Header Logo
Log In
← Back to all posts

Volume 45

Aug 03, 2026

Volume 45 | January 16, 2026

This Week’s Featured Articles & Media

Harish Natarahjan | From Ancient Curses to Intelligent Safety: How We Can Unleash Technology’s True Power
Using powerful lessons from the Mahabharata, Accenture’s Harish Natarahjan challenges the security industry’s reliance on isolated tools and incomplete workflows. He outlines a path toward zero-incident safety built on intentional orchestration, shared meaning, and open collaboration—systems that don’t just see, but act. Originally published on LinkedIn.

Lee Odess | Undervaluation
The electronic security industry doesn’t have a labor shortage—it has a misclassification problem. Responding to Mark Peterson’s paper on transforming the electronic security technician workforce, Lee explains how outdated roles, procurement language, and industry storytelling have systematically undervalued technicians, turning a workforce issue into a structural risk. Originally published on LinkedIn.

Salvatore (Sal) D'Agostino | Some Questions for Your Access Control Vendor – A Physical Security Partner Game
IDmachines’ Sal D’Agostino challenges access control buyers to move beyond marketing claims and ask harder questions about OSDP maturity, engineering practices, and standards participation. Using Extended PDID as a litmus test, he shows how vendor answers can reveal real technical depth, or the lack of it.

Lee Odess | Gallagher Security Industry Trends Report 2026
Reflecting on Gallagher’s 2026 Trends Report, Lee frames the moment as an industry inflection point where security becomes a true utility—central, strategic, and measured by business outcomes. The report doesn’t introduce a new idea, he argues; it validates a permanent change in how security is built, bought, and valued. Originally published on LinkedIn.

The following article is part of the Access Control Executive Brief, available exclusively to subscribers. Sign up here.

Tony Dong | When is it Justifiable to Invest in a Company with Negative Earnings?
In next week’s Access Control Executive Brief, ETF Portfolio Blueprint’s Tony Dong challenges the reflexive avoidance of loss-making companies, arguing that context and trajectory matter more than headline EPS. He outlines two scenarios where negative earnings can make sense—and why most investors fail to recognize the inflection point until it’s already priced in.

Find them all below!

The Access Control Collective | PhySecJobs.com
Visit PhySecJobs.com to see the latest jobs in the physical security industry.


Chapter 1: The Zero-Incident DNA

In the Mahabharata, young Abhimanyu’s tragic fate in the Chakravyuha formation offers a timeless lesson: courage and advanced tools are not enough if your knowledge is incomplete. Modern security technologies often repeat this error—excellent visibility, but fatally incomplete when decisive action is needed. In mission-critical safety, “almost” isn’t good enough. The only acceptable number of incidents is zero.

Despite a proliferation of cameras and AI, security systems frequently fail at their true purpose: not mere surveillance, but prevention and rapid resolution. Too often, our tools are reduced to expensive witnesses rather than active guardians, especially in moments of crisis. The missing link is Intentional Intelligence Orchestration—connecting the right information, at the right time, for the right action.

Chapter 2: The Knowledge Paradox—Lessons from Indian Mythology

Indian mythology warns us: powerful tools are useless without mastery and context. The Mahabharata offers three key lessons:

  1. Data without Context (Drona’s Half-Truth): Commander Drona was deceived by a half-truth—facts alone, without context, can bring disaster. In safety, meaningless data is just noise.

  2. Power without Connection (Karna’s Curse & Ashwatthama’s Weapon): Possessing a weapon means little if you can’t use or control it. Similarly, technology without integration or governance leaves us helpless in critical moments.

  3. Entry without Exit (Abhimanyu’s Trap): Knowing how to enter a system or workflow, but not how to resolve or exit, is a fatal flaw. Today’s incomplete workflows can leave us stranded during emergencies.

The takeaway: Modern safety systems often lack the contextual “liquidity” to move beyond observation toward meaningful action.

Chapter 3: Lifting the Curse

To overcome these pitfalls, we must connect our tools across four pillars:

  1. Standards: Not a cage for innovation, but the nervous system of the ecosystem. True standards enable interoperability, provide shared toolboxes for developers, and support systems that understand the language of public safety.

  2. The Semantic Layer: Turning data into meaning. By linking disparate events with knowledge graphs and ontologies, we gain actionable insights rather than isolated alerts.

  3. The 3Ps—Performance, Privacy, Price: Effective safety requires reliable systems (performance), trust through built-in privacy protections, and affordability to ensure broad access.

  4. The Neutral Zone: Establishing a managed, vendor-neutral trust zone allows secure, real-time collaboration—even between competitors—during crises.

