Volume 3
🎙 Secured Podcast
Episode 29 | Coming next week!
🫣 Premium member-only content | Is Physical Security Finally Going Mainstream?
Is our industry finally mainstream, and what does it cost to act like it? Lee Odess sits down with LVT's Steve Lindsey and Derek Boggs on prevention over reaction, why the scarecrow stops working, and how a company out of American Fork, Utah landed on an NBA jersey patch with the Utah Jazz. No better angels are coming. It's our choice whether we rise to the moment.
✍🏻 Articles
Lee Odess | Access Control Brief #151: The Ninja Temple Floor Was the Alarm
Security has been shaping architecture for centuries. In Brief 151, Lee takes us inside a 400-year-old Japanese temple designed around hidden doors, alarm floors, secret passageways, and one very simple idea: sometimes the environment itself is the security system.
Kumar Sokka | The Most Expensive School Security Mistakes Are Not the Ones You Expect
What if the biggest school security risks aren’t the things districts are buying? Kumar Sokka looks at three common mistakes that have less to do with technology and more to do with how security is planned, operated, and sustained.
Johan Fagerström | From Seeing to Sensing: Why Physical Security Needs More Than Cameras
Cameras have transformed physical security, but seeing isn't the same as understanding. This week’s TSB explores what happens when we start thinking beyond video and bring more of a facility’s “senses” together to create true situational awareness.
Dominic Cornell | I Tried to Put AI Into My Revit Workflow. The Technology Wasn't the Problem...
AI is already making its way into Revit workflows, but for security designers, the biggest question may not be what AI can do. It’s what happens to sensitive project data once you let it in.
Kevin Friedman | The Whopper Playbook: how a security manufacturer runs a real turnaround
Burger King’s turnaround offers a surprisingly relevant playbook for security manufacturers. Kevin Friedman breaks down three moves that can help manufacturers strengthen their products, simplify their channel strategy, and build a more effective path forward.
🚨Breaking News
- dormakaba is acquiring Apollo Security, and with it Azure Access Technology, and this is really four stories in one.
- iLOQ posted Q2 2026 revenue of €39.0 million, up 17% year over year.
- Breaking: Verkada just deployed its platform across Miami Dolphins and Hard Rock Stadium, folding video, access control, guest management, intercoms, and alarms into one cloud system for the Miami Dolphins' 65,585-seat venue.
- Breaking: Third Circuit Rules Pindrop is a "Financial Institution" Under BIPA, Exempting It From Illinois' Toughest Biometric Privacy Law
Scroll down to go deeper ↓

Podcast | Secured: Episode 29 COMING SOON đź‘€

Find these podcasts ONLY in the 'Conversations with Lee' Channel.
Is our industry finally mainstream, and what does it prove when a company actually acts like it?
Lee Odess sits down with the team from LVT, co-founder and Chief Strategist Steve Lindsey and VP of Marketing Derek Boggs, for a conversation that covers a lot of ground.
They get into why competition entering the category isn't a jump-the-shark moment but a signal that it's crossed from niche to mainstream. Why prevention beats reaction, and why the scarecrow stops working the moment criminals figure out it's just a scarecrow. Why most problems happen outdoors first. And why the security tech stack is about to get absorbed into the broader IT and operational stack, changing who the buyer even is.
Then a hard left into something the industry rarely does well: brand marketing. Not product marketing. Brand. How a company out of American Fork, Utah ended up on an NBA jersey patch with the Utah Jazz, why Derek was the biggest skeptic in the room, and how it legitimized them overnight with buying committees that used to ask "who are you?"
The thread through all of it: no better angels are coming. It's our choice whether we rise to the moment or wait for permission while someone else does.

Welcome to Brief 151, which is my first under the new Secured Brief header.
I believe we have great global security stories to tell as an industry. We are a tactical, technical industry, and that's part of our identity. But if we want to be taken seriously and capture the mainstream market opportunity in front of us, we can't stop at making a great product. We have to tell our rich stories in a format meant for the mainstream, connect them to today, and use them to help define tomorrow.
