Header Logo
Log In
← Back to all posts

Volume 8

Sep 25, 2026

šŸŽ™ Secured Podcast

Episode 33 | Why Depth Now Beats Breadth
For 30 years, integrators won on breadth. Lee Odess argues that the Intelligence Era is changing the math, and that for some integrators, going deeper may be worth more than carrying another line. Listen here. 

🫣 Premium member-only content

A New Day at dormakaba: From Hardware to the Full Security Ecosystem with Heather Torrey and Bret Holbrook
The door may still be where the conversation starts, but it’s no longer where the conversation ends. Heather Torrey and Bret Holbrook talk about what it means for dormakaba to think beyond the hardware and build around the bigger customer experience.

šŸ“° The Access Control Executive Brief by Lee Odess | The Normalization of Single-Sourced Integrators. Coming to your inbox Monday šŸ‘€

āœšŸ» Articles

Jon Lunetta, Stefano Pedemonte, Alberto Pedemonte | We Can Have Nice Things
For decades, security has made the door bigger, heavier, and more visible. Now technology is giving us the chance to rethink what the door itself can be, and maybe finally build things that are as thoughtful as they are secure.

Jenna Hardie | Say what you want about GSX, in-person events are king
Everyone has feelings about GSX. But whether you love it, hate it, or dread the walk from the hotel, there’s something this industry keeps proving: getting people in the same room matters.Face-to-face connection still moves the needle in security, and why the best events might not look like events at all.

Erin Wilson | Managing Risks at Critical Entry Points
A school’s security can come down to something as simple as a door that doesn’t latch. Erin Wilson looks at the everyday door and hardware issues that can create bigger security and life-safety risks, and what schools can do about them.

Karlie Turner | RAMP Made Me Feel Like a Writer Again and Inspired Me to Go Build Baselines.
RAMP and SNG 2025 reminded Karlie Turner why she loves writing in the first place, but it also got her thinking about why security marketing can feel so interchangeable. So she went looking for something the industry doesn’t have enough of: its own benchmarks.

Ellie Portugali | A Robot is Just a Phone with Legs: Why Offline Locks Can't Trust You
A robot is just a phone with legs. So what happens when the thing carrying your access credential isn’t a person anymore? This piece looks at the trust problem behind offline locks, access tokens, AI agents, and the growing number of machines that will eventually be making decisions about who gets through the door.

Daniel Schneider | The Attack Is Never the First Event
This piece looks at the missed signals, human behavior, and organizational gaps that happen long before a crisis ever reaches the door. The question is whether organizations are creating the conditions for people to speak up before it’s too late.

Mike Gilliespie | We Should Be Concerned About What the Flock Camera Hack Reveals
A Flock camera was hacked, but the bigger story may be what the hack revealed about how much these systems are actually seeing and recording. Mike Gillespie looks at the scale of the data being collected, the security risks that come with it, and the growing gap between what surveillance technology can do and what the public understands about it.

Brooke Erickson | Part One: Orchestration Cannot Stop at Technology
Security is getting better at connecting technology, but what happens when the organizations behind that technology aren’t built to work the same way? Part One looks at the human and organizational side of orchestration, and why better technology can’t fix unclear ownership, competing incentives, or information that stops moving.

🚨 Breaking News 

  • Cognex Corporation to acquire RealSense for $500M, betting on robotic perception as the next frontier of Physical AI
  • Secure Passage Launches Truman 2.0, an Identity-First Physical AI Operating System
  • Security Industry Association (SIA) and AMAG Technology launch a new OSDP training program.

Secured: Episode 33

For decades, integrators built their businesses by carrying more lines, serving more customers, and being able to do a little bit of everything. But as configuration becomes less of a moat and manufacturers increasingly create demand, Lee Odess argues that the value of specialization is starting to look very different. In ā€œWhy Depth Now Beats Breadth,ā€ Lee makes the case for the single-sourced integrator and why depth may compound in ways breadth no longer does. Listen here. 

Btw, don't miss last week's episode! Lee and Hilary recorded live from VerkadaOne. Listen here.


