Header Logo
Log In
← Back to all posts

Volume 52

Aug 02, 2026

Volume 52 | April 24, 2024

Welcome to Edition 52 of the Access Control Executive Brief and for this one we welcome back Tony Dong for a double feature.

In this insightful analysis, Tony debunks the myth that the security technology industry is recession-proof. Despite claims to the contrary, his deep dive uncovers that this sector, encompassing the integration and manufacturing of access control and surveillance systems, needs to be more immune to economic downturns. Drawing upon evidence and data, he reveals the sector's high sensitivity to market shifts and significant stock price declines during recessions. This article serves as a wake-up call for investors, executives, and the market, emphasizing the need for a more measured approach to risk management and a reassessment of revenue sources to ensure stability and resilience in the face of economic challenges.

I love how Tony busts the old truths with hard truths in this Brief.

He then followed up with a conversation we had on Slack and LinkedIn about basic cyber security practices our industry should follow versus just speaking at conferences about how "cyber security is a trend." Note: It's not a trend. It's a matter of fact.

Side note: I am finishing my "not so obvious trends" highlights from ISC West. I hope to have those to you next week while I am at The Security Event. I shared them already on Slack, but here they are:

  • ISC West is not a security show but a data show

  • Big tech's massive impact (beyond wallet)

  • Single pane of glass or vertical SaaS?

  • Shows are about the ecosystem.

  • End users are frustrated and feel ignored by manufacturers.

  • Integrators need clarification on how mobile helps their business other than being cool and in the mix. There is an opportunity.

  • The system integrator for tomorrow is real. Check the Northland Controls announcement.

  • Fun - legitimate fun

  • It is time to recognize that Wavelynx has arrived, and the HID of today and tomorrow differs from their past.

  • Companies still treat trade shows as a singular offline event. It is not.

  • We don't set metrics on the show's unseen but impactful benefits, and they are not in your booth.

Lastly, ACS24 Europe is not just another event; it's the first access control and smart lock thought leadership conference in Europe. Building off of what we did at ACS24 in Washington, DC, we have 60 speakers from all over the globe, including our industry brands, end users, and ecosystem partners. Your presence at this event is highly valued, and I strongly recommend you attend. As members, you receive a 50% discount on the ticket price. We charge for tickets because we do not do sponsorships for the event. This ensures that we serve you and the attendees and are focused on creating an amazing thought leadership agenda and networking opportunity. ACS24 Europe opens with a reception on 5/29 at 6pm and kicks off at 8am on 5/30. We are thrilled to be cohosting it with Google at their amazing facility. I look forward to seeing you in Zurich. More information and how to get your tickets can be found here.

Four of the ten 1:1 Fireside Chats highlighted here:

And additional 1:1 and panel speakers are:

  • Michael Hill, Global Product Lead, Google

  • Hugo Wendling, Wavelynx Technologies, Chief Executive Officer

  • Roberto Gaspari, Iseo Serrature s.p.a., Chief Executive Officer

  • David Sullivan, AMAG Technology, President

  • Alper Cetingok, Raymond James & Associates Senior Managing Director

  • Rob Schuurman, Nedap, CCO

  • Danny Smith, ColorID, Co-Owner

  • Killian Darcy, Integrated Security Director & Technical Solutions Engineer

  • Caj Gardemeister, IHL Turva Oy, Account Manager

  • Lars Kämpe, Zenitel, Director Global Strategic Alliances EMEA

  • Anthony Chow, igloocompany, CEO & Co-Founder

  • Pierre-Antoine de Morel, STiD Managing Director

  • Ricardo Jardim, Chaviarte Locksmith Group, Founder and CEO

  • James Shannon, essensys ,Chief Product & Technology Officer

  • Jordan Burnsed, Agora Partnerships, CEO

  • Hildur Smaradottir, Defigo, CEO

  • Natalia Armendariz, Veridas, Identity Expert

  • Dan Drogman, Smart Spaces, CEO

  • Matt Bennett, HID Director, Strategic Alliances

  • Chris Boultwood, Workspace, Head of Technology

  • Sharon Yang, Google Strategic Partner Manager, Google Wallet

  • Andreas Raab, Nuki Home Solutions, Head of Corporate Development

  • Marc Sarmiento, Austrian Post, Head of Research & Innovation

  • Roy Jeunen, NineID, Co-Founder

  • Karsten Noelling, KIWI, CEO

  • Jonathan Hays, Silverpine, CEO

  • Kris Riise, Unloc, Founder & CEO

  • Dave O’Toole, Touch2access Ltd, Founder and CMO

  • Divyakant Gupta, IDCUBE, Founder & CEO

  • Dinesh Desai, BASF Security, EHS Services

  • Allan Chester, any2any GmbH, CEO & Co-Founder

  • Philip Tidd, Gensler, Principal/Managing Director

  • Travis Willis, dormakaba, Senior Product Manager

  • James Kendall, SwiftConnect, Director of Enterprise Engineering

  • Christoph Beckenbauer, Legic, General Manager

  • Divyakant Gupta, IDCUBE, Founder & CEO

  • Mikhail Strunkin, Google, EMEA Physical Access Partnerships Lead, Google Wallet

  • Dan Katz, Brivo Vice President, Enterprise and Alliances

  • Michael Vandeven

  • Ivan Kravchenko, CoreWillSoft GmbH, CEO & Founder

  • Gareth Ellams, Honeywell, General Manager

  • Andrew Campagnola, VTS VP, Strategic Initiatives

  • Jake Leichtling, Verkada, Director of Product

  • Rick Caruthers, Galaxy Access Control, President/CEO

  • Sven Teichmann, Uhlmann & Zacher GmbH

  • Rob Lydic, Wavelynx, President

  • Josef Sachta, Sharry, CEO

And more to come!

As always, your feedback is invaluable to us. Please let me know if there's any area where we can better meet your expectations.

Thank you!

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!


Why We Cannot Call the Security Technology Industry "Recession-Proof”

It’s one of my biggest pet peeves—logging onto LinkedIn and seeing some clueless manned guarding providers claim their industry is “recession-proof" in a clear marketing shill piece.

It’s as if they think UberEats couldn’t potentially hire half their workforce tomorrow. Aside from the hyperbole, such statements show a blatant disregard for empirical evidence and even a basic understanding of macroeconomics.

The security technology industry, which includes the integration and manufacturing of access control and surveillance systems, isn’t immune to this flawed thinking either. 

Take this gem from a July 2015 asmag.com article, where Baudouin Genouville, Global Alliances and Integration Manager at Suprema, declared: “Security is viewed as a long-term investment and overall necessity. The industry's unique characteristics allowed it to stay relatively free from the effects of the recession.”

The article further adds: “In fact, the access control industry is driven not so much by economic factors as it is by security-related events, which were aplenty since 2007.”

I'm sorry, what? If you run a business, that business is just as sensitive to the business cycle—hence the name—as any other in your industry, which straddles the technology, industrials, and communications GICS sectors. 

It's a stupid heuristic executives need to stop hand-waving into their strategy as there is little real evidence beyond anecdotes to suggest that demand for security technologies and services is inelastic - its still remarkably sensitive to economic cycles and the broader market, as I will prove shortly. 

This article might resonate more with those actively investing in public security technology companies like Allegion, ADT, Alarm.com, etc. However, for the executives of these companies reading this, you’ll find some key takeaways that might actually make your company more recession resistant.

Understanding the business cycle and recessions

For many of us, the word "recession" evokes scenes from TV channels like CNBC or that dreadful moment when you’re handed a pink slip and a cardboard box for your belongings. 

However, a recession is more than just a trigger for "adult fears"; it's a fundamental phase of the business cycle, which every economy undergoes periodically. It is composed of several stages:

Source: Corporate Finance Institute

  1. Expansion: This phase features increasing economic activity. Key indicators such as employment, production, and sales figures rise. Businesses expand; consumer confidence strengthens and spending increases.

  2. Peak: This is the zenith of economic activity and expansion. The economy is performing at its maximum output. However, it’s also the point where things can start to overheat, leading to inflation and other economic imbalances.

  3. Recession: Following the peak, economic activity begins to decline. Recession is typically marked by a fall in GDP in two successive quarters. Employment, consumer spending, and manufacturing output decrease. Businesses scale back, and economic confidence wanes.

  4. Depression: A severe and prolonged downturn in economic activity. While not a compulsory stage in every business cycle, when it occurs, depressions signify a deep recession with long-lasting effects on employment and economic growth.

  5. Trough: The bottom of the cycle, where economic activity is at its lowest. This stage marks the end of declining economic activity and sets the stage for recovery.

  6. Recovery: During this phase, the economy starts to grow again, moving out of the trough towards a new period of expansion. Employment rises, consumer spending increases, and confidence begins to restore.

Currently, pinpointing our exact position in the business cycle without deep macroeconomic analysis is challenging, especially given the mixed signals in the economy. 