For instance, I'm in Japan with my family, and I toured an entire place built in the 1600s around security. They are telling a story about security every single day, and most people worldwide have never heard it (and, as an industry, we never tell it).
We can. We have to want to. So let me show you what I mean (full disclosure: we are going to turn this into one of the mainstream videos we’ve been doing. You can see examples here and . We’ve started creating for 3 markets: core, adjacent, and mainstream. This Brief and the video we are making are a great example of taking one story and making it fit different audiences. Not to mention, we also take it across multiple outlets like LinkedIn, YouTube, and here, and all done with its own spin built to work for that service… anyway… back to the story)…
In 1643, Maeda Toshitsune ran the Kaga domain, one of the wealthiest territories in Japan at the time. He wanted a fortified outpost on its edge. The shogun had already banned the construction of new castles, as too many castles meant too many private armies, and the shogunate had no interest in giving regional lords that kind of leverage.
So Maeda built a temple instead.
Myōryū-ji, known today as Ninja-dera, looks unremarkable from the street (I mean it’s super cool, but what’s inside is more of the story). It's a very holy place, so photos and English were not allowed during the tour. I'll share some pictures I was permitted to take, along with a few others I grabbed from online.
The place stands two stories tall, made of wood (the curved wood was pretty amazing to see), with a modest footprint like a hundred other temples across Japan. Step inside and you find deception everywhere. Seven floors are packed into that two-story shell, since laws at the time forbid tall structures from being built. There are 23 staircases connecting the different floors, some real, some fake, some built to look identical to a wall.
Here's where the security stories start. The entire tour and the story told were about security.
For instance, the floor itself serves many purposes: a floor, a lock, an alarm, and more. Every board in the main hallway is engineered to chirp when someone steps on it. Nails rest loosely against metal clamps underneath, on purpose. Walk across it today, and it still sings, as they explained, nearly 400 years later. The Japanese call it uguisubari, nightingale flooring, after the bird. Nobody could slip past it quietly. The only way through was to be loud, and being loud meant getting caught.
The sliding walls do the same job for a different reason. A panel that looks like a solid wall slides open onto a hidden staircase. A closet door drops straight into a tunnel. To a stranger, the wall is the wall. To Maeda's men, that same wall was a door, and knowing which panel moved and which direction it slid was the key. Not kidding, the floorboard itself served as the key: sliding it into place, with the perfect custom grooves locked, locked the door beneath, hiding the staircase below. Miss the sequence, and you'd stand there staring at solid wood, one foot from an exit that didn't exist for you (or locked beneath it with no way out).
Neither of those is a lock in the traditional sense: no bolt, no bar, nothing to pick. What stood out to me was that knowledge was the real key. Without knowledge, the doors don’t open. This is old school physical software. The puzzle is the algorithm. The human in the loop is the processor.
In relating this story to our industry, I think about how we still frame security almost entirely as a hardware problem. We need thicker doors, beefy locks, better credentials, stronger authentication. And yes, all of that matters. But Myōryū-ji makes a different argument, one that predates our entire product category by centuries: the building itself can be the control layer. Design, not just device, decides who gets through. It reminds me of CPTED (Crime Prevention Through Environmental Design) and what the Secure Building Council is doing today, just hundreds of years later.
Myōryū-ji worked because it had a small, trusted circle of people who needed to know the layout. Most of what we secure today doesn’t have that luxury. Offices, hospitals, data centers…all of them need systems that work for hundreds or thousands of people who will never memorize a secret staircase or sliding wall, thankfully. Still, the core idea holds up. We spend most of our budgets and most of our conversations on the PACS and the credential: the card, the badge, the biometric, the app. We solved a version of this problem with nails and floorboards, long before any of us showed up.
The environment itself can carry security logic. We tend to outsource it all to a wall reader.
