Header Logo
Log In
← Back to all posts

Volume 5

Sep 04, 2026

🎙 Secured Podcast

Episode 30 | Could Cheaper, More Open Access Control Hardware Help Make Schools Safer?
dormakaba is showing what three years of transformation looks like, Acre is turning its roadmap into something partners can actually sell, and the lines between physical security, AI, and cybersecurity keep getting blurrier. Plus, Lee has a question about access control that might make some people uncomfortable. Listen here.

📰 The Access Control Executive Brief by Lee Odess

Brief 153 | Acre's Partner Event Was a Continuation of the Bridge. In Trust, Not Just in a Product
Acre Security spent the last year telling partners what it was going to build. This year, they showed up with receipts. Lee was in Austin for Acre’s Partner Event and breaks down what stood out, from the move toward a unified platform to the bigger challenge of balancing Acre’s heritage with where the industry is headed. The roadmap is here. Now it has to deliver.

âœđŸ» Articles

Lizelle Maas | Why AI Started Looking Like a PIAM Problem to us,
and what we did about it
AI is starting to make decisions about what it can access and what it can do. That sounds pretty familiar to anyone who has spent time thinking about identity and access. This piece explores what physical security may already know about a problem AI is only starting to wrestle with.

Mike Gillespie | Access Control: The Forgotten Cybersecurity Battleground
The door might be the thing you’re trying to protect, but it’s no longer the only thing at risk. As access control becomes more connected to the rest of the business, the security conversation gets a lot bigger than who can walk through a door.

Hailey Canady | Your Jargon Might Be Costing You Deal$
We spend a lot of time learning the language of physical security. But what happens when the person reading your story doesn’t speak it? A look at why making difficult ideas easier to digest doesn’t make them less technical, it makes them easier to understand, share, and ultimately buy into.

🔓 The Electronic Locksmith 
Don’t miss our new section! Dave O’Toole kicks things off with why electronic access is creating a growing opportunity for locksmiths and why this community matters.

🚹 Breaking News 

  • dormakaba reported their full-year results (FY ended June 30, 2026) and what’s to come is more of the story imo.

Podcast | Secured: Episode 30

dormakaba finished a three-year transformation, and the numbers now give the company a much stronger story to tell. Acre came to Austin with receipts instead of promises, showing partners what has actually changed since last year's roadmap. Meanwhile, two community contributors look at what happens when physical security starts colliding with AI and cybersecurity. And Lee asks a bigger question: are the way we price and sell access control actually getting in the way of making spaces safer?Listen here.


As some of you saw from posts and comments in the Secured Collective, I was in Austin this week for Acre's Partner Event. Overall, I saw continued touches supporting a strategy that bridges, figuratively and literally. More on that below.

First, to the event. I go to a lot of these. I get asked often if I like them
 the truth is, I do. I really enjoy the intimacy of a 100-person event where you get a real chance to meet the room. Plus, I feel these types of events allow teams to really pay attention to the details, and it just feels different. Acre's marketing team ran a very tight event, and it stands out for things you don't see but, again, feel. The details were dialed in: the high-end, well-done barista all day, the boutique hotel selection on purpose, the custom agendas for each person, and the social programming tied to their heritage. That level of production matters because it signals to the 100+ VARs and all the strategic partners in attendance, like Zenitel, HID, and Allegion, that Acre is serious about the relationship, not just the transaction. The truth is, it's not hard to do this. All you need to do is let it happen and budget for it (and that does not mean the budget needs to be big btw. Just means it needs to be allocated properly).

The real takeaway that I saw was the shift in tone from last year to this one. Last year's event was a vision pitch: here is what we are going to do. People left with a feeling that something new was in the air and a sense of "ok, show me." Since then, the team has clearly been busy building. This year was an accountability check: they came "with receipts" (as one of the Acre team told me).

Personally, Acre brought me down for several reasons. I presented the State of Verticals report to that group, and I was thrilled to see the conversation around it reinforcing the same theme. I then moderated a panel discussion with their team that covered the Education, Health Care, and Tech verticals. Then I had the opportunity to interview Kumar Sokka, their CEO, in an AMA style format. We have posted the 20+ minute video in the Secured Collective as exclusive content for those of you in the app. I appreciate the partnership with Acre, which has given me the access and opportunity to bring it all to you here.

All in all, what I saw and heard is that partners are not asking Acre to dream bigger. They are asking Acre to prove the roadmap from 12 months ago turned into something they can sell today (here is what one of their VARs said after).

