Volume 1
Welcome to The Secured Brief! What used to be two publications, the Access Control Executive Brief and The Security Breakdown, is now one. Thank you for rolling with us through this huge transition. This community is what makes it worth doing, and we knew you deserved more, so we made it happen.
— The TACC Team
🎙 Secured Podcast
Episode 27 | The Access Control Buyout Wave Isn't Killing This Industry. It's Saving It.
Consolidation is reshaping the industry, and this week Lee explains why that's a good thing. Tune in for the M&A breakdown, the biggest deals and moves of the week, and his take on why outside capital betting on security is a signal worth more than any single deal. Listen here
✍🏻 Articles
Josh Dempsey | When Access Control Gets a Brain: How AI Is Transforming Security's Most Valuable Data Platform
Brivo just made its Security Platform API AI-native, and Josh Dempsey argues it's the first domino in a much bigger shift. Access control has always sat on incredibly valuable data, every badge read and every door event, but almost nobody uses it. Here's why AI is about to change that and turn security from a cost center into a value driver.
Rick Gallant | Why One Credential Is Never Enough: The Case for Hybrid Access Control
Card, fob, mobile, or biometric: which would you choose? Rick Gallant makes the case that the honest answer is none of them alone, and that the future belongs to hybrid credentials where the weakness of one becomes the strength of another.
Meg A Watt | Secure by Design: Rethinking Access Control Around Real-World Behavior
The security industry is racing to recruit new talent, but Meg A Watt asks the harder question: what are we actually giving people once they arrive? So much of what makes this business work lives in undocumented institutional knowledge, and a talent pipeline only works when that knowledge is flowing through it.
Chris Wilson | The Security Industry Has a Product Management Problem and a QA Problem
Chris Wilson names an uncomfortable truth: most of what ships in physical security is either a decade behind or barely tested. He traces it to two compounding failures, a legacy-versus-modern knowledge gap in product management and a nonexistent QA training pipeline, and asks whether it's a training problem, a leadership problem, or both.
Walter Candelu | Biometrics on Mobile: Rethinking Biometric Identity for a Privacy-First World
As facial biometrics scale, the real question is no longer whether they work. It's where the data lives and who controls it. Walter Candelu lays out a privacy-first approach that keeps the biometric credential on the user's own device, putting transparency and consent at the center of access control.
🚨Breaking
- ASSA ABLOY Group to acquire Gunnebo Entrance Control
- PDQ Manufacturing has acquired Command Access Technologies.
- Splan named a launch partner in SailPoint’s Unified Platform Access Program
- Brivo joins the Secure Building Council and Steve Van Till joins the Advisory Board.
Scroll down to go deeper ↓
![]()
Podcast | Secured: Episode 27
A packed news week on Secured: Splan joins SailPoint at Black Hat, PDQ acquires Command Access, Assa Abloy makes a big move on Gunnebo Entrance Controls, Honeywell completes its PSS sale, and ADI rings the NYSE bell. Lee also digs into the migration from Slack to the new Secured Collective app and why the community is making the switch, then closes with his own take on why the M&A wave, downsides and all, is the signal that capital finally believes in this market. Plus a look ahead to ACS 26 in New Zealand. Listen here