These are the kinds of stories I want us to tell more often. Not because it's nostalgic, but because it's interesting and relevant, and because it shows we've been thinking about this for a long time. I'm confident the mainstream will listen when we bring them something better than a technical spec.
Btw, none of what I wrote was technical. And if you have read this far, it tells me (and you) we can tell stories about topics like CPTED, security by design, and access control without an ounce of product or technical speak.
How many more stories like this are out there?

School security spending keeps climbing - new cameras, new access control, weapon detection, visitor management. And what we hear consistently from the teams doing these assessments is the same vulnerabilities, district after district - most of which no purchase order would ever fix.
That gap, between what schools buy and what actually keeps them safe, is the most important and least discussed problem in campus security. It comes down to three mistakes, and none of them is a missing device.
The failure is usually a door you already have. It’s rarely an absence of technology, it is a door that is propped, unlatched or slow to lock during the day, usually a secondary entrance: a gym door, a delivery door, an arts wing. The front vestibule everyone points to is controlled - but the sidedoor held open for convenience usually isn’t. A district can install every device available and still leave that gap open, because it is a matter of discipline and process, not hardware. Access control on some doors while staff prop others makes the whole investment moot. It is a system problem wearing the costume of a technology problem.
The most expensive purchase is the one you cannot get out of. When schools do spend on technology, the costliest mistake is rarely overspending - it’s choosing a platform without asking how it evolves. And a security platform is fundamentally a fifteen to twenty year decision, not a one-time purchase. The right question at purchase isn’t only what does this do today, but can I still change it in five years without starting over. Districts that build in that flexibility from day one are the ones who can move forward at their own pace, instead of getting boxed in when the next threat, or next technology, arrives.
Grant money buys the system. It does not sustain it. As one-time federal pandemic relief funding continues to wind down, what we’re seeing is that a great deal of that money went into security hardware, not the budget to sustain it. What districts own now are the license renewals, the maintenance and the eventual replacement, with nothing behind them. But security bought on a single grant cycle becomes an unfunded liability the moment that cycle ends. The most sustainable systems are the ones a district can afford to run in a normal budget year, not just install in an exceptional one.
Safety is a system you operate, not a shopping list you buy. The common thread is that safety is not a collection of devices. It is doors that lock, people who challenge a stranger, procedures that hold when the building gets busy, and technology a district can sustain and adapt over time. The cheapest, highest-impact measures, exterior door discipline, an enforced visitor process, a lockdown actually tested with local responders, rarely appear on a capital request, because they are unglamorous and hard to put a price on. They are also what most often decides whether a building is safe.
That’s the role we try to play at Acre: not selling the next device, but helping a district understand what it’s actually buying, what it can sustain, and where the real risk sits. . The districts that come through the next few years in the strongest position will be the ones who stopped treating safety as a shopping list and started treating it as a system they own.

The physical security industry was built on three foundational paradigms: access control, intrusion detection, and video surveillance. Over time, video became the primary way to understand what is happening and capture indisputable evidence.
To get more out of video surveillance, we moved from grainy analog cameras to high-resolution video. We invested in night vision, pan-tilt-zoom capabilities, and eventually AI that can analyze video faster than a human ever could. Today, cameras can tell us an incredible amount about what is happening in a physical space.
But there is still a fundamental limitation: cameras can only tell us what they can see.
Think about how a trained guard dog protects a space. It doesn't rely on its eyes alone. It listens for subtle movements, smells things that don't belong, and reacts to changes in its environment that might be completely invisible to a camera. If physical security systems are meant to deliver true situational awareness, perhaps we should start thinking about them in the same way: not as a collection of individual systems, but as a collection of senses working together.
Beyond Environmental Monitoring
The industry has made progress connecting environmental sensors to security systems. Temperature, air quality, CO2, humidity, and other air quality measurements can provide valuable context around an event. But the opportunity goes much further than airborne metrics.
