Volume 7
š Secured Podcast
Episode 32 | Coming to you Monday, September 21 recorded live at VerkadaOne
š«£ Premium member-only content
YourSix AMA with Jacob Hengel
What happens when you take the lessons from the VoIP/PBX disruption of the 2000s and apply them to physical security? In this AMA, Jacob Hengel of YourSix gets into the shift toward a more unified security category, direct-to-cloud architecture, the future of integrators and MSPs, and why simplicity may be the key to driving innovation. Watch here.
Acre AMA with Kumar Sokka
Missed this one last week? Kumar Sokka, CEO of Acre Security, gets candid about where Acre is today, where he believes it needs to go next, and what it takes to evolve a company without losing sight of the customers, platforms, and relationships that built it. Watch here.
š° The Access Control Executive Brief by Lee Odess
Brief 154 | Don't Take the New and Shove It Through the Old
Real innovation deserves a go-to-market strategy built for the market it could actually reach, not the one physical security has always sold into. In this weekās Brief, Lee Odess breaks down āSailing Ship Syndrome,ā why companies keep pushing new technology through the same old channels, and why the bigger opportunity may be in the mainstream market next door.
āš» Articles
Phil Coppola | The Phone Is the Least Interesting Part of Mobile Access Part 2: Mobile Access Is a Migration, Not a Replacement.
Mobile access doesnāt mean physical credentials disappear overnight. In Part 2, Phil Coppola looks at what happens when mobile and physical credentials coexist, from technical debt and visual IDs to the real cost of managing a credential lifecycle, and why the bigger conversation isnāt phones versus cards, but identity, architecture, and process.
Michael Stuer | An agent at the door
This article explores why an API alone isnāt enough for agentic access control, and why clean, trustworthy access data and clear approval rules will become critical as agents start making access decisions on their own.
Min Kyriannis | When Every Drop is at Risk: Defending Water Treatment Plants from Cyberattacks: Part 2
The risks facing water treatment plants donāt stop at the network. In Part 2, Min Kyriannis looks at how cyberattacks can impact physical operations, what the 2021 Oldsmar attack taught the industry, and why securing water infrastructure requires more than just protecting the IT environment.
Ellie Portugali | Your $1,000 phone is just a copper wire
This piece takes a closer look at Aliro 1.0, mobile credentials, and why true Zero Trust means asking what happens when the phone is completely compromised. The question every vendor should be able to answer: What breaks if I root the phone?
šØ Breaking News
- Pavion names Andy Bierer CEO, Joseph Oliveri moves to an advisory role
- Cobalt AI launched CMI SaaS today a, bringing its judgment layer into customer-managed security operations for the first time.
- ASSA ABLOY Group acquires Pacific Lock Company (PACLOCK) adding a US-based padlock and portable security manufacturer to its Americas Division.
- dormakaba signs agreement to acquire Alliants, connecting hotel access with digital guest experience.

Episode 32
Secured looks a little different this week.
Lee left the home setup, Hilary grabbed a mic, and Episode 32 was recorded live at VerkadaOne.
That means youāll have to wait a few extra days for this one.
Monday, September 21. š

Donāt miss the latest premium member content in the community
The YourSix AMA with Jacob Hengel takes a look at where physical security is going, including the convergence of security technologies, direct-to-cloud architecture, and what the future of the integrator and MSP could look like. Watch here.
The Acre AMA with Kumar Sokka, CEO of Acre Security, dives into where Acre is headed, how the company is evolving, and the balance between modernizing the business while maintaining the customer and partner relationships that matter. Watch here.
Two separate AMAs, two very different conversations, both worth watching. Check them out in the community and let us know what you think!

Every week I sit through calls, demos, and discussions from companies with real innovation. Note, not iteration, but actual innovation. Then I ask about go-to-market, and I get the same answer: same messages about being "open,ā "simple," a "platform," and plans for the same trade shows, but more troubling, the same channel, and the same integrator relationships, with the same programs⦠and without saying it out loudā¦they are just another line added to the long list of other lines carried "just in case." These new companies have built a $100 billion opportunity and brought it into a $12 billion marketā¦and wonder why they don't see different results.
