Header Logo
Log In
← Back to all posts

Volume 8

Aug 03, 2026

Volume 8 | March 14, 2025

This Weeks Featured Articles & Media

Tony Dong | How to Intelligently Read the "Risk Factors" Section of a 10-K Report as an Access Control Executive
A practical guide for access control executives to identify critical business insights within regulatory filings.

Angie Barnes | From Booth to Buzz, How to Dominate ISC West
Tactical approaches to maximize your impact at the industry's premier trade show.

Brian Karas | A Look at Two Vulnerabilities, a Webcam and Vuln2
Technical assessment of two security threats and their implications for physical access systems.

Lee Odess | What Stood Out to Me this Week? More like Whoo Stood Out to Me
Analysis of standout features in Whoo's latest AI offering.

Lee Odess | Access Control as a Feature, Not Just a Function How essensys is repositioning access management as a core business capability rather than just functionality with a new product release.

Lindsay Martin-Nez | Your Badge Has Value
Essential insights into the importance of your name and the badge.

Jeremy Fromm | Cyber Series (Video)
First entry in an ongoing examination of cyber threats to physical security infrastructure.

Find them all below!


How to Intelligently Read the "Risk Factors" Section of a 10-K Report as an Access Control Executive

Written by:

 

I get it—most of you didn’t get into the access control industry because you wanted to play financial analyst and dissect 10-K reports. That’s not your job. 

 

But at a strategic level, understanding how to read the “Risk Factors” section of a 10-K is critical. Whether you’re managing a business, considering an acquisition or investment, or evaluating a competitor, knowing the risks a company faces can give you a real edge.

 

Here’s the good news: Public companies do a lot of the heavy lifting for you. In every annual report (the 10-K), they spell out their risks in a dedicated section called “Risk Factors.” You don’t have to dig for them—they’re right there, often in excruciatingly boring detail.

 

Today, I’m putting ADT in the hot seat. I’ll walk you through snippets from the “Risk Factors” section of its latest 10-K report and show you exactly how to break down and analyze these walls of text. 

 

The end goal? To separate what’s actually useful from the standard boilerplate disclosures and help you make smarter investment decisions.

 

The concept of “material, adverse effect”

 

When you read a 10-K report, you’ll often come across language like this:

 

For you, the critical phrase here is “material adverse effect.” Legally, this means that if the risk described actually happens, it could significantly damage the company’s earnings, balance sheet, or cash flow. 

This concept is your lens for evaluating risks. Management is legally obligated to list every risk they believe could have a material adverse effect on the business. In practice, most of these disclosures are valid, but over-disclosure is also a thing. S

The goal is to develop a sort of litmus test in your mind: “If this risk materializes, would it truly create a material adverse effect on the company?” This is the starting point for evaluating any risk.

Operational vs strategic vs financial risks

There’s no shortage of risk taxonomies out there. These frameworks are essentially just ways to categorize uncertainty, and while some are more complex than useful, I like the approach used by the Basel Committee. Sure, it’s designed with banks in mind, but it applies well to most businesses.

The Basel Committee breaks risks into three main categories: Strategic, Operational, and Financial.

  1. Strategic Risks: These come from executing a flawed strategy or failing to adapt to changes in the market. This includes risks from poor decision-making, missed opportunities, and failing to innovate.

2. Operational Risks: These involve failures in day-to-day processes, systems, or people. Examples include supply chain disruptions, IT failures, cybersecurity breaches, compliance issues, and workplace safety incidents.

3. Financial Risks: These relate to how well a company manages its finances, covering risks from market fluctuations, monetary policy, credit exposure, and liquidity challenges.

Financial risks can cause earnings misstatements or one-time impairments. Operational risks often lead to fines, lawsuits, or bad PR. But it’s the strategic risks that doom a company in the long run—and as an investor, the long term is the only timeframe that really matters.

Just think about it: Blockbuster not buying Netflix was a strategic misstep that arguably hurt the company more than Johnson & Johnson’s talc lawsuits or Archer-Daniels-Midland’s accounting irregularities ever hurt them. Strategic risks are the ones that make or break a company’s future.

