Volume 8
Volume 8 | March 14, 2025
This Weeks Featured Articles & Media
Tony Dong | How to Intelligently Read the "Risk Factors" Section of a 10-K Report as an Access Control Executive
A practical guide for access control executives to identify critical business insights within regulatory filings.
Angie Barnes | From Booth to Buzz, How to Dominate ISC West
Tactical approaches to maximize your impact at the industry's premier trade show.
Brian Karas | A Look at Two Vulnerabilities, a Webcam and Vuln2
Technical assessment of two security threats and their implications for physical access systems.
Lee Odess | What Stood Out to Me this Week? More like Whoo Stood Out to Me
Analysis of standout features in Whoo's latest AI offering.
Lee Odess | Access Control as a Feature, Not Just a Function How essensys is repositioning access management as a core business capability rather than just functionality with a new product release.
Lindsay Martin-Nez | Your Badge Has Value
Essential insights into the importance of your name and the badge.
Jeremy Fromm | Cyber Series (Video)
First entry in an ongoing examination of cyber threats to physical security infrastructure.
Find them all below!
How to Intelligently Read the "Risk Factors" Section of a 10-K Report as an Access Control Executive
Written by:

I get itâmost of you didnât get into the access control industry because you wanted to play financial analyst and dissect 10-K reports. Thatâs not your job.
But at a strategic level, understanding how to read the âRisk Factorsâ section of a 10-K is critical. Whether youâre managing a business, considering an acquisition or investment, or evaluating a competitor, knowing the risks a company faces can give you a real edge.
Hereâs the good news: Public companies do a lot of the heavy lifting for you. In every annual report (the 10-K), they spell out their risks in a dedicated section called âRisk Factors.â You donât have to dig for themâtheyâre right there, often in excruciatingly boring detail.
Today, Iâm putting ADT in the hot seat. Iâll walk you through snippets from the âRisk Factorsâ section of its latest 10-K report and show you exactly how to break down and analyze these walls of text.
The end goal? To separate whatâs actually useful from the standard boilerplate disclosures and help you make smarter investment decisions.
The concept of âmaterial, adverse effectâ
When you read a 10-K report, youâll often come across language like this:

For you, the critical phrase here is âmaterial adverse effect.â Legally, this means that if the risk described actually happens, it could significantly damage the companyâs earnings, balance sheet, or cash flow.
This concept is your lens for evaluating risks. Management is legally obligated to list every risk they believe could have a material adverse effect on the business. In practice, most of these disclosures are valid, but over-disclosure is also a thing. S
The goal is to develop a sort of litmus test in your mind: âIf this risk materializes, would it truly create a material adverse effect on the company?â This is the starting point for evaluating any risk.
Operational vs strategic vs financial risks
Thereâs no shortage of risk taxonomies out there. These frameworks are essentially just ways to categorize uncertainty, and while some are more complex than useful, I like the approach used by the Basel Committee. Sure, itâs designed with banks in mind, but it applies well to most businesses.
The Basel Committee breaks risks into three main categories: Strategic, Operational, and Financial.
- Strategic Risks: These come from executing a flawed strategy or failing to adapt to changes in the market. This includes risks from poor decision-making, missed opportunities, and failing to innovate.

2. Operational Risks: These involve failures in day-to-day processes, systems, or people. Examples include supply chain disruptions, IT failures, cybersecurity breaches, compliance issues, and workplace safety incidents.

3. Financial Risks: These relate to how well a company manages its finances, covering risks from market fluctuations, monetary policy, credit exposure, and liquidity challenges.

