Header Logo
Log In
← Back to all posts

Volume 42

Aug 03, 2026

Volume 42 | December 19, 2025

This Week’s Featured Articles & Media

 
 

Jeff Nigriny | The Digital Identity Crisis Behind Agentic AI
Without new guardrails and accountability models, the security industry risks deploying autonomous systems faster than it can secure, govern or legally defend them. CertiPath CEO Jeff Nigriny makes the case that as Agentic AI accelerates, identity is becoming the weakest link.

Salvatore (Sal) D'Agostino | Why Self-Signed Certificates Put Organizations at Risk
As AI and regulatory scrutiny increase, proper certificate management and PKI aren’t “nice to have.” They’re now foundational to security, compliance and trust. IDmachines CEO Sal D'Agostino argues that self-signed certificates remain a quiet but systemic risk across IP-based physical security systems.

Lee Odess | My SIC Takeaways: A Story about a Segment of the Industry That’s Moved On
After attending the Security Investors Conference (SIC) in New York City, Lee reflects on what the conversations really revealed: software, platforms, APIs, and data are now setting the pace, while AI, biometrics, and hardware are being judged on real outcomes. The takeaway from SIC is clear—the industry has moved beyond incremental change, and the shift toward software-led scale is accelerating fast.

Entry & Exit | Security Is Becoming an Enterprise Software Business
Lee joined Alarm Masters’ Collin Trimble and Stephen Olmon on a new episode of the Entry & Exit podcast this week. They dig into the convergence of security and enterprise technology, how the industry evolved to this point, and what that means for integrators today. Watch the full episode on YouTube.

Breaking News | dormakaba to Acquire Avant-Garde Systems
This week, dormakaba signed an agreement to acquire Avant-Garde Systems, one of the largest independent entrance systems control solution providers in the U.S. Read Lee’s take on why it matters on LinkedIn.

Breaking News | Brivo Launches Brivo Genius Mobile Agent
Lee got a first glimpse into the latest feature inside Brivo’s Access Mobile App: the industry’s first voice-activated, agentic mobile lockdown. For more on how it works, read Lee’s breakdown on LinkedIn.

January 12-14, 2026 | Access Control Theatre at Intersec Dubai
The Access Control Executive Brief will host The Access Control Theatre at Intersec in Dubai. Featuring thought-provoking sessions by some of the industry's leading thinkers, this program will cover a wide range of topics related to access control and the smart lock industry, and is open to anyone interested in these fields. Register to attend.

The Access Control Collective | PhySecJobs.com
Visit PhySecJobs.com to see the latest jobs in the physical security industry.

Find them all below!

 


I have my own version of a December to Remember. It involves sitting at my desk the last couple weeks of the year and refusing to travel anymore. I reflect on what I’ve learned during the year and how I might apply it to the new year. Last December I carried non-person entity (NPE) identity (a.k.a. machine identity) forward.

Many applications do not support centralized NPE identity management; think about the digital identity that services run as, or how API key security is implemented. In truth, many identity management products do not support unique/dedicated NPE identities. There are only a handful of credentialing management systems (CMSs) that support NPE credentialing as well. We spent two decades learning how to centralize identity and get away from passwords, except we didn’t.

This year had a twist, though. If you think back to January and February, generative AI had already reached its pinnacle of hype. It was Agentic AI that was becoming the Talk of Tech. And I began to panic. We simply are not ready for Agentic AI from an identity perspective. We are not done with person identity, we are nowhere close on NPE, and Agentic Identity is rocket fuel on a NPE-compromised identity fire.

What makes this particularly problematic is that the Agentic AI genie is already out of the bottle with the public. It’s a capability everyone believes they want and need. Surging demand kills all calls for more security. I cannot think of a technological historical precedent that featured quite this cocktail. We have an extreme level of demand for a capability with little to no security maturity. That is coupled with the fact that all of Agentic AI identity predecessors are themselves unfinished identity models and implementations.

At the foundation, digital identity is a minimization function of (1) proofing, (2) a credential/token, and (3) the binding between token and presenter. This function applies equally for a person and a NPE. What may be news is there are presently 20 to 100 times more NPE identities on the internet than person identities. And that difference is increasing. Of the vastly larger NPE identity count, the percentage that Agentic AI comprises has increased in just the time it took for me to write this article.