Companies won’t make it easy for you. Most of them don’t neatly follow this taxonomy. Take ADT, for example. Its “Risk Factors” section is divided into categories like “Risks Related to Macroeconomic and Related Factors,” “Risks Related to Regulations and Litigation,” and “Risks Related to Our Operations.” 

To cut through the noise, reread the definition of strategic risk above. Then, use Ctrl+F to search for terms like “strategy” or “strategic” in the risk factors section. This will help you focus on what really matters. As a long-term investor, your main concern should be whether the company’s strategy is sound and if management can actually execute it.

Ignore competition risk

I might catch some flak for this, but it’s the enduring opinion of not just myself but the entire risk management program faculty at Columbia University that any mention of “competition risk,” “high competitiveness,” or “competitive industry” is not a real risk.

Here’s why: Risk is the possibility of uncertainty that could cause variability in an outcome. It’s the “what if” factor that keeps you up at night because it introduces potential volatility to your business results.

But competition is not uncertain. It’s a given. It’s expected. It’s omnipresent. There’s no scenario where a business, whether it’s a restaurant, gas station, or hot dog cart, doesn’t face competition. 

You know it’s there when you start the venture. There’s no (legal) magic bullet to mitigate competition other than just running a solid business—which, frankly, is what you should have been doing all along.

The lack of foresight and absence of concrete mitigation strategies here make “competition risk” a nebulous, superfluous concept. For example, ADT lists competitive pressure from SimpliSafe, Wyze Home Monitoring, and Amazon Ring as a risk.

But ask yourself: What are they going to do about it? Kneecap their competitors’ executives mafia-style? No. The only reasonable response is to introduce better products, lower fees, and improve service—again, things they should be doing anyway.

In short, while competition is certainly material, it’s not a risk. It’s just business. And as an investor, it’s not worth your time or worry.

An analysis of consequences is critical

Another critical thing to watch for when analyzing risk factor disclosures is whether management actually offers a meaningful discussion of the potential consequences. 

It’s not enough to simply list risks—good management should connect the dots between a risk materializing and its tangible impact on the business. Unfortunately, this is where the majority of companies fall short.

For example, ADT talks about the risk of poor customer service and product defects below:

This is boilerplate drivel. The phrase “material adverse effect on our business, financial condition, results of operations, and cash flows” tells you nothing about the actual consequences. How exactly could a bad customer service incident affect the business in a meaningful way? Without breaking it down further, most readers will simply skim past it.

Here’s how I’d break it down: Bad customer service experiences accumulate, leading to negative online reviews or word-of-mouth. This damages the brand's reputation, causing fewer contract renewals or lost sales opportunities. Lower customer retention means reduced revenue. 

From here, a drop in revenue impacts earnings per share (EPS), all else being equal. When a public company’s EPS declines and is made public, it often triggers a negative reaction from investors, leading to a drop in the share price. The end result? Losses for shareholders.

This is the exercise you need to run in your head every time you read a risk: Step-by-step chain of causation, from the risk materializing to a company’s top line to its quoted stock price. 

Yes, the consequence of a risk occurring is often a hit to the share price—but ask yourself, “By which inputs?” Management often stops short of spelling this out, leaving you to connect the dots yourself. 


So today, I sit in my office, emails dinging, linked in blowing up, and a million and one posts about exciting launches as we prepare for, in my opinion, the best technology show for security, ISC West. ISC West has grown so much over the years and just continues to evolve and change, as we see the technology changing. The weirdest ISC West I remember, was after Covid, when the show was probably 1/3rd of what you will expect the first week of April this year. It was really almost manageable! Laughing, where you got to see everything, you really wanted to see in one day. But what fun is that? We want it where it’s the marathon days, with the Starbucks line down the hall at the Venetian, the Grand Luxe CafĂ© for breakfast only has an hour wait, smiling, and the buzz is in the air on what is going to change the world of Security! That is always what I am waiting for, with the integrators and customers, making their rounds to each Technology partner who will be pulling back the magic curtain on their most amazing development, whizzbang, gamechanger product. Smile, I love this part! For the first time in my career, I will be one of those, standing at a booth, waiting to greet and hug my favorite colleagues and new partners, to say, hey, come see what we are doing that is so special and different.  I thought for today’s edition, I might share, being on the other side, how I am going to make the most of my week in Vegas.