Don’t miss the latest premium member content in the community 

Heather Torrey, EVP of dormakaba Americas, and Bret Holbrook, SVP of Access Control and Identity Management, open up about what a ā€œnew dayā€ at dormakaba looks like after years of transformation. The conversation covers the company’s focus on execution, its shift toward solutions and the broader ecosystem around the door, and how acquisitions like Alliants fit into that strategy. They also get into the shift from thinking about identity as a credential to thinking about identity as the person, including dormakaba’s work around biometrics, connectivity, and intelligent endpoints. From Azure Access to Apollo, the conversation looks at the moves shaping dormakaba’s next chapter and what they mean for customers and partners. Listen here. 


In 1861, Linus Yale Jr. patented the pin-tumbler lock, a mechanism so elegant its DNA still sits inside billions of doors today. What's remarkable, looking back, is that Yale's genius was miniaturization. He took the massive Egyptian wooden lock, four thousand years old, and shrank its elements into something that fit in the palm of your hand. Security's great leaps have always been about doing more with less.

Somewhere in the century that followed, we forgot that lesson.

Security began to wear its strength on the outside: bigger housings, thicker faceplates, and heavier boxes bolted onto doors. An entire aesthetic of reassurance grew around a simple equation: the more hardware you can see, the safer you must be.

But there was more behind it than perception. Access hardware has difficult physical, regulatory and installation constraints, and it must withstand force, harsh environments and decades of use.

Over the past decade, we began to break that spell. Connected, software-defined access made doors more intelligent, but the physical language largely stayed the same. We added intelligence to the door without fundamentally rethinking the object itself.

Act two is where things get interesting.

The same forces reshaping the digital world are finally crossing from bits into atoms. Embedded intelligence, advanced sensing and more efficient computing and power systems are opening new possibilities. As some of the industry's old constraints fall away, devices can be reimagined from first principles. This is physical AI for the built world, and it changes what a doorway can be.

The constraints that held back the best designs were not just the customer or taste. Technology was part of the equation. And now, technology has caught up.

The small, daily, human act of passing from one space into another deserves the same care we've lavished on our screens and cars, yet too often withheld from the world we actually move through.

Act two is here. We can have nice things. It's time to build.

This is the first in a series. Over the coming weeks we will take on the rest of the built world we've stopped noticing, one piece at a time. 


A lot of people have feelings about GSX. As a millennial parent, I’m all about validating those feelings (ā€œYes, it’s completely OK to feel some kind of way about this.ā€) But what you can’t deny about this industry is: in-person moves the needle. 

There are a few reasons why this is: 

A post-COVID swing: the burnout on events was palpable when COVID hit. A lot of companies had to re-think their strategy around connection, and as we’ve come out of that, the desire for face-to-face networking continues to grow. 

People want connection: I’ve found in this industry, the people make the difference. There’s a reason why when one person leaves a company, they take their vendors or partners (or even their colleagues) with them. In security, building trust is as essential as building technology that actually works.  

Body language and nuance: it’s one thing to provide a demo of a product to a group of people via Zoom. It’s quite another to be able to read a person’s body language as they experience the game-changing nature of your platform for the first time. The lean in. The ā€œcan I try it?ā€ The way their faces light up when they see something that really catches their attention. And the way that they walk away and bring more people back with them to see it for themselves. That in-person communication? That’s the magic. 

Whatever the reason, face-to-face is the key.

It doesn’t have to be a trade show

Here’s the thing: GSX is just one version of this. A booth on a show floor is great, but in-person connection can look like a lunch, a dinner, a small workshop, or a creative get-together that has nothing to do with a product demo. The format matters less than the result. You want people in the same room, talking to each other.

We saw this firsthand at our recent (and first-ever) customer roundtable. Twelve customers and prospects sat in one room and shared their experiences with each other. We didn’t give a pitch or walk through slides. We just had honest conversations about the challenges they face every day. What stuck with me most was how many people walked away feeling the same thing: I’m not alone.

