Header Logo
Log In
← Back to all posts

Volume 69

Aug 03, 2026

Volume 69 | August 19, 2024

Welcome to Brief 69, a three-part series. It includes my thoughts on the DEFCON HID news titled "Truths From DEFCON," a great write-up by Tony Dong on "Mastering the Acquirer's Multiple: Identifying Attractive M&A Targets," and a recap of a 2024 Americas Office Occupier Sentiment Survey report by CBRE.

Like many of you, the summer or winter season is coming to a close. That means schools are open, Q4 is right around the corner, and trade show season is upon us. Here are some of our upcoming trips, which include a mix of one-on-ones and events. I'm excited about how this is all coming together. More trips are on the way, and we will announce them soon. Please let me know if you are attending any of these events or want more information on what we will do.

  • Meeting with ColorID in Charlotte, NC (August)

  • Meeting with HID in Austin, TX (August)

  • Legic connect24 in Zurich (September)

  • Brivo BProptech Event in Washington, DC (September)

  • VerkadaOne in Denver, CO (September)

  • The Atlantic Festival 2024 in Washington, DC (September)

  • Bergfest (Oktoberfest with Any2Any and a large group) in Munich (September)

  • Securing New Ground in New York, NY (October)

  • AMAG SES24 in Tewkesbury, UK (October)

  • OPTECH in Washington, DC (October)

  • ISC East (Critical Infrastructure Pavilion) in New York, NY (November)

  • Security Investor Conference in New York, NY (December)

  • Intersec Dubai Thought Leadership Pavilion in Dubai, UAE (January)

As always, your feedback is invaluable to us. Please let me know if there's any area where we can better meet your expectations.

Thank you!

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!


Truths From DEFCON

As most of you know, there was news out of DEFCON last week that was previewed by Wired and then broken down by many, including my favorite breakdown by Brian Karas. Links are available if you need to read what happened or the breakdowns.

I received many text messages, DMs, and calls about it. After thinking about it, here are my less apparent observations. I wanted to add some context and additional thoughts to the conversation.

Overall

DEFCON exposed a lot of known truths, and most of them were not the obvious ones. Yes, it revealed that the HID keys have been compromised, but it also exposed the following:

Net Positive for the Future

Just like with consolidation in our industry, moments like this are net positive. We are not an industry that proactively changes or invests in advancements. We rinse and repeat, incentivized to sell old technology—across manufacturers, distribution, consultants, installers, and end users- all in the name of "security." We need moments like this to enable investments and challenge old truths. Net positive for today and tomorrow. Net negative for yesterday.

Another Case for Communication and Community

Our industry has historically underinvested in communications and community building, a fact that becomes glaringly apparent during a crisis. We often find ourselves scrambling and looking unprepared. While I'm not singling out HID, this applies to the entire industry. We need to be more proactive in our approach. We should have clear points of view on such matters and focus on forward-looking analysis rather than hindsight commentary. The resources for this are already available, and we should use them.

Ugly Truths Abound

Every industry, including ours, has its share of ugly truths that come to light as it becomes more mainstream. We've held onto 30-year-old products built for a different time, with specific technological capabilities and far less awareness. The choice is whether to be proactive or reactive. For instance, assume that all legacy credentials and readers are exposed. We should mirror the IT industry and implement multiple layers of security. It's time for us to be more proactive in our approach.

Identity Crisis

The truth is that our industry has an identity crisis. Although we discuss valuing security, practices don't always reflect this. For instance, "Password" remains the most commonly used password year after year. Similarly, prox cards and other low-frequency, low-security cards, and readers are used by over 80% of the market. Even more telling, of the 20% that use high-security readers and credentials, nearly 50% still support less secure credentials. From what I've heard about the IP video industry, the same is true there. Hence, the meme above.

Welcome DEFCON!

The DEFCON community is part of the physical security community and should be viewed and treated as such. I am curious how many companies prioritize attending the show, engaging with its members, and building resources to support them.

IPVM's Exposed Weakness?

My feelings about IPVM, especially their CEO, are well documented. Putting that aside, it has been interesting (and fun) to watch IPVM “report” on this. Are they being exposed?

Although I am not surprised, given my understanding of them and the access control industry, the extent to which they've been wrong on this subject is shocking. The truth is that IPVM has shown that it does not understand the access control industry as well as it understands video. Their "red in the face/we are going to make HID their new HIKVision and others" approach is not as effective.

Is it their pre-social media format, a blog and message board, outdated? Are they losing influence in North America? Are they the Huffington Post or Buzzfeed of our industry that becomes less productive over time due to market shifts, unwillingness to change models, and leaders who put themselves before the product?

To me it is clear. If you followed Wired, Mistial Developer, and Brian Karas, you were more informed than through any of the usual outlets, including IPVM. Is this a sign of the times?

Managed Services for the Win

This is a massive opportunity for security integrators, systems integrators, distributors, and manufacturers to explore managed services more deeply. While we often hear about enterprise end users "managing their keys," most of the market won't, but we would be happy to pay for managed services.

