Header Logo
Log In
← Back to all posts

Volume 6

Sep 11, 2026

🎙 Secured Podcast

Episode 31 | The Water Treatment Hack That Should Scare You
What happens when ALPR becomes a policy issue, end users start writing the rules, and a cyberattack can put an entire water supply at risk? Lee gets into it on this week’s Secured.
Listen here.

🫣 Premium member-only content

The Acre AMA: You Asked, Kumar Answered
What happens when you put the CEO of Acre Security in front of the questions the industry is actually asking? Kumar Sokka gets candid about where Acre is today, where he believes it needs to go next, and what it takes to evolve a company without losing sight of the customers, platforms, and relationships that built it. Watch here.

✍🏻 Articles

Min Kyriannis | When Every Drop is at Risk: Defending Water Treatment Plants from Cyberattacks 
A cyberattack on a water treatment plant isn’t just an IT problem. It can mean changing chemical levels, disabling pumps, manipulating controls, or putting operators in a position where they can’t trust the systems they’re relying on. This piece looks at why water infrastructure is increasingly vulnerable, what the industry can learn from incidents like Oldsmar, and what utilities can do to build resilience before a cyberattack becomes a community emergency. 

Phil Coppola | The Phone Is the Least Interesting Part of Mobile Access
Mobile access is often framed as a simple shift from plastic cards to smartphones. But the real change is much bigger. Moving credentials to mobile can expose the outdated processes, disconnected systems, and technical debt sitting underneath physical access. This piece looks at what mobile access actually changes, and why the phone may be the least interesting part of the conversation. 

Daniel Greenberg | “AI-powered” means nothing anymore.
“AI-powered” is everywhere in physical security. But what does it actually mean? Three very different products can carry the same label, while buyers are left trying to figure out what’s real, what’s being oversold, and what actually works in the field. This piece breaks down the problem and the questions buyers should be asking instead. Read the full piece below..

🚨 Breaking News 

  • Safetrust Inc. just introduced an Aliro 1.0 Migration Credential
  • The LEAF Community has launched a new End User Committee, chaired by Michael Franke, CPPÂŽ of Bank of America, and it includes members from Anduril Industries, The Depository Trust & Clearing Corporation (DTCC), IBM, and Red Hat. 
  • Secure Passage announced the launch of 24x7 Managed Operational Intelligence Services (MOIS) powered by Truman

Podcast | Secured: Episode 31

This week on Secured, Lee looks at the Security Industry Association’s new ALPR guidance and why the industry needs to get ahead of policy conversations before they become a crisis. He also covers LEAF’s new end user committee and what it means to have enterprise security teams helping shape credential standards. Inside the Secured Collective, Lee highlights his conversation with Acre Security CEO Kumar Sokka and a debate around two very different ALPR stories from Oakland and Florida. Plus, Lee breaks down this week’s Secured Brief on water treatment cybersecurity and shares his thoughts on the changing role of marketing, media, and influence in the security industry. Listen here.


Find these podcasts ONLY in the 'Conversations with Lee' Channel.

Kumar Sokka, CEO of Acre Security, joins Lee Odess to talk about Acre’s history and heritage in the industry, the importance of openness and interoperability, and what it takes to build for the future. They also discuss what makes a product “sticky” and why long-term customer relationships go beyond recurring revenue to continually improving the product and giving customers a reason to stay. Watch here.


Water treatment plants are among the most essential and increasingly vulnerable parts of modern critical infrastructure. They purify drinking water, manage wastewater, control chemical dosing, operate pumps and valves, and protect communities from contamination and disease. Yet the systems behind these operations are becoming attractive targets for cybercriminals, nation-state actors, hacktivists, and opportunistic attackers.

A successful hack of a water utility may not look like a conventional data breach. Rather than stealing customer records or credit-card numbers, an attacker may try to disrupt operations by changing chemical levels, disabling pumps, altering programmable logic controllers, locking out plant personnel, falsifying sensor readings, or disrupting treatment operations. The consequences can extend beyond financial or reputational loss; they can threaten public health, environmental compliance, emergency response, and public confidence.

Water and wastewater utilities depend on a combination of traditional Information Technology and Operational Technology. Office networks handle email, billing, and customer information, while industrial control systems manage the physical treatment process.

