Header Logo
Log In
← Back to all posts

Volume 41

Aug 03, 2026

Volume 41 | December 12, 2025

This Week’s Featured Articles & Media

Ivan Kravchenko | Why Identity Design Belongs in Your Physical Access Control Roadmap
Identity design is now a core requirement in Physical Access Control because IT, compliance and security teams all depend on clean, unified identity data. Ivan breaks down real-world failures and the design principles PACS platforms need to avoid duplication, authentication gaps and costly project delays.

Charles McGilvary Johnson | “Negligent Security”
Negligent security isn’t just a legal term—it’s a rapidly growing source of lawsuits tying everyday security decisions to multimillion-dollar verdicts. In the first edition of his new series, Charles breaks down what negligent security is, why it matters, and how the industry can be proactive.

Jerry Burhans | 2026 Advice to the Security Manufacturers
The security industry isn’t asking for flashier products—it’s asking for solutions that work. As locksmiths evolve into hybrid, physical–cyber professionals and electronic access surges, Jerry explores how manufacturers can align with real customer needs instead of chasing the next shiny object.

Don Morron | To Agent or Not To Agent?
AI Agents are becoming the digital workers powering everything around us, and opting out isn’t an option. Don explains what AI Agents are, why knowledge workers are most exposed, and why now is the time to experiment, adapt and lean in.

Austan Palmer Preuett | The Weight We Carry Behind The Badge
The One Big Beautiful Bill Act recently passed by the U.S. Congress didn’t just change healthcare policy—it changed the human dynamics inside hospitals. Austan explores how security officers have become both enforcers and empathizers, and why hospitals must include emotional-intelligence-driven training in their security strategies.

January 12-14, 2026 | Access Control Theatre at Intersec Dubai
The Access Control Executive Brief will host The Access Control Theatre at Intersec in Dubai. Featuring thought-provoking sessions by some of the industry's leading thinkers, this program will cover a wide range of topics related to access control and the smart lock industry, and is open to anyone interested in these fields. Register to attend.

The Access Control Collective | PhySecJobs.com
Visit PhySecJobs.com to see the latest jobs in the physical security industry.

Find them all below!


Across conversations in the U.S. and EU, physical security discussions usually start with panels, readers, OSDP migration, and IP enablement. In parallel, IT and compliance teams are asking a different set of questions: 

  • How do we onboard and offboard people automatically? 

  • Can we enforce Single Sign-On and Multifactor Authentication consistently?

  • Who owns and manages identity records inside the PACS environment?

  • Can the PACS take identity data from our Active Directory or identity provider? 

When identity design is not part of the Physical Access Control System (PACS) roadmap, these questions do not disappear. They surface later as project delays, custom scripting by integrators, increased support demand for manufacturers, and difficult audit conversations with customers.

Where Integration Really Fails: Recurring Patterns From the Field

Case 1: Duplicate cardholders after an employee transition

A multi-site enterprise deployment highlighted the problem clearly: 

  • An employee transfers to another campus. 

  • HR updates the person’s organizational attributes. 

  • Azure Entra ID updates group memberships accordingly. 

  • The PACS imports the record. 

  • Because there is no unique identity key linking Active Directory and the PACS, the  system interprets the update as a new person and creates a second cardholder.

This produces two records for the same individual, often with conflicting access rights. During an incident review, the audit trail becomes fragmented and unreliable. 

  • For manufacturers: the platform appears rigid and outdated. 

  • For integrators: every deployment requires custom logic to reconcile identities.

  • For end users: access becomes inconsistent and accountability weakens.

Case 2: “Single Sign-On” that fails IT security expectations

In a critical infrastructure project: 

  • The IT organisation mandates Single Sign-On with Multifactor Authentication across all systems. 

  • The PACS advertises “Single Sign-On,” but in practice only supports LDAP Bind  Authentication. 

  • The customer’s IT specialist attempts to integrate the PACS with Azure Entra ID and  quickly discovers that the necessary configurations do not exist because the PACS  does not support SAML or OpenID Connect.

IT security rejects the rollout. The PACS functions well at the physical layer but cannot align with the organisation’s authentication policies.

The result: a solution that meets physical security requirements but fails identity and compliance expectations. 

