Volume 146
Volume 146 | June 1, 2026

Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.
I want to use this Brief to go deep on a benchmark report we just published in partnership with Acre Security. I will be transparent about what this is: Acre commissioned it, we wrote it independently, and the findings, framing, and conclusions are ours. The report speaks to verticals as a whole and uses three verticals as examples to drive more context: education (K-12 + University/College, healthcare, and financial institutions. We spoke to experts, studied procurement patterns, and made real observations. We did not use survey data on purpose, as we wanted conversations.
I am writing about it here because what the report found is directly connected to arguments I have been making in these Briefs for 2+ years. The verticals confirmed the thesis, and a few things surprised me.
I hope you enjoy it, and I’d love to hear what you think. (It is also the type of work we love and are pretty proud of how it turned out).

The State of the Verticals Benchmark Report is analytical intelligence built from interviews with practitioners, subject matter experts, integrators, and specifiers across 3 sectors. It also draws from public reporting, regulatory developments, observable procurement patterns, and PhySec Collective community signals.
It is not a product brochure or a market sizing exercise. It is an attempt to answer a straightforward question:
What is happening inside organizations that buy access control, and what does it tell us about where this industry is headed?
The short answer is that physical access control is no longer about door hardware. It's now an infrastructure issue, centered on identity. Every organization in every vertical faces this reality at different speeds, with varying consequences for mistakes.

What I Would Do (Exclusive to You)
Before I get into the vertical-by-vertical analysis (of which you can read in the report), I want to share what I would do if I were a manufacturer, a software company, or a security integrator today.
If I were a manufacturer, I would stop asking whether my product roadmap is competitive and start asking whether I have both the arrowhead and the wood. You need a competitive balance (check out the chapter in my book called “innovation engines”). The arrowhead is what gets you into conversations: hybrid architecture, mobile credentials, AI-enabled configuration, modern interfaces. The wood is what keeps you in business: controllers, readers, integrations, and the foundational infrastructure that holds complex environments together across years and acquisitions. Most companies are heavy on one and light on the other. Legacy vendors tend to be all wood. New entrants tend to be all arrowhead. The platforms that will own the enterprise deals in healthcare and financial institutions have both. That is the product question I would be asking every quarter. I would also look below at what the software company is doing and start doing that too.
If I were a software company, I would be looking hard at the credential lifecycle problem and building that as a core product motion, not an add-on. The provisioning side of access is imperfect but improving across every vertical. The revocation side, particularly for contractors, temporary staff, and acquired entities, remains a real vulnerability. I have written about the Shadow Database problem extensively in Slack and Briefs. It is no longer a niche issue. Every health network we looked at in this report has 6 to 12 disparate identity systems, stemming solely from acquisitions. Every financial institution is running governance risk across an estate that it cannot fully see. The software company that solves the full credential lifecycle, onboarding through offboarding, and connects it to HR and IAM, is gonna own the identity relationship in each of these verticals. That is the $100B era position and the one worth building toward.
If I were an integrator, I would change how I sell. The education buyer is not buying a door system, a lock, or just an access control system. They are buying a safer Tuesday that also works on the worst Friday. The healthcare buyer is not buying a new platform, but a path out of fragmentation without ripping out everything they already have. The financial institution buyer is not buying features, but buying governance: the ability to report, audit, and absorb the next acquisition without creating new liability. In every case, the technology is the supporting evidence, and the outcome should be the pitch. If your salespeople are still leading with hardware specs and integration lists, you are selling the wrong thing to the wrong person in the wrong meeting. Integrators who make this transition, who become outcome sellers and managed service providers rather than project shops, are the ones who will look like technology companies in three years. You will be the system integrators we need. The rest will be competing on margin in a commoditizing hardware market. I wrote about this at length in Brief 132. The data from this report reinforces every word of it.