The Fed has paused interest rate hikes after a vigorous increase, the strongest since the Volcker era, indicating a possible move towards economic stabilization. However, with an inverted yield curve and the Fed Funds Rate (FFR) at 5.25-5.5%, alongside an upward tick in the Consumer Price Index (CPI) for the third consecutive time yet strong employment and new housing starts, signals are mixed. 

Given these factors, I would hazard a guess that we might be transitioning from peak to early recession phase, but again, DYOR. 

Which sectors are defensive?

When financial pundits on TV talk about "defensive" investments, they’re usually referring to sectors that exhibit inelastic characteristics due to their structural features. 

"Inelastic" in economic terms means that the demand for goods and services in these sectors remains relatively stable regardless of changes in economic conditions. This stability is due to the essential nature of the products and services these sectors provide.

Here are three actual defensive, "recession-resistant" sectors (note: security technology is not among any of them):

  1. Utilities are essential services—electricity, water, gas—that people need regardless of the economic climate. The demand for these services does not decrease significantly even in a downturn because they are fundamental to daily living. In addition, they benefit from natural monopolies and government regulations. 

  2. Consumer staples includes goods like food, beverages, household items, and hygiene products that consumers need regularly. People may cut back on luxury items during a recession, but they still need to buy groceries and basic household necessities.

  3. Healthcare is perhaps the most essential of all, as medical needs do not decline during economic downturns. In fact, during periods of economic stress, the demand for certain healthcare services may even increase and is buoyed by insurance subsidies. People continue to require medications, medical care, and hospital services, making this sector highly resilient to economic shifts.

We can see this in play during numerous historical recessions (or in the case of COVID-19, a narrowly averted one due to unprecedented and arguably reckless levels of fiscal stimulus).

Source: Portfolio Visualizer

In each crisis, the three aforementioned defensive sectors suffered lower losses compared to the broad U.S. market (as measured by the S&P 500 index). 

Sure, this chart measures stock prices, but that’s a fairly reliable indicator of market consensus and expectations about the earnings prospects of these companies at the time relative to the economy. As the saying goes – "its priced in."

Why security technology isn't recession resistant

In exploring whether the security technology industry is recession resistant, I analyzed data from prominent names in the ACEB Focus 10 Index, comparing their performance to the broader market during economic downturns. Spoiler alert: they didn’t fare as well as one might hope.

First, let's consider large-cap and mid-cap companies like Allegion and ADT, which had five-year monthly betas of 1.57 and 1.13, respectively. 

For those not steeped in financial jargon, 'beta' measures a stock's volatility and direction relative to the overall market. A beta greater than 1 indicates higher volatility and sensitivity to market movements. 

Thus, Allegion’s beta of 1.57 suggests it's significantly more sensitive to economic shifts compared to the market, while ADT's beta of 1.13 makes it marginally more sensitive than the market. 

To further test their recession resilience, I looked at how these companies' stock prices reacted during the initial shock of the COVID-19 pandemic in March 2020—a recent and relevant stress test. 

If the market perceived them as truly recession-resistant, their stock prices should have fallen less than the S&P 500, similar to sectors like consumer staples, healthcare, and utilities. 

That is, market participants would have agreed that the revenues and earnings of these companies would not be affected as much, and thus would not have revised their valuations accordingly. 

However, the results were telling. ADT's stock plummeted by 45.03%, Allegion's by 28.61%. For context, the S&P 500 fell by 19.63% during the same period.

Source: Portfolio Visualizer

What about older, more established companies in the sector? Consider NAPCO Security Technologies. During the 2008 subprime crisis, NAPCO experienced a staggering 84.16% drawdown, and during the COVID-19 pandemic, it saw a 48.40% loss. Even seasoned management and long tenure in the industry do not shield a company from severe downturn.

Source: Portfolio Visualizer

These data points clearly indicate that the security technology sector is not immune to recessions. The economic sensitivity reflected in their high betas and significant stock price declines during market downturns contradicts any notion of this industry being recession resistant.

Key takeaways for investors and executives

I'm not a fan of simply critiquing an industry without offering actionable insights, so here are some practical takeaways for both parties.

For Security Industry Investors

No amount of expertise, insider knowledge, or "conviction" can shield you from macroeconomic forces. Treat your security holdings as what they empirically represent—a high-beta, cyclical industry that blends characteristics of technology, communications, and industrial sectors. 