There's also an opportunity for security integrators, systems integrators, and distributors to absorb the cost difference between low and high-security cards and readers. Treat it as a marketing expense and promote that you can provide high-security cards/credentials and readers at the exact cost as low-security ones. Eventually, manufacturers may reduce costs, but until then, make it a story you can own, differentiate, and demonstrate its relevance to your customers.

Honest Conversations Needed

The idea that "prox must die" is not a reality. As someone who once promoted that and even made pins that said "kill prox" and wrote an article about moving away from it as an industry, I have reconsidered. I now believe it is a product that should be used properly for the proper use case. That use case may be minimal, but the technology is not the problem. We are not applying the right technology to the appropriate use cases and are overusing prox.

It's easy to say, "See? That's why we must use PKOC (or insert your favorite 'standard')." But make sure your system is in order. Asking one question like, "So, does that mean your system doesn't support proxy anymore?" can make you look foolish. Again, see the meme above.

Clear Points of View

As an industry, we lack a clear perspective on what "good" looks like. Our viewpoints are heavily influenced by the solutions or products we sell or are most comfortable with. When I speak to many of you individually, your tone differs from when it's public. Privately, most of you emphasize a layered approach to security. However, in public, besides consultants, many of you loudly proclaim that your card, reader, biometric device, mobile wallet, or other technology is the ultimate security solution. The reality is that it's a layered approach that incorporates your chosen technology as the appropriate solution for the customer application.

So Now What?

The question I have is, what are we going to do about it? For those pursuing or working in the modern era of electronic access control, the old rules don't apply. We can shape it to be what we want. If we want to apply the right solutions for the proper use cases, let's do it. If we need to "kill prox," then let's do it. Too often, we let the past dictate the future. That's been the case for the past 30 years. Their own rules will define the next 30. Let's make them.


Mastering the Acquirer's Multiple: Identifying Attractive M&A Targets

by Tony Dong

The buzz on the Access Control Executive Brief Slack channel recently has been all about the flurry of merger and acquisition (M&A) activity within the access control sector. 

Just to name a few highlights, Lee pointed out HID's acquisition of Sewio in early August, ASSA ABLOY’s impressive streak of eight acquisitions in the second quarter, and VITAPROTECH’spurchase of Identiv's security business for $145 million in April.

While M&As might seem like esoteric financial maneuvers, they actually boil down to two fundamental objectives:

  1. Paying a fair price for the target company's expected future cash flows.

  2. Realizing the anticipated synergies and cost-efficiencies post-acquisition.

In reality, achieving these goals is far from straightforward. The corporate world is filled with examples of disastrous M&As that eroded massive shareholder value, such as Time Warner's merger with AOL at the height of the dot-com bubble. Conversely, there are also landmark success stories, like Exxon's acquisition of Mobil in 1999, which significantly enhanced shareholder value.

So, as an access control executive potentially involved in overseeing M&A activities—and heeding my call to become a strategic "deployer of capital"—how can you ensure that your acquisitions meet these critical objectives?

One effective approach is by focusing on a key metric: the acquirer's multiple. This measure can guide you in identifying attractive M&A targets that are likely to achieve both a fair purchase price and the desired synergies.

What is the acquirer's multiple?

When evaluating how much a company is worth, financial analysts use various metrics. One commonly referenced metric is the "price to forward earnings ratio," or "forward P/E." 

This ratio divides a company's current share price by its expected earnings per share over the next 12 months. For instance, ADT's share price right now is $7.26 and its expected earnings per share for the next year are $0.70, its forward P/E would be 10.43. This means investors are willing to pay $10.43 for every $1 of ADT's expected earnings.

However, the forward P/E ratio often proves to be a red herring. Despite its popularity, it has mediocre predictive power concerning future returns. Tobias E. Carlisle, in his book Deep Value: Why Activist Investors and Other Contrarians Battle for Control of Losing Corporations, highlights that investing based on the price-to-forward earnings ratio significantly underperformed the broad market with a compound annual growth rate of just 8.6%.

A more effective metric is the aforementioned "acquirer's multiple," which uses the Enterprise Value to EBITDA ratio (EV/EBITDA).

  • Enterprise Value (EV): This is calculated by taking a company's market capitalization (share price times outstanding share count), adding debt, and subtracting cash. This formulation provides a more comprehensive measure because it considers the company's entire capital structure. The rationale here is when you buy a company, you take on its liabilities (debt) and assets (including cash), thus needing a fuller picture than just market capitalization.

  • EBITDA (Earnings Before Interest, Taxes, Depreciation, and Amortization): This measure is a way to look at a company's profitability from its core business operations without the effects of financing and accounting decisions. It strips out the costs of debt (interest), taxes, and the accounting treatments of depreciation and amortization, which may vary from company to company. It also facilitates easier comparisons between companies with different capital structures or tax environments.

The acquirer's multiple provides a clear view of the value of a company, adjusted for its capital structure. It is often seen as a better indicator than just using net income or forward earnings, which can be affected by accounting policies and one-off charges or gains

Interestingly, taking the inverse of the acquirer's multiple (EBITDA/EV) gives you the earnings yield. This metric is valued by legendary investor Joel Greenblatt as part of his "magic formula" for identifying good companies at fair prices.

