Volume 54
Volume 54 | April 10, 2026
This Week’s Featured Articles, Media, & Breaking News
✍🏻 Articles
Paul Labow | Zero Trust Physical Access: Verifying the Person at the Point of Entry
Credentials are not identity, and Zero Trust physical access is built around closing that gap.
Read below
Brian Karas | Is The Integrator Acquisition Pace Hurting Startups?
Two strong industry trends are colliding, and security startups may be the ones feeling it first.
Read below
Taylor Topper | Retail doesn’t need more locks. It needs smarter access
Retail is adding more locks than ever. But the real problem isn’t the lock. It’s what happens next.
Read below
🎙 Secured Podcast
Episode 10 | How AI & ChatGPT are Disrupting Physical Security Sales
AI and ChatGPT are changing how buyers find vendors, build trust, and make decisions, and physical security sales is being forced to catch up. Listen now.
🚨 Breaking News
Breaking: ASSA ABLOY Group acquires Rollerdoor Group in Portugal.
Scroll down to go deeper ↓

Retailers are locking more merchandise than ever in response to rising shrink and organized retail crime—but traditional approaches are creating new challenges.
Manual key management, limited visibility, and delayed access can impact both loss prevention effectiveness and the customer experience.
This guide explores how retailers are evolving their approach with Smart Access—combining digital credentials, connected locks, and real-time data to control access, reduce internal and external shrink, and improve store operations at scale.The Problem: Credentials Are Not Identity
For decades, physical access control has relied on credentials—cards, fobs, PINs, and more recently, mobile devices.
But credentials can be:
-
Lost, stolen, shared, or cloned
-
Intercepted or replayed
-
Used by someone other than the authorized individual
In a world where organizations are adopting Zero Trust architectures, this model introduces a fundamental flaw:
The system trusts the credential—not the person.
The Shift: From Credential-Based to Identity-Based Access
Zero Trust is built on a simple principle:
“Never trust, always verify.”
In physical security, this means:
-
Verifying who the person is, not what they carry
-
Making access decisions at the point of entry
-
Eliminating implicit trust from devices, networks, or prior authentication
This requires a shift from credential-based access control to identity-based access enforcement.
The Architecture: Zero Trust at the Door
A Zero Trust physical access model applies core principles from frameworks like NIST SP 800-207:
Policy Enforcement Point (PEP) at Every Door
Each door becomes an independent enforcement point:
-
Identity is verified locally
-
Policy is enforced in real time
-
No reliance on centralized decision-making
Local Decision-Making
Access decisions are made at the edge:
-
No credential theft or sharing
-
No cloning or replay attacks
-
No reliance on device integrity
Minimal Attack Surface
Biometric palm vein identity is:
-
Stored as encrypted templates (not images)
-
Not transmitted across the network
-
Not reusable outside the system
The Outcome: Measurable Risk Reduction
Organizations implementing identity-based, edge-enforced access control can achieve:
-
Stronger security posture
→ Direct verification of the individual at every access point
-
Reduced attack surface
→ Elimination of credential-based vulnerabilities
-
Operational resilience
→ Doors function independently during network disruptions
-
Audit and compliance alignment
→ Clear mapping to Zero Trust principles and modern security frameworks
Why It Matters Now
As cyber and physical threats converge, the boundary between IT security and physical security is disappearing.
Credential-based access control—once sufficient—now represents a persistent and exploitable gap in enterprise security.
Zero Trust cannot stop at the network.
It must extend to the door.
The Bottom Line
If Zero Trust is about verifying identity and eliminating implicit trust, then physical access control must evolve accordingly.
Verify the person.
Enforce at the door.
Trust nothing else.