Here is what the report told us. I’ll start with Education and title this section “The Silent Tax and the Single Workflow Problem.”
The access control conversation in K-12 has been dominated for years by active shooter response. That is real, and it is not going away. But the practitioners we spoke with described a measurable shift in the conversation's center. A few years ago, lockdown speed drove the conversation at roughly 70/30 in favor of daily operational concerns. That ratio has moved closer to 60/40. The practitioners think that the trend continues.
The shift matters because it changes both your product and customer. A system that works on a regular Tuesday will also work on the worst day. Lockdown capability hidden in a system that no one uses properly is not a security program, but only a drill.
The integration problem is the deeper issue in education. Most institutions manage access control, video, emergency notification, visitor management, and intercoms as completely separate systems. During an incident, staff are switching between multiple screens. A door-force alarm triggers, but there is no corresponding camera feed. That is a workflow failure, not a technology failure. The district's buildings over the next 20 years are being built toward a single incident workflow. The rest are patching, because funding is episodic and full replacement across dozens of buildings is rarely possible all at once.
One pattern from this research that I want to name directly is what Pierce Mayfield called the silent tax. Districts are dedicating entire staff positions to 1 function: unlocking doors for vendors, issuing temporary badges, and resolving credential issues on a loop. When that person is sick, the system stops. When they leave, institutional knowledge walks out with them. That cost never shows up on a security budget line because it lives in headcount and lost hours. Mobile credentials address the lost-card portion directly. The ROI argument is to eliminate reissuance costs, reduce manual intervention, and improve staff time allocation. That is the conversation that drives procurement decisions at the district level, and it is much more interesting than spec sheet comparisons.
The mainstream parallel here is worth noting. In enterprise software, the transition from complex IT environments managed by dedicated administrators to self-service, cloud-native platforms was not driven primarily by technology innovation, but by organizations calculating the true cost of the people required to keep legacy systems running. Salesforce did not win because it was technically superior. It won because the cost of the status quo became visible and unacceptable. That same calculation is now arriving in education access control.
Next up is Healthcare and what I call “The Arrowhead and the Wood.”
Healthcare is the most complex vertical in this report and the one moving fastest. The ramp of change over the past 36 months is unlike anything practitioners in this sector have described in prior periods.
Two forces are driving that acceleration. The first is workplace violence. It is the dominant investment driver in healthcare security and has crossed over into workforce retention. Employee net promoter score, specifically whether staff feel safe on campus, has become a talent metric. Hospitals that cannot answer that question affirmatively are losing nurses and clinical staff to competitors who can. Security is now a workforce issue, not just a safety issue. This pattern is visible across the broader labor market as well. Gallup’s workplace research consistently shows that physical safety concerns rank among the top drivers of employee disengagement and attrition. Healthcare is simply encountering this reality earlier and more acutely than most industries because the physical risks are more visible and the staffing pressures are more acute.
The second force is fragmentation from acquisitions. The average large health network runs 6 to 12 or more disparate identity systems. Every acquired facility arrives with its own access control infrastructure. This was described as painting over the mold versus removing the mold. Acquisitions keep driving fragmentation regardless of what the acquiring organization wants. The market is moving toward platform consolidation, but it is early.
The arrowhead and wood metaphor is a perfect way to explain what buyers in this vertical are selecting. The arrowhead draws attention to cloud management, mobile credentials, and AI configuration. The wood is what holds a complex, multi-site post-acquisition environment together over the years. Legacy vendors are often all wood, while new entrants are often all arrowhead. The system's winning platform consolidation projects in healthcare have both. Enough wood to be trusted, enough arrowheads to be chosen. This is not a new idea in enterprise technology. Workday won HR not because it had the deepest feature set, but because it combined ease of adoption with the ability to scale to enterprise complexity. The healthcare access control market is now sorting itself along exactly those lines.
The procurement question that dominates mature healthcare evaluations is not what this system does, but what this system can connect to, and what we can stop managing separately once it does.
And last, we cover Financial Institutions and what I titled “Governance Is the Product.”
Financial institutions are further along the platform-first transition than most of the industry realizes. Large national and global banks have been running standardized deployments for years, using a single vendor, a single platform, and a global rollout. The “McDonald’s model” is real, but beneath that surface uniformity lies significant complexity. Regional and community banks are lagging. Acquisitions have created fragmented architectures at institutions of every size, and the convergence of physical security with cybersecurity and fraud detection is still in its early stages.
The dominant threat narrative has shifted from external threats to insider threats and fraud. A physical security failure that enables a data breach is a media event. Reputational consequences are the primary driver of senior executive attention, not operational ones.
The real budget trigger is not regulatory pressure, but an audit finding or a merger. Both expose vulnerabilities that the normal annual budget cycle would not surface. Cian Bolger from Acre Security put the vendor conversation correctly: stop leading with the cost of implementation and start leading with the operational cost of managing what the institution already has, then ask what happens if there is an incident before the next renewal cycle. That reframe moves the conversation from procurement to investment.
The 3 questions that consistently surface in enterprise financial institution evaluations are worth noting. 1 - Can this platform produce a consolidated compliance report across every site in a global estate? 2 - Can it onboard an acquired entity without requiring full replacement? And 3 - Can it support an audit response without requiring manual reconciliation across multiple systems? Vendors that can answer all 3 credibly earn a place in the evaluation. Vendors that can answer only 1 or 2 questions are positioned as point solutions, regardless of their individual capabilities.
This pattern is not unique to access control. It maps directly to what happened in enterprise data management over the past decade. The companies that won large financial institution contracts were not the ones with the best individual features. They were the ones with the governance story, the audit trail, and the demonstrated ability to survive an acquisition. ServiceNow, Workday, and Snowflake all won in regulated industries by making compliance and governance the product, not a feature. Access control vendors have the opportunity to make the same move.
Most are not making it yet.
So how does this all come together?
I have written about the $10 billion versus $100 billion market framing in these Briefs many times. The $10 billion market is hardware-first, door-centric, and organized around the credential. The $100 billion market for identity infrastructure is organized around the person, connected to enterprise systems, and governed across the full lifecycle. Been thinking a lot about it, and I am calling it the Intelligence Era.
Every vertical in this report confirmed that the $100 billion market is not theoretical. It is arriving, at different speeds and with different triggers, in every sector where access control touches enterprise operations. The organizations that treat physical access control as identity infrastructure are building operational advantages, compliance resilience, and technology flexibility that their peers are not.
The gap between what is possible and what is deployed is widest in the middle market. That is where the work is, and that is where the opportunity is for every company reading this Brief.
The report is available now. Please read it. Then ask yourself honestly which side of the transition your company is on.
Enjoy your weekend. Thank you for all the support and engagement, and for being part of this community.
Lee
Click on the above image and use code sxst3gkbkn to hear the audio version.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
