Volume 67
Volume 67 | July 10, 2026
This Week’s Featured Media, Articles, & Breaking News
🎙 Secured Podcast
|
Episode 23 | How Extreme Climbers Made a Mainstream Security Story in Manhattan ✍🏻 Articles |
![]()
Podcast | Secured: Episode 23
A couple got engaged 1,450 feet above Manhattan... and turned it into one of the biggest physical security stories of the summer. This week on Secured, Lee looks beyond the headlines to unpack what the Empire State Building climb actually reveals about physical security—and the questions almost no one outside the industry is asking. He also breaks down dormakaba's acquisition of Style Group, explores what iLOQ's latest financial results say about the future of access control, revisits the Verkada–NVIDIA partnership and the role AI is beginning to play across the industry, and introduces a new framework he believes will shape the next era of physical security: Intelligent Access.

Aliro was one of the most talked-about technologies at ISC West 2026 – visible in nearly every access control booth and driving conversations on and off the show floor.
The Aliro 1.0 standard was published in February 2026 as a new communication protocol and credential standard governing how users interact with access points. A few early adopters were already releasing Aliro-enabled readers and credentials at the show.
So what is Aliro? It is a standardized way to access digital wallets across brands and platforms. It was created by the Connectivity Standards Alliance (CSA), a global collective of more than 220 member companies that includes Apple, Google, and Samsung – the same organization behind the Matter smart home connectivity protocol.
What makes Aliro noteworthy is that it was driven largely from outside the security industry, with the security industry holding seats at the table. That matters. It signals that outside industries recognize the capabilities of physical security – and that without that outside influence, those capabilities might never reach a broader market.
“When the three largest mobile wallet providers in the world are helping drive an access control standard, that standard is likely to be part of the future.”
Jim Cooper – former CTO for two major integration firms and founder of Physec Systems, a consultancy focused on the intersection of physical security and cybersecurity – frames it well: "Aliro aims to do for access control what standardized mobile wallets did for payments."
What Problem Does it Solve?
Today, a user might open one app or credential wallet to access the office and a completely different one at the gym, at home, or anywhere else – each location running its own credential system. That fragmented experience, created by the absence of a common mobile-to-reader protocol, has been a significant barrier to mobile credential adoption and has forced proprietary lock-in at the reader level.
Aliro removes that barrier. An Aliro-enabled reader can read credentials across mobile wallets. A user taps their phone at the office in the morning and again at their front door that evening – same device, different credentials, one seamless experience.
How it Works Technically
In the Open Systems Interconnection (OSI) model, Aliro operates at the Transport Layer, which allows application-layer technologies to ride on top of it. Think of it as a secured pipe through which credentials travel. It still relies on secure connectivity – best practice is to deploy it over Open Supervised Device Protocol (OSDP) infrastructure.
Aliro is an open standard built on a device-bound cryptographic key stored in a Secure Element. It uses asymmetric cryptography – a public/private key system – and supports Bluetooth LE, Near-Field Communication (NFC), and Ultra-Wideband (UWB). The encryption is FIPS 185-6 and NIST 800-3D compliant. In plain terms: a secure, manufacturer-agnostic communication between a mobile device or wearable and the reader.
Here's how the transaction works: the mobile device holds a private key. When presented to an Aliro-enabled reader, the reader checks it against a public key. If they match, the door opens. Once the device has the key, the system can operate offline, verifying credentials cryptographically without a network connection.
How Does it Compare to PKOC?
If you read Paul Benne's Tech Trends column in the May 2026 issue (securityinfowatch.com/55373336), you may be wondering whether Aliro and PKOC are doing the same thing.
The short answer: similarly, but not identically. PKOC is platform agnostic – the credential can live on a physical card, a mobile device, or other secure hardware. Aliro is focused specifically on enabling interoperability between mobile devices, wearables, and access control readers. Different scope, complementary direction.
Two important limitations are worth understanding. First, Aliro does not govern the credential itself. As a secure transport, it acknowledges that a key signed a certificate and that a certificate authority vouched for it, but credential governance remains an unresolved challenge that the CSA and credential providers will need to address.
Second, proprietary lock-in has not been eliminated – it has simply moved. Aliro-enabled readers will pass Aliro-enabled credentials, but those credentials still come from specific manufacturers with their own private/public key pairs. The selection of a credential provider will remain a consequential decision.
Why it Matters to Integrators
Mobile credentials dominate access control conversations right now, particularly in multi-family residential, commercial, and higher education – yet actual adoption has lagged. Aliro may be what finally moves the needle.
Integrators have historically chosen credential technology based on familiarity or distributor availability. That approach worked in a simpler market. It won't be sufficient going forward. Specifying OSDP-enabled and Aliro-enabled readers for clients with future-ready deployments in mind is quickly becoming the baseline expectation.
When the three largest mobile wallet providers in the world are helping drive an access control standard, that standard is likely to be part of the future. Integrators who understand it now will be better positioned to lead that conversation with clients.
Originally published here.