Identity as the Control Plane: Design Principles that Make PACS Dependable 

Treating identity as the federating layer for both IT and OT changes how access control platforms are designed and evaluated. Three principles anchor this shift. 

  1. Treat cardholders and PACS system users as one identity population Cardholders are not a separate class of people.

    They are employees, contractors, or partners who may also require administrative or operational privileges in the PACS. Treating them as distinct entities leads to duplicate records and inconsistent  authentication experiences. A unified identity model improves lifecycle management and aligns PACS architecture with enterprise identity expectations. 

  2. Design your platform to manage external identities, not just internal onesSystems that only manage identities created inside their own user interface cannot support enterprise environments.

    PACS platforms must accept authoritative identities from Active Directory, Azure Entra ID, Okta, or HR systems. This requires:

    • external unique identity key support;
    • attribute mapping;
    • lifecycle-driven updates; and
    • clear data ownership.

    This reduces manual data entry, prevents identity drift, and supports clean auditing.

  3. Adopt modern identity protocols such as SAML and OpenID Connect (OIDC) LDAP Bind and Kerberos-based login are no longer sufficient for secure authentication.

    Manufacturers should adopt SAML and OIDC as primary authentication methods. Offering direct connectors for Azure Entra ID, Okta, or Ping enables immediate alignment with IT security policies. Most enterprise and critical‑infrastructure customers will adopt these integrations quickly, as they simplify compliance and operational governance.

Where to Explore Further

This short breakdown illustrates why identity design must be part of every PACS roadmap.

For manufacturers and platform owners preparing next‑generation solutions, the extended article, “The Future of Physical Security Software: Building Open, Identity-Centric Platforms,” expands on these ideas with additional patterns, architectural guidance and case examples. It is particularly relevant for organisations planning multi‑year platform strategies and modernisation programmes. Read the extended article on the CoreWillSoft website.


My hope is that after reading this, you—and your colleagues, companies and our industry—will walk away with a renewed understanding that the decisions we make every day have real consequences. The impact of our work isn’t limited to a poorly wired building, a propped-open door, a failed camera feed, or a PACS running a 12-year-old, end-of-life software version. It’s bigger than that.

I’m talking about “negligent security.” And it’s time our industry understands what it is, why it matters, and how we can do better.

If you’ve never heard of this term, you are not alone. Most people I’ve spoken with—colleagues, friends, and industry contacts—have never heard of it, even though it’s shaping major legal outcomes across the country. This article is the start of a series where I’ll break down recent court filings, settlements, and cases that make it clear how closely security decisions and legal liability are now connected.

In personal injury law, “negligent security” refers to a type of premises liability claim where a property owner, property manager or home owner’s association (HOA) is sued for failing to provide reasonable security measures, resulting in someone being injured or harmed by a criminal act that could have been prevented.

Here’s a breakdown:

  • Legal Basis: Property owners have a duty of care to maintain a safe environment for lawful visitors. This includes taking reasonable steps to prevent foreseeable crimes.

  • Typical Defendants: Businesses such as apartment complexes, condominiums, hotels, shopping centers, nightclubs, parking garages, sports arenas, music concerts/festivals, and other public-access properties.

  • Typical Plaintiffs: Victims of assaults, robberies, sexual assaults, or shootings that occurred on someone else’s property. These can include employees, tenants, customers or visitors to the property.

  • Core Allegation: The injury would not have occurred if the property had adequate lighting, working locks, cameras, trained security personnel, or properly maintained access controls. This includes whether technology was installed correctly, whether software and firmware were updated, and whether broken systems were fixed or upgraded.

  • Goal of the Lawsuit: To recover damages for physical injuries, emotional trauma, and financial losses caused by the crime and by the property owner’s failure to provide proper security.

In short, negligent security cases attempt to hold property owners legally accountable for crimes that happen because they ignored known risks or failed to take reasonable precautions to protect employees, tenants, customers or visitors. On the other hand, some may argue that the property owners did all they could to protect their property and the people who work, visit or live there. Ultimately, it is up to a jury to determine who is responsible for the injury or death that resulted from the incident.

It’s important for the security industry to realize that whether you are directly involved with an end user client (such as an architect, engineer, consultant, security integrator, etc.) or you are somewhat removed from that relationship (as a technology manufacturer, software developer, distributor, etc.), we should all feel some responsibility to guide, educate and advise our clients on the proper industry standards for designing, engineeringing, procuring, installing and maintaining our systems.

