Header Logo
Log In
← Back to all posts

Volume 6

Aug 03, 2026

Volume 6 | February 28, 2025

Act 2: Salto's TouchByte Acquisition and New Product Signals the WEcosystem

Written by Lee Odess

What stood out this week:

When I heard about Salto acquiring TouchByte, the pieces didn't quite fit. The acquisition lingered in the background of industry conversations and trade shows, but its strategic significance remained unclear—until now.

 

A message from Salto's product team about their new Orion solution, debuting at Intersec Dubai, caught my attention. Even more intriguing was the follow-up conversation with Jeremy Sneller, TouchByte's former CEO, now leading Salto's newest venture. What emerged wasn't just another product announcement but a glimpse into the future of access control.

 

Let me tell you why this matters.

 

Orion-C is the company's first single-sourced face recognition access control solution. And yes, you might think: "We've seen this before from Alcatraz.ai, SAFR, and ZKTECO, and didn't HID just introduce something like this." But that's missing the bigger picture.

 

Orion-C

This launch represents a pivotal moment in Salto's evolution and, perhaps, the industry's transformation. The timing aligns perfectly with the convergence of several market forces: the rise of integrated reader/video/biometric devices, the shift toward enterprise-grade software solutions, the demand for "our security stuff" to do more, and the growing demand for seamless user experiences.

As Salto noted during a recent conversation, the industry is rapidly evolving beyond traditional channels. They are moving away from hardware with software as a feature only toward software-driven solutions that fundamentally reimagine how "we" do access control, also. Orion isn't just replacing cards with faces—it's redefining how we bring products to market, package solutions, and think about our traditional "lock" and "reader" companies in a software-centric world.

That's the real story here. And I love it.

While Salto will leverage its existing channels, the product's true potential lies in unexplored territories. Look beyond the spec sheets and security trade shows; you'll see a strategy that speaks to a broader market transformation.

Let's be honest: the world doesn't need another reader with facial recognition capabilities. What it needs are operational efficiency solutions that:

  • Speak the language of mainstream markets

  • Enable new channels to deliver comprehensive solutions

  • Help businesses maximize revenue per square foot

  • Bridge the physical-logical security divide

  • Elevate both security and user experience

This is where Orion's strategy appears to be headed. However, strategy without execution is just wishful thinking. Success will require:

  • Bold decisions and substantial investment

  • Leveraging legacy strengths while embracing innovation and new ideas

  • Creating new paths to market rather than forcing new solutions through old channels

That sets this launch apart – it's not just about the product but the ecosystem built around it.

 

TouchByte's acquisition brought more than facial recognition expertise; it brought deep IT infrastructure experience through the Sneller’s background at Mitsubishi and Fujitsu. This influence is evident in Orion's emphasis on seamless integration, user experience, and enterprise-grade architecture.

 

The solution itself addresses several key market demands that we have seen already:

  • Frictionless access through walk-up authentication

  • Eliminated credential management overhead

  • Self-enrollment from any device

  • Cloud-first architecture matching modern enterprise software expectations

  • Thoughtful design balancing aesthetics with functionality

Perhaps most significantly, Orion introduces a scalable platform that extends beyond door access. Salto's integration capabilities of visitor management, locker systems, and potentially vending machines (as hinted by Salto) suggest a comprehensive technology platform play for specific verticals.

 

This launch represents Salto's "second act" â€“ evolving from an innovative lock manufacturer to a comprehensive technology provider built on security foundations. As Salto observed, in major enterprises, "access control is just another application" within the broader IT infrastructure. Orion's architecture appears designed for this reality.

 

The challenge now lies in execution. Success will require Salto to:

  • Continue to build robust enterprise software capabilities. Even if that means shrinking its hardware capabilities.

  • Develop new channel partnerships that are aligned with IT system integrators, even if that means rethinking some existing partnerships that aren't aligned with the IT industry.

  • Create a go-to-market strategy that resonates beyond traditional security markets, even if that means applying historically allocated resources for transitional security markets to new markets.

  • Hire talent with enterprise software experience and blend them with existing security incident talent. Even if that means letting go of some security talent to make room, it also means rethinking how you pay this new talent pool.

With Orion's release, we'll soon see if the market is ready for this evolution in access control. Based on enterprise user conversations and growing demand for seamless, software-driven solutions, I believe Salto can capitalize on this transformation – if they fully commit to the journey.

 

The question isn't whether this is the right direction or timing but how quickly the industry will embrace this new paradigm.

 

The customer and channel await. The stage is set for Act 2.


What a week I have had, a new networking group was established in Nashville, the Security Titans, I had an opportunity, like our amazingness Lee, to speak at the wonderful BadgeUp conference, which was also local to Nashville. As I have been working my way through the week and talking to different people, the question came up, if you had one piece of sales advice Angie, what would that be? Smiling. I am old you see, laughing, 30 years’ worth of stories here in the security industry, so I must admit, as I tilted my head to the side and started to think? Hmm, what would that be? I have had a career of successes, but I have also had quite a few failures along the way. Filtering out what was good and what was less good (being an optimist) lead’s me down a path of learning to do better, be better for myself, my family, and my company I work for. 