Operational Technology often includes:

- Supervisory Control and Data Acquisition (SCADA) systems, which allow operators to monitor and control treatment processes.

- Programmable Logic Controllers (PLCs) that send computer-based commands to mechanical devices, such as pumps, valves, chemical feeders, and other equipment. 

- Human-Machine Interfaces (HMIs), computers that display process data and let operators adjust settings.

- Remote access, used by plant personnel, engineers, contractors, equipment vendors, and managed-service providers, to provide support and operations.

This technology has existed for decades and enables automation and efficiency. However, modernization and retrofits have created new attack surfaces, increasing vulnerable points to the environment. Many utilities operate aging equipment which was designed for reliability rather than cybersecurity. Some of these systems use older operating systems, or operate with shared accounts, default passwords, weak network security, or remote-access services which expose control environments to the Internet.

The challenge is particularly considerable for small and mid-size utilities. They may have limited security budgets, few dedicated cybersecurity staff, and complex operational environments

Protecting humanity in our digital world.

managed by a small number of employees. A single compromised account or poorly secured remote connection can give an attacker a foothold into systems tied to the broader physical water operations environment.

A water-sector cyberattack can take on several forms. The most common involve remote access, ransomware, phishing, exposed or disabled industrial devices, and third-party connections, such as vendors and service providers.

Part 2 of this article will be released in the next issue. 


One of the most common ways to describe mobile access is also one of the least useful: it replaces the plastic access card with a smartphone.

Technically, that’s true. A mobile badge ultimately performs the same basic function as a physical credential. It presents credential information to a reader so an access control system can make a decision and, when appropriate, unlock a door. Viewed strictly from the reader outward, the difference can seem fairly incremental.

But focusing on that interaction misses most of what makes mobile access interesting. The more consequential change isn’t what an employee presents at the door. It’s what can happen throughout the credential lifecycle before and after that interaction.

Mobile access creates an opportunity to rethink credential issuance as a digital identity process rather than a physical manufacturing and distribution process. That has implications for automation, identity integration, security policy, and the relationship between physical security and IT.

The phone may be the most visible part of mobile access, but it’s probably the least interesting part.

The Physical Process Behind a Digital Identity

Traditional access control contains an interesting contradiction. The identity of an employee generally begins as digital information, but at some point we turn that information into a physical object.

When an employee joins an organization, their information is entered into an HR system and eventually makes its way into the access control system. An access profile is created, a credential is assigned, and a card is printed, encoded, and physically delivered.

Organizations have become very good at this process, but that doesn’t necessarily make it efficient.

Physical credentials introduce requirements that exist primarily because the credential is physical. Cards need to be stocked, printed, encoded, distributed, and replaced. Printers require supplies and maintenance. Remote employees may require shipping. Lost cards need replacement, while forgotten cards often result in temporary badge requests.

It’s somewhat analogous to traditional mail versus email. The benefit of email wasn’t simply reading a letter on a screen instead of paper. The larger transformation was eliminating much of the physical process required to move information from one person to another.

Mobile access has the potential to do something similar with credential issuance.

Credential Provisioning Becomes a Workflow

The most significant opportunity created by mobile access may be automation.

In an integrated environment, the creation of an employee in an authoritative identity source can initiate the processes necessary to establish physical access. Information can flow between HR, identity, and access control systems rather than being manually recreated in each one. Once the appropriate policies and approvals have been satisfied, a mobile credential can be remotely provisioned.

From the employee’s perspective, the experience may be as simple as receiving a notification that their mobile badge is ready. From the organization’s perspective, however, a considerable amount of workflow has potentially disappeared.

For one employee, eliminating a badge-office visit is convenient. Across tens of thousands of employees and hundreds of locations, reducing badge-office visits, shipments, manual entries, and replacement transactions becomes an operational issue.

The meaningful comparison, therefore, isn’t between presenting a phone and presenting a plastic card. It’s between the lifecycle of a physical credential and the lifecycle of a digital one.

Bringing Physical Access Into the Identity Conversation

There is also a broader security consideration.

Many organizations have spent years modernizing logical access. Identity has become central to cybersecurity strategy. Stronger authentication, device management, conditional access, and Zero Trust principles reflect a movement away from simply asking whether someone possesses the correct secret or object.