Other operational data can tell us what is happening inside a facility in ways that video alone cannot. Think of a water meter registering increased water consumption at the same time as a flood detector is going off.
This is where protocols such as Modbus become particularly interesting. Modbus has been around since the late 1970s and remains widely used in industrial automation. Its longevity is part of what makes it valuable: it provides a way to connect SCADA systems, charging controllers, power meters, connectivity routers and essentially any sensor under the sun.
When that data becomes part of a security operation, it can add an entirely different layer of context when an operator is investigating an incident.
Turning Data Into Situational Awareness
Imagine a facility where a temperature sensor suddenly registers a significant increase. On its own, that is simply a data point. But combine it with the signal from a nearby smoke detector and video from a nearby camera, and you have a crystal-clear understanding of what is going on.
Is there an actual fire? Is equipment overheating? Is there another operational explanation for the change?
Think of the same situation but starting out with a smoke detector going off. The operator brings up the nearby temperature sensor and observes that the temperature is skyrocketing. Then it’s most likely a fire and not just a bread toaster being used.
The value isn't necessarily in any one sensor or system; it's about bringing those sources of evidence together so security teams can understand what is actually happening, rather than trying to deduce that from video or alarm detectors alone.
Security Needs More Senses
For years, video has been treated as the primary source of truth in physical security. While it remains incredibly important, the future of situational awareness depends on recognizing that seeing isn't the same as understanding.
Security should therefore not be restricted to traditional paradigms alone. To deliver total situational awareness, we must stop relying solely on a single paradigm and build systems that can see, hear, feel, and smell the full picture.
Just like a guard dog, true protection relies on every sense.

I design security systems for a living. Cameras, readers, door contacts, intrusion, the whole package, mostly for data centers around the world. And a lot of what I do in Revit is repetitive in a way that makes you feel like you're wasting your own time. Placing the same device families across forty doors. Building schedules. Chasing parameters that didn't populate. QA that's really just me looking for the thing I already know I got wrong somewhere.
So, I went looking at what AI could actually take off my plate. I expected to find half-finished tools and a lot of hype. That is not what I found.
Autodesk shipped an official MCP server for Revit 2027 back in June. It's a tech preview and it's deliberately read only, seven tools, safe actions that can't touch your model destructively. Autodesk was clear that they see it as a foundation and not a ceiling, meant to run alongside community-built servers.
And the community servers are not toys. One of them exposes 138 tools and will read, create, modify and delete elements in a live model. Another runs 48 tools through pyRevit across Revit 2024 through 2027, covering editing, clash detection, MEP and documentation. There's commercial tooling now with read-only modes, dry runs, approval gates and an activity log.
The capability is here. Right now. So the honest question stopped being "can this work" and became "why haven't I turned it on."
Here's where I got stuck.
If I hand a set of client drawings to an AI tool, where does that go? My first version of the worry was that some bad actor could prompt the thing later and pull my client's data center floor plan back out of it.
I looked into that, and I was wrong. That's not really how it works. What you send goes into your conversation, not into a pool that other people can query. And the research on models memorizing and regurgitating their training data is a lot narrower than the headlines suggest. Material that shows up fewer than about four times in training has been shown not to pose meaningful extraction risk, because exact recall generally requires the data to repeat. One set of drawings submitted one time doesn't get memorized and can't be prompted back out.
I'll admit I was relieved. For about a day.
Because the real version of this already happened, and it's worse.
In May 2025 a federal judge ordered OpenAI to preserve all of its output logs as part of the New York Times litigation. That order overrode the company's own 30-day deletion policy. Users who tried to intervene got denied, because the court found they were non-parties to the lawsuit. By July, the plaintiffs were going through the preserved logs. The order finally got lifted that October, but anything already preserved stayed preserved. Enterprise accounts and API users with zero data retention agreements were exempt the whole time.
Read that again. The vendor fought the order on privacy grounds. The vendor lost. And the users whose data it was had no standing to say anything about it, because it wasn't their lawsuit.