Two relatively recent trends in the security industry would appear to be really good on the surface:
-
We are seeing startups and investment capital coming in like never before.
-
Well run integration businesses are being snapped up by large buyers like Minuteman, Pye-Barker, and Security 101, among other acquirers.
Not that long ago, investors wouldn’t look at a security industry startup, and integrator businesses struggled to find buyers that would pay a fair valuation. While this seems like a positive thing overall for the security industry, it is actually creating some challenges for the startups.
Launching a new company into the industry is a daunting task, I know this from first-hand experience with a half-dozen security industry startups I’ve been involved in over the years. This is a space where things need to work as advertised, and there is less tolerance for a “move fast and break things” approach that is the go to market approach of startups in more of a consumer space. Security departments don’t have excess budgets, and they don’t have time for products that don’t work as advertised. Unstable companies can also be a risk, nobody wants to build a security strategy around a product or company that suddenly disappears, leaving warranties and promises of software updates a distant fantasy.
While every large integrator has a slightly different business strategy and market approach, one thing they all rely on is scale, and tight relationships with their manufacturer partners. When you have hundreds, or thousands, of technicians in the field, and a massive sales team, you need to standardize on manufacturer partners that can support your scale, and have the stability and financial ability to support large orders, and extend appropriate credit terms. For these reasons, and many others, early stage startups and large integrators are not often a match made in heaven. It is not that these integrators do not want to embrace new technologies, and many will gladly bring new products into their labs, or even into selective deployments, but they won’t typically lead with startup products, for good reason.
A security startup’s best go to market partner is a medium to large regional integrator with a capability to learn new products and incorporate them into their designs. These kinds of integrators are often looking for products and services to help differentiate them amongst their local competitors, and certainly against the big nationals operating in their region. Typically the owner of the company, or their tech lead, is singularly capable of approving new products, and the process is relatively straightforward. Contrast this to national integrators that often have a team of several people involved just in getting a new vendor approved and entered into their systems.
The same integrator profile that is the startup’s best friend is also the ideal acquisition target in the market today. Integrators running a strong business with a highly capable team, the kind that can profitably bring new products and services to market, make great acquisitions. However, once acquired, these businesses generally lose most of the autonomy that made them good partners for startups, which reduces the available market entry or expansion paths for those startups. Two seemingly strong trends in the security industry overlap in a way that potentially inhibits the ability for startups to come to market in this space.
This trend was a frequent conversation topic with startups and small companies I met with at ISC West. While the Startup Pavillion at ISC West showcased many interesting companies and new concepts, many of them appeared to be struggling to find actual customers. The standard go to market model of selling through integrators is well established, and easily understood, but when these startups struggle to get traction through integrators they often resort to selling direct to the end users. When you are desperate for revenue, and have investors breathing down your neck, the established processes are likely to be broken. More and more often it appears that newer companies are preferring to avoid the integrator channel if they don’t get immediate traction. While this often resolves over time (just look at Verkada as an example here), it is disruptive for everyone in the short term.
There is definitely a shift in the industry right now with all of these things colliding. The prevalence of cloud products, and services that don’t depend on complex hardware that requires trained technicians to install, is making it ever easier for new companies to avoid the entrenched go to market models and create more direct customer relationships. It will be interesting to see if the large integrators create an easier way to incorporate startup ideas into their offerings, or if this point in time will be looked back upon as a fork in the road.

Retailers are locking more merchandise than ever in response to rising shrink and organized retail crime—but traditional approaches are creating new challenges.
Manual key management, limited visibility, and delayed access can impact both loss prevention effectiveness and the customer experience.
This guide explores how retailers are evolving their approach with Smart Access—combining digital credentials, connected locks, and real-time data to control access, reduce internal and external shrink, and improve store operations at scale.

![]()
Podcast | Secured: Episode 10
In this episode of Secured, Lee breaks down how AI and ChatGPT are disrupting physical security sales by changing how buyers research, evaluate, and shortlist vendors before ever speaking to a rep. He looks at why marketing now plays a much bigger role in visibility and trust, how AI is accelerating that shift, and why the companies winning attention today are the ones showing up where modern buyers actually are. He also challenges the industry’s mixed signals around convergence, calling out the growing gap between what gets said publicly and what is actually being prioritized behind the scenes.
|
|
​Industry Night at TSE returns for its second year on Tuesday, April 28 at 6:00 PM at The Botanist. Join us for an evening of connection and conversation with professionals from across the access control and security ecosystem. Attendance is capped at 120 guests, with food and drinks included, and a portion of proceeds supporting FAST. Sign up here to register .

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.