That leads us to the 5 announcements they rolled out


The first was Acre Console, which brings access control, intrusion, visitor and identity management, and video into a unified UI. This is the platform move that every legacy manufacturer going after the Intelligence Era is making, and it puts Acre in the same conversation as the software-first players who built unified UX from day one rather than stitching it together after the fact. It's got a clean interface, and what it does, more than anything, is give a home to all the disparate systems that have made up Acre over the years. Each is in a different place regarding migration, but it is very clear where they are all heading (this answered the “who are they now and what are they doing?” question I got from the community).

Then came their Nexus Panel, which combines access and intrusion into a single hardware platform. You see this more often around the world, except in the US (at least for now), but it's clearly where the market is moving as we shift toward more integrated infrastructure rather than siloed solutions. Pairing this with Acre Console reinforced the story to partners about unification and showed it is not just a thin UI skin over separate backends. They brought it to the panel level too. They talked about this last year, and it was nice to see it live.

And speaking of talking about it last year and seeing it live today, they showcased real Bridge migrations that moved from a theoretical conversation to an implementation conversation, highlighting how end users migrated older platforms to the more up-to-date Acre Access Control. This detail really mattered to the VARs in the room when I asked, "What stood out to you?" because migration is where transitions in our industry often seem to die. As it was explained to me, "When a roadmap slides, it does not help me close more customers, as it creates some bad friction and bad blood. But this migration path gives me something I can sell to existing customers."

Then came a bit of a head nod (and a smile from me)
Acre Video. They wanted to make sure I was clear that Acre Video is not a strategy pivot, as they are doing this alongside continued support for third-party video partners like OpenEye (who was there). Acre Video is seen as an opportunity for Acre to reach into industry segments (SMB, for instance) that many legacy-thinking access control vendors have historically ignored. It also gives their integration partners more opportunities to turn on services under the same hood. But it was also clear that this is a bet that unified UI works better with unified capture, even if the camera hardware itself stays open. I've written about this often: access control is video, video is access control, and the quicker we get to that, the better.

And last, Acre Pro Services for VARs (note: not end users) was a recognition that the partner network desired support from Acre on increasingly complex, multi-discipline deployments. Professional services, especially as we continue to move toward looking more like the enterprise software industry, where security is a feature of a larger value proposition rather than security-only, support at the manufacturer level is table stakes for anyone selling a converged platform rather than a single-category product.

The clear takeaway is that the team is executing a vision and product strategy, and the integrators in the room were impressed mostly with the fact that they said they would, and they did.

Before I end, there was something that stood out to me as super interesting, and I wanted to touch on (and I am not sure it was explicitly understood, but it was definitely explicitly done): the use of the word "heritage" throughout the day.

It was very clear to me that Acre is threading a specific needle here between the old and new. They are purposely looking to honor and celebrate their legacy brands (they brought back the Open Options seafood boil and even asked some of the employees who were there back when that was a staple in the industry to speak. It became very emotional for some because it was very meaningful. It was a nice touch) and installed base that built the company's credibility, while, in the same breath, proving that the underlying platform is being rebuilt for where the industry is going. That is not easy. It's really hard. And it's even harder to do this type of messaging and deliver it convincingly. Most companies either lean too hard on heritage and read as stuck, or abandon it entirely and lose the trust of the base that got them here. I respect the way they are doing it and how it's being handled.
Acre Security is living the Platform Squeeze I talk about often, and we are watching it play out in real time. You can see it in their roadmap: hardware standardization, the move up the software stack, and the pressure for a unified UX are not abstract forces in a report. They are also doing it in their messaging: using the past on their toes versus their heels. The past is part of why they can, not the reason why they can't. That is the main tension they are navigating.

The test now is the one every partner in that room implicitly asked: will the Bridge migrations actually ship at the pace promised, and will Console and Nexus Panel show up as sellable products soon rather than as roadmap slides at next year's event? Acre bought itself credibility this week (this year). The main takeaway is simple: it now has to turn that credibility into delivery.

Thank you Acre for the opportunity to be there and see it first hand. 


AI has become part of many organizations, and access control requests increasingly come with the question: “Can we use AI to do it?”

Our work at evolutionID is mainly in physical identity and access management. So when we started working more seriously with AI, something felt uncomfortably familiar. AI can do what we want it to do, but it can also potentially reach, generate, or interact with things we do not want it to. For us, that looked like an access control problem.

Think about a normal access-controlled door. The system makes a specific decision:

“Does this identity have permission to perform this action, against this resource, right now?”

If the answer is no, access is denied. When AI enters the picture, the answer becomes less clear.

Language models are increasingly connected to databases, applications and tools. Then the important question becomes: “What is this system actually allowed to say or do?”

That is an authorization question.