I understand chasing today's revenue and the need for revenue now. Still, you need to build a go-to-market and marketing strategy that fits today and tomorrowā¦not yesterday. A real percentage of effort should go into building the new channel, not just harvesting the old one.
The old-school, high-security physical security industry we have all grown up in, know, and love, at its core, is not a high-growth one. That market takes 20 years to build (to be clear: it doesn't need to, but we have come to expect it, and those in it protect the slow growth as though it's a feature⦠newsflash: it's not, but you aren't going to change that bug in the system. There is a large group of people - giving each other awards right now in Atlanta - making damn sure things don't change). Most early-stage, venture-backed companies aren't built for a 20-year exit and have higher expectations. Most private equity is not either. I do recognize the self-funded startup needs revenue now, so the high-security buy-now market matters, but this is a % game vs. an absolute "only that market" game. The exponential opportunity is not inside the $12 billion room. It is in the mainstream market next door, the one that will pay for what you built if you invest the time, resources, and creativity in it.
Don't believe me? Look to other industries that have already made this move.
Salesforce didn't sell CRM the way Siebel did. Siebel sold enterprise software through consultants and multi-year implementations. Salesforce sold a browser tab and a credit card. Same category, completely different buyer motion.
Stripe didn't sell payments the way the banks did. Banks sold through relationship managers and paper applications. Stripe sold to developers with an API and documentation. It built a new channel instead of adding a line item to an old one.
Netflix didn't grow DVDs-by-mail into streaming by asking Blockbuster to carry a red envelope display. It built direct distribution to a device already sitting in the living room.
Tesla didn't sell cars through the franchise dealer network. It built its own stores and service model because the dealer network existed to protect an old margin structure, not launch a new category.
Each of these companies had a choice: sell the new thing through the old channel and get an incremental result, or build a new channel and get the market the technology actually deserves. They chose the second path.
I know, I know⦠but "it's security." Yes, it is security, but look yourself in the mirror and stop lying to yourself. If you take all this new and shove it through the old and expect different results, that is the definition of insanity.
If you are bringing real innovation into physical security, decide now what percentage of your effort goes toward building the new channel + a marketing message built to support it + a go-to-market strategy that sets you up for exponential success instead of feeding the old one. Even 20%, applied consistently, compounds over time.
Sailing Ship Syndrome isn't just a warning for incumbents optimizing a dying paradigm. It's a warning for anyone, new or old, who defaults to the model already in the room.
What are some examples of what you can and should do? I'll cover more in the Secured Collective.

In Part 1, I argued that the most interesting thing about mobile access isnāt using a phone to open a door. Itās the opportunity to rethink credential provisioning, identity integration, and the processes surrounding physical access.
But digital transformation rarely means replacing everything at once. Mobile access is no exception.
For many organizations, mobile and physical credentials will coexist for years. That isnāt necessarily a failure to complete the transition. It may be the most practical way to manage it.
Mobile Can Expose Technical Debt
One of the most common obstacles to mobile adoption isnāt the phone. Itās everything behind the reader.
Organizations may discover that readers installed years ago cannot support the credential technologies they now want to deploy. That can make a mobile project more complicated and expensive than initially expected, and it shouldnāt be minimized. Not every organization has a compelling business case to replace functional infrastructure simply to let employees use phones at doors.
At the same time, incompatible infrastructure can indicate technical debt. If an access control environment cannot accommodate current credential technologies, itās worth understanding what other limitations exist and when that infrastructure will eventually need modernization.
Mobile doesnāt create those legacy conditions. It often makes them visible.
The Visual ID Problem Is Real
Another practical issue is visual identification. Many organizations still need employees, students, healthcare workers, or others to visibly display an ID. A phone doesnāt always replace that function particularly well.
But does the visual ID badge also need to contain the electronic key to the building?
Historically, combining visual identification and electronic access on one card made sense. Mobile allows us to reconsider that relationship. An organization can continue issuing a well-designed physical visual ID while placing the electronic access credential on a mobile device.
Iāve seen this approach deployed at significant scale. One large organization has approximately 80,000 mobile credential users while continuing to issue physical visual IDs. Users can have mobile badges on their phones and smartwatches, while the physical badge currently retains its RFID capability during the transition.