Chapter 4: Orchestrated Safety—The Synapse Open Platform

The future demands a connected nervous system for security. Synapse is a unified, vendor-neutral orchestration layer that liberates trapped data, enabling seamless collaboration between devices, platforms, and stakeholders. Key features include:

  • Unified Edge-to-Cloud AI for flexible, context-aware intelligence.

  • Bi-directional intelligence so field devices and the cloud work in concert.

  • An open event model—a common language across vendors.

  • An ecosystem marketplace where third parties can enhance capabilities.

Chapter 5: The Reimagined Safety Reflex

When orchestration is achieved, safety systems become proactive allies—not passive witnesses. Imagine a threat detected online instantly priming all cameras for a specific risk, doors locking precisely for those who need shelter, and responders arriving with live situational maps. This is the rapid, intelligent safety reflex made possible by intentional orchestration.

Chapter 6: The Industry Covenant

Zero-Incident Safety requires industry unity. Progress has been made with universal hardware standards and protocols, but a “semantic void” remains: detection alone isn’t enough. We must standardize the meaning of data, democratize situational awareness, and break down proprietary barriers.

Conclusion: Lifting the Curse

We have the technology—now we must orchestrate it. By embracing shared standards, semantic clarity, and open collaboration, we can finally deliver on the promise of true safety: systems that don’t just see, but act—lifting the ancient curse and protecting what matters most.

Read the extended version of this article on LinkedIn.


Occasionally, I read something that articulates a common problem so clearly that I have to say, “Yes! Louder for those in the back.” Not because it’s polished or provocative, but because it gives structure and language to what we often feel but rarely express.

In essence, that's why I started writing in 2020 and continue to do so to this day.

Mark Peterson's paper From Crisis to Opportunity: Transforming the Electronic Security Technician Workforce did that for me. In my opinion, it frames the number one issue facing our industry right now, even though we often skirt it rather than naming it directly.

This paper is not really about labor. It’s about misclassification, misalignment, and neglect.

At its core, Mark Peterson’s paper argues that the United States is facing a growing shortage of skilled electronic security technicians, not because the work is disappearing, but because the industry and the systems around it have failed to recognize what the work has become. Demand is strong across federal, commercial, and residential environments. What’s broken is how these roles are defined, valued, paid, and discussed. (Reference my post on another reason: branding and storytelling).

The technician responsible for modern electronic security systems sits at the intersection of physical infrastructure, digital networks, and life safety. Yet, procurement systems, wage frameworks, and recruiting pipelines still treat this role as general labor, basic IT support, or an interchangeable trade. The result is predictable. Wages don’t match responsibility. Training programs are underfunded or nonexistent. Young talent never sees this as a viable career. Experienced talent leaves.

The paper makes a critical point, and it should be uncomfortable for many. The industry claims labor shortages. Yet it has let consumer markets flood with low-cost, insecure DIY security products. In doing so, we have pushed skilled professionals out of residential environments. We have commodified the perception of security work. We have reinforced the idea that these systems are simple, disposable, and low-value. That narrative doesn’t stay contained. It bleeds upward into commercial and federal thinking, too.

At the federal level, the consequences are more serious. Procurement language, wage determinations, and classification systems don’t account for the hybrid nature of today’s electronic security roles. Contracts are awarded under outdated assumptions. Skilled firms are squeezed out. System performance suffers. National infrastructure readiness quietly degrades. This is not a workforce inconvenience. It is a structural risk.We are stuck in old truth land.

This paper reframes the technician workforce. It is not just a staffing problem to be managed but a national asset that has been systematically undervalued. These workers install, maintain, and integrate systems that protect critical facilities, data-rich environments, and public safety operations. Treating that workforce as interchangeable labor is not just shortsighted; it is also unethical. It’s dangerous.

And no better angels are coming to change it. We need to.

The argument is clear. This cannot be solved by any one company, association, or sector acting alone. It requires coordinated leadership across government agencies, manufacturers, integrators, and trade bodies to modernize classifications, rebuild apprenticeship pathways, clean up procurement language, and restore visibility and respect to the trade. Just as importantly, it requires the industry to stop telling stories that undermine its own long-term credibility.

And again, no better angels are coming to change it. We need to.

This paper lands at an important moment. Without intervention, the talent base continues to erode, quietly increasing risk across mission-critical systems. With leadership, alignment, and willingness to name the problem, there is an opportunity to rebuild a skilled, respected, future-ready workforce. That would reflect the reality of modern electronic security.

This isn’t a warning shot. It’s a line in the sand.

Thank you, Mark, for framing this so well. Now it's time to do something about it.

 Download the PDF 

And if stories like this resonate with you and you want to engage more deeply with the community, consider joining our PhySec Collective Slack, as Mark did. It is free, growing quickly, and increasingly influential. We would value your perspective as part of it.

