Header Logo
Log In
← Back to all posts

Volume 66

Aug 03, 2026

Volume 66 | July 3, 2026

This Week’s Featured Media, Articles, & Breaking News

🎙 Secured Podcast

Episode 22 | $4 Billion Says Your Door Controller Is a Cybersecurity Asset. Is Your Company Listening?
Verkada hits 2.4M devices with Nvidia backing. Accenture bets $4.175B that door controllers are a cybersecurity problem. Plus: Gallagher's new AI visitor management play and why your industry has a marketing problem, not a budget problem…
Listen here

🎧 West to East series | This week we are featuring:
Matt Kopel
Darren Bain
Lucas Mason
Jacob Hengel

🎧 TSE 2026 XPod Series
Listen here

✍🏻 Articles

Tony Dong | How (and Why) Do Access Control Companies Borrow Money?
Using Allegion's latest 10-Q, a plain-English breakdown of revolvers, senior notes, and why borrowing unsecured is a vote of confidence from creditors. The ratios every access control executive should know before sitting down with lenders.

Andrew Campagnola | No Credentials Without Representation
One exec needs fifteen keys just to move around his own building — access control's credential chaos is really a governance problem. A look at why Aliro, Matter, and OSDP are this industry's shot at a shared standard, before it's too late to help write it.

Brian Karas | Verkada + NVIDIA = ???
Nvidia has struggled to gain traction in physical security — until now. Verkada's new collab skips the chipset hype and taps Nvidia's software directly, boosting AI search accuracy by 68%.

🚨Breaking

ASSA ABLOY Group acquires Santos, a Portuguese mechanical locking manufacturer

Gallagher Security launches a visitor management solution powered by Kenai, natively integrated with Command Centre.

Verkada is scaling its "physical AI" platform across more than 2.4 million devices in 170 countries with a new technical collaboration and investment from NVIDIA,

Scroll down to go deeper â†“


Podcast | Secured: Episode 22
Physical security just got a 2.4 million-device data point — and Nvidia's name is attached to it. This week on Secured, Lee breaks down Verkada's massive physical AI scaling announcement and why the real story isn't the investment number, it's the category claim. Then: Accenture just paid $4.175 billion for a majority stake in Dragos, Run Zero, and NetRise, suggesting your door controller is now a cybersecurity problem. Lee also covers Gallagher's new AI visitor management platform and drops a hard truth about the industry confusing small m marketing with big M marketing.

Listen here


As we wrap up the West to East series this week, we're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.

Watch the sneak peak for the following episodes here

Matts’s episode: here
Darren’s episode: 
here
Lucas’ episode: 
here
Jacob’s episode: 
here


Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.

All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.

You can stream directly from our Secured channel.


 

In previous briefs, we’ve talked about cost of capital, hurdle rates, and the three levers management can pull when organic growth starts to slow: acquisitions, buybacks, and dividends. Today’s topic underpins underneath all three: debt.

Forget what Dave Ramsey says - debt makes the world go round because one company’s liability is another investor’s asset. Most businesses already operate on some version of buy-now-pay-later, whether that’s net 30, net 60, or net 90 terms.  If every transaction had to settle in cash immediately, commerce would grind to a halt.

Used properly, debt lets management multiply its influence beyond day-to-day operations by using other people’s money to fund expansion, return capital to shareholders, or bridge timing gaps between the cash coming in and the cash going out.

That is why debt is such a powerful tool at the executive level, but also why it can become a Pandora’s box. Borrow intelligently at the right rate, with the right maturity schedule, and you can compound shareholder value faster. Borrow poorly, at the wrong time, with too much floating-rate exposure or too many near-term maturities, and the same tool can tank the business.

To make this concrete, I’m going to use Allegion’s latest 10-Q as a case study. The goal is not to turn everyone reading into credit analysts. I want to show you how an access control executive should think about leverage before walking into a meeting with lenders, underwriters, or private equity sponsors.

Allegion’s Debt Stack: What Are We Looking At?

Allegion does not rely on one single source of borrowing. It has a mix of a revolving credit facility and several senior unsecured notes. We’ll break each of these down section-by-section, along with a high-level takeaway for you to digest at the end.

The Revolver: Flexible Liquidity With Floating Rate-Exposure
The revolver is basically a corporate credit card, except much larger and more formal. Allegion has access to a $1 billion unsecured revolving credit facility maturing in 2030. As of March 31, 2026, it had drawn $240.6 million on it, up from $190.6 million at the end of 2025. 

The interest rate on this facility floats with the Secured Overnight Financing Rate (SOFR) plus a spread, and at quarter-end the effective rate was 4.798%. Should rates fall, the interest cost on that revolver should come down. But if rates rise, it gets more expensive. 