That feeling is hard to create over email or a webinar. Security leaders carry a lot, and it can feel like nobody else gets it. Then you put them at a table with peers who deal with the same challenges, the same staffing gaps and the same pressure from leadership, and something shifts. They trade ideas. They swap numbers. They leave with a network, not just a notebook full of notes.

And the best part? Our role was mostly to open the door and then get out of the way.

Making room for connection

If in-person moves the needle, the question becomes how to make more of these moments happen. A few things I’ve learned:

Start small. You don’t need a massive event to create a real connection. Twelve people at a table can do more than a thousand people walking past a booth.

Let people talk to each other. The most valuable conversations often aren’t between you and your customer. They're between your customers. Give them the space to find each other.

Make it about them. When the room is focused on shared experiences instead of a sales pitch, people relax, open up and remember how it felt.

Keep showing up. Connection builds over time. The person you sat next to at lunch this spring is the one who waves you over at GSX this fall.

What marketing needs

This part is for the leaders who approve the plans and the budgets. If you want more moments like our roundtable, your marketing team needs a few things from you.

Room to grow the events program. For a lot of companies, ā€œeventsā€ means a handful of big trade shows each year. Those still matter, but they’re only one piece. A strong events program also includes regional dinners, customer roundtables, peer workshops, and small get-togethers built around a city or a shared problem. Expanding the program means planning for these from the start instead of squeezing them in when there's leftover budget.

Space to be creative. The best experiences usually aren’t the ones that follow the standard playbook. Maybe it’s a hands-on workshop instead of a panel, or a cooking class instead of another steakhouse dinner. Your marketing team knows your customers and what will make them want to show up. Give them the freedom to design something people will remember.

Permission to try new things. Not every idea will work, and that’s OK. Some formats will be a hit and some will teach you what not to do next time. If every event has to prove itself right away, your team will keep doing the same safe things. Let them test, learn, and adjust.

A partner in sales. The people in the room are relationships your whole company will build on. When sales shows up, listens and follows up well, what happens at the table keeps going after the event is over.

When marketing has that support, you get more than events. You get a community (and that’s what this group values).

So feel how you feel about GSX

Love it, hate it, dread the walk from the hotel to the convention center, I see you. Your feelings are valid. But whether it’s a show floor, a lunch table, or a room full of peers realizing they’re not the only ones, getting people together is where trust gets built in this industry. Give your marketing team the room to make those moments happen, and watch what comes out of them.

See you in the room.


It’s Fire Door Safety Week (Sept. 21-25), but safe and compliant school doors require attention every day. Schools must maintain a welcoming environment for students, staff, and families while protecting against threats that have become increasingly common in educational settings.

Door security and access control, when strategically designed and properly maintained, serve as a school’s first line of defense. Yet many facilities struggle with aging hardware, inconsistent practices, and technology gaps that compromise both security and life safety.

The Door as a School’s First Defense

A school building’s security posture begins – and often fails – at the door. Improperly functioning doors contribute to unauthorized access, propping, and security breaches. Common challenges include:

  • Doors and frames that are not level, square, true, and plumb, resulting in incomplete closing and latching.
  • Worn, missing, or disengaged door closers.
  • Damaged or weak frames and reinforcements.
  • A mismatch between intended use and installed hardware.
  • Absence of access control on staff entry points.
  • Overreliance on physical keys without proper key control.

In many schools, a single broken hinge reinforcement or malfunctioning closer can mean a perpetually propped exterior door, effectively inviting unauthorized entry. Because doors represent a system of connected components, failure in any part undermines the entire system.

Assessing Door Vulnerabilities in Educational Facilities

A structured vulnerability assessment helps school leaders identify weaknesses that could escalate risk. Even a quick visual evaluation offers actionable insights.

Door and Frame Condition

Inspect for rust, damaged glass, deteriorating seals, and excessive gaps. These issues compromise both security and fire protection.

Many may be unaware that National Fire Protection Association (NFPA) 101 requires annual inspections for fire-rated and special locking arrangements. The NFPA Life Safety Code is a widely used source for strategies to protect people based on building construction, protection, and occupancy features that minimize the effects of fire and related hazards.