Legal analysts flagged the obvious next move, which is litigants in completely unrelated cases going after an opponent's preserved AI logs in discovery.
So, the threat model I should have been worried about was never a hacker. It's a lawsuit I'm not a party to, reaching my client's data through a vendor's discovery obligations, while my delete button means nothing.
And underneath all of that sits the part that doesn't require anything bad to happen at all. My NDAs say I don't disclose client information to third parties. Once those drawings hit somebody else's servers, I can't tell a data center client that their data never left my control. Whether it gets breached, subpoenaed or ignored forever, the disclosure already happened. That's a contract problem, and contract problems don't care about probability.
There's one more piece that I think our industry needs to say out loud, because the AI governance conversation is being written by people who don't do what we do.
Most of that writing treats leaked project data as a commercial issue. Somebody's IP, somebody's pricing, a competitive disadvantage. Our drawings aren't that. A security submittal for a data center is camera coverage, blind spots, reader placement and door hardware. It's a map of how to get into a building and where nobody is looking. Put that in a leak, a breach or a discovery production, and the exposure isn't commercial. It's physical.
So, I haven't deployed any of it against live client work. What I've done instead is use AI to write generic pyRevit and Dynamo scripts that never see a real project, and then run those scripts myself, locally. Slower than what the demos promise. Also, the only version I can currently defend if a client asks me a hard question.
I don't think that's the permanent answer. Enterprise terms, zero retention agreements and local models all move this. What bothers me is that almost nobody in our industry is asking the question yet, and the tools are already installed.
Sources: Autodesk AEC blog, "Introducing the Revit Public MCP Server," June 17, 2026; the revit-mcp-server and pyRevit-based MCP projects on GitHub; Carlini et al. on extraction and memorization thresholds; Ars Technica and OpenAI's own statements on the NYT preservation order and its October 2025 termination.

Burger King spent most of the last decade losing. Aging restaurants, menu items its own crews couldn’t execute, franchise groups filing for bankruptcy, and hundreds of closed locations. But its recent turnaround offers an interesting lesson for security manufacturers: the recovery wasn't driven by simply spending more.
The interesting part isn't that Burger King recovered. It's the order in which it did things.
Before Restaurant Brands invested heavily in upgrading restaurants and expanding marketing, it fixed the Whopper. It improved the product, put someone in charge of owning it, and focused on the experience itself. Only then did the bigger investments in kiosks, digital menu boards, and marketing follow.
That same sequence translates surprisingly well to a security manufacturer selling through a dealer channel.
01 — Put a single owner on the flagship
Burger King's solution wasn't creating an entirely new product. It was taking the product already driving most of its orders and taking it seriously again.
Security manufacturers often have a similar problem. A flagship product may sit at the center of countless quotes and installations, but nobody is ultimately responsible for whether the product is actually good in the field.
Product management owns the roadmap. Engineering owns the release. Marketing owns the launch. But who owns whether the product works as well as it should for the people actually installing it?
The answer should be someone specific.
And “better” shouldn't simply mean another feature. One of the most useful measurements in physical security is installed labor: how long does it actually take a two-tech crew to get a panel, reader, or camera from the box to commissioned and handed over?
Not in a lab. On a retrofit. In a real building with the wiring and conditions technicians actually encounter.
That measurement can reveal the competitive problem much faster than another round of positioning work.
The improvements that come from this kind of exercise aren't always flashy. They might be firmware that provisions without a laptop, a mounting bracket that doesn't require a third hand, default configurations that match how integrators actually deploy, or documentation a technician can follow from a phone.
None of those things make for a particularly exciting press release.
All of them can make a difference in the next bid.
02 — Pick one offer and leave it alone long enough to be memorized
Burger King also simplified its commercial offer and, importantly, stopped changing it constantly. The point wasn't simply the price. It was consistency. Customers could actually remember the offer.
Security manufacturers can fall into the opposite trap.