This is why access control executives can’t only live in product and service land. At a certain level, you have to be a mini-CFO too, because what the Federal Reserve and bond markets do directly affects how cheaply, easily, and flexibly your company can borrow. So, keep an eye on macroeconomic indicators and releases such as Fed rate decisions, Treasury yields, credit spreads, CPI inflation, unemployment data, GDP growth, and bank lending standards. 

Econometrics may feel removed from day-to-day operations, but they shape the cost and availability of capital that funds acquisitions, hiring, inventory, R&D, and shareholder returns.

Senior Unsecured Notes: Long Term Capital Without Collateral

The revolver is only a relatively small part of Allegion’s total debt. Most of the borrowing sits in fixed-rate senior notes, which are traditional corporate bonds where Allegion agrees to pay a set coupon until principal is returned at maturity, regardless of what happens to short-term interest rates.

Specifically, Allegion has $400 million due in 2027 at 3.55%, $400 million due in 2029 at 3.50%, $600 million due in 2032 at 5.411%, and $400 million due in 2034 at 5.60%. These are unsecured obligations, meaning they are not backed by specific collateral the way a secured loan would be. 

Collateral management is a major part of corporate borrowing. If a lender is worried about repayment, they want assets they can claim if things go wrong. The cleanest collateral is usually tangible and liquid: cash, receivables, inventory, equipment, real estate, or ownership interests in subsidiaries. 

Some intangible assets can count too, such as patents, software, trademarks, or customer contracts, but lenders usually haircut those heavily because they are harder to value and harder to sell in distress. Importantly, goodwill, brand reputation, management talent, and “competitive moat” are not useful collateral in the practical sense, even if they matter enormously to an access control business

When Allegion can borrow unsecured, that says something. Creditors are comfortable lending against the overall enterprise, not just a pile of pledged assets. They are effectively underwriting the durability of the business model, cash flow, margins, credit rating, and management’s ability to keep servicing debt. 

For an access control company with a mix of hardware, services, software, and installed-base relationships, being able to borrow unsecured is a meaningful vote of confidence.

Why Debt Timing Matters As Much As Debt Size

The maturity ladder also looks reasonable because there is no giant wall of debt due tomorrow. The first real maturity is the 2027 senior notes, followed by 2029, 2032, and 2034. That gives management time to refinance, repay, or roll debt depending on market conditions.

Timing mismatches are what kill leveraged entities. For banks, the classic failure mode is borrowing short and lending long. Depositors can pull money immediately, while the bank’s assets are tied up in longer-duration loans or securities. If too many liabilities come due before assets can be converted into cash, you get a liquidity crisis even if the institution looks solvent on paper.

An access control company is obviously not a bank, but the same basic timing problem can still show up. You may have debt maturing at the same time customers delay payments, inventory needs to be rebuilt, acquisitions require integration spending, or a weak construction cycle pressures orders. If too much debt comes due at once, management loses flexibility. They may be forced to refinance at bad rates, issue equity at a poor valuation, cut investment, or pause dividends and buybacks.

This is also why I dislike extreme just-in-time thinking. It looks efficient right up until conditions change. Running lean on inventory, cash, borrowing capacity, or supplier redundancy can flatter margins in normal periods, but it removes margin of safety.

A well-laddered debt schedule is the financial version of keeping spare parts on hand. It may look suboptimal in a spreadsheet, but when markets seize up, it gives management room to breathe.

The Ratios Executives Should Know

My overall read is that Allegion is borrowing reasonably well. The company has locked in a meaningful portion of its debt at fixed rates, including some legacy borrowing at attractive coupons in the mid-3% range. It uses the revolver for flexibility rather than as the foundation of the balance sheet. It has spread maturities over time. And it remains in compliance with its leverage covenants.

But as an access control executive, you do not need to live inside a 10-Q to understand whether a company is borrowing well. I still recommend thoroughly reading the filings (especially if you invest), but there are a handful of ratios that can do most of the heavy lifting.

Total debt to equity tells you how much debt the company uses relative to shareholder capital. A high ratio is not automatically bad, but it means the company is leaning harder on creditors. For stable, cash-generative businesses, that can be fine. For cyclical businesses, it can become dangerous quickly.

Current ratio compares current assets to current liabilities. A ratio above 1 means the company has more short-term assets than short-term obligations. Allegion’s recent current ratio sits 1t 1.91, which indicates robust coverage.

Quick ratio is a stricter version of the current ratio. It excludes inventory, because inventory may not be easy to convert into cash quickly. This matters more for hardware-heavy businesses in access control where inventory can become stale, delayed, or mispriced.

The last distinction is operating cash flow versus levered free cash flow. Operating cash flow tells you how much cash the business generates from operations before financing decisions. Levered free cash flow tells you what is left after capital expenditures and debt servicing. 