The strategy isnāt to eliminate cards overnight. Itās to allow behavior to change over time. The organization has already reported roughly an 80 percent reduction in temporary badge requests associated with forgotten or lost physical badges.
The lesson is important: mobile migration doesnāt have to be binary.
Stop Comparing Credential Prices
The business case for mobile is sometimes reduced to the unit cost of a physical card versus a mobile credential. That comparison misses much of the actual expense.
The purchase price of a physical credential isnāt the cost of issuing it. There is labor associated with administration, printing, encoding, and distribution. There are printers, supplies, maintenance, shipping, replacements, and temporary-badge workflows.
The same scrutiny should be applied to mobile. Mobile credentials have costs. Integrations may require investment. Reader upgrades can be significant. Deployment and support arenāt free.
The useful financial question isnāt whether a mobile credential costs more or less than a piece of plastic. Itās what the organization spends operating the entire credential lifecycle today and how that lifecycle would change under a mobile model.
āOur Badges Work Fineā Is a Reasonable Position
For some organizations, existing physical credentials really do work fine. Their infrastructure is current, issuance is efficient, their population is stable, and there may be little operational justification for changing.
Mobile should solve a problem or create meaningful value, not simply satisfy a desire to deploy newer technology.
The more interesting question is what an organization would design if it were building its credential program today. Would identity information be manually maintained across multiple systems? Would employees visit a physical location to receive an electronic credential? Would remote employees be mailed credentials? Would lost and forgotten cards remain an unavoidable administrative workflow? Would physical access operate separately from the identity and device-management infrastructure used elsewhere in the enterprise?
Those questions move the conversation away from phones versus cards and toward architecture, process, and identity.
Mobile access is better understood as one component of physical securityās broader digital transformation. It can enable automation, tighter identity integration, additional security controls, and new approaches to credential lifecycle management. It can also require investment and coexist with physical identification for a very long time.
The smartphone is simply where the user sees the result.
If all we do is take the credential that was on a plastic card and put it on a phone, weāve missed the more important conversation.
Disclosure: This content was produced by me, in my capacity as an HID Employee. I am also a board-certified PSP (Physical Security Professional) by the ASIS International Organization.

Ask a serious site who can get into the server room right now and why, and see how long it takes. Someone exports a list from the access control system. Someone else checks the two doors that still run on the old controller because that one keeps its own list. Thereās a contractor group left over from a project in March and nobody is quite sure if itās still active. Thereās also a stack of temporary cards at reception that were never assigned to anyone. An hour later the one person who properly knows the estate has pulled together an answer thatās mostly right and nobody can tell you how much of it to trust.
Iām not saying thatās a failure because itās how most working buildings run and every operator reading this has lived some version of it. The answer turns up eventually and the day carries on, and so far the difference between mostly right and right hasnāt cost anyone very much.
But that changes once an agent is asking and it needs the answer in a fraction of a second at 2am with nobody around to ring. Most of our industry seems to believe an open API takes care of that and I donāt think it does.
Everyone is going to claim an API and an AI story over the next twelve months and most of them will be telling the truth about the API. What actually separates one system from the next is whether a machine can work out who can go where, under what rules and why. An API will hand an agent the list of who has access today but only the reasons someone wrote down. On most sites nobody ever did and theyāre still in the head of whoever set the system up.
Most of the conversation so far has been about agents that need their own credentials to book a room or pull a report, and there are already decent answers for that.
Thereās been far less talk about the agent that hands out access. It onboards a contractor on Tuesday, extends their access at 2am when the job runs long and revokes it on Friday with no person in the loop for any of it. I donāt see that as some distant future. Someone will build it next year if they havenāt already, and itāll get built whether the data underneath it is any good or not.
When it works itās genuinely better. The job runs long, so the agent reads the work order and extends the contractorās access by four hours. It notes why and closes it again at six, which beats ringing a supervisor at home. Now picture the same agent working off the site I described at the start with a contractor group from March that nobody closed and a stack of cards at reception it doesnāt know exist.
Who answers for it when the agent gets that wrong? At the moment nobody can tell you. Todayās contracts werenāt written for it and the operator never saw the decision being made.
