Volume 70
Volume 70 | July 31, 2026

This Week’s Featured Media, Articles, & Breaking News
🎙 Secured Podcast
Episode 26 | Allegion & ASSA ABLOY: Are They Even Playing the Same Game Anymore?
Allegion just posted its strongest quarter on record, and this week Lee wonders if the company everyone compares it to isn't really its peer anymore. Plus why the camera "box" model ages like milk, and Planck's Principle, the real reason this industry changes so slowly. New episode of Secured is live.
Listen here
✍🏻 Articles
Lee Odess | Intelligent Access: The Era, The Tenets, Why NowAccess control isn't on a steady march of better readers and cameras; it's moved through distinct eras, and Lee Odess argues we've just entered a new one worth $100B+. He names it the Intelligence Era, lays out the five tenets a company can be measured against, and makes the case for why the door is no longer the asset.
Lon Bazelais | Why Legacy Access Control Is Losing Its Grip on the Enterprise
For decades, physical security stayed anchored to on-site servers while every other business system moved to the cloud. Lon Bazelais makes the case that the infrastructure argument for legacy access control is getting harder to defend, and organizations are increasingly concluding it no longer holds.
Vikrant Pelia | Secure by Design: Rethinking Access Control Around Real-World Behavior
Most access control is designed around the system's needs, not the people using it, and that gap is where security breaks down. Vikrant Pelia shows how three real deployments cut friction and tailgating by making the secure choice the easiest one.
Donna Chapman | Trusted Identity. Trusted Elections. Trusted Future.
Public confidence in elections begins with trust that every ballot goes to one eligible voter, exactly once. This piece lays out how a privacy-first identity assurance layer can strengthen that trust, verifying the voter and not the vote, without replacing existing election systems.
🚨Breaking
- Breaking: ASSA ABLOY Group acquires Classic Brass Inc in the US
Scroll down to go deeper ↓
![]()
Podcast | Secured: Episode 26
Allegion just posted its strongest quarter on record, and this week Lee spends most of the episode wondering if the company everyone reaches for as its comp isn't really its peer anymore. It's the theme running through the whole episode: an industry still keeping score on yesterday's scorecard while the game quietly moved somewhere else. Lee gets into Allegion's record Q2, why the camera "box" business model is dying (the steel lasts 10 years, the software inside ages like milk), and a CTO hire that brings someone in from outside the industry. Then in My View: why the companies paying for that six-foot table in the hallway have far more power than they're using, and Planck's Principle, the real reason the industry moves so slowly. Science advances one funeral at a time. New episode of Secured is live. Listen here

For years now, I've circled one simple, inevitable truth: we are firmly in a new era in access control. And today I am naming it: Welcome to the Intelligence Era.
I'm doing this because things are truly different now for many, though for some, nothing has changed, and this difference needs a home. Companies working toward this era have had to use modern vocabulary, like open, cloud, mobile, and platform, in outdated eras, which no longer signal differentiation, as every company claims them, regardless of underlying architecture, go-to-market strategy, product-market fit, talent, or truth. This mismatch isn't just a branding problem, but a market failure. A company in prior eras built or rebuilt around identity, AI, mobile, software, and infrastructure has no language to prove its difference, because the prior construct can't contain it. Intelligent Access is that home: a place for companies to anchor, showcase, highlight real differentiation, share future visions, and stake their claim in a new era, rather than blending into generic language from the previous one. Concretely, that means treating this era's opportunity as enterprise infrastructure, the layer that powers security, operations, compliance, and workplace intelligence together, not a vertical called access control that occasionally touches those other functions.
Intelligent Access is not a product category. It's an era, like electronic access control and mechanical locking before it. Each era holds a core promise, a record system, channel dynamics, truths, and companies that recognized the shift early and worked within it. Each era is important. Each is different and needs to be treated as such. This overview introduces, names, and defines the era. It lays out its distinguishing tenets. And it invites companies to share their stories, their promises for this era, and showcase how they stand out. The overview provides a backbone for companies competing in this new era.