Yes, we all have limitations-of-liability clauses in our contracts and agreements. But the question is whether our industry fully understands the scale of what’s happening in civil courts and the attention now being placed on our work, our decisions, and the technology we deploy.

According to my research, more than 100 law firms within the state of Florida advertise on their website that they offer negligent security services to their clients. Keep in mind, most law firms have multiple attorneys on staff, so the number of lawyers offering these services is likely two to three times the number of law firms.

One Florida-based law firm, who will not be named, advertises on their website: “We have litigated nearly 500 cases involving severe injury or death due to inadequate security, recovering nearly one billion dollars in verdicts and settlements for our clients since 2007.”

Additionally, in a recent negligent security case in Florida, the jury found the property management company, HOA, security guard company and tenant liable and negligent for the death of a young man in 2021. The jury awarded $100 million in damages, assigning the following percentage to each defendant:

  • 57% to the property management company;

  • 18% to the HOA;

  • 18% to the security guard company; and

  • 7% to the tenant (girlfriend of deceased)

Moving forward, I will be interviewing those directly involved or potentially affected by negligent security cases, such as industry leaders, C-Suite executives, attorneys, insurance companies, technology manufacturers, integrators, and architects, engineers and consultants.

If you would like to be included in this series, please reach out to me at cjohnson@ngasa.us or on the The PhySec Collective Slack channel.


Manufacturers love to launch “the next big thing.” But, too often, these new products land on our desks without a clear need behind them. My past research found that the integrator and locksmith markets aren’t clamoring for the latest new widget. They want solutions that save time, improve security outcomes and deliver real value to customers. It’s not about brand names, either. It’s about fit, function and reliability.

I’ve found that locksmiths consistently choose products based on what works best, not who makes it. I’ve been told, “people call me because I’m the expert. I find what fits their need.”

This mindset is what makes the security channel so powerful. We aren’t just selling; we’re solving. And in a profession built on trust and performance, that problem-solving instinct is what earns us lifelong customers.

Several recent statistics highlight this seismic shift. According to a recent IBISWorld global research study, 81 percent of locksmiths now say electronic access control significantly impacts their product portfolio, and nearly half plan to expand those offerings in the coming year. Over 60 percent already install IoT-enabled lock systems that connect to apps and cloud platforms, while 45 percent report rising demand for multi-factor authentication, using PIN codes, mobile credentials or biometrics.

Just as telling, 65 percent of locksmiths now provide cybersecurity services such as software updates, firmware management and encrypted communication for smart locks. The days of focusing solely on keys and cylinders are giving way to a hybrid skillset that blends IT expertise with physical security. The result? A new generation of locksmiths fluent in both the mechanical and the digital languages of protection.

The market data underscores why this evolution matters. The U.S. locksmith sector now encompasses more than 29,000 businesses, with nonresidential security system installation (alarms, access control, and surveillance) accounting for the largest share of industry revenue.


The short answer: You don’t have a choice.

Even if you aren’t working, you’ll use AI Agents. If you are working, you won’t keep your job without depending on them. Simple as that.

So what are AI Agents anyway? Think of them as intelligent software systems, digital workers that operate on your behalf. Sometimes you ask them to do something. Sometimes they act on their own based on rules, goals, or context. Their levels of autonomy, often described as their “agency,” determine how much work they take off your plate.

Depending on your job, this is either a slow wake-up call or a blaring alarm clock.

If you work purely in the digital realm and your job is repeatable, and therefore predictable, your job is at risk. AI Agents excel at anything structured, pattern based or rules driven. On the opposite end, if you work with your hands, have a specialized trade or operate in the physical world, you’re generally safe for now. Why? Because what these digital workers find easy, we still struggle with. And what we find easy, they struggle with. Need a complex math equation solved? You don’t stand a chance. Need someone to load a dishwasher properly? You’re the undisputed champion.

Everything in your day-to-day life is changing because of them: shopping, travel, customer service, healthcare, entertainment… all of it. How much you choose to lean into AI Agents is up to you, but the world you live in will be running on them regardless.

Now, about this thing called the technology adoption curve.

