Volume 51
Volume 51 | March 13, 2026
This Week’s Featured Articles, Media, & Breaking News
Jeff Cianni | Small Deployments Have Large Potential
Small deployments are easy to overlook. They may be one of the biggest growth plays in access control.
Read below
Brian Karas | Are AI Agents Ready To Report For Duty?
AI agents are moving fast. The real question is where they actually help security teams.
Read below
Jon Polly | The Value of the Security Assessment
Before adding more tech, assess the risk. Better security starts with the right questions.
Read below
James Gammon | Are Your Door Openings Secure? Part 2
Interior door security goes well beyond the lock. Glazing, visibility, and control level all matter.
Read below
Tony Dong | Big Oil vs. Big Tobacco
Two depletion industries. Two very different paths to shareholder returns.
đź”’ Exclusive to Access Control Executive Brief subscribers. Excerpt below.
🎙 Secured Podcast
Episode 7 | Physical Security vs IT: Solving the Industry Friction
Small deployments are scaling, IT is taking the wheel, and the industry still hasn’t figured out what customer trust really means.
Listen now.
🚨 Breaking News
Breaking: SOS Technologies and Regroup Mass Notification® partner to automate life-safety alerts
Scroll down to go deeper ↓

Every year, the physical security trade press celebrates the blockbuster wins: the 500-door enterprise rollout, the stadium-wide deployment, the Fortune 100 headquarters migration. The case studies are impressive. The logos are recognizable. And for most of us in the industry, they are probably not as relevant to our day-to-day reality as we pretend they are.
Here is the truth no one seems eager to say out loud: small access control systems — the 2-door office suite, the 8-door medical clinic, the 15-door light industrial facility — represent the overwhelming majority of deployments happening right now. Not by a little. By a lot.
Some of the most impactful experiences I’ve enjoyed have been with small-to-mid-sized integrators and locksmiths doing exactly this work, and what defines their businesses is the depth of their relationship with the end customer. They are not handing off a completed project and moving on — they are often the same person who installed the original lock hardware, who gets the call when something does not work, and who will be back next year when the business expands. That continuity changes the nature of the deployment entirely. It raises the stakes for getting adoption right, and it creates a level of trust that no enterprise sales team can manufacture.
Segments Within Segments
One of the more interesting dynamics emerging in this space involves larger property management firms and real estate developers who have diversified into segments like affordable housing and mixed-use residential. These are organizations that already operate sophisticated access control at their flagship properties — they understand the value, they have seen the amenity lift it provides, and their residents and tenants have come to expect it. The challenge is that their smaller properties cannot support the same infrastructure costs.
The result is a genuine and growing demand for systems that deliver modern functionality at a fraction of the cost and complexity. This is not a race to the bottom on features — it is a demand for right-sized solutions. A 40-unit affordable housing building does not need the same platform as a 400-unit luxury tower, but its residents deserve the same basic dignity of a secure, well-managed entry. Property managers in this segment are actively looking for partners who understand that constraint and build to it, rather than simply discounting an enterprise product until it barely fits the budget.
It is also worth being honest about what “feature requirements” actually look like at this scale. A small school moving off physical keys for the first time does not need a sophisticated analytics dashboard. They need to know whether a door is closed, locked, or propped. That’s it. But do not underestimate what that visibility means to a principal or an office manager who has never had any oversight at all. The step from zero to something — from a ring of keys and a prayer to a modern interface that tells you the side entrance has been propped for eleven minutes — is transformative. The baseline is low, and the impact is high.
Winning In The Small Market
The integrators and manufacturers who are quietly building sustainable businesses in this segment are doing a few things differently. First, they have ruthlessly simplified the day-two experience — the credential management, the user additions, the lockout recovery — so that a non-technical owner can handle routine operations without a service call. Second, they have made peace with the fact that the initial deployment needs to be nearly invisible: fast, clean, and requiring almost no behavioral change from staff. Third, they treat the first 30 days post-install as part of the sale, not the end of it. A single check-in call or a brief walkthrough video has an outsized impact on whether a small customer becomes a reference account or a silent detractor.
