Volume 64
Volume 64 | June 19, 2026
This Week’s Featured Media, Articles, & Breaking News
🎙 Secured Podcast
|
Episode 20 | OpenAI’s $150M Bet: A New Era for Security Integrators? 🎧 West to East series | This week we are featuring: ✍🏻 Articles Tim Miller | The Evolution of Proper Anchoring of Doors 🚨 Breaking News Breaking: Triton Partners announces they rolled up 6 Nordic security installers into a new platform company called Varna, focused on perimeter protection, access control, and surveillance across the Nordics. |
![]()
Podcast | Secured: Episode 20
After six conversations at the Connectivity Standards Alliance’s Unify event, one conclusion kept coming back: open standards are inevitable, and waiting is not a strategy. In this episode, Lee breaks down Matter, Aliro, and the broader interoperability movement mean for access control, why fragmentation is giving way to standards, and why the companies that engage early will build the advantage while others accumulate risk.
YouTube: Listen here

From West to East, the conversation doesn’t stop at the show floor. This podcast series brings together 45 voices from across the industry to share what’s actually top of mind right now. You can stream right from our Secured Youtube channel.
Haniel’s episode: here
Dallan’s episode: here
Jordan’s episode: here
David’s episode: here
![]()
Secured Presents: XPod from The Security Event
Over two days at The Security Event in Birmingham, we set up a microphone, called it XPod, and sat down with more than forty operators, founders, and leaders from across the global physical security industry.
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.
Three episodes. Three theses. Thirty-three voices.
Closing episode of the series: Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.
You’ll here from:
Steve Van Till | Brivo
Steven Humphreys | Hirsch Group
Karen Chiang | Rhombus
Ross Bennett | Genetec
Trevor Ball | Keri Systems
Maximilien Inukai | Macnica ATD Europe
Aaron Eastwood | Solo Secure Group
Kevin Sherwood | CIE-Group
Roman Bratishko | CoreWillSoft GmbH
Wayne Pearce | March Networks
Sam Griffiths | Ajax Systems
Servaas Kamerling | Honeywell
Don’t miss out on the previous episode’s!
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
You can stream directly from our Secured Youtube channel.

I am on my flight back from Austin spending time in 6 different sessions on open standards and connected infrastructure at the Connectivity Standards Alliance (CSA) event called Unify. I had the privilege of moderating one, sitting on a panel for another, and for the rest, I was in the audience, listening to engineers, product leaders, and standards executives talk through where Matter, Aliro, and the broader interoperability movement actually stand today.
Coming out of the 6 different rooms was 1 conclusion that kept showing up everywhere: this is inevitable, and waiting to engage with it is not a strategy that works.
Tobin Richardson, CEO of the CSA, opened with a frame that made it clear in plain language: Every major technology inflection follows the same pattern where innovation happens in silos, silos fragment the market, and fragmentation eventually gives way to standards once the value of network effects becomes too large to ignore. He walked through it with the lightbulb, the telephone, and the internet, three technologies where the infrastructure became invisible once the standard took hold. Nobody worries about voltage when they flip a switch. Nobody thinks about TCP/IP when they click a link. Tobin’s point was that we're at the same inflection point now with the connected home, the connected building, and even physical access. The pattern doesn't change. Only the technology does and he made the case that AI doesn't disrupt this pattern, it amplifies it. AI built on open systems turns devices into services for intelligence, while AI built on closed systems turns those same devices into legacy.
Kevin Ashton, who coined the term Internet of Things back in 1998 while trying to solve a lipstick inventory problem at Procter & Gamble, brought the historical weight to the same argument from a different angle. It was a fun journey down memory lane. He's watched this industry for 30 years, and his reflection on Cisco was spot on. Cisco waited on the early IoT wave, came in late, and never recovered the position. His advice to any company telling itself it will "wait and see how this washes out": you are not just missing the market, you are missing the years of organizational muscle memory that come from building inside a standard while everyone else figures it out together. There's no recovering that later.
There's always something else next, and the companies that wait for the next thing never actually move.
The Matter ecosystem panel showed me what this looks like once it's already working. Product leaders from Google, Samsung Electronics SmartThings, Homey, and CableLabs, companies that compete directly with each other, sat together describing how Matter changed their conversations with each other from negotiating proprietary APIs to building features on top of a shared foundation. One panelist put it simply: instead of fighting over how things connect, they're now fighting over what they can build once they're connected. That's the entire argument for open standards in one sentence. It doesn't kill differentiation, it moves differentiation to where it actually creates value for the customer.