First and most important, coffee and catch up with those people that mean the most to you and may only see once a year. Always make time for those people! They are the ones that pull you through the good and tough seasons, so book that coffee, maybe even a margarita at Yardbirds today. 

The next thing I am going to do is sign up for anything that Lee Odess is putting on, from the FAST Networking Breakfast, to his session on Innovation to Implementation: How to Transform the Legacy Security Industry to the Modern Era! Boom, we will be there! Lee will also be hosting several sessions from The Access Control Executive Brief, so line up your calendar to be there. I will also be looking to sign up for all things Video Monitoring of course to learn more about what the industry is saying, where its going, and where we fit so nicely in that puzzle. I also encourage my up and comer leaders, to attend anything that has to do with SIA Rise from early morning coffee networking to the amazing Rise to Service Charity Dinner on April 2nd! There are so many ways to sharpen the sword and make you and your company better by jumping in feet first! 

Last but never least, spend time with the partners who have taken time to put on some wonderful networking events in that week and evenings! Sharpen all of those Networking muscles and lock in Darts with Velesea, Wesco Networking Dinners, Brivo, Hanwha and AXIS, you name it, they are out there providing amazing opportunities to connect.

The DMP Owner’s forum was and is always an amazing time as well.  When I was on the other side of the fence, laughing, this was always my highlight, to spend time with customers and partners. Take advantage of those one-on-one opportunities to build your relationship bridges. Remember I always say you can’t cross a bridge until its built. ISC West is the perfect time and place to start building those bridges of connection, value, and trust. 

So, stop! Open your calendar today and start locking in your times and dates, and of course, come by and see ME! The Impatient Sales Lady, at the AXIS Booth, #14051 and learn why I made my move to Evolon at this point in my career! Remember, your time is important at ISC West, so craft a plan and strategy to make it valuable for you and the money the Venetian charges us all just to live in their space a few days in April!  Go be amazing! 


In the last couple of weeks two potentially interesting vulnerabilities were published online, and covered by multiple outlets. What I found interesting is that the lesser of the two seemed to get much broader coverage (at least from the many dozen places I lurk for tech stuff). Let’s take a quick look at these two reported vulnerabilities and what they mean (or not) for security.

The first one related to ransomware running on a “webcam” (it is sometimes funny to see how the rest of the world still calls IP surveillance cameras webcams). The writeup linked does a good job of giving a detailed overview. What made this interesting to me is how a surveillance camera that runs linux, which is pretty much every IP surveillance camera, and most DVR/NVR appliances, was leveraged for a ransomware attack. 

 

If you don’t want to read the linked article above, or just wanted a more succinct summary, here it is: Ransomware attacks work via attackers taking control of a vulnerable device that has access to network shares, and then the attackers load their software on the vulnerable device and the software encrypts the data on the shared drive. Once all the data is encrypted they spring the ransom demand on the victim.

 

The IP camera was used as the vulnerable device instead of a more common Windows machine because antivirus tools have finally become good enough and ubiquitous enough that it is not as easy to find a vulnerable Windows box any more. However, just as Windows machines are getting good security deployed, we are seeing a massive rise in IoT devices, mostly running linux, and frequently not very secure. Remember, the “S” in IoT stands for “Security”.

 

Due to the nature of embedded device architectures, it is usually not practical to load any kind of antivirus software on the device. This means you need to rely on the vendor for cybersecurity, or deploy something at the network layer. 