To manage risk effectively, consider using a barbell strategy: pair your security investments with risk-off assets like Treasuries or gold, which have low correlation to stock markets, or diversify into truly inelastic sectors with strong brand power and wide margins, such as large consumer staples like Coca-Cola and Procter & Gamble. (Full disclosure: I own shares in both.)

For Executives

Dividends and buybacks are attractive, but what really counts during tough times is having a robust, fortress-like balance sheet. This concept is not new—Global Systemically Important Banks (GSIBs) like JPMorgan Chase maintain high regulatory capital requirements for this reason. 

Leaders like Warren Buffett at Berkshire Hathaway and tech giants like Apple exemplify this approach, keeping substantial cash reserves that allow for flexibility in product development and market positioning during downturns. 

While leveraging can fuel growth during favorable economic conditions, remember that both investors and employees have longer memories of hard times than good.

Also, take a close look at where your revenues are coming from. For instance, consider the current plight of commercial real estate investment trusts (REITs). 

Those focused on sectors with high vacancy rates, like certain office spaces or discretionary retail, are currently under strain. Conversely, self-storage REITs or retail REITs with durable tenants like Walmart or Kroger are performing more robustly. 

Assess whether your products are predominantly leased to volatile sectors like tech startups, which may be facing a crunch in a rising rate environment and shrinking venture capital flows, or more stable industries like self-storage facilities and distribution centers.


The Access Control Industry Needs to Follow Cybersecurity When it Comes to Bug Bounty Programs

Recently, a LinkedIn post caught my eye. Lee Odess and Daniel Raines discussed the futility Raines felt in disclosing vulnerabilities, with Raines expressing, "I'm no longer disclosing any vulnerabilities. It is a monumental waste of my time." Lee's response? It's time the access control industry started paying for bug bounties.

I'm not claiming to be an industry expert, but the dissonance is striking. Organizations like ASIS often tout the importance of "convergence" with cybersecurity, yet tangible actions, especially those mimicking cybersecurity's best practices, seem sparse. 

Beyond proliferating "alphabet soup" post-nominals, ego-stroking seminars, and hosting networking events, there's a notable practical gap in adopting effective cybersecurity measures like bug bounty programs.

To underscore this point, I've compiled empirical data and real-life examples demonstrating the effectiveness of bug bounty programs in cybersecurity. My hope is that this evidence will inspire access control executives to champion the changes necessary to enhance their industry's security posture.

What are bug bounty programs?

Bug bounty programs are essentially a call to arms for cybersecurity enthusiasts and researchers. Companies invite individuals to find and report vulnerabilities in their systems, offering monetary rewards for their efforts. 

The logic is simple yet profound: bad actors are constantly on the lookout to exploit vulnerabilities, and identifying these weak spots internally can be challenging. Without knowing your system's vulnerabilities, how can you defend against or intercept potential threats?

These programs play a critical role in preventing zero-day attacks—vulnerabilities that are exploited by hackers before the developers are aware of or have patched them. By encouraging the discovery and disclosure of these vulnerabilities, companies can significantly enhance their security posture before malicious actors can cause real damage.

At the highest echelons of the tech world, bug bounty programs are not just common; they're considered a crucial part of the security strategy. For instance, Meta Platforms (formerly Facebook) runs a high-profile program with payouts that can reach up to $300,000 for particularly critical vulnerabilities. 

To give you an idea of the scale and impact, as of 2022, Meta Platforms has disbursed over $16 million in bug bounties for more than 8,500 awarded reports out of over 170,000 submissions. In 2022 alone, they awarded over $2 million to researchers across more than 45 countries, from roughly 10,000 reports received, with more than 750 earning a bounty.

Similarly, Alphabet runs a comprehensive program for Google bug hunters, covering Android, Google devices, Chrome, Google Play, and more. Their approach includes extensive rulesets, incentives, and even a leaderboard to foster a competitive yet collaborative environment for uncovering vulnerabilities.

Do these programs work?

Beyond the intuitive benefits of combining good publicity, competitive spirit, and financial incentives to motivate individuals to uncover vulnerabilities, there's solid research underscoring the effectiveness of bug bounty programs. 

An analysis by Thomas Walshe and Andrew Simpson from the Department of Computer Science at the University of Oxford provides substantial evidence. 

They found that overall, the average annual cost of running a bug bounty program is actually lower than the expense of employing two additional software engineers, demonstrating a net positive impact for organizations.

Here's a concise summary of their findings:

  • Expected Cost per Year: The daily operation of a bug bounty program averages $230, resulting in an annual cost of approximately $83,950. This figure is based on a 95% confidence interval of [$126, $334] daily. This is less than the cost for two full-time engineers.