Historically, new tech starts with innovators and trickles out to everyone else over time. What makes today different is speed. Knowledge is becoming democratized faster than any other era. Jobs centered on information, creativity, analysis and decision making are being reshaped in real time. This is why knowledge workers are losing their advantage much faster than farmers did when tractors first rolled in.

If you work in the trades and think this whole “AI Agents” wave is hype, then, cool, this article isn’t for you… yet. But everyone else? You don’t get to opt out.

So what are the next steps for knowledge workers? Slide yourself into the “innovator” or at least “early adopter” segment of the adoption curve. Start experimenting. Start learning how AI Agents actually work. If you’re a business leader, stick to what should always be your philosophy: problem solving first, applied technology second.

And if you’re a business leader who doesn’t know where to start…I know a guy.


When Congress passed the One Big Beautiful Bill Act (OBBBA) in 2025, the headlines focused on taxes, Medicaid reform and cost savings. But while legislators debated policy, those of us working inside hospitals saw the ripple forming long before the ink dried.

For healthcare security professionals, this legislation doesn’t just change budgets; it changes human behavior. It alters how patients, visitors and staff interact. It shifts the emotional temperature of the environment. And it puts officers in the position of enforcing policies that, while necessary, can feel deeply personal to those affected.

The Unseen Fallout: Tension at the Door

Under the OBBBA, hospitals, especially safety-net and public facilities, are expected to absorb more uninsured or underinsured patients. The Congressional Budget Office estimates nearly 9 million more Americans could lose coverage by 2034.

That translates to higher volumes of uncompensated care and longer wait times, as well as stricter enforcement of hospital policies meant to manage the strain.

For security teams, that means being the face of those policies.

When a visitor is denied entry after hours, when a patient is asked to move to another ward, or when ID checks are tightened to comply with new procedures, it’s often the security officer delivering that message. And increasingly, that interaction comes with frustration, confusion or outright anger.

It’s not just about protecting property anymore. It’s about de-escalating emotion in real time.

Policy Enforcement = Emotional Impact

Every hospital policy—from visitor limits to access restrictions to discharge timelines—has an operational reason behind it. But to someone who’s scared, grieving or exhausted, those policies can feel cold or unfair.

Security officers are now in the unique position of being both enforcers and empathizers.

The challenge? Balancing professionalism with compassion when you’re enforcing a rule that someone perceives as unjust.

Without proper training and leadership support, this tension can quickly spiral into hostility, turning waiting rooms into flashpoints and routine patrols into confrontations.

The Bureau of Labor Statistics reports that nearly 75 percent of all workplace assaults occur in healthcare environments. As shocking as this number is, the actual percentage is believed to be significantly higher due to underreporting.

With new hospital legislation, that number could climb unless our frontline teams are ready.

How 360 Security Group Is Preparing Teams

At 360 Security Group, we train our officers to see the story behind the situation.

Our healthcare security programs combine Crisis Intervention Training (CIT), de-escalation tactics and empathy-based communication—because enforcing a policy shouldn’t come at the expense of human dignity.

“More than guards. A full force security partner.”

Here’s how we help hospitals and their teams navigate this shifting environment:

  1. Policy Enforcement with Emotional Intelligence
    We teach officers to communicate the “why” behind the rule, not just the “what”. A calm explanation paired with active listening often diffuses frustration before it escalates.

  2. Role-Play for Real-World Scenarios

    From visitor restrictions to behavioral health interventions, our training uses scenario-based learning that mirrors real hospital challenges, helping officers practice their response under pressure.

  3. Unified Command Communication
    Security shouldn’t stand alone. We work with nursing and administrative leaders to ensure policies are communicated consistently across all departments. That alignment builds trust internally and externally.

  4. Post-Incident Review and Learning Loops
    Every conflict is an opportunity to improve. We encourage hospitals to review high-stress encounters and adjust procedures to support both staff safety and patient experience.

Why This Matters

When legislation reshapes healthcare, it also reshapes the emotional landscape inside facilities. Security officers are no longer just the eyes and ears of safety; they are the voice of empathy, the first point of contact in an environment that’s becoming increasingly strained.

Ignoring that reality risks burnout, turnover and preventable violence. Acknowledging it and investing in training, communication and proactive support ensures that even in the most difficult moments, care and compassion stay at the center of security.



 

 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.