Note: naming this era doesn't mean another era will follow or that it will be the era for the foreseeable future. In fact, just as there was an Intelligence Access Era preceding the Modern Electronic Access Era, there will be one after this (and another after that). What I'm doing here is breaking away from the old constructs of the past era and creating a home for this new era.
How We Got Here: Three Eras, Not One Long Story
The physical security industry often presents its history as a single, uninterrupted journey of continuous improvement, moving from rolling boulders in front of caves to today's advanced security technologies. Access control is described as a steady progression: better readers, controllers, and cameras each year. However, this perspective overlooks the major shifts that have taken place. Instead of a linear story, the industry has evolved through distinct eras, each offering different answers to four core questions: the promise to customers, delivery methods, value creation, and ways of being rewarded. The distinctions between these eras mark fundamental shifts rather than incremental changes.
The first era, known as the Electronic Access Control Era (roughly 1970–2020), created a $10 billion high-security industry, evolving from the Mechanical Lock and Key Era. Its distinguishing promise was clear: replace physical keys with electronic credentials, control who enters, maintain records, and verify access when needed. The threat it defended against was physical: a person trying to pick a lock, clone a badge, or walk in behind someone who held the door open. We are the experts, and you should trust us. In this era, the door, which includes its panel, attached locks, and accessories, access rights, and event log, was the system of record. Value stemmed from system complexity, making certified experts indispensable. Identity was simply a number on a card, not tied to the individual's true identity. Manual provisioning and infrequent deprovisioning led to a growing gap between technical and actual access. Despite this, the era succeeded in its core aim of keeping bad people out and providing reliable access control. This approach was fundamentally different from the refinements of later eras, as its complexity and exclusion were features, not issues to be solved.
The second era, called the Modern Electronic Access Control Era (2020–2025), grew at a 5-7% incremental pace and rapidly saw the emergence of a new market to be addressed at a $70 billion opportunity, driven by enterprise software and accelerated by COVID. Unlike the first era, this era promised to combine the security of specialized systems with modern conveniences: cloud-based access, mobile credentials, user-friendly software, and a balance of convenience and security. The system of record started shifting from the door to the credential and its management in the cloud, though it still resided within the access control system. Technology additions and new market entrants, like Brivo, Openpath, Kisi, Prodatakey, and Genea, further distinguished this era. Enterprise sales strategies began to resemble SaaS, separating this period from the expert-driven, hardware-centric past. IT departments grew in buying influence, and some in the industry saw brand-building as a strategic asset… Continue reading here

As organizations modernize every other business system, security leaders are increasingly questioning the cost, complexity, and operational burden of maintaining server-based access control infrastructure. The result is a steady migration toward cloud-managed platforms that promise greater scalability, simplicity, and long-term value.
The physical access control industry moved at its own pace for decades. Other sectors had long since migrated to cloud infrastructure and SaaS platforms. Physical security remained behind, anchored to on-site servers, thick-client software, and VPN-dependent architectures. The industry's conservatism was not without logic. Security system failures carry real consequences, including life-safety exposure, operational disruption, and liability. Stability mattered more than novelty.
That posture served legacy systems well for a long time. Now it is starting to cost them.
The shift is happening project by project, client by client, as organizations question whether the infrastructure overhead of traditional access control still makes sense. Increasingly, they are concluding it doesn't.
Why Legacy Systems Held On So Long
Cloud-managed access control has been commercially available for over two decades. Slow adoption was never a technology problem. The physical security industry resists change for structural reasons that go beyond habit.
Consultants, engineering firms, and enterprise standards committees have specified the same manufacturers and deployment architectures for years. Approved vendor lists calcify. Specification templates get recycled. Once a manufacturer is embedded in an organization's security standards, displacement requires effort most organizations prefer to avoid. For years, that inertia was enough. Administrators tolerated onsite servers, SQL databases, VPN configurations, and manual patching cycles because those requirements had been normalized. That was simply how enterprise access control worked.
