Header Logo
Log In
← Back to all posts

Volume 69

Aug 03, 2026

Volume 69 | July 24, 2026

This Week’s Featured Media, Articles, & Breaking News

🎙 Secured Podcast

Episode 25 | SwiftConnect Just Bought 20 Years of Trust: Inside the HID SAFE Deal
Two decades of governance trust just changed hands — SwiftConnect acquired HID's workforce business unit this week. Also: the quiet Kansas City operation that ran security behind the entire World Cup.
Listen here

✍🏻 Articles

Tony Dong | The Curious Case of Napco Security Technologies (NSSC)
Napco has been public for more than 35 years, built a high-margin recurring revenue business, and sits in the middle of one of the biggest shifts in access control. So why is it still independent? This article explores whether Napco is caught between two eras—or positioned to define the next one.

Austan Palmer | Smart Building Management Solutions
Every credential swipe and denied entry tells a story — most organizations just aren't reading it. Austan Palmer makes the case for treating your PACS data as an intelligence source, not just a historical record.

Jon Polly | Access Control Is Obsolete; A Glimpse At Its Future
In this piece, Jon argues the access control panel itself may be the industry's biggest legacy holdup. A provocative case for IP-native, PoE-powered door intelligence — and why he thinks Prox and Wiegand need to go.

Michael Stuer | It has to work on a Tuesday
The biggest risk to physical access isn't always a lost key or a break-in. Sometimes it's the everyday processes we rely on without questioning. This article explores why key management isn't a day-one problem—it's an every-day problem.

🚨Breaking

-
ASSA ABLOY Group posts record Q2 2026 margin and organic grows to 4%

- Allegion posted Q2 2026 earnings, its strongest quarter in the trendline.

- Kahl Betham is stepping down as Gallagher Group CEO at the end of the company’s financial year on March 31, 2027.

- Secure Passage turned its Kansas City headquarters into the Joint Operations Center for FIFA World Cup 2026™ - Canada, Mexico and the United States, and we now have more detail behind the story we posted earlier about security's silent role in the tournament.

Scroll down to go deeper ↓


Podcast | Secured: Episode 25
While the world watched the World Cup, a company in Kansas City was quietly running the security operation underneath it — proof, Lee argues, that access control is mission-critical infrastructure, not a back-office afterthought. That story shares the episode with a bigger one: SwiftConnect has acquired HID's workforce business unit, picking up HID Safe, EasyLobby, and two decades of governance trust they couldn't have built on their own. Lee also digs into NAPCO Security's numbers, a piece on why "day one" access control thinking quietly fails, and his case for why the real TAM in this industry is bigger than most people want to admit.

Listen here


This brief started from a Slack conversation with Lee, who flagged Napco Security Technologies (NSSC) to me as one of the more interesting under-discussed names in access control.

His thesis was simple: access control is moving from a roughly $10 billion hardware business into a much larger identity, software, and platform market. In that world, the winners are not necessarily the companies that make the best panels, locks, or intrusion devices. The winners are the companies that successfully change their business model around recurring revenue, software attach, identity, and platform economics. Napco sits right at that awkward fork in the road.

It has been around since 1969 and has built recognizable brands across security hardware, including NAPCO Security Systems, Alarm Lock, NAPCO Access Pro, and Marks USA. Its products span access control, door locking, intrusion, fire alarm, video surveillance, and connected communications, and it sells primarily through independent distributors, dealers, and installers.

Napco also been public for a long time. Based on the stock history I pulled, Napco has been listed for about 36 years. Over that period, it compounded at roughly 12.6% annually, good for a cumulative return of more than 7,287%. But the path was not remotely smooth. At one point, the stock suffered a drawdown of more than 90% and spent around 12 years underwater.

That is the first odd thing about Napco. For a company that has been public for more than three decades, generates high-margin recurring service revenue, and now sits in the middle of a major industry transition, it is still only a small-cap company. Its current market cap is about $1.34 billion.

So, the question is not simply, “Is Napco a good business?” The better question is, “why (and how) is Napco still independent in 2026?”

A Company Caught Between Two Eras

The financials show both sides of the story. On the positive side, Napco is not just a sleepy hardware manufacturer. In fiscal 2025, recurring service revenue increased 14% to $86.3 million, carried a 91% gross margin, and represented 48% of full-year revenue.

Management also reported a prospective annual recurring service revenue run rate of about $94 million based on July 2025 recurring service revenues. That is the part of the business the market should care about. Hardware gets you into the building. Recurring communication services, subscriptions, platform usage, and connected devices are what improve the multiple.