Weāve already run into a small version of this inside our own company. A couple of weeks ago I told one of our agents that a second agent could go ahead and publish something, so it passed my approval on. The second agent refused to act on it because it had no way of checking the approval had actually come from me. It cost us ten minutes and it was the right call. Every building will hit the same thing once agents start handing out access, because the agent at the door needs to know the approval came from someone who was allowed to give it.
I build with these tools every day and they already do stuff others can only dream of, so this isnāt an argument for less AI. A smarter agent just doesnāt help much if the record itās working from is wrong. To make that call safely it has to know who can open what and under what rules, who could have opened it a year ago and whatās left as evidence. That record has to hold across keys and credentials for the life of the system, and it has to give an agent the same answer it would give a person.
Weāre building portierX to be that record. For now itās invitation only.
Iāve been resisting giving any of this an acronym, because the moment it has one people start arguing about the category instead of doing the work. Sooner or later an agent is going to ask your building that same question about the server room, and it isnāt going to wait an hour for someone to put the answer together.

Not every incident immediately disrupts the water handling process. Water utilities often have physical safeguards, alarm systems, laboratory testing, process limits, and trained operators that can prevent a cyber event from becoming a public health emergency. However, a cyberattack can still create dangerous uncertainty where operators may no longer know whether data is accurate, whether control commands are legitimate, or whether equipment will behave as expected. The danger elevates once the trustworthiness of the Operational Technology comes into question.
Although water treatment attacks are increasing, one of the best-known U.S. cases occurred in Oldsmar, Florida, in February 2021. An unauthorized actor accessed the SCADA system at a drinking-water treatment facility and attempted to increase the level of sodium hydroxide (commonly known as lye) used in water treatment.
An operator observed the unusual change and quickly reversed it before the altered setting affected the water supply. The incident became a major warning for water utilities because it demonstrated how remote access to an operator workstation could be used to manipulate a treatment process directly. DHS CISAās subsequent advisory identified measures such as strong passwords, multifactor authentication (MFA), updated systems, improved network security, and restricted remote access as important protections.
The central lesson from this incident was not simply that a hacker can penetrate a water treatment plantās network. It was that cybersecurity breaches can have physical consequences that impact human and life safety when an attacker gains access to operational controls.
Water systems are becoming more connected. Utilities use remote monitoring, cloud-connected dashboards, mobile maintenance tools, telemetry, smart sensors, automated chemical controls, and vendor support platforms to improve efficiency. These technologies can bring significant operational benefit, but each connection must be secured and monitored.
Recent government and industry guidance has placed special emphasis on protecting Internet-exposed PLCs. Attackers have targeted these devices by changing passwords to lock out legitimate operators or changing network settings that interrupt communications. DHS CISA and WaterISAC (https://www.waterisac.org/) recommend disconnecting PLCs from the public Internet, using a VPN or secure gateway for necessary remote administration, changing default passwords, restricting access to known IP addresses, and maintaining clean, tested backups of controller configurations. Unfortunately, a lack of experts and resources that understand how these systems work creates barriers to securing them.
The differentiating factor between a water hack and a typical office-network security incident is that the target is not merely information; it is a physical process. This is why water-sector cybersecurity must be treated as a resilience and life-safety discipline. The goal is not only to block hackers, but also to ensure that the utility can identify abnormal activity, keep operations within safe limits, operate manually if needed, and recover from a compromise without endangering its clients and the broader community.
Water treatment cybersecurity is not merely an IT issue, nor can it be solved by purchasing a single security product. Protecting our water infrastructure requires urgent, sustained coordination among plant operators, engineers, IT and OT teams, cybersecurity specialists, executives, contractors, equipment vendors, emergency managers, government partners, and others. These stakeholders must work together to identify vulnerabilities, strengthen operational resilience, and establish effective procedures to detect, respond, and mitigate these attacks. As adversaries employ an expanding range of sophisticated tools, emerging capabilities may help organizations better understand and mitigate these risks. Such capabilities are only one part of a broader strategy that depends on informed leadership, disciplined processes, continuous collaboration, and a shared commitment to safeguarding the safety, reliability, and continuity of our water supply.
Water is an essential service, and the systems that deliver it must remain safe, even under sustained cyber pressure. The question is no longer whether water utilities will face attempted intrusions ā they already do. The more important question is whether each utility has aligned its people, processes, technology, and physical safeguards to prevent a cyberattack from becoming a community emergency.