How to Use the Acquirer's Multiple

The acquirer's multiple is a crucial tool for identifying potential M&A targets, but it's important to understand that it doesn't provide a full valuation on its own. 

For comprehensive valuation, detailed financial modeling is required. As an access control executive involved in capital deployment, you should ideally delegate the intricate modeling work to your team while focusing on strategic decision-making.

Your strategy should involve using the acquirer's multiple to periodically screen the universe of potential acquisition targets. Keep an eye on how this metric evolves over time to gauge whether a company becomes more or less attractive as an acquisition target. 

For example, when considering a company like ADT, review how its acquirer's multiple has changed over the years:

  • ADT's Latest Twelve Months EV/EBITDA: 5.9x

  • Average EV/EBITDA (2019-2023): 7.4x

  • Median EV/EBITDA (2019-2023): 7.5x

  • 5-Year Peak (December 2021): 8.7x

  • 5-Year Low (December 2023): 6.2x

  • Yearly Changes:

    • 2022: 7.9x (-8.7%)

    • 2023: 6.2x (-22.2%)

    • 2019: 6.8x (+14.3%)

    • 2020: 7.5x (+9.6%)

    • 2021: 8.7x (+15.5%)

It’s also essential to compare these figures not just with direct competitors in the access control industry, but also with broader intra-sector and external sector competitors:

Based on the above data, ADT's relatively lower EV/EBITDA compared to its peers suggests it could be an undervalued target, meriting further investigation. 

If ADT appears promising, the next step is to instruct your team to begin the due diligence process. This includes a comprehensive review of ADT's financials, business model, market position, and potential synergies with your business. 

As a leader, your role is to guide this process, ensuring that your team thoroughly understands the financial and strategic implications of the acquisition. 

You should focus on overseeing the analysis, asking critical questions, consult with the board and prominent shareholders, and ensure that all potential risks and benefits are carefully weighed before any decisions are made.


2024 Americas Office Occupier Sentiment Survey report by CBRE

Here's a summary of the key points from the 2024 Americas Office Occupier Sentiment Survey report by CBRE. I found this report highly relevant to our industry. Although it's focused on North America, from my travels, the sentiments are felt globally and can be applied.

The 2024 office landscape continues to evolve, with some interesting shifts from previous years. Let's break down the key takeaways:

  1. Return-to-Office Policies: While 80% of organizations have implemented RTO policies, only 17% actively enforce them. This disconnect is creating a gap between employer expectations and employee behavior. I find this conversation exhausting and don't understand why it's polarizing. You should run your business how you want and need to and work at a place that fits how you want to work. I recognize that some will say they have no choice, but that's all part of the decision process. We all do things we don't want to do at the expense of others, and we make those decisions entirely by understanding their implications. I don't know why this is a continued conversation.

  2. Office Utilization: We're seeing a stabilization in office utilization patterns, with 64% of respondents reporting they've reached a steady state. However, there's still a mismatch—60% of employers want employees in the office 3+ days a week, but only 51% show up that frequently.

  3. Portfolio Strategies: There's a notable shift towards expansion. 38% of respondents expect portfolio growth, up from 20% in 2023. This suggests a potential rebound in leasing activity, particularly among smaller companies.

  4. Flight to Quality: The trend continues, with 59% of respondents looking to relocate to better-quality space. A desire for improved amenities and services for employees drives this.

  5. Flexible Solutions: Occupiers are increasingly seeking flexibility. 49% are exploring or executing shorter lease terms, and 58% want more flexible expansion and contraction options. This demand for flexibility is also driving growth in flex space usage.

  6. Technology Adoption: 65% of respondents have a digital strategy, with larger companies leading the charge. AI is gaining traction, with 43% of respondents using it in their real estate processes, particularly for leasing and contract management.

  7. Sustainability Focus: 57% of respondents (and 86% of large companies) have publicly stated net-zero pledges, mainly targeting 2030. Green building certification is a critical factor in site selection for 55% of respondents.

The office market is clearly in a state of flux. Occupiers are balancing the need for quality space to attract employees with the desire for flexibility in an uncertain economic environment. The emphasis on technology and sustainability suggests that the office of the future will be brighter and greener. As we progress, I'll closely monitor how these trends evolve and impact office demand and design, ultimately affecting the access control and smart lock industry.

Volume 139
Volume 139 | April 7, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Part of my process when preparing to moderate a discussion or conduct interviews is working from large speaker cards. On those cards are my questions and the details I want to make sure I cover, and I always leave space to tak...
Volume 138
Volume 138 | March 31, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. ISC West is done, and here are my takeaways. Below, I clarify the most important patterns and insights from the event. 🎧 Prefer to listen instead? Hilary and I recorded this week’s Secured episode on the show floor at the end...
Volume 137
Volume 137 | March 19, 2026 Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here. Hello! I wanted to get this Brief out to you before I (we all) headed to ISC West, but it got lost in the trade show shuffle. This Brief does something the quarterly earnings calls rarely allow. Allegion’s CFO, Mike Wagnes, s...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.