As we’ve discussed before, for shareholders, levered free cash flow is often the more relevant number because it represents the pool available for dividends, buybacks, acquisitions, or debt reduction.

Free screeners like Yahoo Finance can show some of these metrics, but they are not always accurate. My recommendation is to manually calculate them a few times from the 10-Q or 10-K. It forces you to understand the inputs and relationships. After that, use a reliable data source to save time. SEC EDGAR, company investor relations pages, StockAnalysis, Macrotrends, and Koyfin are all useful starting points, but the audited filing should always be the source of truth.

To sum it up, debt is not good or bad in isolation. It depends on the rate, maturity, structure, and what management does with the proceeds. If you can understand those four variables, you’ll be much more confident in high-level meetings when the CFO, controller, lender, or underwriter starts talking about credit facilities, covenants, refinancing windows, and cost of capital.


"No taxation without representation" was a governance argument disguised as a tax dispute. One distant authority wrote the rules; everyone downstream paid and complied without a vote. This weekend the country that argument built turns 250.

Access control has spent the last twenty years living under a quieter version of the same deal. A manufacturer publishes a credential format, stamps the word "standard" on it, and every building downstream pays to operate inside it with no say in where it goes next. We just never called it what it was.

I felt it long before I could name it. Years ago, working out of an office in NYC, I carried five separate credentials to get from the parking garage to my own suite. Five systems, five formats, five things on the lanyard, each one certain it was the front door.

From the panel stage at the CSA's first Unify conference in Austin a couple of weeks ago, I put the bigger version on the record. A commercial tower with forty tenant floors above the base building can run forty-one different access control systems, the base building plus one for every floor, with forty-one credentials to match. Phil Jang, an end user representing SIA SPARC, boiled it down to a single number: fifteen keys to get around his own organization. That is the default now. It's an Articles of Confederation problem, a collection of sovereign, well-meaning systems that never had to talk to each other and so never learned how.

Tobin Richardson, CEO of the CSA, spent his keynote tracing the way out. Every technology walks the same road: innovation, silos, fragmentation, standards, and finally invisible infrastructure nobody thinks about. The lightbulb did it. The telephone did it. The internet did it. His wager is that AI speeds the trip up, rewarding the open systems that can absorb it and stranding the closed ones that can't.

What made Unify land for me was the room itself. The panels put direct competitors on the same stage: Kastle, Allegion, ASSA ABLOY, HID, Dormakaba, Safetrust, LastLock, and MC Dean. Aliro is governed by the CSA's members, which means the companies that have to live with the standard are the ones writing it. That is what representation looks like, and it is the whole difference between a standard and a "standard." Lee Odess described Aliro as the first credential built for the fragmented world we actually have: asymmetric, wallet-native, and sitting with IT instead of facilities.

The shift it demands is real. Ratifying the Constitution meant every state handed over a concrete piece of sovereignty to get a durable union back. Aliro asks that same trade of vendors, as does Matter, and so does SIA's OSDP. Some manufacturers will feel it as a loss. What they get for it is a market that scales past any one company's roadmap.

Kevin Ashton, who coined "the Internet of Things" in 1999, gave the line that stuck with me hardest. Companies that wait forfeit something they can't buy back later: the muscle memory that only comes from being inside a standard while it's still being written. The states that showed up early to the Constitutional Convention shaped the document. The ones that dragged their feet spent the next century arguing over what they had signed.

Jason Hart at Safetrust is already earning that early-mover interest. He's demoing an Aliro card reading in well under 300 milliseconds, about as close as an open, secure credential has come to the instant tap of legacy prox, and he's blunt about what follows: the standard guts the old reader-vendor fee model, the one where you pay a hardware company to provision your own credential in its proprietary format.

Travis Willis offered the honest counterweight. Most large enterprises still don't grasp what Aliro is or what it changes, and closing that gap is real work. Fair enough. The framers didn't agree at first either. A standard earns its trust by being stress-tested on the way up, before it hardens into infrastructure.

So here is the question that hung over the room in Austin, and the one I'll leave with you. If your company committed tomorrow, would it move the curve at all? A lot of the biggest names in this industry were there telling everyone else to get on board while their own houses sat half-finished. The cobbler's kids need shoes too.

Two hundred fifty years ago a handful of people signed onto a shared framework before it was proven, comfortable, or fully written, because the alternative was worse. Sitting out Aliro, Matter, or OSDP is a choice with the same shape. It's just risk, dressed up as patience.

Happy almost-Fourth. This year, be a framer.


The PR of Verkada’s collab with NVIDIA was posted in the PhySec Slack group this week (if you’re not already there, definitely check it out). My initial take that I posted was “There is absolutely nothing noteworthy about this.” And while I do stand by that, I think this is worth digging into just a little bit more to see what it could signal for AI in the security industry.