Hardware Integrity

Confirm that locks, hinges, exit devices, and closers function as intended. A door that does not latch is essentially unlocked.

Access Control Integrations

Where access control exists, confirm that it truly supports operational needs. For example, ask questions like: Do teachers struggle to unlock or secure classrooms quickly? Do staff entrances have card readers, and do all employees have credentials? Does the system monitor door status as well as authorized vs. unauthorized openings?

Where access control is absent, consider whether the space now requires it due to changes in operations, threat levels, or school culture.

Code Compliance

Any upgrade – whether adding an electric strike, modifying a frame, or installing a mag lock – must align with the International Building Code (IBC) and NFPA requirements. For example, modifying a fire-rated frame in the field may void its fire label.

Locking Hardware Solutions for Educational Spaces

Hardware selection directly influences lockdown effectiveness and code compliance.

Mechanical Locking Options

  • Classroom security locks allow teachers to secure the room from the inside.
  • Locks with a simple thumb turn on the interior side enhance speed during high-stress moments.
  • Panic hardware must be used on doors with occupant loads over 50, which is common in schools.

Electronic Locking Options

From conversations with K-12 customers and security professionals, a clear trend creating opportunities for dealers and consultants is the growth of electronic access control. As costs fall, more districts than ever are getting away from using keys altogether and instead deploying card access at classroom doors with electronic readers. Once considered out of reach at $10,000 per door, newer platforms make digital access more affordable and scalable. This shift underscores the role of security professionals in guiding schools toward affordable digital access solutions such as:

  • Card readers.
  • Electric strikes.
  • Mag locks with required sensors and override functions.
  • Networked lockdown systems.

These solutions must allow free egress, integrate with fire alarm systems, and avoid creating bottlenecks.

As mentioned, standards are evolving with national priorities in recent years. Notably, starting in the 2027 IBC, all classroom and exterior doors in educational facilities must be lockable from the inside without opening the door.

Practices That Sustain Security

Well-designed systems can fail without consistent operational discipline. Everyone on campus should understand the access control system and emergency procedures via staff training.

And importantly, schools should include security as a cost center in their budget planning. School leadership should implement phased security upgrades, beginning with high-impact, low-cost improvements (e.g., securing exterior doors) and expanding toward long-term technology investments.

The full version of this article appeared in the May issue of Door Security + Safety Magazine.


I came home from RAMP and SNG 2025 with a stack of ideas and no idea what to do first.

I had heard so much about Agentic AI. The difference between genuine AI, smart automation and the analytics tools everybody calls AI anyway. Pain-point campaigns. Case studies. Where end users get stuck. All of it worth writing about, all competing for the same space in my brain.

But the thing nagging at me was not on the list. It was storytelling, and how much of it we are losing to the hustle.

The part nobody puts on a slide

Storytelling is an art. That sounds obvious until you notice how much nuance and humanity are disappearing from our industry's content.

Instant gratification has been a problem in marketing for a long time, but now we have tools that can meet the demand, so the pressure has no ceiling. Everyone wants everything faster, until the people making it burn out.

I will admit something that sounds absurd outside this work. I hesitate over punctuation now. I second-guess transition words. I worry that writing too cleanly, the way the AP guidelines I learned early in my career taught me, will get my work mistaken for something a tool produced. I still type Alt+0151 out of muscle memory, and then delete it.

Industry events usually give me content ideas. RAMP made me feel like a writer again. That is such a different feeling coming out of an event.

So why did that send me looking for numbers?

It sounds like a contradiction. It definitely is not. So much security marketing feels interchangeable because most of us have no idea what good looks like in our own industry. We go looking for a benchmark and find general B2B averages built from software and e-commerce brands, then measure ourselves against companies that sell nothing like what we sell.

So you end up guessing a lot. And when you are guessing, you default to whatever is fastest to produce. That is how you get a feed full of content nobody chose to write.

I wanted our industry to have its own baselines, so we built them: our digital marketing audits of integrator websites, plus a survey of 74 PSA Security Network integrators on how marketing actually gets done.