The latest 10-Q continued that pattern. For the nine months ended March 31, 2026, total revenue grew 11.9% to $146.5 million. Equipment revenue increased 10.9% to $74.3 million, while recurring service revenue increased 13.0% to $72.2 million. In other words, recurring revenue is now almost matching equipment revenue dollar for dollar.

That is meaningful, but it also reveals the tension. Napco is not yet a pure software platform. It is still a hybrid company with one foot in the legacy hardware-and-dealer-channel world and one foot in recurring services. The dealer and integrator network remains central to the model.

The company itself says its products are sold principally through independent distributors, dealers, and installers, and that those dealers rely on Napco’s platform for communication services tied to radio communicators and smart security devices.

That makes Napco a classic transition story. The recurring revenue and subscription attach model is real. But the company is still structurally tied to the hardware channel that got it here, for better or worse.

Platform Squeeze

This is where Lee’s “platform squeeze” framework is useful. A platform squeeze happens when a company is large enough to have a real installed base, real customers, and real recurring revenue, but not large enough to control the full platform layer.

It can be squeezed from above by larger strategic acquirers with broader ecosystems, and from below by newer software-native entrants that do not carry the same legacy hardware economics. To me, that feels like the right way to think about Napco.

On one side, you have the large consolidators like Allegion and Assa Abloy. They have scale, balance sheets, channel reach, and the ability to acquire technology rather than build everything internally. On the other side, you have software-first and identity-first companies trying to redefine access control around cloud, mobile credentials, user identity, permissions, analytics, and integrations.

Napco is not irrelevant in that world. Quite the opposite, as its recurring revenue base proves it has something valuable. But the company now has to decide what it wants to become. Does it stay a solid, profitable, founder-influenced security company that grows at a reasonable pace in a cottage industry? Or does it invest more aggressively to become part of the larger identity, software, and platform layer?

Both outcome becomes more complicated when you are publicly traded, as opposed to privately held. Thus, the next point of inquiry I had was ownership.

The Ownership Question

If Napco were a tightly controlled family company with dual-class shares or majority insider ownership, the answer to “why hasn’t it been acquired?” would be easier. The family could simply block a deal. However, that does not appear to be the case. There also does not appear to be a dual-class structure in the proxy. Each common share gets one vote.

According to Napco’s 2025 proxy, Richard Soloway beneficially owned about 1.5 million shares, or 4.23% of the common stock, while Donna Soloway owned less than 1%. All named executive officers and directors as a group owned about 2.0 million shares, or 5.65%. Vanguard and BlackRock were listed as larger 5% shareholders, at 8.00% and 7.07%, respectively (likely through their funds).

So, Napco is family-influenced, but not family-controlled in the way many private company operators might assume. Richard Soloway has been involved with the company for decades, serving as chairman since 1981 and CEO since 1998, and Donna Soloway has also served on the board.

In July 2026, Napco announced a leadership transition, with Richard Soloway moving from chairman and CEO to Founder and Executive Chairman, and Kevin Buchel becoming CEO and President. Once a founder-led company transitions into its next leadership era, the market often starts asking whether independence still maximizes shareholder value.

If you are a public small-cap company, have no controlling shareholder, have high-margin recurring revenue, and operate in a consolidating industry, you are at least theoretically exposed to activists, hostile approaches, or strategic acquirers. But Napco has escaped acquisition scrutiny so far.

Why Hasn’t Allegion or Assa Abloy Bought It?

I don’t know whether Allegion, Assa Abloy, or anyone else has ever approached Napco. If there have been serious discussions, they are not disclosed in the filings I reviewed. But from my perspective, there are a two plausible reasons Napco has stayed independent.

First, the valuation may not have been easy to justify. A company with a high-quality recurring revenue stream can trade at a premium, even if the overall business still has hardware cyclicality. A strategic buyer has to ask whether it is buying a software-like recurring revenue business or a hardware business with a recurring revenue wrapper. The answer affects the multiple, which right now for Napco is rich at an EV/EBITDA of 20.3x-22.2x.

Second, the channel may matter. Napco’s dealer and installer network is an asset, but it is also a constraint. Strategic buyers have to think carefully about channel conflict, product overlap, and whether the acquired installed base can be migrated into their broader platform without disrupting dealers.

However, both arguments get weaker as the company becomes more strategically relevant and still remains small. At a $1.3 billion market cap, Napco is not too big to buy outright. For a global strategic with a large balance sheet, this is digestible.