Now is the time for water utility leaders, governing boards, and community stakeholders to act. Assess critical systems, strengthen cybersecurity and physical protections, train personnel, test incident-response plans, and invest in the resilience needed to maintain safe and reliable service. By taking these steps before an attack occurs, utilities can reduce risk, protect public health, and ensure that a cyber incident does not become a community crisis.

It usually takes me twenty minutes of arguing to convince security teams of this. People look at modern phones and see almighty computers. (They are).
So when the industry builds mobile access for physical doors, we naturally want the phone to do the heavy lifting. We let the mobile app hold the access token. Or worse, the actual encryption key to generate access tokens.
We treat the phone like a trusted vault.
Now we have Aliro 1.0. Apple, Google, and Samsung finally blessed it.
I am genuinely happy about this. Anyone who has shipped a mobile credential across two operating systems, four Bluetooth stacks, and a customer's ten-year-old reader fleet knows exactly how much pain a standardized handshake removes.
But I want to spoil the wedding slightly.ā
"Aliro-certified" is about to become the new "AI-powered" on trade-show banners. People will assume it means "secure."
Aliro standardizes the handshake. It is deliberately silent on where the access decision actually livesā
If you want real Zero Trust at the door, try this test:
Take your architecture diagram. Draw a red line right through the phone. Assume everything inside that line is fully compromised. The OS is rooted, the app is malicious, and the attacker has a debugger attached (and a decent cup of coffee).
Does the door still stay locked?
If your answer involves the words "well, the wallet's Secure Element...", your system trusts the phone.
In a properly designed system, the lock is born with its own private key. The server encrypts a token that only that specific lock can open.ā
The phone's only job is to carry those opaque bytes from the server to the lock. It doesn't read them. It doesn't check them. It acts as a dumb network component.ā
Recently, a system I led was certified as a high-security distributed access control system, with the mobile phone officially classified as an "extraneous component."
In auditor language, that is a beautiful phrase.
It means the phone could be an iPhone, a Pixel, or a potato with an NFC coil ā and the security claims would still hold.
Before you bet your corporate campus on a new mobile credential, ask the vendor one question:
What breaks if I root the phone?
If they give you a list, be worried.
If they give you a shrug, you found a lock that treats the phone exactly the way it deserves to be treated.
Like a very expensive, very pretty, completely disposable piece of wire.
š As Seen In the Secured Community š
š¤ AI & Technology
Jon Polly shared a story from WIRED about Clearview AI testing an AI tool that lets police instantly uncover a personās online activity. Link
š Identity & Privacy
Sal DāAgostino shared a New York Times story on identity theft and a data breach involving the FBIās NEXUS program. Link
He also shared NISTās finalized guidelines for protecting online identities and access tokens from misuse. Link
š£ Shameless Plugs
Dominic Cornell is getting ready to officially launch D2eight and is looking for industry feedback. The first 100 users with code D28-30-FREE get 30 days free to test the rack builder and punch/commissioning tool. Link
š” Interesting Topics
Lee Odess shared a story about a Framingham garage door company, Door Systems, suing Latch after the company rebranded to āDOORā and reincorporated as Door Systems Inc. Link
š° Industry News & Insights
Lee Odess shared an update on changes at iLOQ, with both board chair Tzachi and CEO Heikki no longer with the company. Lee shared that heāll find out more and return with additional details. Read here.
He also shared his roundup from the Verkada keynote, breaking down the announcements from VerkadaOne Miami in āThe Five-Hour Product Rollout.ā Read here.
š LEGIC Connect 26
Vikrant Pelia shared one of the most impressive demonstrations from connect26: a robot created through a collaboration between ANYbotics, dormakaba, and LEGIC. The robot is already deployed at a GE facility in Ireland, with what he called fantastic results. Check out the robot here
š General
Brian Karas asked for any other recommendations for handheld/mobile badging for Lenel? Answer here.

We are officially 3 weeks away from ACS26. The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.
Registration is still open! Sign up here.
Speaking at the event? Go here.
On the fence? View some testimonials from previous years here.
š£ļø Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here: https://www.tacc.me/secured Thank you!