  • Expected Benefit per Year: Programs typically receive 0.429 new valid reports each day, totaling 156 valid reports annually. Newly launched programs may see up to 20 new reports per day, highlighting the initial rush to uncover easily identifiable vulnerabilities. On average, 13 critical vulnerabilities are identified each year through these submissions.

  • Program Activity Over Time: Analysis shows that after an initial surge, the rate of vulnerability discovery stabilizes over the lifespan of a bug bounty program, maintaining a relatively constant flow of reports. This can help assuage concerns from executives that "the program won't be active enough to justify the cost."

  • Impact of Bounty Amounts on Submissions: Interestingly, increasing bounty payouts does not proportionally increase the number of reports. The study found only a weak correlation between higher bounties and submission numbers, with many participants driven more by reputation and the opportunity to access private programs than by direct financial rewards.

Bug bounty adoption in the access control industry

The urgency for adopting bug bounty programs in the access control industry cannot be overstated, underscored by high-profile breaches that reveal profound vulnerabilities. 

A notable instance is the hacking of hotel keycard systems using a technique dubbed "Unsaflok." This method targets Saflok-brand RFID-based keycard locks by Dormakaba, which are installed on 3 million doors across 131 countries, many of which are residential or hospitality.  

By exploiting encryption weaknesses and flaws in the MIFARE Classic RFID system, white-hat hackers demonstrated the ease with which they could gain unauthorized access, raising significant security concerns due to the breach's severity and widespread impact.

However, the access control sector is not alone in facing such challenges. A distressing incident involving a Ring security camera hack in a family's home illustrates the broader implications for related security technologies in surveillance.

Hackers accessed the camera, harassed an 8-year-old child, and compromised the family's sense of security, showcasing the dire and personal consequences of inadequate cybersecurity measures.

Despite these glaring incidents, the adoption of bug bounty programs within the access control industry appears to be lagging. 

A sparse example can be found in https://www.boxlock.io/vulnerability-disclosure-programBoxLock's "Vulnerability Disclosure Program," which lacks detailed information on incentives, past reports, or any form of engagement strategy akin to best practices observed in the tech industry. 

However, not all is bleak. For example, Axis Communications has taken a proactive step by partnering with Bugcrowd to launch a private bug bounty program, offering cash rewards based on the severity of vulnerabilities found, with plans for public disclosure and patching.

How to create a successful bug bounty program

Finally, as with any project, the success of a bug bounty program depends on proper execution. An analysis by Standoff 365 found that the best bug bounty programs embodied the following attributes. 

  • Result-Oriented: Rewards are distributed based on vulnerabilities found, not the time spent searching for them. This approach ensures that the program's costs are directly tied to its benefits, which also makes it an easier sell to management.

  • Appropriate Infrastructure: Having the right tools and systems in place is crucial for managing submissions, communications, and rewards efficiently – consider outsourcing to a dedicated public platform like HackerOne.

  • Competent People with Relevant Expertise: The success of a program often depends on the team behind it, requiring individuals with the technical knowledge to evaluate reports accurately. Forget hiring for post-nominals – find people who have documented, but informal experience breaking into systems and get them to work on your side. Hackers aren’t screening recruits for a CPP or CISSP, why should you?

  • Positive Company Public Image: A company's reputation can influence a program's attractiveness to potential participants. A positive image can attract more and higher-quality security researchers. People flock to test Google and Meta's architecture beyond the high payouts for a reason. 

  • Selecting the Right IT Assets for Testing: Knowing which parts of your digital infrastructure to subject to these tests is vital for uncovering the most impactful vulnerabilities. Is it databases? Do you have blockchain integrations? Is your API vulnerable?

  • Clearly Defined Program Scope: Clear guidelines help ensure that participants understand what is expected, reducing the number of irrelevant submissions.

  • Severity-Based Reward Structure: The payment scale must vary with the severity of the vulnerabilities discovered. Standoff 360 suggests $7,200 for critical, $3,000 for high-severity, $1,100 for medium-severity, and $254 for low-severity issues.

For a thought exercise, try and assess how many of these Axis Communication's new bug bounty program possess.

What about your own organization?


The Forum at The Security Event in Birmingham

We partnered with The Security Event, held April 30 - May 2 in Birmingham (UK), to activate The Forum. The Forum is a thought leadership pavilion hosting over 25 companies and 30 discussions on various topics. You can find the full schedule, topics, and presenters here.

