Volume 52
Volume 52 | March 20, 2026
This Week’s Featured Articles, Media, & Breaking News
|
✍🏻 Articles Allan Bleakley | The Invisible Key Kabir Maiga | The Credential Got Smarter. The Bill Didn’t. Brian Karas | What I Want To Find At ISC West 🎙 Secured Podcast Episode 8 | ISC West 2026: 5 Security Trends You Can't Ignore 🚨 Breaking News Breaking: Scott Lordo has been appointed Chief Executive Officer at Wavelynx Breaking: ZKTECO USA and braXos Security Software have integrated Armatura Breaking: AMAG Technology receives a growth investment from Egis Capital Partners Editor’s Note: Last week’s article on The Value of the Security Assessment by Jon Polly was originally published in Jade Learning. You can read the original version here. Scroll down to go deeper ↓ |

For decades, the low voltage and physical security industry has relied on the "something you have" model. We’ve all been there: fumbling at a card reader with a handful of groceries or realizing the office badge is sitting on the nightstand.
But as we move further into 2026, the definition of identity is shifting. We are transitioning from tangible credentials to behavioral and environmental identity. The goal is no longer just security, but "biological integration".
Here is where I believe access control is headed next.
Long-Range Spatial Awareness The Death of the tap
The traditional RFID badge isn't disappearing, but it is getting a significant range boost. UltraWideband (UWB) can turn credentials into passive beacons, while advanced BLE (Bluetooth Low Energy) can turn credentials into active beacons.
Instead of stopping to present a card to a reader, the next generation of sensors detects your encrypted "handshake" from several meters away. By the time you reach the door, the strike has already released. This creates a "concierge experience" where the building anticipates your arrival rather than challenging it.
Multi-Modal Biometrics: Geometry and Intent
Traditional fingerprinting is effective but requires physical contact; a drawback in a post-pandemic world. The industry is pivoting toward Hand Geometry combined with Dynamic Gesture Recognition.
Imagine a high-security data center where a simple "hand signal" acts as a second factor of authentication. The system scans the unique bone structure and surface area of your hand while simultaneously verifying a specific gesture, like a three-finger salute or a closed fist. This adds a layer of intent to the identity; a stolen credential or a forced entry becomes much harder to execute when a specific, private movement is required to trigger the "Open" command.
Sentiment-Based Access: "Smile to Enter"
It sounds like science fiction, but computer vision is reaching a point where liveness detection and sentiment analysis are becoming gatekeepers.
"Smile to open" protocols are being piloted in hospitality and high-end corporate offices. By requiring a specific facial expression, the system ensures:
• Liveness: It’s a real human, not a high-resolution photo or a silicone mask.
• Consent: The user is actively engaging with the system.
• Brand Atmosphere: It reinforces a positive environment from the moment an employee or guest hits the perimeter.
The Mobile Credential as the Root of Trust
While hardware is evolving, the smartphone remains the root of trust. Through secure enclaves and decentralized identity (DID), your phone doesn't just hold a digital badge; it holds a verifiable credential that can be revoked or updated in real-time across a global enterprise.
In the low voltage space, this means we are shifting from installing "dumb" readers to "intelligent" edge devices capable of processing complex AI locally, ensuring privacy while maintaining lightning fast response times.
The Road Ahead
The future of the low voltage industry isn't just about pulling CAT6 and mounting cameras. It’s about Identity Orchestration. We are building environments that recognize us, not just our plastic cards.
As a Sales Engineer, my challenge is to balance this "invisible security" with user privacy. The most secure door in the world is the one that knows exactly who you are, and opens for you before you even have to ask.

Every year at ISC West, our industry announces a new generation of credentials. Smarter cards. Better mobile wallets. Slicker enrollment. The technology keeps getting better. But underneath it, the business model stays the same: a per-user, per-year fee paid to the vendor who controls the ecosystem.
The format keeps changing. The economics never do.
I build software that runs on access control panels, the hardware already inside your walls. What I’ve learned is that the biggest barrier to the next phase of physical access isn’t technology. It’s that we haven’t yet figured out how to layer a fundamentally different identity model alongside the credential infrastructure we’ve already built.
The gap we should all be talking about.
IT figured this out years ago. Cloud migration didn’t happen in a single cutover. It happened in hybrid mode, on-prem and cloud running side by side, sometimes for years, while organizations migrated workloads incrementally. Nobody serious proposed ripping out Active Directory on Day One. But critically, the cloud didn’t just change the deployment model, it introduced a fundamentally different economic model alongside the old one.
Physical security is approaching that same inflection point. The industry can already mix mobile credentials and plastic badges on the same system. That’s real progress. But the economic model underneath hasn’t shifted; every mobile credential still carries a per-user, per-year fee. For a 10,000-person enterprise, that’s $40,000 to $120,000 annually. At that math, most pilots don’t scale. The budget gets reallocated. And the industry leaves adoption on the table.
The identity shift changes the equation
Here’s what makes this moment different: governments are becoming the identity layer. Mobile driver’s licenses are rolling out across U.S. states and accelerating internationally. These aren’t vendor-issued tokens. They’re government-attested, cryptographically verifiable identities that people increasingly carry in their phones.
For our industry, this opens a question we haven’t had to answer before: how do you consume a verified identity that a person already has without replacing the infrastructure that’s already in place?
That’s not a replacement for the credential ecosystem. It’s a new layer alongside it. And the companies that figure out how to build for it, whether they make panels, write PACS software, or integrate systems, will own the next phase of access control.
What building for it actually looks like
I didn’t fully believe this until we built it.
An employee with a mobile driver’s license taps a reader. The system verifies their government-issued identity, translates it into a standard credential the panel already understands, and makes an access decision on the existing controller, using the existing PACS logic, appearing in the existing audit trail alongside every badge swipe from every other employee. No new management console. No parallel system. No migration event.
An employee without a mobile driver’s license keeps using their existing badge. Same door. Same panel. Same PACS. The two populations coexist. As digital ID adoption grows state by state, the ratio shifts organically. There’s no switch-over day.
This is what mixed-mode looks like in practice: identity-based access and legacy credentials running in parallel on the same infrastructure. The controller becomes the bridge between the credential model we’ve built over decades and the identity model that governments are now rolling out.
Why this matters for the industry
The enterprises we all sell to are watching the identity shift happen in IT with zero trust, passwordless authentication, verifiable credentials. They’re going to ask why physical access hasn’t caught up. When they do, the industry that has an answer will win the next decade.
Mixed-mode is that answer. It doesn’t ask enterprises to abandon their installed base or SIs to walk away from existing business. It adds identity as a layer alongside credentials, running on the same panels, the same PACS platforms, the same infrastructure the industry has spent decades building and deploying. The playbook isn’t disruption. It’s expansion.
The access control industry doesn’t need another credential. It needs a bridge to identity. And the foundation for that bridge, verified digital identity issued by governments, is already in people’s pockets.
Next week at ISC West, I’m showing this running on real hardware. Not a roadmap. Not a render. A door that opens when a person proves who they are.