Financial risks can cause earnings misstatements or one-time impairments. Operational risks often lead to fines, lawsuits, or bad PR. But itâs the strategic risks that doom a company in the long runâand as an investor, the long term is the only timeframe that really matters.
Just think about it: Blockbuster not buying Netflix was a strategic misstep that arguably hurt the company more than Johnson & Johnsonâs talc lawsuits or Archer-Daniels-Midlandâs accounting irregularities ever hurt them. Strategic risks are the ones that make or break a companyâs future.
Companies wonât make it easy for you. Most of them donât neatly follow this taxonomy. Take ADT, for example. Its âRisk Factorsâ section is divided into categories like âRisks Related to Macroeconomic and Related Factors,â âRisks Related to Regulations and Litigation,â and âRisks Related to Our Operations.â
To cut through the noise, reread the definition of strategic risk above. Then, use Ctrl+F to search for terms like âstrategyâ or âstrategicâ in the risk factors section. This will help you focus on what really matters. As a long-term investor, your main concern should be whether the companyâs strategy is sound and if management can actually execute it.
Ignore competition risk
I might catch some flak for this, but itâs the enduring opinion of not just myself but the entire risk management program faculty at Columbia University that any mention of âcompetition risk,â âhigh competitiveness,â or âcompetitive industryâ is not a real risk.
Hereâs why: Risk is the possibility of uncertainty that could cause variability in an outcome. Itâs the âwhat ifâ factor that keeps you up at night because it introduces potential volatility to your business results.
But competition is not uncertain. Itâs a given. Itâs expected. Itâs omnipresent. Thereâs no scenario where a business, whether itâs a restaurant, gas station, or hot dog cart, doesnât face competition.
You know itâs there when you start the venture. Thereâs no (legal) magic bullet to mitigate competition other than just running a solid businessâwhich, frankly, is what you should have been doing all along.
The lack of foresight and absence of concrete mitigation strategies here make âcompetition riskâ a nebulous, superfluous concept. For example, ADT lists competitive pressure from SimpliSafe, Wyze Home Monitoring, and Amazon Ring as a risk.

But ask yourself: What are they going to do about it? Kneecap their competitorsâ executives mafia-style? No. The only reasonable response is to introduce better products, lower fees, and improve serviceâagain, things they should be doing anyway.
In short, while competition is certainly material, itâs not a risk. Itâs just business. And as an investor, itâs not worth your time or worry.
An analysis of consequences is critical
Another critical thing to watch for when analyzing risk factor disclosures is whether management actually offers a meaningful discussion of the potential consequences.
Itâs not enough to simply list risksâgood management should connect the dots between a risk materializing and its tangible impact on the business. Unfortunately, this is where the majority of companies fall short.
For example, ADT talks about the risk of poor customer service and product defects below:

This is boilerplate drivel. The phrase âmaterial adverse effect on our business, financial condition, results of operations, and cash flowsâ tells you nothing about the actual consequences. How exactly could a bad customer service incident affect the business in a meaningful way? Without breaking it down further, most readers will simply skim past it.
Hereâs how Iâd break it down: Bad customer service experiences accumulate, leading to negative online reviews or word-of-mouth. This damages the brand's reputation, causing fewer contract renewals or lost sales opportunities. Lower customer retention means reduced revenue.
From here, a drop in revenue impacts earnings per share (EPS), all else being equal. When a public companyâs EPS declines and is made public, it often triggers a negative reaction from investors, leading to a drop in the share price. The end result? Losses for shareholders.
This is the exercise you need to run in your head every time you read a risk: Step-by-step chain of causation, from the risk materializing to a companyâs top line to its quoted stock price.
Yes, the consequence of a risk occurring is often a hit to the share priceâbut ask yourself, âBy which inputs?â Management often stops short of spelling this out, leaving you to connect the dots yourself.