I then attended a panel I was really interested in as I wanted to understand the nuances of adoption beyond North America as it is easy to miss if you only think about this from a U.S. vantage point. China is mandating a national smart home standard. The Cyber Resilience Act in Europe is making compliance with open standards a legal requirement, not a competitive choice. Japan is dealing with infrastructure and education gaps that are forcing slower but still forward movement. Every market is arriving at the same place by a different road.
And then there's the 2 sessions closest to home for those of us in access control. In the session I moderated (on the panel was Jason Hart of Safetrust Inc., Olivia Renaud of Allegion, Philip Jang of SPARC, Nelson Henry of Last Lock, and Bret Theakston of dormakaba Americas) and the panel I sat on with Sanjit Bardhan of HID, Eric Dean of M.C. Dean, Inc., Andrew Campagnola of Kastle Systems, Olivia, and moderated by Nelson, the conversation centered on Aliro and what it solves in the real world. Phil described carrying fifteen separate badges across the buildings he visits regularly. Another described the scenario of a portfolio with countless different occupant companies running countless different access control systems in a single high-rise. We’ll all know the story. These aren't theoretical problems waiting for a future solution. They're operational headaches that exist right now, and Aliro is the first credential standard built to solve them from the ground up, native to the wallet, asymmetric by design, owned by IT departments instead of facilities teams that were never equipped to manage cryptographic risk.
[BTW: when was the last time all the brands in our industry were on the same page like this? Go ahead, I’ll wait.]
Here's how I walk away from all of this after sitting through all 6 of these conversations: the pattern Tobin described, Kevin lived through, the Matter panel is already executing, and the global panel confirmed is happening on every continent, is the same pattern playing out in access control right now with Aliro. Innovation, fragmentation, and now the move toward standards and scale. Anyone in this industry telling themselves they have time to wait and see is making the same mistake Cisco made with IoT in the late 1990s. The standard doesn't need your permission to win. It needs adoption, and the only choice you actually have is whether you're inside that adoption curve building advantage, or outside it accumulating risk.
I don't see how waiting at this point works for you. I'd rather be wrong early than right too late.
Choice is yours.
Thank you CSA, Tobin, Krista Ingram and all the members for the opportunity to be in the room and trust and partnership to moderate and create content.
Originally published here.

I’ve been in the standards world for a long time. One thing I’ve learned is that the hardest part of building a standard isn’t the specification itself, but getting the market to care. Access control taught us this when ONVIF developed interoperability profiles years ago. The industry was, and still largely is, a deeply proprietary world. Vendors built business models on closed architectures, and no one was asking for interoperability. The profiles existed, but the timing was off, and the market moved on without them.
Why that’s worth revisiting now
I can tell that something is shifting. Conversations at industry events, among integrators, manufacturers, and within ONVIF, are different now. Cloud-based access control is moving into mainstream enterprise deployments. AI is correlating access events with video, flagging anomalies, and informing real-time decisions. Building systems and security infrastructure are sharing data in new ways, and identity is emerging as the thread connecting all of it. Each trend creates new integration points. These points must either be built on a published, tested, and unified specification or become a custom integrator project—working around a proprietary scenario that didn’t have to exist.
What we learned from video and from OSDP
The working model isn't complicated. OSDP, developed by SIA and now an IEC international standard, replaced the legacy Wiegand signal with modern security: bidirectional communication, AES-128 bit encryption, and device authentication. OSDP achieved this through a published, shared standard maintained by a multi-stakeholder body, not a single vendor's roadmap.
What ONVIF contributes is at a different, system-level layer. Our profiles address how access control devices, like door controllers, and other peripheral devices can communicate not only with access control management platforms but also with video systems.. This ensures deployments can evolve over time rather than needing a complete rebuild when changes occur. Crucially, conformance testing, a core tenet of ONVIF’s founding, taught us that a published specification and a verified standard are not the same. A vendor can implement a specification loosely and still claim compatibility. Conformance testing closes that gap, making an interoperability claim reliable in a real deployment. Without it, you rely on the honor system.
The specifications that still need to be written
The standards work that exists addressed the most obviously broken layers. What’s next is harder because the use cases are newer and specifications don’t exist yet. Cloud access control needs standardized authentication and device management protocols across vendors. AI analytics require consistent event structures and data models for system intelligence to be useful. Agentic AI puts additional requirements on data produced by the system. The infrastructure for identity — connecting physical security, logical security, HR, and building operations — needs standardized interfaces that aren’t vendor-decided. These aren’t abstract problems; they are integration challenges practitioners already face, and they will grow more acute as adoption accelerates. The architecture is still being defined, but this window of opportunity won’t stay open indefinitely.