Companies participating are IDCube, Tapkey, ISEO, Galaxy Systems, acre security Syngaurd, CoreWillSoft, Touch2Access, Sharry, STiD, ILOQ, Comelit, Honeywell, Keynetics, Wavelynx, Gallagher, AMAG, Suprema, Hivewatch, and HID.

We are taking a different approach to presenting ideas and discussions. We broke down the topics into five different formats:

  • Trends: Innovative Approaches to Presenting Industry-Impacting Trends

  • Vertical Market Discussions Conventional approach to addressing particular industry verticals

  • State Your Claim: Introducing a new format: presenters will have 2 minutes to state their claim on controversial industry-related topics. This unfiltered insight into leading manufacturers' views will shape the industry for tomorrow. Attendees' views will be collected and shared in a cohesive report after the show.

  • Your POV & Live Poll: Presenters will have 2 minutes to express their views on a topic in the new format. This will provide attendees with unfiltered insights into how leading manufacturers perceive controversial issues affecting the industry today and shaping it for the future. At the end, attendees will vote for the presenter they believe best conveyed their point of view.

  • Position Paper Live In the new format, presenters will use a previously published position paper as a foundation to develop their perspective on the topic. Subsequently, the position paper will be updated to incorporate the shared views.

Topics will include:

  • AI in Access Control and Smart Locks: Today's Innovations and Applications for Tomorrow's Future

  • Vertical Discussion:

    • Industrial Vertical

    • Critical Infrastructure Vertical

    • Commercial Real Estate Vertical

    • Hospitality Vertical

    • Residential Vertical

    • High-Security Government and Federal Vertical

    • Retail Vertical

    • Education Vertical

  • Merging Horizons: Are Video Surveillance and Access Control Now Indistinguishable?

  • Integrating Access Control: Enhancing Business Operations with Digital Keys, Companion Apps, and Add-Ons

  • Is going direct to customers by manufacturers good or bad? A case and a conversation on both.

  • State Your Claim:

    • Convince Us Why Proprietary or Non-Proprietary is Better

    • What defines the new enterprise in access control system?

    • Balancing Security and User Experience in Physical Access Control Systems: Challenges and Best Practices

    • What Modality Will Win and Where - cards, mobile, biometrics, etc?

  • Breaking Barriers: Advancing Inclusion in the Physical Access Control Industry

  • Your POV & Live Poll: Is Cloud, Onsite, or Hybrid architecture better? Why?

  • Establishing and Maintaining a Robust Cybersecurity Framework: Strategies for Enterprise Security Excellence

  • Are Visitor Management and Access Control One in the Same?

  • Position Paper "Live": Your Thoughts and Why a Power Shift is Happening Right Now in the Global Access Control Market

  • Optimizing Security and Communication: Strategies for Efficient, Scalable, and Integrated Access Control Systems

  • State of Digital Credential Market Adoption in the UK and Surrounding Areas

Designed by the industry for the industry, The Security Event returns to the Birmingham NEC from April 30 - May 2, 2024, reuniting manufacturers, distributors, installers, integrators, consultants, and end users.

The exhibition will showcase the world's leading security brands, offering you the best opportunity to source the latest products, technologies, and solutions while networking and meeting with key experts from across the industry. Ensure you're up-to-date with the latest developments and issues in security via our comprehensive education program.


ACS101 Course Development

Access Control Executive Brief members collaborate weekly to develop the industry's first 2-week Access Control 101 education sprint. Through 12 planned modules and weekly 1 hour webinars, the members want to bring a highly effective and non-influenced primer course for everyone and anyone looking to enter the access control industry. We hold weekly calls on Fridays and work together in shared docs, Miro boards, and Slack to create this curriculum. If you want to contribute, please message me and join us on Slack at channel #acs101. Thank you to the following members who have contributed so far.

Volume 139
Volume 139 | April 7, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Part of my process when preparing to moderate a discussion or conduct interviews is working from large speaker cards. On those cards are my questions and the details I want to make sure I cover, and I always leave space to tak...
Volume 138
Volume 138 | March 31, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. ISC West is done, and here are my takeaways. Below, I clarify the most important patterns and insights from the event. 🎧 Prefer to listen instead? Hilary and I recorded this week’s Secured episode on the show floor at the end...
Volume 137
Volume 137 | March 19, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Hello! I wanted to get this Brief out to you before I (we all) headed to ISC West, but it got lost in the trade show shuffle. This Brief does something the quarterly earnings calls rarely allow. Allegion’s CFO, Mike Wagnes, s...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.