The Infrastructure Argument Is Getting Harder to Make
Organizations now manage most business-critical software through browser-based platforms and cloud-hosted services that require no local servers and minimal IT overhead. Then they look at their access control system and see a dedicated server, a SQL database, a VPN dependency, and a maintenance cycle that requires coordination among IT, the integrator, and sometimes the manufacturer.
The question that keeps coming up is a fair one. Why does this system still work this way? Multi-site organizations feel this friction most acutely. Managing separate legacy deployments across multiple facilities creates administrative complexity that compounds over time. Cloud-managed platforms consolidate everything into a single interface. The server room stops being an asset and starts being overhead nobody wants to defend.
A Shift in Industry Relationships
Cloud-based access control changed who talks to whom and how accountability gets distributed. Traditional legacy manufacturers kept end users at arm's length, with the integrator handling everything. That structure protected certain commercial arrangements but created bottlenecks that frustrated clients. Modern cloud-based manufacturers function more like software companies, maintaining active relationships with end users and serving as genuine partners across the entire service chain. When an end user has an after-hours problem and the integrator's support desk is unavailable, the manufacturer can step in, gather diagnostic information, and hand off a clear picture so the integrator can act efficiently.
That continuity raises the overall service standard. It also allows integrators to scale operations in ways that were previously impractical. At Grid Squared Systems, we manage deployments well outside the New York City market, coordinating local service resources across multiple regions. That operational model didn't exist in any practical form under traditional legacy structures.
Getting the Subscription Conversation Right
The recurring revenue model associated with cloud-based access control is misread on both sides. Some integrators treat it primarily as a financial instrument. Some end users see it as a fee layered on top of hardware they already paid for. Neither framing gets to the real point.
Cloud-managed systems earn sustained adoption because they deliver a better operational experience. Easier to administer, easier to scale, easier to support remotely. That experience drives retention, and retention is what makes the recurring model work for everyone.
It also changes integrators' behavior in ways that benefit clients. Traditional models front-loaded revenue into the installation itself, leaving little commercial incentive for ongoing engagement beyond reactive service calls. Subscription-based relationships change that. The integrator now has a direct stake in long-term client satisfaction, and that alignment tends to produce better outcomes for the people actually using the system.
Where Legacy Still Has a Case
Certain environments still favor on-premise deployments. Air-gapped networks, classified government facilities, and organizations with highly specialized compliance requirements may have legitimate constraints that make cloud management impractical. Those use cases are real…. Continue reading here

Traditional access control systems focus on authentication and compliance but often overlook the people who interact with them. By making the secure choice the easiest choice, organizations can reduce risk, improve user adoption, and eliminate common security workarounds.
On a busy Monday morning, a member of staff arrives at a controlled entry point, hands full and running late. They badge in, hold the door, and the person behind them walks through without presenting a credential. Just like that, vulnerability exists.
In most cases, fingers are pointed at a flawed policy or insufficient training. But I'd like to introduce a third problem that doesn't get highlighted as much as possible: not designing around human behavior. Because in this scenario, the system made it easier to let someone follow you in than to enforce the rule.
The Gap Nobody Talks About
Access control is typically designed around the system's needs: authentication, authorization, and auditing. What isn't always taken into consideration are the people using it: how they move, what they're carrying, or how much patience they have at 8:47 on a Monday morning.
That gap is where human behavior takes over. Under pressure, in a rush, or simply on autopilot, people make the quickest decision available to them. If the system hasn't made the secure option the easiest one, that decision won't always be the right one. The industry's default response is to push more training and stronger enforcement, but that only papers over the gap.
The question worth asking isn't whether users are following the rules; it's whether the system is making the rules easy to follow.
What Good Design Actually Delivers
This isn't theoretical. Real deployments show what happens when access control is redesigned around the user rather than the policy.