Let’s build this together
The access control market is finally ready for this conversation. While the industry is still proprietary, the pressure for system integration is now coming from end users, enterprise IT, and the realities of deploying AI and cloud infrastructure at scale. This pressure is permanent.
ONVIF's role is to be the place where the industry builds shared specifications, backed by conformance testing, to make integration possible. We’ve done this in video, and we've built the foundation in access control. The next chapter starts now.
If you’re a manufacturer, integrator, consultant, or end user who has felt the friction of proprietary access control, or who sees the next set of integration problems forming, I’d like to talk. The standards that will shape the next decade are being written now, by the people who show up.

The conversation around Cloud in the security industry has been the topic of discussion for more than a decade and a half and while some people are still asking, or trying to answer, Why Cloud, the conversation has changed and there is no longer a need for such a debate.
Not because cloud has fully “won,” and not because every organization has already migrated. In fact, adoption is happening far slower than many manufacturers, analysts, and investors predicted. The industry moves at the industry speed, and is, and will likely always be, the steady turtle, not the dashing hare. But the direction is no longer really in question as cloud adoption is occurring and picking up speed every year.
The conversation has shifted from Why Cloud? to something much more practical:
When does cloud make sense for your organization, and how do you get there the right way?
The Industry Is Moving, Just at Its Own Pace
Cloud-based security management systems are no longer hypothetical. Tens of thousands of organizations are already using them, and most others are evaluating their timeline for migration.
The reality is simple: physical security is tied to infrastructure that moves slowly and budgets that take time to replenish.
Unlike many traditional IT systems, security environments are connected to doors, readers, locks, cameras, and field hardware with lifecycles that often stretch 7–15 years. That alone changes the pace of adoption. Costs to do a full migration out of cycle can be financially prohibitive, especially if they extend across a corporate enterprise.
And honestly, that’s okay.
The industry is moving to the cloud at the speed operational environments and security department budgets allow, not necessarily at the speed marketing decks predicted.
Small and Mid-Sized Organizations Are Leading the Way
For many smaller and mid-sized deployments, especially under a few hundred readers, cloud is becoming the obvious choice.
In commercial office environments, K-12, higher education, state and local government, and distributed enterprise environments, cloud often makes immediate operational and financial sense.
Especially for organizations moving into new buildings or replacing aging infrastructure, the decision becomes easier:
• Reduced infrastructure overhead
• Simplified updates and maintenance
• Anywhere access
• Modern interfaces
• Improved cybersecurity posture
• Easier scalability across multiple locations
In these environments, legacy infrastructure is often the biggest thing slowing adoption, not resistance to cloud itself. Organizations moving into new facilities is a significant driver for making this move.
Enterprise Customers Are Taking a Different Route
Enterprise organizations are approaching cloud differently.
Enterprise organizations have numerous sites, with thousands of end points, and multiple integrations, all of which require careful consideration as part of the cloud migration.
When enterprise users do decide to make the move to cloud, they have another decision to make. While smaller customers are often comfortable with manufacturer-hosted environments, larger organizations are also considering security platforms deployed within their own AWS, Azure, or Google Cloud environments.
That approach allows enterprise teams to:
• Maintain tighter control over data
• Align with broader IT and cybersecurity standards
• Leverage existing cloud provider relationships
• Integrate security into larger business ecosystems
This isn’t hesitation. It’s intentionality.
Different organizations are carefully evaluating different paths to the same destination.
Regulated Markets Still Have Real Concerns
There are still environments where full cloud adoption remains more complicated.
Airports, utilities, critical infrastructure, and highly regulated environments continue to move cautiously due to concerns around compliance, latency, resiliency, and data sovereignty.
Video also remains nuanced.
For some organizations, hybrid approaches that combine on-premises recording with cloud management or cloud storage continue to make the most sense, depending on bandwidth, retention requirements, and operational needs.
But even in these environments, cloud is increasingly part of the strategy.
The Real Challenge Isn’t the Cloud, It’s the Edge
One of the biggest misconceptions in the industry regarding the timeline to cloud migration is treating cloud as purely a software conversation.
Physical security doesn’t live entirely in the cloud. It lives at the edge:
• Control panels
• Readers
• Wireless locks
• Sensors
• Cameras
• Biometric devices
• I/O infrastructure
And much of that hardware was never originally designed for cloud-native operation. A significant amount is proprietary in nature and tethered to on-premise solutions.