If we start with my new role, Chief Revenue Officer, I am doing a whole lot of listening, learning, and developing a lot of new muscles on the manufacturing side I never had, versus the integration side of the house. When I was fortunate to make this move in my career to Evolon, I knew it was not one going to be the option to coast out the rest of my career. I knew it would challenge me to stretch myself and bring the best of what I am hopefully, to this amazing company. I also did not expect it to happen overnight. I have been incredibly fortunate I walked into a fabulous team. 

So, Angie, back to the topic, what would be that one piece of sales advice you might give? Hmm. Bring it, girl! Well, I think I have preached this for a long time, and it come’s very naturally to some, and really difficult for others, but it would be that it IS okay to be persistent in the sales cycle at all times, but EVERY SINGLE TIME you need to bring VALUE. What does that mean? Using our Security Breakdown leader here, why do people follow and love me some Lee Odess? Because you can count on his posts, newsletters, articles, etc. to bring value every time to our industry and the readers. Lee would be a huge poster child for bringing value. Now, you may not be a Lee, but it certainly doesn’t preclude you from following up on a potential prospect using your value muscle. Using an example, Let’s say their name is John, “Hey John, just checking in to see how the evaluation of our product is going? How are we doing on making our decision on next steps?”  Now, this isn’t horrible, and if you have built a great relationship bridge of trust, integrity and maybe even vulnerability, you might actually get a response to this. But let’s rephrase this with a value proposition in mind, “Hey John, hope all is well, I know you are right in the midst of an evaluation of our product, I just wanted to share a new case study where we were successful in a parallel industry to yours. Hope this might help in your ROI building process!” Cheers! Now, if I am on the other end, and really interested in your product, this is definitely value and helpful for me to understand who else is using it successfully, and how they applied it, justified it, etc. Boom! That’s what you bring. 

You see value can be done in so many different ways, but it will differentiate you from your competitors every time, I promise you that. I have learned quickly, being on the manufacturing side, there are quite a few comparable products, solutions, etc. on the market, but it still comes down to who is selling them, building the relationship bridges, to allow people to make decisions to move forward. Bring the value every time, every call, every follow up, every trade show walks, let that be your mantra. I am a value champion or my superpower is Value and you will see the difference you will make to your company and your customers. 


"The Path to Becoming a Physical Security MSP" by Jacob Hengel, of YourSix, offers a comprehensive guide for transforming security technology businesses into recurring revenue generators. The ebook outlines five practical steps to developing a successful Physical Security Managed Service Provider practice, including understanding the business model, navigating the competitive landscape, building a trusted advisor culture, properly packaging solutions, and effectively launching your practice. It emphasizes the benefits of the PS-MSP model, which offers predictable revenue through proactive services while increasing customer satisfaction and system reliability. The guide serves both security integrators looking to grow their businesses and traditional IT MSPs interested in adding physical security as a valuable revenue layer. You can download it here.


New: Talking Shop Podcast: Your Monthly Dose of Physical Security Insights Watch and listen to Episode 3 here.

We are excited to highlight our newest collaboration with the team from "Talking Shop" - the podcast that dives deep into physical security's biggest questions, challenges industry norms, and covers everything from cutting-edge technology to practical tactics. Our expert panel features Bear Halvorson (PSP, Security Today Podcast host, and hands-on integrator), Benji Bolick (the "Door Dork" and access control specialist at ProdataKey), and John Harris (Next Level podcast host and founder of Apex Performance). Each episode tackles three critical security questions with lively debate and insider knowledge. Don't miss this month's thought-provoking discussions - one topic was ripped from the channels in Slack. Watch and listen to Episode 3 here.

In This Episode:

  • Will mobile credentials completely replace physical badges? The panel explores security implications, user experience challenges, and emerging technologies like ultra-wideband.

  • The future of burglar alarms in an era of non-response policies, improved camera technology, and access control integration.

  • Career development strategies: how to build skills for your next role while excelling in your current position.

Watch and listen to Episode 3 here.


Earlier this week a blog post, Breaking Into Dozens of Apartments in Five Minutes, called attention to an issue that has been plaguing the security industry ever since network connectivity started showing up on devices. That issue, default passwords, is multi-layered and not as easy to efficiently solve in commercial security as it is in DIY residential security.

As the blog post outlined, the vulnerability was phone in a Hirsch Enterphone MESH product, commonly used in multi-tenant residential buildings. These devices are designed to function as all-in-one systems, where you have a reader, controller, and user database all in a single unit. Management of the system is via a web interface, which of course implies network connectivity. Many multi-tenant buildings are managed by outsourced property management companies, so these devices naturally wind up being accessible from the public internet. Couple this internet-connected access control system with a default password shared across all devices and you have a recipe for all kinds of headaches.