First and most important, coffee and catch up with those people that mean the most to you and may only see once a year. Always make time for those people! They are the ones that pull you through the good and tough seasons, so book that coffee, maybe even a margarita at Yardbirds today.
The next thing I am going to do is sign up for anything that Lee Odess is putting on, from the FAST Networking Breakfast, to his session on Innovation to Implementation: How to Transform the Legacy Security Industry to the Modern Era! Boom, we will be there! Lee will also be hosting several sessions from The Access Control Executive Brief, so line up your calendar to be there. I will also be looking to sign up for all things Video Monitoring of course to learn more about what the industry is saying, where its going, and where we fit so nicely in that puzzle. I also encourage my up and comer leaders, to attend anything that has to do with SIA Rise from early morning coffee networking to the amazing Rise to Service Charity Dinner on April 2nd! There are so many ways to sharpen the sword and make you and your company better by jumping in feet first!
Last but never least, spend time with the partners who have taken time to put on some wonderful networking events in that week and evenings! Sharpen all of those Networking muscles and lock in Darts with Velesea, Wesco Networking Dinners, Brivo, Hanwha and AXIS, you name it, they are out there providing amazing opportunities to connect.
The DMP Ownerâs forum was and is always an amazing time as well. When I was on the other side of the fence, laughing, this was always my highlight, to spend time with customers and partners. Take advantage of those one-on-one opportunities to build your relationship bridges. Remember I always say you canât cross a bridge until its built. ISC West is the perfect time and place to start building those bridges of connection, value, and trust.
So, stop! Open your calendar today and start locking in your times and dates, and of course, come by and see ME! The Impatient Sales Lady, at the AXIS Booth, #14051 and learn why I made my move to Evolon at this point in my career! Remember, your time is important at ISC West, so craft a plan and strategy to make it valuable for you and the money the Venetian charges us all just to live in their space a few days in April! Go be amazing!
![]()
In the last couple of weeks two potentially interesting vulnerabilities were published online, and covered by multiple outlets. What I found interesting is that the lesser of the two seemed to get much broader coverage (at least from the many dozen places I lurk for tech stuff). Letâs take a quick look at these two reported vulnerabilities and what they mean (or not) for security.
The first one related to ransomware running on a âwebcamâ (it is sometimes funny to see how the rest of the world still calls IP surveillance cameras webcams). The writeup linked does a good job of giving a detailed overview. What made this interesting to me is how a surveillance camera that runs linux, which is pretty much every IP surveillance camera, and most DVR/NVR appliances, was leveraged for a ransomware attack.
If you donât want to read the linked article above, or just wanted a more succinct summary, here it is: Ransomware attacks work via attackers taking control of a vulnerable device that has access to network shares, and then the attackers load their software on the vulnerable device and the software encrypts the data on the shared drive. Once all the data is encrypted they spring the ransom demand on the victim.
The IP camera was used as the vulnerable device instead of a more common Windows machine because antivirus tools have finally become good enough and ubiquitous enough that it is not as easy to find a vulnerable Windows box any more. However, just as Windows machines are getting good security deployed, we are seeing a massive rise in IoT devices, mostly running linux, and frequently not very secure. Remember, the âSâ in IoT stands for âSecurityâ.
Due to the nature of embedded device architectures, it is usually not practical to load any kind of antivirus software on the device. This means you need to rely on the vendor for cybersecurity, or deploy something at the network layer.
While I havenât seen this vulnerability executed first-hand, the report definitely appears plausible when reading through it. Iâve written about highly vulnerable IP cameras in years past, and while some things have gotten better the problem is far from solved. It is also common for IP cameras to be deployed on converged networks, with other IT equipment. An IP camera having network access to a file share is not uncommon, in fact some IP cameras and file servers have support for the camera to send video packets direct to the network share for long term storage.
Overall, I was surprised I didnât see this one getting reported all over the place, it seemed to mostly fly under the radar.
Vuln2
This brings us to the other related vulnerability report to pop up in the last week, a purported backdoor in ESP32 chips discovered by a cyber security firm. If youâre not familiar with the ESP32 chip, it is a highly popular device from Espressif, and odds are you have some in your house. The ESP family has been the go-to chipset for consumer IoT devices for the last several years. These chips are under $2 in quantities, small, low power, and support various flavors of Bluetooth and Wifi, along with a bunch of IO pins. Theyâre also widely popular with hobbyists for all sorts of projects, and there are communities like ESPHome built around them.
A backdoor in the bluetooth implementation on these chips would certainly be a big deal, affecting literally billions of devices. Links to various reports on the Tarlogic disclosure were all over tech groups in the past week. The initial panic was understandable.
The problem is that this discovery sounded odd right from the drop, at least to me. First, Espressif has been known for being very open and very supportive of their products. While the chips themselves are cheap, Espressifâs core customers spend 10âs of millions of dollars with them annually, and build products not with Espressifâs brand, but with their own. Espressif seems to understand this well, and in my experience takes security seriously. That isnât to say a vulnerability canât happen, but a so-called Backdoor seems highly unlikely.
Digging into the report, the supposed Backdoor wasnât something that existed in every device in a way that allows a bad actor to gain access to a deployed device. Instead, using the undocumented commands they discovered required loading new firmware on the device which was designed to exploit these commands. And additionally that firmware would have to mimic all the normal functionality of the device to go undetected. Firmware updates for IoT devices, if they exist at all, tend to be handled in a way that abstracts most of the work and process away from the user. I know that my mom wouldnât be downloading a firmware.bin file and manually updating all of her light switches and thermostats in her underground bunker. That is just too much work. It is possible that some attacker could gain access to the network and leverage these devices, similar to the âwebcamâ example above (though in my momâs case, her internal network is airgapped and has an intrusion detection stack running for good measure).
The ESP32 backdoor did not seem much like a backdoor at all. It was technically some undocumented commands that existed in the chipset, and the undocumented nature of them means the odds of them being used in any typical devices is near zero. Additionally, if youâve ever worked with chipsets at low levels, especially ones with RF capabilities, then you have probably already been aware of undocumented commands or features. Sometimes there are commands used for post-manufacturing calibration, tuning, or other âFactory-onlyâ type functions. RF devices in particular often need to be tweaked based on where they are deployed globally. There are many wifi chipsets that can be adjusted to transmit on unauthorized channels, or put out excessive power, depending on what geography they are in. Granted, these are typically documented commands, but in the early days of wifi chipsets there were several that could be exploited via undocumented commands to output extra power and clobber other devices.
Unfortunately this Backdoor discovery looked more like a cybersecurity firm overhyping a typical scenario with embedded chipsets, and as additional information came out it became more clear that calling this a Backdoor was serious overhype. Espressif put out a statement a few days after this had already gone around the internet a thousand times, describing the undocumented commands in more detail, and why they were undocumented (and also not any kind of a backdoor).
What Does Any Of This Mean For Security?
Previously cyber security and physical security were distinct things, with minimal overlap for practitioners of either. Now, the two are very tightly linked, and physical security practitioners need to be up on cyber security. To me, this means not just understanding that cybersecurity is a thing, but also learning how to evaluate reported vulnerabilities to prioritize responses and mitigations. It will also mean we will likely see new generations of network security equipment designed to help protect IoT devices that are now prevalent, and unable to be managed by traditional IT security software packages and policies.
The next generation of successful physical security integrators will also be equally network security integrators.
What Stood Out to Me this Week? More like Whoo Stood Out to Me đ
by Lee Odess