 

While I haven’t seen this vulnerability executed first-hand, the report definitely appears plausible when reading through it. I’ve written about highly vulnerable IP cameras in years past, and while some things have gotten better the problem is far from solved. It is also common for IP cameras to be deployed on converged networks, with other IT equipment. An IP camera having network access to a file share is not uncommon, in fact some IP cameras and file servers have support for the camera to send video packets direct to the network share for long term storage.

 

Overall, I was surprised I didn’t see this one getting reported all over the place, it seemed to mostly fly under the radar.

Vuln2

 

This brings us to the other related vulnerability report to pop up in the last week, a purported backdoor in ESP32 chips discovered by a cyber security firm. If you’re not familiar with the ESP32 chip, it is a highly popular device from Espressif, and odds are you have some in your house. The ESP family has been the go-to chipset for consumer IoT devices for the last several years. These chips are under $2 in quantities, small, low power, and support various flavors of Bluetooth and Wifi, along with a bunch of IO pins. They’re also widely popular with hobbyists for all sorts of projects, and there are communities like ESPHome built around them. 

 

A backdoor in the bluetooth implementation on these chips would certainly be a big deal, affecting literally billions of devices. Links to various reports on the Tarlogic disclosure were all over tech groups in the past week. The initial panic was understandable.

 

The problem is that this discovery sounded odd right from the drop, at least to me. First, Espressif has been known for being very open and very supportive of their products. While the chips themselves are cheap, Espressif’s core customers spend 10’s of millions of dollars with them annually, and build products not with Espressif’s brand, but with their own. Espressif seems to understand this well, and in my experience takes security seriously. That isn’t to say a vulnerability can’t happen, but a so-called Backdoor seems highly unlikely. 

 

Digging into the report, the supposed Backdoor wasn’t something that existed in every device in a way that allows a bad actor to gain access to a deployed device. Instead, using the undocumented commands they discovered required loading new firmware on the device which was designed to exploit these commands. And additionally that firmware would have to mimic all the normal functionality of the device to go undetected. Firmware updates for IoT devices, if they exist at all, tend to be handled in a way that abstracts most of the work and process away from the user. I know that my mom wouldn’t be downloading a firmware.bin file and manually updating all of her light switches and thermostats in her underground bunker. That is just too much work. It is possible that some attacker could gain access to the network and leverage these devices, similar to the “webcam” example above (though in my mom’s case, her internal network is airgapped and has an intrusion detection stack running for good measure).

 

The ESP32 backdoor did not seem much like a backdoor at all. It was technically some undocumented commands that existed in the chipset, and the undocumented nature of them means the odds of them being used in any typical devices is near zero. Additionally, if you’ve ever worked with chipsets at low levels, especially ones with RF capabilities, then you have probably already been aware of undocumented commands or features. Sometimes there are commands used for post-manufacturing calibration, tuning, or other “Factory-only” type functions. RF devices in particular often need to be tweaked based on where they are deployed globally. There are many wifi chipsets that can be adjusted to transmit on unauthorized channels, or put out excessive power, depending on what geography they are in. Granted, these are typically documented commands, but in the early days of wifi chipsets there were several that could be exploited via undocumented commands to output extra power and clobber other devices.

 

Unfortunately this Backdoor discovery looked more like a cybersecurity firm overhyping a typical scenario with embedded chipsets, and as additional information came out it became more clear that calling this a Backdoor was serious overhype. Espressif put out a statement a few days after this had already gone around the internet a thousand times, describing the undocumented commands in more detail, and why they were undocumented (and also not any kind of a backdoor).

What Does Any Of This Mean For Security?

Previously cyber security and physical security were distinct things, with minimal overlap for practitioners of either. Now, the two are very tightly linked, and physical security practitioners need to be up on cyber security. To me, this means not just understanding that cybersecurity is a thing, but also learning how to evaluate reported vulnerabilities to prioritize responses and mitigations. It will also mean we will likely see new generations of network security equipment designed to help protect IoT devices that are now prevalent, and unable to be managed by traditional IT security software packages and policies. 