The more recurring service revenue grows, the more attractive the asset becomes. The irony is that the more Napco proves Lee’s thesis right, the more likely it becomes that someone else wants to own it.

Nokia Moment or Oracle Moment?

The risk is that Napco remains a good hardware-and-dealer-channel company in an industry increasingly valued around software, identity, and platform control. The opportunity is that its recurring service revenue gives it the bridge to become something more valuable. Recognizing both, I’d personally place Napco somewhere between the first and second of three company archetypes.

  1. The first is Legacy Incremental. These are companies that keep doing what has worked historically. They add products, improve hardware, raise prices, and grow through the existing channel. This can be profitable, but it rarely commands a platform multiple.

  2. The second is Bolt-On Transformed. These companies still have legacy hardware roots, but they successfully attach recurring software or service revenue to the installed base. This is where Napco appears to be today. The numbers support that view. Recurring service revenue is growing faster than equipment revenue and carries much higher margins.

  3. The third is Built for the $100B Era. These are companies designed around identity, platform economics, software integrations, and recurring revenue from the start. Hardware may still exist, but it becomes the wedge, not the business model.

What This Means for Family-Owned Security Companies

There is a broader lesson here for family-owned security companies: going public is not automatically the superior path. Public markets give you liquidity, visibility, access to capital, and a currency for acquisitions. They also expose you to mark-to-market volatility, institutional shareholder pressure, activists, and hostile approaches unless you have voting control.

Napco’s history shows both sides. Long-term shareholders have done very well if they endured the volatility. But the company also spent long periods underwater, experienced severe drawdowns, and remains small enough to be strategically digestible despite decades as a public company.

For a family-owned security company, the question is, “what problem does going public solve?” If the goal is to preserve independence, build patiently, and choose your own exit, staying private may be more rational. If the goal is to scale aggressively into software, identity, and recurring revenue, public capital can help, but only if management is ready for the accountability that comes with it.

Napco is a case study in the middle. It is not a failed company nor a sleepy hardware relic. It is a profitable, strategically relevant, founder-influenced small cap sitting at the edge of a much bigger market transition. The company has enough recurring revenue to prove the model is real, enough hardware exposure to keep the legacy risk alive, and enough public-market vulnerability to make independence an open question.

So, Lee’s original point stands: Napco can keep growing at a respectable pace and remain a good company in a cottage industry, or it can change, invest, and try to become something much larger. The numbers suggest the door is open, the risk is whether management wants to walk through it before someone else decides to knock aggressively.


Every credential swipe, denied entry, and after-hours access event tells a story.

Organizations invest significant resources to identify risk earlier, improve compliance visibility, and better understand how people interact with critical facilities. Yet many overlook one of the richest sources of intelligence they already possess: their physical access control system (PACS).

Most enterprises have accumulated years of access control data. Every credential transaction, denied access attempt, after-hours entry, and movement through a facility has been recorded. Despite the volume and value of this information, it is often treated as little more than a historical record.

That perspective no longer reflects the role access control data can play in modern security programs.

Traditionally, a physical access control system was designed to determine who should have access to a space and document the outcome. Those functions remain essential, but they represent only part of the value these systems generate.

Access Control's Untapped Intelligence Advantage

What many organizations fail to recognize is that access control systems continuously capture behavioral information. Over time, those records establish patterns that reveal how facilities are used, how employees and contractors move through an environment, and what normal activity looks like across the organization.

Once those patterns are understood, deviations become easier to identify.

An employee begins accessing areas outside their typical workflow. A contractor's credentials remain active long after a project ends. Sensitive spaces experience increasing after-hours activity. One facility consistently generates more denied access events than comparable locations. Viewed individually, these events may seem insignificant. Viewed collectively, they provide valuable context about operational risk, policy compliance, and emerging security concerns.

This is especially relevant as organizations strengthen insider risk programs. Conversations about insider threats often focus on cybersecurity controls and digital activity monitoring. While those capabilities are essential, physical behavior can provide equally valuable signals. Changes in access patterns, unusual movement through facilities, or repeated attempts to enter unauthorized areas may indicate the need for closer review.

The data itself is not evidence of malicious intent. It is an intelligence source that helps organizations identify anomalies earlier and investigate concerns with greater context. Beyond individual behavior, access control data also provides a clearer picture of facility risk.