Three numbers I did not expect

55% of integrators have no dedicated marketing team, or a team of exactly one. Meanwhile HubSpot's State of Marketing 2026 found 94% of B2B teams run multiple channels. We have been holding ourselves to a standard built for departments we do not have.

The median mobile website score is 58. Overall site health across the same audits came in at 91. Mobile is where every other channel sends people, and where we are weakest.

Posts featuring real people earn about six times the engagement of brand-voice posts. On one integrator's LinkedIn page, every top post by engagement had an identifiable person in it, averaging around 33 likes. The brand-voice posts averaged around five.

The baselines and the storytelling are the same argument

That six times the engagement stat is what RAMP reminded me to focus on, but in data form. Our clients' pages run 10% to 14% engagement by impressions against a Buffer benchmark of about 6.5%, and LinkedIn's 2025 B2B Marketing Benchmark with Ipsos found 55% of B2B marketers now partner with creators and subject matter experts. The whole market is leaving the anonymous corporate voice, because buyers stopped responding to it.

So the humanity is not the soft part of the strategy. It is the part that performs. AI moves output metrics. People move outcome metrics: trust, engagement and leads.

Baselines are not the opposite of good storytelling. They let you stop guessing about the mechanics so you can spend attention on the part that requires a human. Fix the phone experience because the data says to, then go take a real photo of a real technician and write something only you could write.

That is the version of this industry I want to work in. Slower where it counts, and honest about where we stand.

Read the 2026 Swell Security Marketing Trends Report to learn more.


After my last piece, an engineering friend texted me to point out a logic gap.

He wrote: "Fine, I root the phone. The access token is still sitting on it. I present it. The door opens. What exactly did you win?"

He was right.

I skipped the technical plumbing to make the article readable. (My mistake. Let's suffer through the plumbing).

The question "what breaks if I root the phone?" is really shorthand for a much scarier question:

Can the holder now open a door they weren't already allowed to open?

If the lock is online, it's easy. The server issues a token for this exact door, for this exact second, for one use. The lock just refuses anything it has already seen.

A lock doesn't need a clock. It needs memory and a calendar that only turns forward.ā €

But take the network away, and things get ugly.

The lock can no longer tell a fresh token from a hoarded one. A token issued this morning and a token lifted last month look identical.

So the lock must never accept a stored token on its own. Whatever carries the token has to bring something the lock can check at the door: something you know, something you have, something the lock itself prepared. There are several ways to do this. I've built one.

The IT world learned this the hard way with bearer tokens. They fixed it with "proof of possession"—binding the token to something the thief doesn't have. NIST just finished writing guidance on it.

Physical security folks hate this comparison.

When I bring it up, they tell me, "It's different! We have cameras. We have guards. A teenager in Iran can't hack a physical door."ā €

Which is a comforting bedtime story, right up until you realize that if you protect something actually valuable, people will show up to take it.

We need to learn IT's lesson now, because the "holder" of the token is no longer human.

Michael Stuer wrote in last week's issue a brilliant piece about the automated agent that manages access. It reads a work order and extends a contractor's access at 2 AM. No human in the loop.

NIST says the exact same token rules apply to AI agents, and freely admits it doesn't yet know what else agents will need.

Neither does anyone else.

Or look at the robots walking up to readers at GE facilities.

A robot is just a phone with legs. Same trust question, no human behind it.

You cannot interrogate an AI agent about why it issued a token. You cannot ask a robot if it's lost.

Soon, there is going to be a lot of intelligence in the access chain. Some of it will be wrong at 2 AM.

The lock is the one place in that chain where nothing has to think.

It has a key that never left, a memory that only moves forward, and a single rule: prove it, or the door stays shut.

Let everything else be clever.


Every after-action report I've read starts in the wrong place.

It starts with the moment someone pulled a weapon, breached a perimeter, or walked past a checkpoint they shouldn't have. That gets treated as the beginning of the story. It isn't. It's the end.