Imagine securing a door with instructions. “You shall not pass!” It sounds ridiculous, but instructions are a common way to control a language model.

“Don't reveal this information.”

“Only use these tables.”

“Never perform this action.”

“Stay within this format.”

Prompting is useful, but from an access-control perspective, relying on instructions alone feels like putting a sign beside a restricted door saying:

AUTHORIZED PERSONNEL ONLY. PLEASE DO NOT ENTER.

It communicates policy, but it does not enforce it.

Another approach is to reject the output if it violates a rule. From a physical-security perspective, that resembles evaluating access after somebody has crossed the threshold.

Our instinct was to make the decision earlier. That led to a research project we called GRID, short for Grammar-Railed Decoding. The idea was to explore whether, instead of asking the model to avoid certain outputs and checking afterwards, we could restrict what the model can generate in the first place.

Take a simple database example. Imagine an AI assistant that should only read data. You could tell the model: “Do not delete anything.” With a stricter approach, the model should not be able to generate the DELETE command. It must not be able to reach those tokens, basically be “physically” unable to reach for that option.

Once we started thinking about the problem in those terms, the parallels with access control became quite clear, and several principles we already rely on in PIAM translate surprisingly well into AI systems.

  1. Enforcement should happen before the action

A properly configured access system evaluates credentials before granting access. If AI can interact with business systems, unauthorized actions should be unavailable as early as possible.

  1. Permissions should be specific

We don't give somebody access to an entire building because they need one laboratory. If a language model needs access to three database fields, why should it be able to access fifty? If a process only needs read access, why should destructive actions remain available?

  1. Auditability matters

“The system shouldn't have allowed it” is a poor answer during an investigation. As AI moves into operational and access processes, a record needs to be kept of what the model was permitted to produce.

  1. Boundaries should be explicit

No single security measure covers everything. A badge reader does not necessarily secure the window beside the door, and a PACS does not replace physical barriers, procedures or good system architecture.

AI controls need similar thinking. If a constraint cannot be enforced at the token level, it must be identified so another control can deal with it downstream.

We saw how important that was while testing with AI development frameworks. In one test case, constraints specified in code disappeared before they reached the model, but the application still ran. The output still parsed. Nothing obvious failed. The rule had simply never been enforced. Anyone who has worked in access control knows how worrying that can be.

Physical and digital security have converged for years. AI now adds another participant: something capable of reading information, selecting actions, invoking tools and affecting the systems around it.

That raises familiar PIAM questions. What may it access? What may it do? Under which conditions? Who defined that permission? Can we revoke it? Can we prove what it was allowed to do six months ago?

Our industry has spent decades working with these questions, and AI engineering is now wrestling with many of the same concepts, just named differently. That means the people who understand readers, controllers, credentials, identity lifecycles and authorization policies may have something useful to add to a conversation that currently sounds like it belongs entirely to software engineers.


For many years, access control was viewed primarily as a physical security function. If the doors opened for authorised users and remained closed to everyone else, the system was considered secure. Today, that assumption is dangerously outdated.

Modern access control systems sit at the intersection of physical security, operational technology and enterprise IT. Gone are the days of standalone card readers connected to isolated control panels. Today's systems are cloud-connected, integrated with HR databases, visitor management platforms, CCTV, building management systems and mobile applications. They are increasingly accessible remotely and frequently form part of wider smart building ecosystems.

This connectivity delivers significant benefits. We can automate onboarding and offboarding processes, improve user experience through mobile credentials, gain greater visibility of site occupancy and generate valuable operational intelligence. However, every integration creates another potential attack surface.

As I have often said, as soon as a system becomes connected, it becomes a target.

The threat landscape has evolved significantly. Criminal groups increasingly recognise that physical security systems can provide a route into broader corporate environments, while nation-state actors continue to focus on operational technologies that support critical infrastructure. Government agencies have repeatedly highlighted the risks associated with internet-facing operational systems, weak authentication mechanisms and poorly secured remote access services. Many of these weaknesses remain commonplace within access control environments.

What makes access control particularly attractive to attackers is the potential impact. A compromise is not simply a loss of data. An attacker who gains control of an access management platform could potentially unlock doors, disable security controls, interfere with emergency procedures or create opportunities for physical intrusion. Equally concerning is the possibility of using a vulnerable access control platform as a foothold into the wider corporate network.

Recent years have demonstrated how operational disruption has become a primary objective for cyber criminals. Ransomware attacks are increasingly affecting operational environments, with threat actors targeting systems that support core business operations rather than simply stealing information. Industrial cybersecurity research has identified significant growth in ransomware activity impacting operational technology environments, reinforcing the reality that cyber risk now extends well beyond traditional IT systems.