Everyone goes to ISC West with different expectations, but one goal shared by a large portion of the attendees is a goal to find new products. Here are a few products I would love to find, let me know if these resonate with you, or what your ideal find would be. None of these are necessarily easy, but they are all technologically achievable, and have logical business cases.
In no particular order:
A camera that was designed with aesthetics in mind. It often feels like one person designed every camera on the show floor. Off-white bullets, domes, and turrets. Maybe black housings instead of white, or the very occasional steel grey. But they are all kind of utilitarian looking, and do not blend into premium environments. While sometimes the visual appearance of cameras adds a deterrence factor, in other cases we want cameras to be able to blend into the surrounding architecture and aesthetic. This can be for covert surveillance purposes, but more commonly I find that newer high-end commercial buildings want to create a particular look and feel. A small variety of housing options, more easily paintable exteriors, or industrial designs that do not shout “CCTV” would likely find enough of a market to justify the expense.
A modular access control reader. Maybe someone will tell me why this can not work, but it would be nice to give customers a way to add NFC, BLE, or even fingerprint readers in the future without having to completely replace the reader. Of course this kind of modularity adds cost, and adds complexity for weatherproofing, but it does not feel like a huge ask. Also, whoever is designing most readers could probably stand to make them a little less boring looking.
Definitive cyber security statements. I often feel that too many companies think that listing “HTTPS” amongst a dozen other “supported protocols” in 8pt font on a spec sheet counts as having a cyber security posture. Cyber hardening is a critical need, and with that in mind signed firmware, bug bounty programs, openness to PEN testing, and similar concepts should be a front and center part of product descriptions, with sales teams able to actually discuss the topics intelligently.
Cloud Architecture Flexibility. Cloud is definitely here to stay, and there is nothing wrong with that, but it would be nice if users were given some choices on how and where their software actually ran. Given the critical nature of security products, it would be nice if “cloud” wasn’t so often synonymous with “a datacenter of our choosing with no resiliency and we are all stuck with whatever outages happen”. Ability to deploy on more than one vendor, or even in a private cloud would be a nice option to see as something more like a default expectation than an extreme rarity.
Vision AI companies focusing on solutions instead of "98.2875081% false alarm reduction". Video analytics has come such a long way, but we still primarily see marketing of various claims of accuracy/false alarm reduction. It seems like we should have moved into the ability to understand scene context, or do more complex object analysis by now. The other extreme is AI companies listing a dozen things that turn out to barely work in real life. It would be nice to see some very creative uses of LLMs and agentic AI being demonstrated in the context of real applications users will pay for.
A line in the sand on prox and wiegand. Just kill these both already. Force customers into a transition, EOL production of such outdated and insecure mechanisms. Have the strength to make a stand.
Credentials issued from user to company instead of the other way around. I love my digital wallet, but it is getting full and I’m getting hesitant to add more proprietary credentials to scroll through. Why can’t we have a provisioning workflow where my phone has a unique certificate that I exchange with whatever organization needs to authenticate me, and they store the public key side of my private key? If you’ve ever used SSH keys you know that this is 99% solved. I don’t want separate digital credentials for my gym, my self storage site, my office door, the parking garage, etc.
Those of some of the things I would love to unexpectedly discover at ISC West, what are yours? Throw your comments in the PhySec Slack.
![]()
Podcast | Secured: Episode 8
In Episode 8 of Secured, Lee breaks down the biggest signals heading into ISC West, from interoperability and AI to mixed-mode identity and mission-critical automation. He also introduces the three types of booths, the five forces driving change, the four personas you will meet on the show floor, and the one sentence to keep in mind the entire time: the center of gravity has shifted from the door to the person.
![]() |
​Industry Night at TSE returns for its second year on Tuesday, April 28 at 6:00 PM at The Botanist. Join us for an evening of connection and conversation with professionals from across the access control and security ecosystem. Attendance is capped at 120 guests, with food and drinks included, and a portion of proceeds supporting FAST. Sign up here to register .

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.