When adoption fails at a small site — and it fails constantly — it does not generate a support ticket or a formal complaint. It generates a propped door, a shared credential, a system that goes mostly ignored within 90 days. The customer does not call to complain. They just quietly decide that physical access systems are more hassle than they’re worth. That perception could spread to the next prospect they refer, if not for the responsive service of integrators who are highly engaged and local.
The Opportunity Is Right In Front Of Us
The next wave of growth in physical access control may not be announced at ISC West or celebrated in a press release. It will come quietly — one small deployment at a time — from finally serving a market that has been waiting patiently for this industry to take it seriously.

Are AI Agents Ready To Report For Duty?
Unless you are one of the lucky few people who manage to avoid online media (in which case, why are you reading this?), you have surely heard about AI Agents. In fact, odds are you have been inundated with content proclaiming how AI Agents are changing the world and allowing people to gleefully outsource all the boring parts of their jobs, like buying plane tickets and responding to emails.
Unlike previous technological revolutions, such as IP networking, cyber security, and cloud services, the security industry does not appear to be waiting a solid decade to get on this bandwagon. If you are an integrator, consultant, or person with 3 layers of management above you, you are surely hearing questions like “how can we leverage AI Agents”, or “how quickly can you agentize our SOC”. Perhaps I can help you answer those questions.
The biggest thing that sets AI Agents apart from just about every technology wave before them is the concept of enabling this software to make decisions, and execute those decisions, on your behalf and without your express authorization each time. An AI Agent is like a software doppelganger, it is an almost-you. You give the agent a set of tasks, some guardrails, and hope it makes good decisions and does not email a resignation letter to your boss and then book a first class ticket to Tahiti with a loan from your 401K.
While I might exaggerate slightly, there are already plenty of stories online of perplexing and scary agent behaviours. And to be fair, there are also plenty of stories from people who have seen significant productivity improvements from AI agents. Such are the perils of a non-deterministic software. Finding optimal use cases in security requires careful planning, and expectation setting.
Like all other AI software, agents are a replacement for human tasks, where the optimal implementation replaces time a person would have otherwise had to spend on a task. In looking for ideal use cases, we start by looking at where our personnel are spending large blocks of time. Further, because the concept of agents is still very new and unproven, we tend to look for tasks that are not necessarily mission critical, or part of a workflow that could have cascading negative impacts from an imperfect decision.
One emerging use case for agents is in the remote monitoring space, where frequently the first action of an operator for a verified event is to do a live audio talk down. Live audio tends to be much more effective than pre-recorded messages, but that means you are using a lot of human time to essentially yell at people to leave a parking lot, making the service prohibitively expensive for some otherwise valid use cases. Companies like HeyYou (https://getheyyou.com/) are jumping in to offer solutions that use agentic automation to provide lower-cost approaches to live monitoring that are scalable and can offer more consistent pricing than pure human-based monitoring. While we likely still need to see more maturity from the underlying AI technologies powering these true virtual guards, meaning this might not be the best approach for very high value locations, it can provide a great mechanism to offer “live” remote monitoring to applications that otherwise would not have been able to afford such a service, creating wins all around.
Another application can be using agents to assist with data gathering and summarization in the process of responding to events. This tends to be a time consuming task that requires more repetitive process than domain expertise. Tying up time from operators or detectives to gather and summarize video clips, access logs, and other data tends to slow the process down, making this a potentially ideal use case for an AI agent.
It is important to note a few things in the two example cases above. The first one utilizes a mostly outsourced software solution, meaning that you can configure things to your needs, drop some billing info into a form, and then mostly forget about it. The second case is more likely to require customization and integration to your specific software systems, making it more costly to implement, and requiring careful planning.
In almost every application of AI agents, you are giving the software API keys, passwords, or other sensitive credentials. This can technically enable them to wreak havoc or make brand-damaging decisions. While I am not discouraging the use of AI agents where it makes sense, you do have to be fully aware of the degree of access they are granted, and pay continual attention to their output early on in the deployment to ensure you are getting expected results and not introducing new risks or weak points.