By the time an attack happens, the person behind it has already made a dozen decisions. They've watched. They've tested. They've talked to someone, or written something, or shown up somewhere they had no reason to be. Somebody usually noticed. Almost every post-incident review has that same sentence: "he'd been acting strange for weeks," "she mentioned it to a coworker," "we had a bad feeling about that guy."

The information was there. It just didn't go anywhere.

I spent close to fifteen years inside corporate security and loss prevention, watching organizations pour money into cameras, access control, and dashboards. Systems built to flag policy violations and law violations. None of that money is wasted. But none of it is built to catch a person before they've broken a rule. It catches them after.

Human behavior doesn't show up on an access log. A guy who's suddenly withdrawn, fixated, venting to a coworker about being wronged. None of that trips a sensor. The people around him notice. The system doesn't.

This is the gap I've built my practice around: the space before the crisis. Not "workplace violence prevention" in the HR tipline sense. That's downstream of the problem, triggered only once something already qualifies as a violation. What I'm talking about sits earlier. It's the culture and habits that determine whether the person who noticed something says anything at all.

Most people freeze. Not because they don't care, but because they're untrained, unsure if what they saw matters, and afraid of overreacting or being wrong about a coworker, a neighbor, a family member. Fight or flight training doesn't help here. Most people in that moment aren't going to fight, and they can't flee a relationship or a workplace. What they need is permission and a clear, simple channel to say something before it escalates.

Organizations get the next part wrong even when they build that channel. They build a tipline and call it done. A reporting system without a feedback loop trains people not to use it. If someone reports a concern and hears nothing back, ever, they learn that reporting is a dead end. You don't need to tell them what action was taken. Privacy and legal limits are real. But you need to close the loop: confirm it was received, confirm something happened. That single acknowledgment is the difference between a system people trust and one they quietly stop using.

"Call 911" isn't the backstop it used to be either. Law enforcement agencies across the country are losing more people to retirement than they're bringing in. The assumption that a fast, well-staffed response is always one call away is getting shakier every year. Organizations that haven't built any internal capability to notice and act before that call is necessary are betting everything on a system that's thinning out in real time.

This isn't about more technology. It's about paying attention to the six months before the incident instead of the six seconds during it. Train people to notice behavioral and emotional shifts, not just policy breaches. Build a reporting culture with a real feedback loop. Treat prevention as a leadership and governance condition, something the organization is responsible for building, not a staffing line item or a piece of software.

The attack is never the first event. It's the last one in a chain that was visible the whole way through, to somebody. The only question is whether your organization gave that person a reason to say something.


The most troubling aspect of the recent compromise of a Flock Safety camera is not that hackers managed to access the device. Given enough time, resources, and physical access, nearly any technology can be reverse engineered. The real concern is what the incident revealed about the expanding scale of surveillance in modern society and how little the public understands about it. 

The analysis conducted by WIRED and 404 Media exposed details of a surveillance platform deployed in thousands of communities across the United States. According to the reporting, a single camera generated approximately 1.6 million images and recorded more than 50,000 vehicles in just 21 days. That volume of data is staggering. It demonstrates that these systems are not merely taking occasional snapshots of passing traffic. They are creating a persistent, searchable record of movement at an extraordinary scale. 

Equally significant is the discovery that the software running on the device was capable of detecting people as well as vehicles, bicycles, and license plates. While there is an important distinction between identifying a person and recognizing their identity, the capability to detect and classify human beings raises legitimate questions about where the boundaries of automated surveillance should lie. Most citizens understand the concept of a license plate reader. Far fewer understand that the underlying technology may be observing much more than the plate attached to a vehicle. 

The incident also highlights a recurring lesson in cybersecurity: collecting data creates responsibility. The hackers reportedly recovered an encryption key from the device itself, allowing access to stored surveillance material despite claims that the system's data was protected through encryption. Whether this represents a design flaw or an implementation issue, it reinforces a simple reality. Data cannot be breached if it was never collected, but once it exists, organizations must assume someone will eventually attempt to obtain it. 