Q1 SPIFF. Q2 bundle. A mid-year rebate restructure. A fall promotion with different qualifying SKUs. New MDF rules. Each change might make sense individually, but eventually the program becomes so complicated that even the company's own regional managers can't explain it from memory.
That's the real test.
A commercial promise should be able to travel from the manufacturer to the integrator's principal, from the principal to the estimator, and ultimately to the end user without getting distorted along the way.
Every additional condition is another piece that can disappear somewhere in that chain.
The practical answer is simple: identify the one commercial promise you want associated with your brand, state it clearly, and give it enough time to actually stick.
Consistency only compounds if you let it run long enough.... Continue Reading →
đź‘€ As Seen In the Secured Community đź‘€
🤖 AI & Tech — Salvatore D'Agostino shared 'Show How 3M Is 0% at Fault:' Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit. Borja Ganzarain shared that Google's Gemini app surpassed 1 billion monthly active users, its fastest-growing product ever. Michael Stuer shared that Qwen 3.8 - 27B is a game changer.
🔍 Research — Daniel Raines shared a hard look at ACRE Vanderbilt ACT Pro: "one of the most insecure/vulnerable PACS software I have ever looked at... definitely not 'enterprise' grade." More to follow. (Respond in the 'Research' channel!) Jonathan Horvath asked: will my wiring support OSDP?
🤝 Deal Activity — Brian Karas shared that Pro-Vigil was acquired by GardaWorld, announced today. A solid exit that's been in the works, and another sign M&A is picking up in the space. (Jump in on the 'Deal Activity' channel.)
📰 Industry News & Insights — Lee Odess shared a piece for the many of you who work (or should) with Workday. Borja Ganzarain shared an interesting read on commercial access control systems.
🔌 Shameless Plugs — Kevin Baldwin shared his first GraphQL API connection to WaveFusion by Wavestore, and a challenge: what would you build with an API pulling the best of Mercury, video streaming/analytics, and other data sources? Jenna Hardie invited LA folks to HiveWatch's grand opening, HiveFest, Wed Aug 26, 4-7 p.m. (registration required, fun mandatory). Rodney Thayer flagged the OSDP Bootcamp at ISC East, asking how OSDP-literate your vendor supply chain is. Salvatore D'Agostino is heading to NZ from NYC after his IEEE Symposium on Privacy Expectations (ISoPE) talk on ethical/moral measurements of AI as represented in Magnifica Humanitas. Dominic Cornell is building a product data submittal, wiring diagram, and installation detail generator, and is looking for a few beta testers. (Find them all in the 'Shameless Plugs' channel.)
🪪 Identity & Privacy — Manish Dalal is looking for a law firm to create end-user privacy policies and consent forms around biometric data for access control. Lee Odess flagged a privacy topic for the experts to weigh in on. (Chime in on the 'Identity & Privacy' channel.)
📢 Marketing & Branding — Borja Ganzarain shared his thinking on "Brand as an Operating System," where a brand becomes a decision-making system across product, culture, and operations (think Apple, Ikea, Patagonia, Lego, Stripe). (Continue reading in the 'Marketing & Branding' channel.)
💼 Jobs & Opportunities — Jeff Nigriny shared that The Walt Disney Company is specifying a replacement global company badge with a 10-year supportability window, seeking a multi-tech badge (prox, symmetric key, asymmetric key, plus interest in an Aliro app on the card). Discretion appreciated. Email CertiPath at AWholeNewCard@certipath.com with the requested details by COB PDT August 25th, evaluated in order received. Kevin Baldwin shared that Wavestore has an open Flutter/Rust Developer role in Ottawa.
📊 This Week's Community Poll — Dmitry Berman asked: enclosures/controllers above the door or in the server room only? Options: Server room only, Above the door, Both. (Vote in the 'Community Polls' channel.)

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.
Registration is OPEN NOW! Sign up here.
Speaking at the event? Go here.
On the fence? View some testimonials from previous years here.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.