The next generation of successful physical security integrators will also be equally network security integrators.

What Stood Out to Me this Week? More like Whoo Stood Out to Me đŸ˜Ž

by Lee Odess

When Jessica Hecht and Arturo Falck from Whoo reached out recently saying "I had to see what they were up to," my interest was immediately piqued. Having known Arturo for years, I've come to recognize that behind his friendly demeanor lies a serious professional. When he says "you need to see this," i feel it is worth paying attention.

And in this case, I wasn't disappointed.

I've previously shared my thoughts on AI's transformative potential and how it’s an architecture that many are building on that will disrupt many old truths of our industry, particularly regarding Agentic AI or AI Agents (as discussed in my earlier posts about REKS.ai). What Whoo is doing takes this concept even further into the realm of Conversational AI.

Their focus on transit applications particularly resonated with me, but it quickly became apparent: why wouldn't this technology be everywhere there is a callbox or intercom? Like, every intercom system—those blue light emergency callboxes on campuses, entry systems for multifamily residences and gated communities, information points in malls, hospitals, and beyond—enhanced with intelligent, conversational capabilities.

What sets Whoo apart is their collaborative approach with intercom manufacturers, seamlessly integrating Conversational AI agents into existing products. It's rare to encounter such an intuitive solution that the general public would readily embrace. My mom would 100% understand how to use this and see the value in it without having to be educated on it or trained. This interface isn't just for wayfinding—it handles recommendations, lost item assistance, customer service inquiries, and much more.

I strongly encourage you to check it out and then tell me how you don’t think AI will impact our industry and the way the general public interacts with us. I also challenge you to not see the + in this adds to our utility as an industry.

And if you're attending ACS25, you won't want to miss Arturo's presentation during a My View session, where he'll share his perspective on conversations becoming the next frontier in user interfaces.


Access Control as a Feature, Not Just a Function

by Lee Odess

I have known James Shannon, Chief Product & Technology Officer, and the company essensys for quite awhile now. In fact I was also a customer in a few coworking spaces over the years as they managed wifi at a good number of them. They were the classic identity provider and service provider you could see take a hard swing at the access control industry given they have digital identities, a captured audience, and a use case where the user is super digital and looking for a great experience. Well, they recently came out with something to put that idea into motion.

The recent announcement of elumo by essensys represents another example of how access control is evolving from a standalone security function into a strategic feature of a larger value propositions. essensys, already a formidable player in the commercial real estate technology space (publicly traded on the London Stock Exchange AIM Market since 2006), has clearly identified a critical pain point in the flexible workspace market. The traditional binary approach to meeting rooms—either locked (causing frustration) or unlocked (inviting "squatting")—has created a significant challenge for property operators balancing experience with revenue generation.

What makes elumo particularly compelling is how it seamlessly integrates three critical elements: bookings, access, and intelligence. By leveraging mobile wallet technology, the solution enables users to instantly book and access spaces with a simple tap, completing the process in under half a second. This approach prioritizes the user experience while simultaneously addressing operators' revenue concerns. The real innovation here is positioning access control not as a security afterthought or siloed system but as an integral component of the overall space management and monetization strategy. essensys has recognized that controlling who enters which spaces at what times isn't just about security—it's about creating frictionless experiences that drive adoption while enabling operators to maximize revenue from their physical assets. For property managers and operators in today's hybrid work environment, the promise of "ROI in days, not years" is particularly appealing. The ability to instantly monetize meeting spaces and even convert vacant offices into revenue-generating assets represents a fundamental shift in how commercial real estate can perform financially. The real-time intelligence component further elevates the offering, providing operators insights into space utilization patterns that can inform future decisions about their portfolios.

essensys has effectively transformed the expectations for what technology should deliver in flexible workspaces. By approaching access control as a strategic enabler rather than just a tactical function, they've created a solution that addresses multiple stakeholder needs simultaneously—enhancing user experiences while optimizing operational efficiency and revenue generation. This integrated approach demonstrates how the commercial real estate industry is evolving to meet the needs of today's flexible, hybrid work environment, with technology solutions that go far beyond traditional access control to deliver comprehensive space management capabilities.