I do think it will be interesting to see what security tasks become common use cases for agents, and how this impacts the perceived value prop of security departments and operators as a whole. I predict this will be very disruptive over the next decade.

The security industry has been labeled as ambulance chasers. It's an honest label, as many security implementations only occur after a major incident, either to that user or others, and it is realized that the current risk mitigation strategies may not be adequate. Recent events such as the New York subway shooting and the Uvalde school shooting has prompted many organizations to make sudden reactionary security technology purchases. While this knee-jerk reaction to reduce the perceived attack has been seen repeatedly, it many times results in a revolving door of failure; failure where great technology was selected for the wrong application, or the right integration partner was overlooked for a myriad of reasons. The decisions inevitably result in increased risk, not less, and lost return on investment (ROI).
In the police department, the Range Master repeated the statement; "slow is smooth, smooth is fast." The concept is to slow down, make smooth trigger pulls, take the time needed and make the shot count. Another way of saying that is "if a job is worth doing; do it right, once, and only once." The same applies to partnering with customer organizations, especially those that needed answers yesterday. While the instinct is to help them as quickly as possible, the initial step must be to assess the current level of risk. Once the level of risk is truly known, the right process, technology solution, and/or partner(s) can be identified.
Physical security risk assessments can find problems before they begin and correct poor behaviors — such as propping doors open and ensuring locks and cameras work. They also provide the customer organization deliverable(s) that can be used to identify and prioritize risks, and metrics for evaluation. Security risk assessments are and should be a repeatable process after any major technology or methodology implementation. Physical security risk assessments have deliverables and should be charged to customer organizations, but risks should be evaluated with a technology agnostic mindset. Security risk assessments can be offered by independent third-party assessors such as a security consultant but can also be offered by an integration partner; the assessment should have a consultative approach and not appear biased. Herb Ubbens, President of Paratus Consultants Group articulates that, "The risk assessment should be looked at as the cornerstone of any program. When performed by persons with knowledge and experience in that field, the assessment can help you address operational issues and more importantly, provide insight into security and safety concerns as it relates to the Duty of Care that an employer or organization must provide a safe environment."
Types of Assesments
There are three distinct types of security risk assessments that should be discussed with the customer organization, as each one of them can provide more information and direction. The below mentioned risk assessments are for physical security assessments but could be used for cybersecurity assessments or corporate risk management applications. The physical security risk assessment is not a gap analysis, though it can be part of the organization's overall gap analysis process.
For each of these types of assessments there are checklists, templates, proprietary software, and homegrown spreadsheets to help identify the risk, vulnerability, or functionality. There is no one right deliverable. The goal is to provide the customer organization with the information they need to make an informed decision about the priority of risk, vulnerabilities, or technology to address.
The Risk Assesment
The risk assessment is a very probative assessment of not only the security risks, but many times includes operational risks, as well as safety and procedural reviews. The risk assessment typically involves a risk matrix that measures "Likelihood" and "Potential Severity." For example, a severe risk, with no likelihood of ever happening would have less risk than a moderate risk, with a high likelihood of happening.
The risk assessment should evaluate both internal and external threats to the organization, and suggest ways to mitigate, transfer, avoid or accept the risk. Once risks are identified and mitigation strategies implemented what risk is left is considered "residual risk." At that point, the organization can decide if the residual exposure or risk is tolerable to the organization or not. A full physical security risk assessment should include some background on the surrounding area of the organization, including direct threats to the organization as well as criminal activity in the surrounding area.
There is a two-part caution to risk assessments; 1) The assessor should hold an industry certification to understand the risks. An example would be the ASIS Physical Security Professional (PSP) equivalent or higher. 2) The Scope of Work should clearly state that only the physical security of the organization is going to be assessed, lest the assessment be hijacked in ways that could affect the assessor's liability or errors and omissions (E&O) insurance policies.