The reason to really look at this is we have never had a technology that could operate on its own and make its own decisions. Society requires that we hold people accountable for the decisions they make. To do that, we must be able to uniquely identify someone and then, to a legal standard, attribute actions they took. Agentic AI can take actions. It can take actions that were intended by someone or—perhaps more startling—that no one intended. We are already living in a world where Agentic AI is operating beyond our ability to directly control all outcomes because it can take actions we did not intend. See the Replit case as an example.

We currently have no way to identify an agent uniquely. There are no biometrics to fall back on. We are going so fast that the societal implications aren’t even being publicly pondered, yet alone worked. The following is a comparison in which I highlighted overlapping or contiguous terms to further make the point in a legal context.

Words comprising the core of society as defined by Merriam Webster:

  • Consciousness â€“ Awareness/perception of surroundings. Is required for thought, self-awareness, and intentional action.

  • Conscious decision making â€“ Evaluating options, predicting outcomes, and selecting a course of action with awareness and reflection.

  • Intent – to act with purpose.

Now consider these new terms defined by the legal profession’s LexisNexis:

  • Agentic AI â€“ Designed to act autonomously, making decisions and performing tasks based on its environment and goals.

  • Autonomy – Execute tasks without human input.

I want to applaud CoreWillSoft’s Ivan Kravchenko for his article in The Security Breakdown last week. It inspired me to share this identity problem with a group that “gets it.”

I’ve been working on a new identity model for Agentic AI that I’ll share early in 2026. I’m also working on a longer form version of this article. For any OEMs, you will need to very carefully consider how you incorporate AI agents into your products and what guardrails you can put around them. Similarly, this goes double for the forward-leaning integrators. You will be relying on software for which you likely have little legal recourse if your customers or even third parties suffer damage. Your legal counsel will be critical for navigating this brave new world and transitionary period.


The physical security world has come a long way to understanding the need to use cryptographically sound techniques in systems and services over the last 20 years. Examples include: abandoning Wiegand interfaces to doors; adopting OSDP; providing hardening guides; and making it a requirement to change devices for password resets. Yet today, a critical vulnerability persists in physical security systems: the widespread use of self-signed digital certificates.

The explosive growth of IP security systems, led by surveillance cameras, has outpaced organizations' ability to properly manage digital keys and certificates. The result is widespread deployment of devices using authentication methods that fall short of current security standards and regulatory requirements.

Understanding the Self-Signed Certificate Problem

Self-signed certificates lack independent third-party validation from trusted Certificate Authorities (CAs). This creates an inherent trust problem: there is no external verification of device identity, and no way to differentiate between legitimate devices and imposters. They are vulnerable to man-in-the-middle attacks, and organizations have no practical way to determine certificate validity or manage device authentication privileges with granularity. When a device is compromised or decommissioned, there is seldom a mechanism to invalidate its certificates systematically.

Key Management Failures

Perhaps most concerning is the practice of using identical self-signed certificates across multiple devices or entire product lines. It is possible to deploy cameras where the same certificate and private key are used in multiple devices—analogous to using the same username and password across an entire organization.

IoT devices have implemented poor random number generation or use deprecated cryptographic algorithms. Weak cipher suites such as MD5 and SHA-1 continue to appear in deployed systems. Self-signed certificates often remain valid indefinitely without rotation, creating persistent attack vectors. Then there is the looming issue of post-quantum cryptography, few if any physical security device uses these algorithms and associated certificates.

Real-World Vulnerabilities

The 2016 Mirai botnet attack leveraged weaknesses in IP cameras. As with any digital and software/firmware systems, documented vulnerabilities span manufacturers. The problem extends from surveillance cameras to smart door locks, network video recorders, and industrial control systems. Electronic locks have been compromised through MITM attacks that captured unlock codes. SCADA systems with self-signed certificates have been exploited, with operators unknowingly connecting to malicious interfaces.

Regulatory and Standards Frameworks

ISO, NIST, GDPR, PCI DSS, HIPAA, and the CA Browser Forum all provide guidance that effectively precludes or severely restricts the use of self-signed certificates in production environments. This is particularly true for Security as a Service, which crosses networks and national boundaries.