This article was originally published on LinkedIn.


The next time you (as an access control customer) are having a conversation with your access control providers, and you want to do a temperature check on vendor health, imagine and try this.

You want to explore where they stand in terms of supporting the OSDP standard and the extent to which they are up to date on providing OSDP capabilities in their reader or panel. Try asking them about Extended PDID.

[TLDR; a new response message that provides more/better/detailed PD/reader/IO device identification, this has been specified in the SIA OSDP Technical Subcommittee, is going to be part of the OSDP 2.3 release at the end of Q1 and is already being coded in open-source tools. PDID is a critical command that is a response from a Peripheral Device (PD, typically a reader but could also be I/O module, keypad, or even a thermostat) that provides the device information about the vendor, model, serial number and firmware version, and allows a system to provide the current state of devices in a standards-based method.]

Then pay attention and be able to parse the answer. Do not simply accept “on the roadmap, beta under evaluation with selected customers”. Instead consider the response and ask yourself and follow up with these questions:

  • Did they (and this can include system integrators as well) say “huh?” Can you confirm this vendor really does OSDP, or do they simple know how to spell it? Do they know it is an international standard, and that it was published by ISO/IEC as 60839-11-5 (ok so they don’t need to know that off the top of their head). Is the product OSDP Verified™?

  • Do they follow standards processes? This is one of many (you can ask what other standards they follow, e.g. Transport Layer Security (TLS), NIST cryptographic standards, Message Queuing Telemetry Transport (MQTT), Simple Network Monitoring Protocol (SNMP), and syslog) if you want to further follow this path. Are they aware of SIA, and are they participating in the OSDP Technical Subcommittee?

  • Ask about what kind of activity is underway in their engineering organization? Is there ongoing development activity? Do they have bug reporting and tickets? How do errors are corrected, are there different paths depending on severity. How are vulnerabilities exposed, and fixes provided?

  • How do features get added. Is there an update process? Who handles this, what is the procedure?

  • Do they have an upgrade story? Can the solution handle firmware changes at scale, in an acceptable manner? (In general and specifically for OSDP, in which case are they using osdp_FILETRANSFER)

  • Do they have a mechanism to socialize enhancements with customers? Do they have an evaluation program, a beta test program, an early adopter’s scheme? What is the method to interact with their customers to get feedback to ensure updates? Will fit in to a customer’s environment without disruption?

These sorts of questions can be asked about many technologies in use today in physical security. Looking at who can, and how the vendor answers these questions can provide insight into technical maturity of their organization. It provides a measure of their level of engineering expertise. It allows you to interact directly, and to exert some independence and control over your supply chain and vendor community. You can identify how comfortable they are working in a diverse vendor ecosystem. Keeping track of the health of your vendors can be a valuable addition to your access control strategy.

While OSDP is not a new protocol (it’s been around since the mid-2000’s) it is also not a dead protocol. There are active discussions within the Security Industry Association’s OSDP Technical Committee. Enhancements, clarifications, and corrections are under discussion. New features are being proposed, several of which have reached the point where there is consensus. The enhanced identification reporting mechanism is one example. The current standard has a PD identification message that was designed in an earlier time when readers and firmware were less complex, your supply chain should be enthusiastic about supporting improvements to the protocol, but to do this they should be active in the technical community. This (now accepted) proposal will benefit OSDP consumers by delivering more fine-grained information about a reader’s firmware and other details.

Participation in the OSDP Technical Sub-Committee is open to all, there is an information sharing site (Basecamp), where all of the active discussions are taking place and where anyone is free to provide feedback. Besides enhanced PDID there are updates to the Personal Identity Verification (PIV) support, auto-discovery and device configuration and other improvements that will improve system performance, security, and operational capabilities.

If you are not active and want to get involved reach out to Cameron (Cam) Walker-Miller, SIA’s Director of Standards and Technology at cmiller@securityindustry.org.


Industry reports predict what’s next each year. Most describe current trends (and are terrible at it btw), but few explain why they matter if you’re building, buying, or investing in the industry.

The Gallagher Security Industry Trends Report 2026 stands out. I read it every year. It doesn’t present radically new ideas, but instead validates what many of us already sense.

Security has crossed a threshold.

This transition marks a shift: security is no longer positioned at the edges of organizations. It is increasingly recognized as vital infrastructure at the very center of business operations. It is a utility+.

The report’s findings match what I’ve written, said, and observed among manufacturers, integrators, investors, and end users. This is convergence, not coincidence. Comparing the 2026 report to previous years shows a clear storyline.