Tampa General Hospital's workforce had to rely on helpdesk support whenever they were locked out of an account. This was a slow, frustrating process that took an average of 4.5 days to resolve. In a busy clinical environment, that kind of friction doesn't just inconvenience people; it encourages them to find shortcuts. They replaced the process with biometric verification so that staff could complete it themselves, resulting in a drop-in resolution time from 4.5 days to 20 minutes. For clinical staff, that's the difference between a frustrating multi-day wait and getting back to work within the hour.
At the University of Basel, new employees and associates waited weeks for their physical access cards and system credentials to be processed manually. Starting without access doesn't just slow people down; it pushes them toward informal arrangements, borrowed credentials, and workarounds that become habits. A central self-service portal changed that, letting users request access and upload their own ID photo with automated approval flows handling the rest. System access now arrives within minutes or hours, and physical access cards within a few days rather than weeks. For a new employee, that's the difference between starting a new job frustrated and starting it ready to work.
Agora's 6,000-employee site in Budapest was running on cards and fobs, and the friction of that system was showing up as tailgating risk at the door. When entry feels like an obstacle, people hold doors open, wave colleagues through, and avoid confronting someone. Facial biometric access replaced the cards, with self-enrolment on tablets and entry logic designed to keep movement touchless and fast. That meant bottlenecks disappeared, crowding was eliminated, and tailgating risk was addressed through design rather than relying on staff to enforce the rule. For 6,000 people moving through that building every day, the secure path became the effortless one.
Three deployments, three different contexts, the same principle: when you design for how people actually behave, security improves alongside the experience.
Where to Start Without Starting Over
None of these organizations rebuilt from scratch. They identified specific points of friction and redesigned those interactions.
Look at where your users are struggling. Where are the support calls coming from? Where are the workarounds happening? Where does the process take longer than it should? Those are your design problems and your biggest opportunities.
Here are four starting points worth examining in almost any access control deployment:
Credential recovery — If regaining access after a lockout requires a helpdesk call, that's a solvable design problem. Self-service recovery flows with clear interface guidance can resolve this and remove the frustration that affects every user who gets locked out.
Onboarding — First impressions shape long-term behavior. If new users hit a wall on day one, they'll find ways around the system for as long as they're in the building.
Entry feedback — Does the reader clearly tell the user what just happened? Denying entry without explanation creates hesitation and tailgating opportunities. Clear, immediate feedback — a specific message, a distinct sound, or an unambiguous light — changes behavior at the door.
Admin interfaces — If the people managing your system find it hard to navigate, permissions drift, alerts get ignored, and configurations go stale. Access rights linger too long when approval logic is hard to interpret. Alerts get dismissed when urgency isn't clear. Exception requests go unresolved when the process requires too many steps. None of that is negligence; it's what poor interface design produces.
The Opportunity
Design investment in access control is still in its early stages. Most products were designed by engineers who solved technical problems, and they did so well. But the user experience layer hasn't kept pace, and that gap is now a differentiator for manufacturers, integrators, and consultants willing to close it.
For manufacturers, it's an opportunity to build products that people actually want to use. For integrators and consultants, it's a conversation worth having at the specification stage because a system that works well for its users performs better in the field and generates fewer callbacks.
Design that path well, make it fast, clear, and frictionless, and the secure choice becomes the obvious one. When the secure path is also the easiest path, people take it. That's not just a design ideal; it's what happens when access control is designed to work with human behavior rather than against it… Continue reading here

Public confidence is the cornerstone of every democratic election. That confidence begins with trust that every ballot is issued to one eligible voter, exactly once, while preserving voter privacy, ballot secrecy, and accessibility.
As identity fraud and cyber threats continue to evolve, election officials face growing challenges in establishing trusted voter identity using verification methods designed for a different era. Strengthening election integrity requires more than verifying credentials, it requires confidence that the individual requesting or receiving a ballot is the legitimate owner of that identity.