When Jessica Hecht and Arturo Falck from Whoo reached out recently saying "I had to see what they were up to," my interest was immediately piqued. Having known Arturo for years, I've come to recognize that behind his friendly demeanor lies a serious professional. When he says "you need to see this," i feel it is worth paying attention.
And in this case, I wasn't disappointed.
I've previously shared my thoughts on AI's transformative potential and how itâs an architecture that many are building on that will disrupt many old truths of our industry, particularly regarding Agentic AI or AI Agents (as discussed in my earlier posts about REKS.ai). What Whoo is doing takes this concept even further into the realm of Conversational AI.
Their focus on transit applications particularly resonated with me, but it quickly became apparent: why wouldn't this technology be everywhere there is a callbox or intercom? Like, every intercom systemâthose blue light emergency callboxes on campuses, entry systems for multifamily residences and gated communities, information points in malls, hospitals, and beyondâenhanced with intelligent, conversational capabilities.
What sets Whoo apart is their collaborative approach with intercom manufacturers, seamlessly integrating Conversational AI agents into existing products. It's rare to encounter such an intuitive solution that the general public would readily embrace. My mom would 100% understand how to use this and see the value in it without having to be educated on it or trained. This interface isn't just for wayfindingâit handles recommendations, lost item assistance, customer service inquiries, and much more.
I strongly encourage you to check it out and then tell me how you donât think AI will impact our industry and the way the general public interacts with us. I also challenge you to not see the + in this adds to our utility as an industry.
And if you're attending ACS25, you won't want to miss Arturo's presentation during a My View session, where he'll share his perspective on conversations becoming the next frontier in user interfaces.
Access Control as a Feature, Not Just a Function
by Lee Odess
I have known James Shannon, Chief Product & Technology Officer, and the company essensys for quite awhile now. In fact I was also a customer in a few coworking spaces over the years as they managed wifi at a good number of them. They were the classic identity provider and service provider you could see take a hard swing at the access control industry given they have digital identities, a captured audience, and a use case where the user is super digital and looking for a great experience. Well, they recently came out with something to put that idea into motion.
The recent announcement of elumo by essensys represents another example of how access control is evolving from a standalone security function into a strategic feature of a larger value propositions. essensys, already a formidable player in the commercial real estate technology space (publicly traded on the London Stock Exchange AIM Market since 2006), has clearly identified a critical pain point in the flexible workspace market. The traditional binary approach to meeting roomsâeither locked (causing frustration) or unlocked (inviting "squatting")âhas created a significant challenge for property operators balancing experience with revenue generation.
What makes elumo particularly compelling is how it seamlessly integrates three critical elements: bookings, access, and intelligence. By leveraging mobile wallet technology, the solution enables users to instantly book and access spaces with a simple tap, completing the process in under half a second. This approach prioritizes the user experience while simultaneously addressing operators' revenue concerns. The real innovation here is positioning access control not as a security afterthought or siloed system but as an integral component of the overall space management and monetization strategy. essensys has recognized that controlling who enters which spaces at what times isn't just about securityâit's about creating frictionless experiences that drive adoption while enabling operators to maximize revenue from their physical assets. For property managers and operators in today's hybrid work environment, the promise of "ROI in days, not years" is particularly appealing. The ability to instantly monetize meeting spaces and even convert vacant offices into revenue-generating assets represents a fundamental shift in how commercial real estate can perform financially. The real-time intelligence component further elevates the offering, providing operators insights into space utilization patterns that can inform future decisions about their portfolios.
essensys has effectively transformed the expectations for what technology should deliver in flexible workspaces. By approaching access control as a strategic enabler rather than just a tactical function, they've created a solution that addresses multiple stakeholder needs simultaneouslyâenhancing user experiences while optimizing operational efficiency and revenue generation. This integrated approach demonstrates how the commercial real estate industry is evolving to meet the needs of today's flexible, hybrid work environment, with technology solutions that go far beyond traditional access control to deliver comprehensive space management capabilities.
And if you're attending ACS25, you won't want to miss Jamesâs as he participates in a panel titled âThe Plus Protocol: Redefining the Power of Access Systemsâ where we will breakdown âThe Plus Protocol explores how modern access control has evolved beyond traditional security functions to become a strategic business asset. This panel brings together global thought leaders to discuss the untapped potential of these systems, from operational efficiency to enhanced user experiences. Join us to discover what actions industry stakeholders should take today to realize the shared vision of tomorrow's intelligent access ecosystem.â