Security glazing has become an increasingly common component of building design, particularly in schools, healthcare facilities, places of worship, government buildings, and other public spaces. As specifications continue to evolve, it is important to recognize that attachment methods suitable for window systems may not always perform the same way when applied to door assemblies.
One area that deserves careful consideration is the use of structural silicone as the primary attachment method for security film on glazed doors.
Windows and Doors Are Different Systems
Although windows and doors may appear similar from a glazing perspective, they are engineered differently and experience different loading conditions throughout their service life.
Many commercial doors are manufactured with removable glazing stops and compression gaskets that allow glass replacement and routine maintenance. These components become an important consideration when evaluating how a security glazing system is expected to perform after glass breakage, forced entry attempts, blast events, or severe weather.
Because of these design differences, an attachment strategy that performs well on a fixed window assembly may not produce the same results on a door assembly.
Understanding Attachment Methods
Security film manufacturers typically publish installation guidelines that specify how the film should be anchored to the supporting frame. These recommendations often exclude removable glazing stops and compression gaskets, emphasizing attachment directly to structural framing whenever possible.
Depending on the door design, frame geometry, and glazing configuration, achieving the recommended attachment dimensions may be challenging. This is particularly true for certain insulated glass units and doors incorporating angled or removable glazing stops.
These limitations should be evaluated during the specification process to ensure the selected attachment method aligns with both the manufacturer's installation requirements and the intended performance objectives.
The Importance of Performance Testing
When specifying security glazing systems, architects and consultants should review available performance testing rather than relying solely on material selection.
Relevant standards may include:
-
ANSI Z97.1
-
CPSC 16 CFR 1201
-
ASTM standards applicable to glazing systems
-
Project-specific forced-entry, blast, or impact testing where required
Because different attachment methods can produce different outcomes, reviewing complete test reports—including the door assembly, framing system, glazing configuration, and installation method—provides valuable context when evaluating performance claims.
Questions Worth Asking During Specification
Before specifying a security glazing attachment method for door assemblies, consider asking:
-
Was the complete door assembly tested, or only individual materials?
-
Does the attachment method comply with the security film manufacturer's installation guidelines?
-
How does the system perform after glass breakage?
-
How does the attachment interact with removable glazing stops and compression gaskets?
-
Is the tested assembly representative of the door system being specified for the project?
Designing for Long-Term Performance
Security glazing is one component of a broader life-safety strategy. Selecting an attachment method should involve consideration of the door assembly, framing system, manufacturer guidance, applicable testing standards, maintenance requirements, and the specific performance objectives of the building.
By understanding how different attachment methods interact with commercial door systems, architects and design professionals can make more informed specification decisions based on project requirements, available testing data, and applicable industry standards.
đź‘€ As Seen in the PhySec Community this Week:
#shameless-plugs
-
Zachary Klares shared
-
Sal D’Agostino shared
Refining the Design Principles of Identity Relationship Management. -
Janet Fenner shared
Jersey Shore Beach Party- Defined Marketing -
Virginia Ramsey shared
Calling all Safety Champions! Verkada extended the deadline to nominate Safety Champions until July 16.

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration is OPEN NOW! Sign up here.
Want to view some testimonials from previous years? Go here.
![]()
Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.
All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.
You can stream directly from our Secured channel.

West to East series: We're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.