Building a More Data-Driven Security Strategy

Security leaders are routinely asked to justify investments, prioritize resources, and explain why certain locations require additional attention. Those decisions are often influenced by anecdotal information or perceived risk. Access control data introduces a more objective foundation.

Patterns in credential usage, after-hours occupancy, access violations, and facility activity help organizations identify locations that warrant closer examination. Instead of relying on assumptions, security programs can make decisions supported by observable behavior.

The challenge is rarely a lack of data. It is a lack of integration.

In many organizations, access control remains isolated within the physical security function. Security teams manage credentials and investigate incidents, while risk, compliance, operations, and executive leadership rarely engage with the information being collected. As a result, a valuable source of operational intelligence remains disconnected from broader business decisions… Continue reading here


As enterprise security leaders demand cyber-hardened infrastructure, lower deployment costs, and greater scalability, traditional access control architectures are facing growing scrutiny. This provocative industry perspective argues that the future of access control lies beyond legacy panels, proprietary ecosystems, and decades-old communications protocols—toward IP-native, PoE-powered, software driven door intelligence.

There is a divide in the security industry, maybe you've noticed. Talk of innovation and next-generation systems, and finally, access control. While this article challenges the access control industry, let's first look at the security camera.

Internet Protocol (IP) cameras were released in 1996 by Axis Communications. Some companies, like Pelco, chose in the early 2000s not to innovate around technology, costing the company dearly; a decision they have since reversed. Today, many of the cameras installed are IP cameras.

The argument now is, can a camera's functionality get any better? We have camera sensors that can see in starlight. They can take pictures at any frame rate between 1 fps and 120 fps. Cameras capture anywhere from 1080p (2MP) to 96MP with a single imager. There is not much more to a system. Access control is not sexy. It does not grab attention until it fails. Most people view access control as little more than a database of actionable users, mobile credentials, biometrics, etc.

The question should be, why? Access control manufacturers seem to be making futile attempts to stay relevant by answering the following question: how to take market share from HID and Mercury, while keeping their access control systems from being ripped out. Concerns like how can make a better board or how can we replace or retrofit the "x" brand with the "y" brand. Here, let's add MQTT so this board can talk to that board, or let's make a new standard so all who use it are "open," a term that has become synonymous with the kitchen sink. Who can make a better credential (card, fob, mobile credential, etc.)? These are very good ideas, but they are band-aids at best.

What's difficult is that some of the access control manufacturers know it. For example, a VP of product at an access control manufacturer recently stated that "the status quo is no longer good enough." That limiting mindset seems to be at the heart of most access control manufacturers, when the status quo is never good enough. Here's a novel idea: instead of trying so hard to keep customers through proprietary systems designed as traps, give them a reason to stay. For some, the answer is to suck less; yes, I said it. Maybe the product was rushed to market or is marred by years of technical debt, but that does not function optimally.

Maybe it's just better support for the integrator and the end user. For others, this will require removing the bloat and kludgy aspects of the software. "Maybe it's time for genuine innovation, rather than simply matching your competitor's features," says Brett Zelnio, Principal Consultant with Stratified Logic Group and co-thinker on this article. The access control industry is the only segment within the security industry where innovation can stall, sometimes for years or decades, and no other company will overtake it. Those brands that do innovate get to talk about it for years, as it may be years before their next innovation. Compare that to a camera manufacturer that fails to innovate: 50 other companies release their "x brand killer" within a year.

While we are not tackling issues like 125 kHz Prox and Wiegand, which are being perpetuated as "security" solutions? Opinion time: Prox, as a technology, is not going away because it has many applications beyond security. For the security industry, 125 kHz Prox is the tech that just will not die, despite most respected security practitioners calling for its demise. As an industry striving to provide true security, we must design away from it. For those selling Prox, an end-user license agreement (EULA) is long overdue and states that if you use Prox, all liability falls solely on the end-user.

Watch how fast Prox goes away. Integrators who install Wiegand readers should be required to complete a similar EULA with the distributor. Wiegand's lifespan will likely drop dramatically. Wiegand has a migration path to Open Supervised Device Protocol (OSDP), a bidirectional secure RS-485 communication protocol between the panel and peripherals. However, many installers are still unaware or untrained on OSDP. So are manufacturers… Continue reading here


It is a Tuesday, and the key desk is doing what it always does. A technician signs for a key to the pump house, due back by four. A new starter is given hers, logged with the building, the date and a signature. A contractor hands back his fob with the two keys he borrowed last week. The person running the desk writes down every movement as it happens, keeps the record straight, and can tell you from memory who holds what across the whole site. It works. It is admirable. And it is the most fragile arrangement in the building.