The rise of artificial intelligence adds a new dimension to this challenge.

AI is already transforming physical security for the better. Security teams can use machine learning to identify unusual access patterns, detect credential misuse, correlate events across multiple locations and highlight anomalous behaviour that might otherwise go unnoticed. AI-powered analytics can significantly improve threat detection and reduce response times, particularly within large estates where manual monitoring is impractical.

Unfortunately, attackers have access to the same technology. Generative AI enables criminals to create highly convincing phishing campaigns targeting facilities managers, security teams and system administrators. AI can accelerate reconnaissance activities, automate vulnerability discovery and assist threat actors in identifying weak points across complex environments. The result is an escalating technological arms race where both defenders and attackers are becoming more capable.

Looking ahead, the challenge will become even more complex. Mobile credentials, digital identities, biometric authentication, cloud-native management platforms and converged security operations centres are becoming standard components of modern access control deployments. At the same time, digital twins and AI-driven building automation are creating increasing levels of integration between physical and digital environments. While these technologies deliver enormous benefits, they also increase the importance of robust security architecture and governance.

The solution is not to avoid innovation. Rather, organisations must ensure cybersecurity becomes a fundamental part of access control design, procurement and operation.

Every organisation should understand exactly what systems are connected, maintain an accurate asset inventory, remove unnecessary internet exposure, enforce strong authentication, segment networks appropriately and continuously monitor for suspicious activity. Government guidance consistently identifies visibility, asset management and secure remote access as critical defensive measures.

Access control is no longer just about controlling who enters a building. It has become a critical component of organisational cyber resilience.

The organisations that recognise this convergence of physical and cyber security will be far better positioned to defend themselves against the threats of today and the increasingly sophisticated threats of tomorrow.

In the connected world, protecting doors means protecting the business.

References

  1. Dragos 2026 OT Report Shows Surge in Threat Groups and Ransomware
  2. The 2026 State of OT/ICS Cybersecurity in Critical Infrastructure
  3. Primary Mitigations to Reduce Cyber Threats to Operational Technology | CISA
  4.  CISA, FBI, EPA, DOE issue joint alert on rising cyber threats to critical infrastructure OT systems - Industrial Cyber

I’ve been thinking about how often I have to Google something just to understand what people in this industry are talking about.

It happens pretty regularly. I’ll be scrolling through LinkedIn, see a post about something I’m genuinely interested in, and come across an acronym or technical term I don’t know. So I look it up. Then I’ll read another article, find another term, look that one up, and eventually I’ve spent ten minutes trying to understand a post that probably took thirty seconds to write.

I don’t really mind doing it. I’m still pretty new to physical security and there’s still a lot I don’t know, and I actually want to learn the language of the industry so I can better understand and engage with the community.

But it also makes me think about the person who doesn’t have any reason to look it up.

They just scroll.

And that matters a lot more than whether someone understands an acronym on LinkedIn.

Because the person you’re selling to is rarely the only person involved in the decision. Maybe your security director knows exactly what you’re talking about. Great. But the proposal gets passed to IT. Then finance. Maybe HR. Maybe facilities. Maybe an executive who has to sign off on the budget. Suddenly, the story you told one person has to make sense to a bunch of people who don’t live in physical security every day.

I guarantee they don’t have a glossary of security terms sitting next to their laptop.

And I’m not saying we need to dumb anything down. Technical language exists for a reason, and there are absolutely times when it makes sense to use it. If you’re talking to a group of integrators, engineers, or security professionals who work with this stuff every day, speak their language. That’s part of knowing your audience.

But there’s a difference between being technical and making people translate your message before they can understand why they should care.

I think that difference gets overlooked a lot in physical security.

We spend so much time thinking about the product, the technology, the deployment, the features, the specifications. But when it comes time to market those things, we sometimes forget that a great story is part of the product too.

A customer story is marketing. A really interesting deployment is marketing. A point of view about where the industry is going is marketing. The way you explain your product is marketing.

And if the story only makes sense to people who already know the language, you’ve made your own audience smaller.

This is especially important on LinkedIn. If your following is mostly technical people you already know, and your goal is to have a conversation with that audience, then great. Use the terminology. Speak their language.

But if you’re posting because you want the story to travel, you have to think differently.

The person who sees your post might be an executive. It might be someone in IT. It might be someone in finance who has no idea what OSDP means but does understand that you’re trying to solve a very real problem.

They’re not going to stop and Google it (and they shouldn’t have to).

That doesn’t mean removing the technical language. It means being more strategic about where you use it. Explain the problem before the acronym. Tell people why something matters before explaining how the technology works. Give the story enough context that someone outside the room can follow it without needing you there to translate it.