Modern identity assurance offers a privacy-first approach built on continuous identity attestation and Zero Trust security principles. Rather than replacing existing voter registration systems or election infrastructure, a trusted identity assurance layer can complement existing processes by helping establish trusted voter identity before a ballot is issued.
By combining multiple sources of trust such as verified identity credentials, trusted device validation, cryptographic authentication, and continuous risk assessment, modern identity assurance is designed to help strengthen confidence in voter identity while reducing the risk of voter impersonation, stolen or synthetic identities, credential misuse, unauthorized absentee ballot requests, and other forms of identity-based election fraud.
Importantly, identity assurance verifies the voter, not the vote. Once voter eligibility has been confirmed and a ballot is issued, identity is separated from the ballot, preserving ballot secrecy, constitutional protection, and voter privacy.
A trusted identity assurance layer complements existing election systems by strengthening security, operational efficiency, auditability, transparency, and public confidence, without replacing established election processes or changing how votes are cast, counted, or certified.
Election integrity depends upon confidence in voter identity. As digital identity standards continue to mature, trusted identity assurance provides a practical, scalable, and privacy-conscious approach to strengthening confidence in the electoral process while preserving the democratic principles of accessibility, ballot secrecy, voter privacy, and the integrity of existing election systems.
The future of election integrity is not simply about verifying identity, it is about establishing trust in identity. I believe the future of digital trust begins with trusted identity. If these ideas resonate with you, or if you are exploring how trusted identity assurance could strengthen confidence in elections, government services, healthcare, financial services, or other trust-critical environments, I welcome the opportunity to continue the conversation.
đź‘€ As Seen in the Secured Collective this Week
#ai
-
Salvatore D’Agostino shared
- Students helped design the A.I.-powered creation as a young female with dark hair and an upbeat personality. Then came the outrage.
- AI might throw a wrench into some basic assumptions about the logic of markets and competition
- Meta desperately trying to ban creeps misusing its AI pervert glasses
-AI Data Center Security Analysis
-Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security
- Anthropic A.I. Model Finds Flaws in Tough-to-Crack Encryption Algorithms
- Mark Zuckerberg Blasts Centralization of A.I. Power
#aliro
-
Brooke Grigsby shared
-As industry adoption of Aliro continues to grow, Safetrust has developed a collection of resources to help organizations better understand the standard, migration strategies, and enterprise deployment considerations.
#identity
-
Luke Rettstatt shared
We currently capture an id photo of a cardholder, then have them submit a photo of their gov issued ID (optional). We perform facial rec against the ID photo and the photo on their gov issued ID.
#job-board
-
Andrew Campagnola shared
If anyone knows someone that would be a great fit for a role that's at the intersection of product management & presales/application engineering feel free to send them my way.
#news
#security-research

ACS26, The Access Control Summit, is heading to New Zealand in 2026 October 6 & 7th, hosted in collaboration with our city-host, Gallagher Security. Registration is OPEN NOW! Sign up here.
Speaking at the event? Go here.
Want to view some testimonials from previous years? Go here.
![]()
Secured Presents: XPod from The Security Event
We asked everyone the same four questions. What came back was not a recap. It was a read on where the industry actually is, told through the people doing the work.
All stories:
Intro: What We heard at TSE
Episode 1: Identity Is The Center, Hardware Is The Floor.
Episode 2: Regulation Is Not the Tax. It Is the Moat.
Episode 3 — The Mainstream Moment Is Real, But It Is Not Singular.
You can stream directly from our Secured channel.

West to East series: We're looking back on 45 conversations with leaders from across the industry. Each episode offers a different perspective on the ideas, challenges, and opportunities shaping security today. You can stream all episodes right from our Secured channel.
🗣️ Your Voice Matters.
Share your feedback, suggest topics, and tell us what questions we should be answering. Help us shape future issues and contribute to the conversations that move the industry forward.