Physical access has not always evolved at the same pace. A traditional access card is fundamentally a possession-based credential. Once issued, the system generally assumes the person presenting it is the person to whom it was assigned.

Mobile introduces additional possibilities. Depending on the architecture, credential use can benefit from capabilities already present on modern devices, including passcodes, biometrics, secure credential storage, device management, and remote security controls.

That doesn’t mean putting a credential on a phone automatically creates Zero Trust physical access. Zero Trust is an architectural approach, not a credential format. But mobile can give physical security teams mechanisms that better align with the identity and device-trust principles their IT counterparts are already implementing.

That alignment may ultimately prove far more important than replacing a piece of plastic with a phone.

In Part 2, I’ll look at the practical side of that transition: legacy infrastructure, visual identification, credential economics, and why moving to mobile doesn’t have to mean abandoning physical badges.

Disclosure: This content was produced by me, in my capacity as an HID Employee.  I am also a board-certified PSP (Physical Security Professional) by the ASIS International Organization.


How much of the industry's AI messaging outpaces what's actually deployed, and what that gap means for buyers evaluating vendors.

Walk any security industry trade show floor and count how many booths avoid the phrase "AI-powered." You won't get far. The term has become so ubiquitous in physical security marketing that it has nearly stopped meaning anything at all, and that's a problem, because somewhere underneath the branding, actual AI capability does vary wildly from vendor to vendor, and buyers are rarely given the tools to tell the difference. This isn't a complaint about hype for hype's sake. It's a structural issue in how the industry sells itself, and it has real consequences for the organizations trying to buy security systems that work.

Breaking it down into its four fundamental flaws.

Three products, one label

Consider what "AI-powered" can mean in a typical product listing today. It might mean a system trained on millions of hours of footage to distinguish a person from a shadow, a package from a loitering figure, a break-in attempt from a raccoon knocking over a trash can. It might mean a rules-based motion detection algorithm with a marketing refresh, unchanged in substance for a decade but repackaged for a buzzier moniker. Or it might mean something in between: real machine learning applied to a narrow task, oversold as general intelligence.

All three get the same label. All three appear, functionally identical on paper, in the same RFP responses and sales decks. The buyer evaluating them? Often a facilities director, a risk manager, or a procurement officer without a technical security background and almost no reliable way to distinguish a mature computer vision system from a decade-old algorithm with new packaging.

Why the gap persists

Part of the problem is that AI claims are extraordinarily hard to verify from the outside. Unlike a camera's resolution or a sensor's range, model performance isn't something a spec sheet communicates in a standardized way. False positive rates, training data diversity, and real-world accuracy under adverse conditions such as rain, low light or crowded scenes are the metrics that actually matter, and they're almost never published, let alone audited by a third party.

Vendors also have limited incentive to close this gap unilaterally. If competitors can claim "AI-powered" without substantiation and face no penalty, the rational move for any single company is to match the language rather than absorb the cost of proving it. That's a classic race-to-the-bottom dynamic, and it's one that buyers rarely notice happening because every product in the category sounds equally advanced.

The result is an industry where marketing sophistication and technical sophistication have become only loosely correlated and where the companies best at the former don't always overlap with the companies best at the latter.

What buyers should actually ask

The fix isn't complicated, but it requires buyers to shift their questions. Instead of asking whether a system uses AI, the more useful question is what specific problem the model was trained to solve, and how its performance was measured. A vendor with a legitimately capable system should be able to answer concretely: what the false alarm rate looks like in a live deployment, how the model handles edge cases like poor lighting or partial occlusion, and how often it's retrained or updated as conditions change.

It's also worth asking what happens when the AI is wrong. Every model has a failure rate. The organizations that have thought seriously about their systems will have a clear answer about how false positives and false negatives are caught and corrected, whether that's human review, feedback loops, or some combination. Vendors without a real answer to that question are often the ones for whom "AI-powered" is doing more marketing work than technical work.

An industry at an inflection point

None of this means that the underlying technology isn't real or improving. Computer vision and anomaly detection genuinely have gotten better, and some deployments now do meaningfully more than the video systems of ten years ago. But the pace of marketing claims has outrun the pace of independent verification, and that mismatch is now a bigger risk to buyers than any single vendor's shortcomings.