The Vulnerability Assesment
A lesser version of the physical security assessment would be the vulnerability assessment. This assessment is still going to assess internal and external threats and should include homework on both direct threats to the organization as well as criminal activity in the surrounding area. Where the vulnerability assessment differs is that the assessor is looking for ways into the organization; failures in the physical building, technology, and people. A vulnerability assessment does not typically review polices or procedures. The vulnerability assessment has a strict scope of work, to assess all points of potential vulnerability for a threat; human, animal, or acts of God to gain entry or create damage to the organization.
Just like the risk assessment, the vulnerability assessment should be conducted by an assessor that holds an industry certification to understand the risks. An example would be the ASIS Physical Security Professional (PSP) equivalent or higher. The vulnerability can be assessed two ways; 1) As a penetration test, where the assessor assumes the role of a threat actor attempting to gain entry, or 2) as a reverse of the penetration test and assess the security from the inside out, in an attempt to identify weaknesses that could lead to vulnerabilities.
The Technology Audit
The reality is that many organizations may not necessarily need or want the risk or vulnerability assessment. While this can and probably should be argued slightly, there may be other influences preventing the full assessment.
The technology audit is simply a test of all existing technology to confirm functionality. Does the currently installed technology work in the manner that it was installed to do? A second question that then must be asked for reasons of the initial engagement, should it do more? While technology can be audited through any number of remote programs that are typically included with Service Level Agreements (SLA), a physical audit should be completed by the integration partner on at least a yearly basis, more if the customer organization has created Key Performance Indicators (KPIs) that can negatively affect the integration partner for failures. Herb Ubbens added that the adage, "what gets measured, gets managed," is quite accurate and should be a part of every agreement.
Many times, the customer organization will request a technology audit when key employees have left or are leaving, to ensure the technology is accurately identified and located. The metrics for the audit are much simpler than those of the previous assessments, where the technology audit should include locating the technology on a drawing and identifying its functionality.
Unlike the previous assessments, the technology audit needs only be performed by a service technician or project manager knowledgeable of either the organization's site, or in the types of technology the organization has deployed (if known).
Closing
Albert Einstein is credited with saying that the definition of insanity is "doing the same thing over and over and expecting different results." Yet, this is exactly what many customer organizations experience when making sudden, reactionary purchases of technology. To reduce their attack surface, they inevitably create a larger risk to the entire technology ecosystem or even the organization, losing the ROI, not gaining. While the instinct for many is to purchase the widget or "shiny object," it is a system of uncertain success. The first step when partnering with a customer organization must be to assess what they have, how it works together (or not), and define and measure the risk. Once this is completed the solution can be clearly identified. Is this methodology foolproof? No. Each implementation, interaction, process, and new risk can affect the variables. Assessments should be a repeated process after each implementation of technology or methodology, and on a set time basis to evaluate and measure the risk, vulnerability, or the technology.

In part one, James breaks down why secure doors are only part of the equation and why the full opening, from frame and hardware to access control and latch monitoring, needs to be evaluated based on risk.
In part two, James expands the conversation to interior applications.
Additional security level recommendations for openings located within the INTERIOR of a building:
The security level recommendations are meant to be a baseline and can be applied to any opening within a structure. For interior applications, wall construction and opening material may change, and Appendix A of this publication can provide additional information regarding door, frame, and hardware materials for reference.
In addition to the previous security levels listed, the following modifications should be considered for interior applications per security level.
Security Level 1 – Basic level of control and security.
The opening is flush and may or may not have a visible glass area within the door. It is latched by means of mechanical hardware. Monitoring of the door position and latch position is not required, but it is recommended.
Security Level 2 – Intermediate level of control and security.
The opening is flush and may or may not have a visible glass area within the door. It is latched and includes an electronic access controlled latching device with remote locking capability. Monitoring of the door position and latch position is not required, but it is strongly recommended.
Security Level 3 - High level of control and security.
The opening is flush and may or may not have a visible glass area within the door. It is latched and includes a networked online access control system with remote locking capability. The access control system can be wired or wireless.