On May 14, Brivo did something I believe is the first domino to fall in the access control space.
They announced that their Security Platform API was now AI-native. They rolled out the llms.txt standard across their entire video and access control documentation, meaning the API isn't just open to developers. It's open to AI agents that can build against it and ship integrations on their own.
We've all sat through the last few years of ISC West, where every booth touted "AI" everything. Most of it was analytics or machine learning dressed up as AI. This feels different.
The case study that accompanied the announcement offers a glimpse of where this is headed. An integrator used the agentic tool OpenClaw alongside the Brivo API to connect the access control platform with a non-native third-party intrusion detection system. Their CEO was quoted as saying, "We're now at the age where your ability to develop an integration is only limited by your imagination. I described the outcome I wanted in natural language, and OpenClaw built it."
His broader point matters more: integrators are no longer beholden to a manufacturer's roadmap. They can build their own integrations without hiring a developer, waiting years, or spending tens of thousands of dollars. I have no affiliation with Brivo. I'm just genuinely impressed by the AI native direction. The API announcement was their third move in 90 days, signaling where the company is going.
First, an AI video agent that lets operators set monitoring rules in plain English. Instead of programming detection logic, you tell the system what to watch for: "alert me when someone loiters near the back door after 9 PM," or "flag any vehicle in the parking lot after closing."
In April, they launched a mobile agent that lets security professionals execute emergency lockdowns using voice commands. A school administrator can say "lock down the building" into their phone and the system executes across every door, every reader, every credential, in real time. This is an AI agent acting on a critical security workflow. It feels like a next-gen version of what we built years ago at S2 with our Threat Level Escalator app, which allowed an operator to manually initiate a lockdown.
Access Control's Untapped Intelligence Layer
Here's the part of access control that's been talked about for years but never fully leveraged.
The systems sit atop incredibly valuable data. Every badge read is a piece of information about who's where, when, and how often. Every credential is tied to an identity, a role, a department, and a schedule. Every door event is a record. Multiply that across a multi-location enterprise with thousands of cardholders and you have one of the richest operational datasets in the building.
And almost nobody uses it.
Many companies have never thought about it. Many don't know how to leverage it. Some would love to, but don't have the time or resources to extract and organize the data into a usable format. Done right, this is the kind of data that gives security a real ROI story and shifts the department from cost center to value driver. That's what LLMs change... continue reading here →

Card, Keyfob, Mobile, or Biometric? If you had the choice, which credential would you choose for access control? Depending on the end user, that answer may vary.
Whenever I am involved in the design, installation, and commissioning of a project, the keyfob is usually the default choice. Why? Portability and convenience. Just attach it to your keyring, and you are done; no app to download or open on your phone. But just like regular keys, what if you forget them at home or lose them? Do you have a backup?
This exact scenario recently happened to me on a project. Halfway to a job site, I realized I had forgotten my keyfob. There was no way I was going to turn around and go back. When I arrived, the property manager handed me his fob and said, "Go ahead, use this to get around." Then I remembered I also had a mobile credential on my phone. Yet, habit took over; I accepted his fob because it felt more immediate.
Mind you, this was a condo/mixed-use multifamily building where audits were not a major concern, and the readers were primarily for keyless entry and convenience. So, I walked around using both credentials. It wasn't an ideal situation, and in a different environment, it definitely would not have been a good choice, given that I was essentially using someone else's identity to gain access. But after using both, I was left wondering: Why settle for one? And what are the true benefits of blending these technologies into a unified ecosystem?
Why No Single Credential Wins
Given the many verticals in which access control is deployed, organizations often mandate a single preferred credential. In schools and corporate offices, the printed ID badge remains king.
With your photo, position, and company details printed on the card, it offers decades of proven utility. Many assume this is the most secure option because the credential is visually tied to an individual; an average passerby is unlikely to steal a specific badge to gain entry (unless they have ill intent, of course).
However, this assumption overlooks a critical weakness: the badge is a static token. Once it detaches from your lanyard, leaves your pocket, or is set down somewhere, it becomes vulnerable to theft or temporary misuse. Or, as in the scenario above with the keyfob, you might be tempted to lend your card to a colleague to help them unlock a door "just for a few moments."
While it may seem harmless, you are creating risk. If that badge is lost or stolen, there is a time gap between reporting it missing and the administrator deleting it or changing its state in the system. This scenario has happened before.
Contrast this with a biometric credential, which cannot be lent to a colleague, or a mobile credential that you are less likely to share. A badge has no second layer of defense. Relying solely on this one credential creates a single point of failure that can easily be exploited ... continue reading here →