The Trouble With Passwords

If you’ve installed any consumer oriented devices that have public-facing web interfaces in the last decade or so you have probably been prompted on setup to enter a unique admin password. Even this process is becoming more and more rare, as things have switched to being managed via apps and implementing network access controls that don’t allow for open internet connectivity. For devices that are installed and setup by the user of the device this process works fairly well. The user is responsible for setting their own password, and if they pick something weak and easily guessed, they have only themselves to blame.

Admin password configuration on B2B products installed by security integrators can make this much more cumbersome. The person installing the system may be doing so before the building is officially open, or may be doing so without having contact information for the person who will be the ultimate administrator. In many cases products might be bench tested before installation, or pre-configured offsite in order to make the onsite portion of the installation easier and more efficient.

Many “professional” products then wind up with a challenge in how admin passwords are handled. The manufacturer wants to make it easy for the technician to get the system up and running, and making the process as simple and repeatable as possible leads to default passwords still being persistent for products in these categories. Asking a technician to specify an admin password of their own choosing is not always a great idea.

Who Owns Responsibility for Admin Passwords?

Ultimately the person or organization responsible for the property the equipment is intended to secure should own the designation and handling of all accounts, passwords, and related data on the system. And while this sounds good in theory, it can lead to support headaches for the end-user, the integrator, and even the manufacturer when admin passwords are lost or forgotten. On top of this, you have a variety of mechanisms for resetting or recovering passwords which can be very inconsistent across various brands. All of these factors only encourage more use of default passwords when nobody wants to own the problem or take responsibility for administration.

The Manufacturer’s Responsibility

No security manufacturer should be shipping equipment in this day that trades cyber security for physical security in an out of the box state. This means that default passwords for example should have been long eradicated by now. The particular CVE was entirely preventable if Hirsch had followed the protocol of other organizations like Axis or Hanwha on the video side, and shipped products in a state that requires a strong unique admin password to be set before any configuration or integration can be done. 

Beyond basic passwords we are really at a point where 2FA should be an optional, but recommended mechanism, for web-interfaces, particularly any that allow for configuration changes or viewing/editing of sensitive data. Few, if any, products support 2FA mechanisms for admin interfaces.

The Integrators Responsibility

Like the manufacturer, an integrator should not create a scenario where installing new physical security equipment creates a cyber security risk for the customer. I would also argue that unless the integrator has a support contract in place with the customer they should not retain admin rights and passwords to any equipment after the installation has been completed and control of the system is handed over to the end user. I do recognize that this is not always a clearly delineated point in time, but a good compromise is handing over the admin account and requiring the user to provision a technician account that is specific to the integration company.

The End Users Responsibility

In the end, ultimate responsibility falls to the end user. We are at a point where every person should understand the need for strong passwords and good password management. Devices exposed to the open internet have been getting hacked for decades now. If a person cannot recognize that account credentials along the lines of “admin/password” are not a giant red flag, that person should not be in a position to have administrative access to any sensitive or vital equipment.

A cyber security minded administrator will take the time to go into any systems after installation and verify pre-configured accounts, reset passwords to fresh values not known to outside entities, and ensure that devices and systems are not exposed to open internet connections unless absolutely required.

Security Is A Joint Effort

Cyber security can be thought of as a chain, where the links in the chain are every person or entity that had a hand in making a piece of equipment network accessible. If any of those links are weak there is a high probability of data loss, hacking, ransomware, or other undesired outcomes. Manufacturers and integrators in particular have too much at stake to be weak links in that chain. Lawsuits for data loss, or personal loss and harm, are becoming more common. An organization that is proven to be a major contributor to such a loss can stand to lose a lot financially and reputationally.

Opportunity For Integrators

These ongoing cyber security issues have created significant revenue opportunities for savvy integrators. I know of several integrators that have begun to offer cyber security scanning, penetration testing, and managed VPN offerings to their end users. These services not only help keep their customers more security in both physical and cyber security, but they also provide for additional revenue streams, in particular with managed VPNs that have monthly subscriptions.


 

 

 

 

 

 


5513 Oak Place, Bethesda, MD 20817, United States

Unsubscribe

 

 

Volume 40
Volume 40 | December 5, 2025 This Week’s Featured Articles & Media Danny Smith | The Physical Card Renaissance: My TRUSTECH Wake-Up CallDanny’s trip to TRUSTECH flipped his assumptions about the future of credentials. Instead of a mobile-only world, he found a global market doubling down on both physical and digital, creating a hybrid reality that demands smarter strategies, better integrations...
Volume 39
Volume 39 | November 21, 2025   This Week’s Featured Articles & Media   Lee Odess | Why We Continue to Bet on ISC Security EventsMost events can rinse and repeat the same formula for 30 years, call it a day, and then try to control all aspects of creativity. Instead, ISC Security Events is proving what real investment and evolution look like. Lee writes about at how initiatives like the Start...
Volume 38
Volume 38 | November 14, 2025   This Week’s Featured Articles & Media Karsten Nölling | From Metal Keys to Minimalist Design: The Security Dealer of the FutureThe locksmith’s wall of keys is giving way to the digital access showroom. As door security moves from metal to mobile, Karsten looks at how dealers can evolve from key-cutters to Digital Access Consultants, creating modern, experience-...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.