Security is, at its core, a trust business. An industry that lets a marketing term substitute for a technical standard is quietly eroding the thing it's supposed to sell. Until that changes, through clearer disclosure norms, third-party benchmarking, or simply more informed buyers asking harder questions. Until then "AI-powered" will keep meaning everything and nothing at once.


👀 As Seen In the Secured Community 👀

📣 Shameless Plugs

Jon Harris shared a new podcast episode on how EOS changed the way he approaches business operations, meetings, and teams. Link

Jack Merrifield shared Loudin, an open-source access control management platform built to separate hardware from software. Link

🔐 Identity & Privacy

Salvatore D’Agostino shared a story about a Georgia woman suing Flock Safety over license plate tracking. Link

LG TV vulnerabilities that could allow attackers to listen in, even when the TV is off. Link

FinCEN guidance on digital credentials and identity verification. Link

💡 Interesting Topics

Jon Polly shared two ALPR stories: Oakland reported major drops in carjackings and shootings, while Florida banned ALPRs on state-owned roads. Oakland link & Florida link

💬 General

Marcus Tonndorf asked whether GSX is worth attending compared to ISC West as he looks to grow Hexlox in the U.S. Hexlox link

Frank Hayes asked about ASSA ABLOY’s electronic/electro-mechanical business compared to its core metal business.

Jonny Bowers is looking to connect with the person responsible for C•CURE 9000 at Johnson Controls.

🔑 Aliro

Ryan Kaltenbaugh shared an update on Aliro, highlighting major pilots underway ahead of its expected Q4 2026 launch. Check out his post and join the conversation.

🛠️ Products & Solutions

Rodney Thayer shared questions to ask access control vendors about OSDP at GSX. If you’re attending, check out his post. 

💼 Jobs & Opportunities

Ryan Kaltenbaugh shared three new M.C. Dean roles in Tysons, VA, along with 1,600+ open roles worldwide. Link

📰 Industry News & Insights

Steve Pineau shared a new voice-activated access control concept that lets users tell their phone which door or gate to open.

Lee Odess shared SIA’s new guidance on responsible ALPR use and why the industry needs to get ahead of policy conversations. Link

🌐 LEGIC connect26

Reto Imwinkelried shared that LEGIC connect26 is one week away, featuring speakers from Apple, Google, Acre Security, HID, Aliro, and more. Use code CONNECT26LEE for a discount.

📣 Shameless Plugs

Jenna Hardie invited GSX attendees to Career HQ on Monday, September 14 at 12:30 PM for a personal branding conversation with marketers.

🔎 Research

Daniel Raines questioned Flock Safety’s vulnerability disclosure approach and shared its policy. Link

He also shared a DEF CON demonstration on using patterns to interfere with facial recognition. Link


ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.

Registration is OPEN NOW! Sign up here.

Speaking at the event?
Go here.

On the fence? View some testimonials from previous years
here.


🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.

Community input form!


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here: https://www.tacc.me/secured Thank you!

Volume 5
🎙 Secured Podcast Episode 30 | Could Cheaper, More Open Access Control Hardware Help Make Schools Safer?dormakaba is showing what three years of transformation looks like, Acre is turning its roadmap into something partners can actually sell, and the lines between physical security, AI, and cybersecurity keep getting blurrier. Plus, Lee has a question about access control that might make some p...
Volume 4
🎙 Secured Podcast Episode 29 | Flock and LPR as a Category Are Losing Right NowFlock isn't the only one with a problem. LPR as a category might be losing right now. In this week's Secured, Lee gets into the growing backlash surrounding Flock, the questions around surveillance and governance, and why every company in the LPR space should be paying attention. Listen here. 🫣 Premium member-only co...
Volume 3
🎙 Secured Podcast Episode 29 | Coming next week! 🫣 Premium member-only content | Is Physical Security Finally Going Mainstream?Is our industry finally mainstream, and what does it cost to act like it? Lee Odess sits down with LVT's Steve Lindsey and Derek Boggs on prevention over reaction, why the scarecrow stops working, and how a company out of American Fork, Utah landed on an NBA jersey patc...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.