Coming into the security industry from the outside, I learned quickly that understanding the technology was only part of understanding the business.
The rest lived in the people.
It lived in the person who remembered why a process had changed years earlier. The leader who understood the history behind a complicated customer relationship. The technician who could recognize a problem before anyone else saw it coming. The employee who knew which written procedure worked perfectly on paper—and which additional step actually made it work.
Some of that knowledge was documented.
Much of it was not.
As a communications professional, that immediately stood out to me. When important context is not captured or shared, people are forced to operate with only part of the story. They may know what to do without understanding why it matters, how the decision was made or what experience taught the organization along the way.
That is challenging for anyone entering a new company.
Across an entire industry, it becomes a leadership risk.
The security industry is already paying close attention to the need to attract and develop talent. At PSA TEC’s State of the Industry discussion, workforce development was identified as one of the integrator community’s greatest challenges, while SIA CEO Don Erickson described the workforce situation as a “real crisis.”
SIA, PSA and organizations across the industry are doing important work to build the next generation of security professionals.
But recruiting people into the industry is only half of the equation.
We also have to ask what we are giving them once they arrive.
Are we intentionally sharing the history, judgment and context they will need to lead? Or are we expecting them to collect decades of institutional knowledge through observation, proximity and luck?
We should be building the workforce of tomorrow by guiding, nurturing and igniting their enthusiasm today.
A talent pipeline only works when knowledge is flowing through it.

Here's an uncomfortable truth about physical security and access control: we talk a lot about innovation, but most of what ships is either a decade behind or barely tested. Neither is acceptable when the product in question is protecting a building, a hospital, or a school.
I think this comes down to two compounding failures — a knowledge gap in product management, and a training gap in QA. Let's take them one at a time.
The Old Guard vs. The New Guard
Every mature industry eventually splits into two camps: the people who built the foundation, and the people building on top of it. Security is no exception, and right now the split is wide.
The old guard — the folks who've spent 15, 20, 25 years in this space — understand the legacy systems at a level newer hires never will. They know why a panel behaves the way it does, what happens when you integrate a 2009 controller with a 2026 cloud platform, and which “simple” feature request is actually a landmine three layers down. That's hard-won knowledge, and it doesn't show up in a job posting.
But a lot of that same group hasn't kept pace with how software is built and expected to work today. Cloud-native architecture, modern UX expectations, API-first integration models — these aren't add-ons anymore, they're the baseline customers expect. When product decisions are made entirely through a legacy lens, you get roadmaps that protect the past at the expense of the future.
Flip it around, and the newer generation of PMs and engineers has the opposite problem. They can design a clean, modern interface and ship fast — but they often don't understand the legacy technology that a huge share of the installed base is still running. They don't know what it takes to migrate a customer off a 12-year-old panel without breaking their site, because they've never had to.
Here's the part that should worry all of us: if we only build for “new,” we leave migration paths broken for the customers who make up most of our revenue today. If we only protect “legacy,” we never actually innovate. Both failure modes lead to the same place — customers stuck on old technology.
The fix isn't picking a side. It's building product teams that deliberately pair legacy depth with modern product thinking, instead of treating them as competing philosophies. Right now, most companies don't have both in the room when decisions get made — and the roadmap shows it.
Nobody's Training QA for This Industry
The second problem is quieter but just as damaging: where is anyone actually learning to test these products?
Generic software QA training will teach you to write test cases, automate a regression suite, and file a clean bug report. What it won't teach you is how to validate a real-world install: wiring quirks, power conditions, integration with a controller nobody's manufactured in a decade, or the specific ways access control fails silently in the field. That knowledge is industry-specific, and there's no real pipeline building it.
The result is QA that checks boxes instead of finding the failures that actually matter — the ones that show up on a job site, not in a test lab. And when QA depth is thin, it doesn't just mean more bugs. It means the basics — reliability, consistent behavior, clean integrations — don't get validated properly before ship, let alone the advanced features and polished UI/UX customers are increasingly demanding.
Replicate, Not Innovate
Layer one more problem on top of both of these, and you get the real pattern I see across the industry: too many companies are optimizing to replicate a competitor's spec sheet rather than actually innovate on the customer's problem.
It's an easy trap. Matching a competitor's feature list is measurable and low-risk. Actually solving the underlying problem — the way customers install, maintain, and use these systems day to day — requires the kind of cross-generational product thinking and real QA rigor most teams aren't set up to do.
Put a thin knowledge base, a thin QA bench, and a “match the competitor” strategy together, and you get an industry full of products that struggle with the basics, let alone the differentiated experience customers are actually asking for.
So What Actually Fixes This?
A few places to start:
• Pair legacy expertise with modern product thinking on every team, instead of letting either dominate a roadmap in isolation..
• Build QA training paths specific to physical security and access control — not borrowed wholesale from generic SaaS QA practices..
• Stop measuring innovation by feature parity. A matched spec sheet isn't a strategy; it's an admission that nobody asked what the customer actually needs..
This industry has the talent to do better. What it's missing is the structure to combine legacy knowledge with modern thinking, and the training pipeline to test what we build with the same rigor we expect it to perform in the field.
The question worth sitting with: is this a training problem, a leadership problem, or both?