That’s where the real complexity begins.
Modern cloud platforms are dynamic, integration-driven, and continuously evolving. Physical hardware is lifecycle-driven, proprietary, and expected to remain operational for years and sometimes decades.
Bridging those two worlds is where successful cloud strategies are won or lost.
The Questions We Should Actually Be Asking
The industry doesn’t need another generic “cloud vs. on-premise” debate.
The more important questions today are:
Who are you getting your Cloud from?
The provider of the cloud security solution is critically important. Long-term provider viability matters. So do certifications like SOC 2 Type II and ISO standards. Organizations need to deeply understand and fully vet their provider organizationally, as much as the functionality of their product, as they are who owns the data, who manages it, and who has access.
What’s your migration strategy?
Moving from on-premise to cloud isn’t just about flipping a switch. Migration costs, operational impact, historical data retention, and hardware upgrade strategies all matter. These migrations can take months to plan, and working with experts who have completed them before is critical to success.
Cloud Adoption Is Becoming More Practical and More Mature
A lot of the traditional barriers are steadily disappearing.
Migration tools are improving. Feature sets are catching up, and in some areas surpassing, traditional on-premise systems. Integration toolkits are becoming more robust, incorporating a variety of technology components, APIs, webhooks, SCIM, and cloud-native connectors. AI capabilities are being introduced faster in cloud-native environments.
Technologies from outside of the security industry, like MQTT, and more standardized IoT communication models will only accelerate this shift further by simplifying endpoint connectivity and interoperability.
And that’s probably the most important takeaway.
Cloud isn’t some future vision anymore. It’s a strategic direction the industry is actively moving toward, just with more realism, more complexity, and more operational nuance than early conversations suggested.
The question was never really just Why Cloud?
Now it’s about building the right path to get there and the time to do it.

Let me give you a bit of background. After 2001, demand for physical security upgrades increased across commercial buildings, schools, retail spaces, and other public facilities. Safety and security film became part of that conversation because it offered a way to strengthen existing glass without fully replacing it.
At the time, many people treated windows and doors the same way when it came to film installation. Apply the film, anchor it, and move on. But over time, it became clear that doors created a different challenge.
I remember an installation from the mid-2000s at a jewelry store. A few weeks after the project was completed, the customer called and said the security film had not stopped an intruder. After reviewing what happened, we realized the issue was not the film itself. The weak point was how the film had been anchored to the door.
That moment changed the way I looked at door film installation.
The problem was that the film had been attached to a removable part of the door frame using a method that was commonly accepted at the time. On paper, it checked the box. In real life, it did not perform the way the customer expected it to perform.
That is where the industry has had to evolve. Security film is only as strong as the system around it. The glass matters. The film matters. But the anchoring method matters just as much, especially on doors.
A few years later, another project made the same lesson even clearer. We were working on a large retail rollout that included both windows and doors. The specification called for a traditional anchoring method on the doors, even though we knew that approach had limitations. We raised the concern, but the response was simple: that was the specification, and that was how the team had been trained.
Not long after, there was an attempted break-in. The film performed well on the windows, but the door remained the easier point of failure. Again, the issue was not whether security film could add value. The issue was whether the door had been treated as its own problem with its own requirements.
That distinction matters.
For years, many door film installations were handled as if they were just another version of a window installation. But doors move. Doors flex. Doors have hardware, clearances, frames, and operational requirements that windows do not have. If the anchoring approach does not account for that, the result can look secure without actually providing the level of protection people believe they have.
This is especially important for schools, retail spaces, houses of worship, and facilities trying to improve security without replacing every door or piece of glass. These organizations are often working within real budget constraints. They are trying to make practical improvements with the infrastructure they already have. That makes it even more important that the solutions being installed are not just visually reassuring, but properly designed for the application.
The bigger issue is not just product selection. It is education.
Facility leaders, school administrators, security teams, and property owners should understand the difference between applying film and properly anchoring it. They should ask how the film is attached, what part of the frame it is attached to, whether the door will continue to operate correctly, and whether the full system has been tested for the way it will actually be used.
A security upgrade should not create a false sense of confidence. It should reduce uncertainty.
The industry has come a long way since the early days of safety and security film. We have better materials, better testing, and a better understanding of how different openings behave under stress. But the lesson remains the same: the details matter.
If a door is part of the security plan, then the anchoring method cannot be an afterthought. It has to be part of the design from the beginning.