In addition to the security levels listed, the best practice for the highest degree of security includes video surveillance and active communication functions at the secure opening.
Application of Glazing to the door itself, or to the surrounding frame at the opening:
When you apply visible glass or glazing to a wall or door, you are changing its security level. The following requirements outline the different security levels for glass and glazing applications. Glazing applications must meet the requirements specified in the project documents or as required by applicable code. These levels are to be used in conjunction with the security levels listed above to maintain the desired security level.
Security Level 1 – Basic level of control and security.
To maintain security level 1, any glass or glazing applied to an opening must include a transparent film with a minimum thickness of 14 mils. There are a variety of films available on the market, but for security purposes, the film should be rated for impact resistance.
Security Level 2 – Intermediate level of control and security.
For additional security, we recommend using attack-resistant security glass for level 2 glazing applications. This type of glass is designed to remain intact even if it is intentionally broken, making it more difficult for intruders to gain entry, intentional breakage, or escape.
Security Level 3 – High level of control and security.
Bullet-resistant glass that meets the requirements outlined by UL 752 published Standard.[1]
In interior applications, especially at classroom entry openings, glazing should be restricted to a maximum of 100 square inches of visible glass. This will allow for a safe zone, out of the line of sight. Attack-resistant security glass (level 2) is recommended, but for minimum application to maintain security level 1, a security film with a minimum thickness of 14 mils should be applied to all openings.
[1] – UL 752 Standard for Bullet-Resisting Equipment - This standard is a US standard, from Underwriters Laboratories. The standard covers materials, devices, and fixtures used to form bullet-resisting barriers which protect against robbery, holdup, or armed attack such as those by snipers. This standard can also be used to determine the bullet resistance of building components that do not fit the definition of equipment, such as windows, walls, or barriers made from bullet resistant materials.
[2] – The term “Egress” in this publication is based on the definition as outlined in NFPA 101 Life Safety Code and includes the following:
3.3.170* Means of Egress – A Continuous and unobstructed way of travel from any point in a building or structure to a public way consisting of three separate and distinct parts (1) the exit access, (2) the exit, and (3) the exit discharge.
3.3.170.1 Accessible means of Egress – A means of egress that provides an accessible route to an area of refuge, a horizontal exit, or a public way.
[3] – Test Method – American Society for Testing Materials (ASTM) F1233 – Standard Test Method for Security Glazing Materials and Systems.
ASTM F3561 Forced-Entry-Resistance of Fenestration Systems After Simulated Active Shooter Attack.

In one of my earlier briefs, I walked through how, despite a customer base that is quite literally dying off. Altria Group has delivered total returns, including reinvested dividends, that have meaningfully out performed the S&P 500 over long stretches of time.
The point wasn’t to glorify cigarettes. It was to highlight that there can be opportunity in so-called legacy industries. Businesses that lack flashy year-over-year revenue growth. Companies whose management teams aren’t pitching ambitious five-year TAM expansions or AI-enabled transformations.
Some industries are about extraction. These are what I call depletion industries. This is one in which the underlying monetizable base, whether that’s customers or natural resources, is expected to decline over time. The product is either socially discouraged, environmentally constrained, or physically finite…… Continue reading by subscribing to the access control brief Sign up here.
![]()
Podcast | Secured: Episode 7
In Episode 7 of Secured, Lee breaks down the customer “trust and comfort” shift reshaping access control, unpacks why physical security and IT still struggle to speak the same language, and explores how Aliro is moving from spec to movement. He also highlights the overlooked opportunity in small deployments, what declining industries can teach security leaders about strategy, and why the center of gravity is moving from the door to identity. Listen now.

​Industry Night at TSE returns for its second year on Tuesday, April 28 at 6:00 PM at The Botanist. Join us for an evening of connection and conversation with professionals from across the access control and security ecosystem. Attendance is capped at 120 guests, with food and drinks included, and a portion of proceeds supporting FAST. Sign up here to register .

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.