannot answer the question of how big, how impactful, and how essential your industry actually is. The data infrastructure comes first. The narrative authority follows.
In rooms where decisions are made, the people without the data lose the argument before it starts.
We have accepted a limited identity. The industry has spent decades calling itself the door industry, the lock industry, or at best the security industry. Those are not wrong, but they are incomplete. An incomplete identity is invisible in rooms that care about infrastructure, identity, and intelligence.
And to add, here is why some don’t want us in those rooms.
This one is harder to say, but it needs to be said.
Some people in this industry are comfortable being a big fish in a small pond. They know everyone, win the awards, buy big booths, run the committees, and have built their status in a defined and bounded world. Expanding that world means more competition for attention, more scrutiny of ideas, and greater exposure to being wrong in front of people watching.
There is also a self-perception problem. We have internalized smallness as an industry. A version of the industry's identity that says we are the people who install the hardware so that the important people can get into the building. That is not malicious. It is just a story that got told for a long time and started to feel true.
Some of it is protectionism. The old association (yes, ASIS), the industry media (see above), the certification programs, the dealer networks … all built around a contained market. More external visibility and influence could mean more external scrutiny, more non-traditional competitors, and a harder case to make for the existing infrastructure's current share of investment.
And some of our most celebrated companies are preying on it.
None of this is a reason to stay still or bury our heads in the sand. It is a reason to understand why the change is uncomfortable and move anyway.
And now to one of my classics and favorites: This is an “And Conversation,” not an “Or Conversation”
Nothing I am describing requires us to stop doing what we do. SIA still matters a lot (heck, even more). ISC West still matters. The dealer relationships, the trade press, the industry events, big and small, and the community we have built. All of it matters, and all of it should continue. (Except for GSX. It doesn't matter anymore. It needs to be in a museum where we celebrate its past success and history.)
The argument is that we add to it. We bring our expertise into rooms where it has been missing. We show up at the policy table, the investment table, and the public conversation with a point of view grounded in actual operational experience with identity and access at scale.
We do not abandon the rooms we are in. We walk into more of them.
Why would we not want to? Instead of me convincing you why we should, please explain to me why we wouldn't.
The seat at Munich is available. So are dozens of others. The only question is whether we are ready to take them.
I am. Hilary is, and I know many of you are too. This is why we are holding a 50-person C-Suite Leadership Retreat in Washington, D.C., in May and have invited experts from technology, business, and policy to join us. This is why ACS27 will be in Munich in February during the Munich Security Conference. All are welcome, and we hope to see you there.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