Proper anchoring is not about making security film sound more impressive. It is about making sure the system performs the way people expect it to perform when it matters.

As someone who is still relatively new to the security industry, I arrived at Security LeadHER excited, but admittedly a little intimidated.
Not because of the event itself. Because of the people in the room.
When you’re early in your career, it’s easy to look around and see titles, accomplishments, years of experience, and leadership positions and wonder where exactly you fit into all of it.
That feeling lasted about five minutes.
What struck me almost immediately was how welcoming everyone was. Not in the surface-level networking-event way, but in a genuine way. The kind where people wanted to hear your story, share their own, and help you feel like you belonged.
And that’s when I started to understand why Security LeadHER is so important.
The security industry has always felt different to me. For an industry that is highly competitive, it also has an incredible sense of community. People compete during the day and then spend the evening sharing advice, making introductions, and helping one another succeed. There is a recognition that while companies may compete, people don’t have to.
Security LeadHER takes that spirit and amplifies it.
Not only does it create space for women in an industry where they remain underrepresented, but it brings together women from every corner of the industry. Manufacturers, integrators, consultants, end users, associations, technology providers, marketers, sales leaders, executives, and newcomers all sharing the same room.
The result is something special.
Every conversation becomes an opportunity to learn from a different perspective. Every table feels like a masterclass in leadership, career growth, resilience, and industry knowledge. You quickly realize you’re surrounded by decades of collective experience and people who are willing to share it.
One statistic shared during the event particularly stuck with me. Ellie Baldwin of Wavestore noted that women make up only about 11% of the security industry.
Eleven percent.
Sitting in a room filled with accomplished women leaders, innovators, and decision-makers, that number felt almost impossible to believe. Yet it made the purpose of the event even clearer.
When you’re part of a minority in any industry, visibility matters.
Seeing women leading companies, building teams, driving innovation, and shaping the future of security matters.
Meeting them is important..
Learning from them is important.
For newer professionals especially, it provides something that can be difficult to find when you’re first starting out: confidence.
Throughout the conference, I heard stories from women with completely different backgrounds and career paths. Some planned to enter security. Others, like me, found their way into the industry unexpectedly. Some came from technical backgrounds. Others came from marketing, operations, sales, or leadership.
No two journeys looked the same.
Yet there was a common theme throughout nearly every conversation: nobody waited for confidence to magically appear.
They advocated for themselves. They took chances. They raised their hands. They accepted opportunities before they felt fully ready. They trusted themselves enough to take the next step.
One keynote speaker Minda Harts delivered a message that clearly resonated throughout the room: advocate for yourself. Own your space. Take control of your career because nobody can do it for you.
Looking around the room, it was easy to see the proof.
These women didn’t arrive where they are by accident.
They built careers. They created opportunities. They opened doors for others.
And perhaps my favorite part of the entire experience was seeing how often women spoke about other women.
I’d meet someone impressive, only to hear them immediately recognize another woman who had helped them, inspired them, or paved the way for them. Then I’d talk to that person and hear them do the exact same thing for someone else.
It was a real-life example of the phrase, “We lift as we climb.”
Not as a slogan.
As something actively happening in front of me.
For someone entering the industry, that was incredibly powerful to witness.
Security LeadHER reminded me that representation matters, mentorship matters, and especially- community matters.
It reminded me that there is room for new voices in this industry and that the people already here genuinely want to help the next generation succeed.
Most importantly, it reminded me how fortunate I am to have found an industry that values relationships as much as results.
I did not leave Security LeadHER with a stack of business cards. I left with new friends, an unwavering support system, and a level of comfort in this industry that I did not expect to find so quickly.
I truly would not trade being part of this community for the world. I feel incredibly lucky to have fallen into a career field filled with women who make you feel supported, seen, and right at home.
đź‘€ As Seen in the PhySec Community this Week:
#security-research
-
Salvatore D’Agostino shared
How Millions of Digital Home Devices Are Secretly Powering Cyberattacks
#shameless-plugs
-
Auston Bunsen shared
Here's a little something for anyone wanting to exchange pubkeys and reader groups.

The ALOA Convention & Security Expo is coming up fast. From technical training to meaningful connections, ALOA 2026 is where the people behind physical security come together to learn, connect, and move the industry forward. This is where the industry gets back to the fundamentals, real skills, real conversations, and the people who actually make security work every day. Learn more and register here.

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 6–7, and sign up here to be notified first when registration goes live.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.