A critical issue is their generic nature—self-signed certificates lack the specificity required in today's advanced analytics environment. Modern surveillance cameras vary, some do basic video capture, others employ facial recognition, behavior analysis, crowd counting, license plate reading, and real-time classification. Self-signed certificates provide no mechanism to differentiate these capabilities or encode specific analytics functions. This creates compliance challenges, as these certificates don’t reflect processing purpose, data classification levels, or privacy controls required for different analytics capabilities.

Regulations governing video surveillance and biometric analytics vary dramatically by location. What is permissible in one jurisdiction may be prohibited in another. EU requirements under GDPR can differ substantially from U.S. state privacy and AI laws, which vary from California to Illinois to Connecticut. The lack of location-specific information and processing purpose details in self-signed certificates makes demonstrating compliance nearly impossible. Properly issued certificates should contain accurate location data, processing justification, analytics capabilities enabled, and metadata generation parameters—all essential for regulatory compliance and audit trails.

The CA Browser Forum passed a requirement that all SSL certificates should last no more than forty-seven days starting in 2029, reflecting movement toward shorter certificate lifespans and frequent rotation—practices incompatible with typical self-signed certificate deployments.

Moving Toward Proper Certificate Management

The solution requires implementing proper certificate management using trusted CAs, even for internal systems. This includes certificate rotation policies, proper key generation with sufficient entropy, and certificate pinning where appropriate. Organizations must move beyond the convenience of self-signed certificates toward comprehensive public key infrastructure (PKI).

The Path Forward

The combination of issues with self-signed certificates makes them a risky choice. As video analytics and machine learning capabilities expand, the need for proper certificate policies that capture device location, purpose, and processing capabilities becomes even more critical.

Organizations must recognize that deploying IP security systems without proper certificate management is not a technical detail to address later—it is a fundamental security requirement that should be incorporated from initial system design through deployment and ongoing operations. The physical security industry has the knowledge and tools to address this challenge; what remains is the commitment to implementation and the recognition that convenience cannot supersede security in systems designed to protect people and assets.

Read IDmachines’ full whitepaper on replacing self-signed certificates here.


With the end of SIC, my 2025 travel calendar comes to a close. It was great to see so many of the community in New York, and I hope everyone that is heading home safely.

Overall, another great SIC. I’ve always liked this show, or as I call it, John Mack’s BBQ. It’s consistently well attended, with strong energy throughout. There’s a unique mix of modern growth conversations layered on top of classic New York banking vibes.

The 15-minute company presentations were generally solid, but for me, the real value continues to live in the hallway conversations and 1:1 meetings. The networking still outperforms the agenda.

A huge thank you to Alper and John at Raymond James for trusting Hilary and me to do something different this year. They gave us the room to create a new format, Future of Access Control, featuring five companies with five minutes each, all using a standard framework: the market problem, how they solve it, how it’s going, and what “good” looks like in three years. The goal was simple: showcase global companies across the value chain and challenge the idea that everything in this industry is incremental. The feedback was immediate and consistent: “Love it. Do more of this.” Huge thanks to AccessGrid, igloo, Nuki, Ones Technology, and Seam for traveling far and showing up strong.

This show happens every December and it’s a must attend. As long as Alper and John will have me, I’ll keep coming back, and I strongly recommend you do the same. There’s also no better place to be than NYC in December.

I usually do a “Takeaway before takeoff” but honestly, I’m exhausted so I’m going to summarize the themes I walked away with…

Across presentations and conversations, the themes were clear. Software and SaaS now lead every growth narrative. Unification and platform thinking dominate buyer expectations. APIs and extensibility are no longer optional. Mobile wallets are powerful but messy, creating opportunity for those who can abstract complexity. Retrofit-friendly hardware is unlocking massive legacy markets. Privacy-first biometrics are winning regulated environments. AI is finally being judged on outcomes, not features. Scale matters. Data matters more. And M&A continues to favor software-rich, recurring revenue businesses.

That’s a mouthful of a paragraph but it’s what I walked away with.

SIC made one thing very clear: while plenty of yesterday still exists, the industry has moved on, and the pace is only acceleratin



 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.