That desk is everywhere. A council depot in regional Australia, a plant gate in Germany, a university campus with one issue window. The software differs, the paper differs, the Tuesday does not.

An auditor sees a desk like this once, and asks you to prove one decision. The person behind it answers for all of them, every day.

Most of our industry treats physical access as a day-one problem. Set it up correctly when someone starts, issue what the role requires, and the job is done. I think day one is the easy part, and it is where most of the effort stops. Day one announces itself. Someone is standing at the desk, the form has arrived, the role says which doors. The days after do not announce themselves. Work runs long and access quietly outlives it. People move between buildings and the keys do not move with them. Nothing fails, nobody decides anything, and by Friday the record is a little less true than it was on Monday. A careful register records what went out. The rule about what should come back, and when, lives somewhere else. Usually in someone’s head.

You see what that costs the week the desk changes hands. The handover took three days and it was thorough. The records are immaculate, every movement entered on the day it happened, going back years. By Wednesday the new person has found the edges of what those records never held. The contractor who always gets the gate key without signing, because everyone knew him. The master key lent to the works crew and never booked back in. The fob that still opens the yard under a name that left last year. None of it was written down, because it never had to be. It lived with the person who just left.

That is not the operator’s failure. It is the arrangement’s. We have built a job that only stays correct while one person carries it, and then we call that person indispensable and hope they never get sick. The discipline deserves respect. It should not have to be heroic. What the desk needs is one place that holds the rule itself. It knows who may hold what, shows you where the record has drifted from it, and remembers it the same way in three years as it did in the moment. Being correct stops depending on someone being there to remember. That is the part of the job portier exists to carry.

The daily work does not go away. Keys still move, jobs still run long, someone still has to say yes at the gate. The right system does not make any of that effortless. It makes it hold. Our industry designs for the worst day, the break-in, the lost master key. But the worst day is rare, and the ordinary day is where a record quietly becomes true or untrue. A site that is right on every Tuesday is already right on the day it matters.

Originally published here


👀 As Seen in the PhySec Community this Week

#ai

  • Laurie Dickson shared

    Wasabi just launched a MCP beta feature that connects Wasabi Hot Cloud Storage to AI systems/agents.  I would love to hear thoughts on how you guys might find this valuable for an AI-aided platform or analytics.

  • Salvatore D’Agostino shared
    OpenAI admits its models hacked another company in "‘unprecedented cyber incident’

  • Tony Dong shared
    The ChatGPT maker said the ‘agent’ escaped a testing environment, gained internet access stole login credentials and hacked into the start-up Hugging face by itself…

#job-board

  • Brett Ennals shared
    Director of Key Accounts – Access Control | Remote (US) | Extensive Travel (Join the job-board channel in the PhySec Collective to view details on this role)

  • Ryan Knoll shared
    Security system admin role with Marvin windows: https://talent-marvin.icims.com/jobs/9439/security-system-administrator/job

  • Su Subburaj shared
    SiteOwl is hiring a Customer Success Manager. Must have prior B2B SaaS CS or AM experience

#shameless-plugs

  • Auston Bunsen shared
    you can now issue multi-family credentials on accessgrid unit numbers, balances, parking spots, etc.

#security-research

  • Nate Doepper shared
    This flock camera leak is like Netflix for stalkers


ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration is OPEN NOW! Sign up here.

Speaking at the event? Go here.

Want to view some testimonials from previous years? 
Go here.


Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.

All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.

You can stream directly from our Secured channel.


West to East series: We're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.


🗣️ Your Voice Matters.

Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.

Community input form!

 

Volume 70
Volume 70 | July 31, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Princip...
Volume 68
Volume 68 | July 17, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast   Episode 24 | Access Control Hit CNBC — And VTS Made the Industry's Biggest ReversalVTS covers over 60% of Class A office space in the US — and just walked away from building access control in-house. Lee breaks down why, plus access control's mainstream moment on CNBC.Listen here ✍🏻 Articles...
Volume 67
Volume 67 | July 10, 2026 This Week’s Featured Media, Articles, & Breaking News 🎙 Secured Podcast Episode 23 | How Extreme Climbers Made a Mainstream Security Story in ManhattanA proposal 1,450 feet above Manhattan became one of the biggest security stories of the summer. This week, Lee explains why, shares his latest thinking on Intelligent Access, and breaks down the week's biggest stor...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.