Supporters of automated license plate readers point to genuine public safety benefits. These systems have been used to locate stolen vehicles, assist criminal investigations, and identify vehicles connected to serious crimes. Those are legitimate uses that should not be dismissed. However, public safety and privacy are not mutually exclusive goals. The question is not whether technology should help law enforcement. The question is whether adequate safeguards exist to prevent misuse, overreach, or mission creep.

What this episode ultimately exposes is a growing trust gap. Communities are increasingly being asked to accept powerful surveillance technologies while relying largely on vendor assurances regarding security, privacy protections, and operational boundaries. When independent researchers or journalists reveal capabilities that were not widely understood, public confidence inevitably erodes. 

The Flock story should serve as a catalyst for greater transparency, stronger oversight, and more rigorous security standards. Surveillance systems may help keep communities safe, but they must also remain accountable to the public they observe. In a democratic society, trust cannot be built on secrecy. It must be earned through openness, proportionality, and demonstrable respect for privacy and civil liberties.


This is the first in a two-part series exploring what orchestration means beyond the technology itself and what it might require from our organizations and leaders. 

Physical security is becoming more connected by the month. Access control is tied more closely to identity. Video is feeding other workflows. Cloud platforms connect systems that once operated independently, while AI is beginning to interpret signals across them and help trigger action. 

A few industry data points show why orchestration is becoming more important every day: 

  • Axis found that 41% of end customers say bringing different security systems together in one unified platform is a top priority over the next one to three years.  

  • HID’s 2026 State of Security and Identity Report found that 75% of organizations have deployed or are evaluating unified identity solutions. More than half also pointed to integration complexity as a challenge for identity systems, and more than a third said the same about bringing physical and digital security together.  

SIA’s 2024 convergence research points in the same direction. Security outcomes depend on connections across systems, people and departments that cannot accomplish those outcomes in isolation. 

The security industry is designing technology around interdependence. If security is going to become better at orchestration technically, we need people who can support that orchestration organizationally. We also need to look at whether the organization around them makes that possible. 

Lee Odess has been pushing the industry to think more broadly about orchestration, including the human side of it. His recent conversations around incentives and the idea that some of our biggest challenges are human rather than technological got me thinking about how this shows up inside organizations. In my work on organizational intelligence, I spend a lot of time looking at how information moves and where it stops, where friction develops and whether the structure supports the outcome everyone says they want. 

Most organizations divide work into functions. There is good reason for that. It gives us clear ownership and allows people to build deep expertise. The challenge is that the outcomes we care about often depend on more than one function. 

A security initiative might pull in technology, risk, facilities and outside partners. One group may own the technology. Another understands the risk. Someone else owns implementation or the relationship with the end user. Decisions made in one area create consequences somewhere else. 

Each group can be doing good work and still produce a poor outcome together when the organization does not support how their work needs to come together. 

Organizational research has been studying versions of this challenge for years. A 2026 Academy of Management Annals review of ecosystem orchestration identified four broad mechanisms for coordinating interdependent participants: codified mechanisms such as processes and rules, cognitive mechanisms that create shared understanding, incentive mechanisms that align interests and hierarchical mechanisms involving authority and decision rights. 

Those categories widen the questions we can ask when collaboration breaks down. 

Consider two teams that repeatedly struggle to work together. An orchestration lens asks: 

  • Are they working from the same information and toward the same outcome?  

  • Are the functional incentives pulling them in different directions?  

  • Is ownership clear when the work moves between them?  

  • Is the right expertise entering the decision early enough to shape it?  

What looks like a communication problem may involve several of these things at once. Asking people to communicate better will not fix competing incentives, unclear decision rights or information that arrives after a decision has already been shaped. 

Research on cross-functional and management teams has also found that cooperative goals and shared outcomes can support information sharing, learning and team effectiveness, particularly when teams examine how they are working together. 

Two teams can be doing exactly what they have been asked to do and still create predictable friction when the organization has not been designed to support the way their work depends on each other. 

That is the part I think deserves more attention as orchestration becomes a bigger conversation in security. We can continue adding more connected technology, more information and more intelligence to our systems. But the value of that connection still depends on an organization’s ability to coordinate what happens around it. 