For years, Gallagher’s reporting has been less about chasing headlines and more about documenting progression. Earlier reports focused heavily on stabilization and modernization. The industry was upgrading aging systems and strengthening foundations. At the same time, it was grappling with emerging concepts such as cloud, mobile, and integration.

The tone reflected an industry catching up to broader digital transformation, still largely measured by how well security systems performed their traditional job.

As those years progressed, the narrative began to shift. Integration stopped being a “nice to have” and became a meaningful source of value. Data was no longer just something security systems produced; it became something organizations were curious about using.

Gallagher’s reports began highlighting the growing complexity of decision-making and the expansion of stakeholders beyond the security sector. They also noted the increasing importance of support, training, and partnership. You could feel the industry stretching, even if it wasn’t quite ready to redefine itself yet.

With the 2026 report, this redefinition becomes unmistakable, ushering in the next phase for the industry.

The report now asks how security can improve the business, not just itself. ROI is a shared language between security teams and executives. Security is seen as an investment that delivers measurable business outcomes: efficiency, resilience, and clarity. This is a fundamental shift.

This is most evident in how integration is treated. In earlier reports, integration was something organizations aspired to. In 2026, it’s the leading factor in system decisions. That change reflects a deeper truth. Value is no longer created by adding features to isolated systems. It’s created by reducing complexity across the organization.

Integration is no longer about making products talk to each other. It’s about making security usable, understandable, and relevant to IT, operations, facilities, and leadership.

The same evolution shows up in the treatment of data. Past reports acknowledged that security systems generate a lot of it. The 2026 report focuses on how that data becomes a shared language across departments.

Access events, system usage, and operational signals are increasingly tied to space utilization, business continuity, and performance planning. At that point, security stops looking like a department and becomes infrastructure.

Gallagher’s focus on data centers and AI in the 2026 report also fits cleanly into this longer arc. Earlier reports positioned digital transformation as an external force shaping demand.

Now we’re seeing the consequences.

As AI and digital infrastructure become core to economic growth, physical security moves up the priority stack. Protecting these environments isn’t just about preventing loss. It’s about ensuring uptime, trust, and continuity in systems businesses can’t afford to lose. In that world, security can’t remain tactical. It has to be strategic.

What I appreciate most is that the report doesn’t sugarcoat the reality. Budgets are under pressure, while at the same time, talent shortages persist. Decision-making is slower and more complex.

But these challenges aren’t framed as reasons to stall. They’re framed as proof that the industry has to mature. Organizations now need partners who can help them articulate value, guide tradeoffs, and connect security decisions to broader business outcomes.

Pulling together the themes from multiple years of Gallagher reporting reveals a pattern: initial years focused on fixing broken elements, followed by an era of connecting fragmented parts. Now, the industry is tasked with articulating business value. This marks a clear inflection point rather than a passing trend.

The 2026 report doesn’t start a revolution. It confirms it. Security has shifted from the edge to the core, permanently changing the entire conversation.

There’s no going back to the old language. Long live the new truths!

And I am so here for it. 

This article was originally published on  LinkedIn.


When is it Justifiable to Invest in a Company with Negative Earnings?

I’ve been on the road more than usual this month, which meant a lot of time listening to audiobooks. One of them was One Up on Wall Street by Peter Lynch.

There’s a section where Lynch lays out his own informal taxonomy of equity investments. Slow growers, fast growers, stalwarts, cyclicals, asset plays, turnarounds. It’s not meant to be rigid, but it’s a useful way to impose some structure on an otherwise messy universe of stocks.

Reading that in the context of today’s capital markets got me thinking. The 21st century has produced an entire class of public companies that doesn’t fit neatly into Lynch’s original buckets. I’ll give them a name though: shitcos.

A shitco usually has a micro or small market cap, a vague or overhyped product, promotional management, persistent dilution, heavy stock-based compensation, and a habit of mashing thew dilution button whenever cash runs low. The unifying feature is persistent negative earnings.

That last point matters. Negative earnings are a necessary but not sufficient condition for shitco status. In other words, not every company with losses is a shitco, but every shitco loses money.

The distinction is important because there’s an asymmetry here that trips up a lot of investors. Some companies with negative earnings end up being terrible investments for years and then disappear into chapter 11 bankruptcy. A few flip seemingly almost overnight and go on sustained runs.

You’ve probably seen examples of the latter. Palantir (PLTR) is a good one. Loss-making for years, widely dismissed, then suddenly profitable, self-funding, and repriced accordingly. Once that switch flips, the market reaction tends to be fast and nonlinear.

So, the real question isn’t whether negative earnings are bad. It’s how to tell the difference between a shitco and a potential 10-bagger. Or more precisely…Continue reading by subscribing to The Access Control Executive Brief.



 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.