What happens when you’re no longer in the room to explain what you meant?

If the answer is that your customer is the only person who understands the pitch, you may have a communication problem.

You might actually sound more confident when you can take something complicated and make it easy to understand. And the best part is, you haven’t made the idea less technical. You’ve just made it more accessible to the people who ultimately have to buy into it.

Your customer may understand the acronym. Their CFO might not. Their HR leader probably doesn’t. And if your story has to make its way through all of them before the deal gets done, clarity isn’t dumbing anything down.

It’s part of the sale. 


🔓 The Electronic Locksmith

A dedicated space for the people installing, servicing, and troubleshooting electronic access every day. Smart locks, mobile credentials, and cloud-managed access are already changing the trade, and this section is here to help locksmiths keep up, learn, and connect. A new eddition will appear in this section as articles come in. 

Built in partnership with ALOA, ELF, and The Access Control Collective, and anchored at globallocksmiths.org.

Well, it has been a great journey getting to where we are with the Electronic Locksmith Group and the launch of the website and forum. What started off as a chat over coffee with Lee at the Access Control Summit in Zurich about locksmiths and the phenomenal surge in the smart lock and wireless access control business, developed into something deeper. We both concurred that electronics was the way forward for locksmiths to grow and to future proof the locksmith industry globally but they needed help and the support of other locksmiths and the manufacturers to develop it into a new sector of the security industry. Many locksmith business owners may think that they are too old and settled to join this electronic lock revolution but many have employees and family members who would love to get involved and contribute to the growth of the business... Continue reading here ->


👀 As Seen In the Secured Community 👀

đŸ€– AI & Technology — Brian Karas shared a behind-the-scenes look at Anduril’s WISP and its approach to drone detection without relying on RF. He also shared another LPR system that makes Flock look “adorably simple.” WISP | Leonardo ELSAG SignalTrace

🔍 Research — Daniel Raines shared an update on Dark Ether v2, including one-click exploits running on a LattePanda. Definitely one for the research folks to dig into.

📰 Industry News & Insights — Lee Odess shared the latest Flock coverage from The New York Times, along with thoughts on dormakaba’s latest announcements and Allegion’s quarterly dividend. He also shared some takeaways from the Acre Security partner event in Austin, including the State of the Verticals report and campus deployment conversations.

📱 Marketing & Branding — Brian Karas shared shared a post from Unlimited Technology about their approach to GSX this year: “We’ll be on the floor at GSX, not standing in a booth.” Their team is inviting attendees to connect around roadmaps, renewals, and inherited systems rather than just stopping by to scan a badge.

🏠 General — Jason Hart opened up a pretty heated conversation around HID’s SEOS vulnerabilities and the industry’s broader cybersecurity practices. Read more

🔐 The Most Secure Places — Hailey Canady introduced a new series from Lee looking at some of the world’s most secure places and the stories behind them. First stop: Fort Knox. Watch the kickoff video

đŸȘȘ Identity & Privacy — Lindsay Martin-nez shared a story about an FBI investigation into a service allegedly selling access to 153 million driver’s licenses and asked the community for their thoughts. Read the story


ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.

Registration is OPEN NOW! Sign up here.

Speaking at the event?
Go here.

On the fence? View some testimonials from previous years
here.


đŸ—Łïž Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.

Community input form!


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here: https://www.tacc.me/secured Thank you!

Volume 4
🎙 Secured Podcast Episode 29 | Flock and LPR as a Category Are Losing Right NowFlock isn't the only one with a problem. LPR as a category might be losing right now. In this week's Secured, Lee gets into the growing backlash surrounding Flock, the questions around surveillance and governance, and why every company in the LPR space should be paying attention. Listen here. đŸ«Ł Premium member-only co...
Volume 3
🎙 Secured Podcast Episode 29 | Coming next week! đŸ«Ł Premium member-only content | Is Physical Security Finally Going Mainstream?Is our industry finally mainstream, and what does it cost to act like it? Lee Odess sits down with LVT's Steve Lindsey and Derek Boggs on prevention over reaction, why the scarecrow stops working, and how a company out of American Fork, Utah landed on an NBA jersey patc...
Volume 2
🎙 Secured Podcast Episode 28 | Silicon Valley Is Coming For Your Lunch Money The enterprise software crowd is at our door, and most of the industry isn't paying attention. This week on Secured, Lee breaks down who's coming, why the playbook always looks the same, and the one thing these outsiders keep getting wrong about our world. Listen here đŸ«Ł Premium member-only content | Between the Lock an...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.