So the next question is what we do with that. In Part Two, I’ll look at where I think organizations can start: how we account for work that moves across functions, how information moves with it and the people already helping connect those pieces. 


šŸ‘€ As Seen In the Secured Community šŸ‘€

šŸ¤– AI & Technology

Joe King kicked off a conversation around drones in the enterprise after Lee’s Verkada keynote breakdown mentioned Command Center expanding to support drone integration. He’s asking the community where drones could actually provide meaningful value in enterprise environments.

Salvatore D’Agostino also shared a piece from Ed Zitron digging into the broader conversation around AI and technology. Read here.

šŸ” Identity & Privacy

Lee Odess highlighted work from Zachary Klares, Kabir Maiga, and their team around real identity-based credentials for access. Read here.

šŸ“° Industry News & Insights

Lee Odess shared an update on the recent security officer strike in California, bringing attention to the role security officers continue to play in the broader security ecosystem and the labor issues surrounding the industry.

šŸ—Æļø Interesting Topics

Rit Das kicked off a conversation around recurring revenue in electronic access control, asking how integrators are actually building RMR beyond simply passing through cloud licensing. He broke it down into cloud licensing, service and maintenance, and managed administration, and is looking for examples of what is actually working in the market.

šŸ¤ Deal Activity

Brian Karas shared the news of Knox Lane’s acquisition of SAGE Integration and opened up a bigger conversation around M&A in the integrator market, asking whether the industry is starting to run out of strong independent integrators. Read the announcement.

šŸ’” Consulting

Charles M. Johnson sparked a conversation around the different types of security assessments after being asked to provide a security assessment for a large gated community. He broke down the differences between threat, vulnerability, risk, CPTED, and technology assessments, and why understanding those distinctions matters when talking about physical security.

šŸ™ļø CPTED

Charles M. Johnson also shared details on an upcoming CONSULT session in Kansas City, where he’ll moderate a discussion on ā€œBringing CPTED into Physical Security Projectsā€ with a panel of CPTED practitioners. The conversation will focus on how environmental design, architecture, landscaping, and site circulation can be incorporated into physical security projects before technology is even applied. Learn more about CONSULT.

šŸ“£ Shameless Plugs

Tony Dong shared his latest piece on unit economics and ā€œenshittification.ā€ Read here.

šŸ’¼ Jobs & Opportunities

Kevin Baldwin shared an opening with Wavestore for a Rust Developer on its development team in Ottawa. View the job.

šŸ”Ž Research

Mark Freedman shared a new guide from Liferaft on managing political violence and instability, designed for security, intelligence, and GSOC teams. Read the guide.


We are officially less than 2 weeks away from ACS26. The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security.

Registration is still open! Sign up here.

Speaking at the event?
Go here.

On the fence? View some testimonials from previous years
here.


šŸ—£ļø Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.

Community input form!


PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here: https://www.tacc.me/secured Thank you!

Volume 7
šŸŽ™ Secured Podcast Episode 32 | Coming to you Monday, September 21 recorded live at VerkadaOne 🫣 Premium member-only content YourSix AMA with Jacob Hengel What happens when you take the lessons from the VoIP/PBX disruption of the 2000s and apply them to physical security? In this AMA, Jacob Hengel of YourSix gets into the shift toward a more unified security category, direct-to-cloud architectur...
Volume 6
šŸŽ™ Secured Podcast Episode 31 | The Water Treatment Hack That Should Scare YouWhat happens when ALPR becomes a policy issue, end users start writing the rules, and a cyberattack can put an entire water supply at risk? Lee gets into it on this week’s Secured.Listen here. 🫣 Premium member-only content The Acre AMA: You Asked, Kumar AnsweredWhat happens when you put the CEO of Acre Security in fron...
Volume 5
šŸŽ™ Secured Podcast Episode 30 | Could Cheaper, More Open Access Control Hardware Help Make Schools Safer?dormakaba is showing what three years of transformation looks like, Acre is turning its roadmap into something partners can actually sell, and the lines between physical security, AI, and cybersecurity keep getting blurrier. Plus, Lee has a question about access control that might make some p...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.