As organizations adopt facial biometrics at scale, the industry’s focus is shifting from authentication performance to where biometric data should reside, who controls it, and how organizations can build trust while strengthening security.
For many organizations, the challenge is no longer whether facial authentication can reliably verify identity. The larger question is how to balance security, operational efficiency, and growing expectations around transparency and data stewardship. As biometric technologies become more commonplace, architectural decisions around credential storage are becoming just as important as algorithm performance.
One emerging approach shifts biometric credentials from centralized repositories to trusted mobile devices under the user’s control. In a society where employees increasingly expect greater transparency over the storage and use of personal data, where biometric credentials reside and how they are governed matters more than ever.
Image that during enrolment, the person’s biometric is converted into an encrypted credential and stored locally on their own device rather than in a centralized repository. When the individual presents at the access point, the mobile device securely provides the credential needed for the authentication. The user experience remains the same, but the biometric stays under the individual’s control. That’s what we mean by “Biometrics on Mobile”.
This approach also elevates Privacy by Design principles. Rather than treating privacy as a compliance exercise, it embeds express consent into the authentication process from the outset. Individuals choose whether to enrol, manage the credential stored on their device, and decide when it is used for access.
The next phase of biometric access control is no longer about the biometric performance alone. It’s about giving end users more control. The access control solutions that will define the future will combine high-performance biometric authentication with strong cryptographic protection while offering options that give individuals greater transparency and control over their biometric data.
Originally posted here.
đź‘€ As Seen In the Secured Community đź‘€
🤖 AI & Tech
-
Salvatore D’Agostino shared
- How LLMs Distort Our Written Language
- OpenAI's Hacking Debacle Comes Down to Human Error
- When a baby monitor is not enough...
- My AI shows up at my wake and does stand up?
- More on how big AI players wants to set governance framework
🔍 Research
🤝 Deal Activity
-
Tony Dong shared
- The NYSE welcomes ADI Global Distruption to celebrate its first day as an independent public company!
- Honeywell Tech nologies Completes Sale of Productivity Solutions and Services Business to Brady Corporation
🪪 Identity & Privacy
🔌 Shameless Plugs
đź’Ľ Jobs & Opportunities
-
Scott Naiper shared
We are going to be announcing an opening in EMEA for an Intel Analyst in the next 2 weeks. I think it will be based in either Krakow or Lisbon, more to follow as soon as I get the details. If you know anyone that might be a good fit, give them a heads up!
🗓️ Events
- Kevin Baldwin shared
I'll get the ball rolling here... I don't have an event to post about - more of a request for help! I'm interested in keeping connected with the community in the UK; but outside of the 'usual' larger events.
Can anybody recommend any local/regional gatherings?
(Reply to Kevin in the 'Events' channel!)
📦 Products
- John Morris shared
I have a question for the group. I’m currently evaluating biometric access control solutions and comparing the different modalities. (Reply to John in the 'Product' channel!)

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration is OPEN NOW! Sign up here.
Speaking at the event? Go here.
On the fence? View some testimonials from previous years here.
![]()
Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.
All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.
You can stream directly from our Secured channel.

West to East series: We're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.