First, if you’ve been following the progress of AI in the security industry as long as I have, especially as it relates to NVIDIA, you will have seen that NVIDIA has failed to carve out a real segment in our industry. Despite being practically synonymous with the term “AI”, NVIDIA’s name does not really come up much in security. Their GPU’s power 99% of the PC/server-based AI software platforms in the market, but this is not very noteworthy and does not tend to get called out as a primary spec in any of these products. NVIDIA has been an on-again off-again exhibitor at ISC West, but they’ve failed to make much traction in the embedded devices common in the security industry. For the most part, their smallest GPU’s, the Jetson family, have been considered too expensive and too power hungry (and often overkill) for the typical embedded devices market. In this area, Ambarella, and more recently Hailo, have been the dominant chip suppliers for AI-enabled edge equipment.

For some of the very few NVIDIA-powered devices, like the Hanwha PNM-C32084RQZ multi-sensor camera, reception has been limited at best, often due to very high prices compared to similar products with competitive processors. While press releases were issued when the Hanwha and NVIDIA partnership was launched, the fanfare was much less. In particular most of these releases focused on the Jetson chipset itself, and did not elaborate as much on the real-world use cases enabled.

In contrast, Verkada’s press release specifically mentions:

By leveraging NVIDIA Cosmos world foundation models and NVIDIA Physical AI Data Factory, Verkada has accelerated model training and inference across its rapidly expanding global footprint on NVIDIA accelerated computing. Since the collaboration began, Verkada has improved the mean average precision (mAP) of its AI-powered search by 68% for spatial-temporal understanding, delivering faster, more accurate, and more robust search capabilities.

This is where I think the real news is. Verkada is not getting caught up in chipsets and GPU specs, in fact they are more focused on the side of NVIDIA that NVIDIA thinks they are best at: software. If you talk to NVIDIA employees, they will tell you that NVIDIA at the core views itself as more of a software company than a hardware company, the hardware is just the means to the end. Verkada appears to be one of the few security companies embracing this, catching up to most of the rest of the world deploying AI for sensing applications. Build on top of, and wrap specific applications, around the software that NVIDIA has already spent hundreds of millions of dollars developing.

There is a risk though, by taking this route, Verkada becomes dependent on NVIDIA, and has less control over another company releasing features with similar capabilities, built around the same NVIDIA core. Verkada would surely tell you they can do this better and more effectively than their competitors, but that is also the standard line any company would give.

When it comes to AI development, this “buy vs. build” approach has been a core element in product design and messaging strategy. By building your own AI stack, you can claim a more unique set of capabilities, but at much higher R&D cost. By buying your AI stack you can get to market faster, but often at the risk of less control over the core performance of your system. I’ve been on both sides of that at various AI startups, and I do not think there is a perfect answer. More importantly, the market does not really care where your AI comes from, or even where and how it runs, they just want assurance it will perform predictably, and at a reasonable price.

In the big picture, this partnership is not noteworthy to me. It’s two big companies doing what they do. Verkada has built a monster brand in security and so it is not surprising to see NVIDIA want to associate themselves with Verkada this way. NVIDIA is an AI powerhouse, and it does not make sense for Verkada to try and build their own AI stack alongside everything else they are doing. In some ways, the most notable aspect of this partnership was that it did not happen sooner.

I do want to be clear, while this may not be noteworthy, I do think it is significant, even if that sounds a bit like an oxymoron. Verkada stumbled in their early days finding an optimal GTM strategy, but by most accounts they have fixed those issues. With a respectable install base of cameras, and an army of a sales team, Verkada should be able to leverage this collab to major benefit. But I’d like to think this is exactly the sort of thing we should be able to expect in the market, it is hopefully something we will see with enough frequency that these releases become absolute yawners.


đź‘€ As Seen in the PhySec Community this Week:

#ai

  • Salvatore D’Agostino shared

    -AI firms craft state rules as White House, Congress stall
    -AI Agent Resource Extension for the System for Cross-domain Identity Management (SCIM)

  • Tony Dong shared

    The concerns about Mythos-class models and cybersecurity were not, in fact, hype.

#shameless-plugs

  • Jon Harris shared

    I've posted a lot on LinkedIn about my joy of running and how it saved my life.


Kiwi AMA from 7/1 @12pm EST titled: Why Access Control Needs a Pull Strategy with Karsten Nolling.

Watch the full session here!


ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration opens next week. Sign up to be notified first — early access pricing ($200 off) is available to the first registrants. Pre-register now to lock it in: Sign up here.

Want to view some testimonials from previous years? 
Go here.


🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.

Community input form!

 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 69
Volume 69 | July 24, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE DealTwo decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.Listen here ✍🏻 Ar...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.