Too often, the security industry undervalues the ID badge.
In fact, it's often an after-thought in systems implementations, viewed as simply a "means to an end"... A utility to do something else within the facility.
IDs are more than just a piece of plastic though. They are more than a key to unlock a door, or a form of validation. True; they serve these purposes, but their true power lies in something greater. IDs have the power to connect people.
Think about the last conference you attended. When someone hopped in the elevator wearing the same attendee badge as you, how much easier was it to start up a conversation since you already had a point of connection?
What about your last corporate get-together? When you haven't seen your out-of-town co-workers since the last company event, or you've never met some of the newer team members in person, how helpful are badges to identify everyone on the team by name?
Think about the student walking into their middle school for the first time. How much more welcome do they feel when a teacher greets them by name as they walk through the door?
Our names hold deep significance to us. It is one of the few sounds we instinctively recognize even in the most crowded of rooms. When someone greets us by name, we immediately feel a stronger connection to them.
Wearing a photo ID with the first name displayed in large letters creates a gateway to recognition. It fosters a culture where team members are not just numbers, not just faces in a crowd, but one where they are truly recognized and valued.
Schools all over the country are worried about balancing safety and security of staff and students with the desire to have an open and friendly environment, while constantly trying to build a strong sense of community among everyone who walks in the building.
These are real problems that our customers are talking about every single day.
These are problems that we get to help solve. With something as simple as a badge.
Your name has value. Your badge has value too.

Join industry expert Jeremy Fromm as he dives into the fascinating world of Wiegand protocol exploitation using the ESPKey device in this YouTube video. In this episode of âCyber Series,â Jeremy demonstrates how to intercept and analyze data from card readers and access control systems that utilize the Wiegand protocol. What you'll learn in this video:
-
Understanding the Wiegand protocol and its vulnerabilities
-
Setting up and configuring the ESPKey device
-
Live demonstration of Wiegand sniffing techniques
-
Real-world security implications and risk mitigation strategies
-
Considerations for security professionals
This educational content is intended for cybersecurity professionals, ethical hackers, and IT security specialists looking to understand potential vulnerabilities in physical access control systems.