And if you're attending ACS25, you won't want to miss James’s as he participates in a panel titled â€œThe Plus Protocol: Redefining the Power of Access Systems” where we will breakdown â€œThe Plus Protocol explores how modern access control has evolved beyond traditional security functions to become a strategic business asset. This panel brings together global thought leaders to discuss the untapped potential of these systems, from operational efficiency to enhanced user experiences. Join us to discover what actions industry stakeholders should take today to realize the shared vision of tomorrow's intelligent access ecosystem.”


Too often, the security industry undervalues the ID badge.

In fact, it's often an after-thought in systems implementations, viewed as simply a "means to an end"... A utility to do something else within the facility.

IDs are more than just a piece of plastic though.  They are more than a key to unlock a door, or a form of validation. True; they serve these purposes, but their true power lies in something greater.  IDs have the power to connect people.
 
Think about the last conference you attended. When someone hopped in the elevator wearing the same attendee badge as you, how much easier was it to start up a conversation since you already had a point of connection?
 
What about your last corporate get-together?  When you haven't seen your out-of-town co-workers since the last company event, or you've never met some of the newer team members in person, how helpful are badges to identify everyone on the team by name?
 
Think about the student walking into their middle school for the first time. How much more welcome do they feel when a teacher greets them by name as they walk through the door?

Our names hold deep significance to us.  It is one of the few sounds we instinctively recognize even in the most crowded of rooms.  When someone greets us by name, we immediately feel a stronger connection to them.  

Wearing a photo ID with the first name displayed in large letters creates a gateway to recognition. It fosters a culture where team members are not just numbers, not just faces in a crowd, but one where they are truly recognized and valued.

Schools all over the country are worried about balancing safety and security of staff and students with the desire to have an open and friendly environment, while constantly trying to build a strong sense of community among everyone who walks in the building.  

These are real problems that our customers are talking about every single day. 

These are problems that we get to help solve.  With something as simple as a badge. 

Your name has value.  Your badge has value too.

Join industry expert Jeremy Fromm as he dives into the fascinating world of Wiegand protocol exploitation using the ESPKey device in this YouTube video. In this episode of “Cyber Series,” Jeremy demonstrates how to intercept and analyze data from card readers and access control systems that utilize the Wiegand protocol. What you'll learn in this video:

  • Understanding the Wiegand protocol and its vulnerabilities

  • Setting up and configuring the ESPKey device

  • Live demonstration of Wiegand sniffing techniques

  • Real-world security implications and risk mitigation strategies

  • Considerations for security professionals

This educational content is intended for cybersecurity professionals, ethical hackers, and IT security specialists looking to understand potential vulnerabilities in physical access control systems.



5513 Oak Place, Bethesda, MD 20817, United States

Unsubscribe

Volume 40
Volume 40 | December 5, 2025 This Week’s Featured Articles & Media Danny Smith | The Physical Card Renaissance: My TRUSTECH Wake-Up CallDanny’s trip to TRUSTECH flipped his assumptions about the future of credentials. Instead of a mobile-only world, he found a global market doubling down on both physical and digital, creating a hybrid reality that demands smarter strategies, better integrations...
Volume 39
Volume 39 | November 21, 2025   This Week’s Featured Articles & Media   Lee Odess | Why We Continue to Bet on ISC Security EventsMost events can rinse and repeat the same formula for 30 years, call it a day, and then try to control all aspects of creativity. Instead, ISC Security Events is proving what real investment and evolution look like. Lee writes about at how initiatives like the Start...
Volume 38
Volume 38 | November 14, 2025   This Week’s Featured Articles & Media Karsten Nölling | From Metal Keys to Minimalist Design: The Security Dealer of the FutureThe locksmith’s wall of keys is giving way to the digital access showroom. As door security moves from metal to mobile, Karsten looks at how dealers can evolve from key-cutters to Digital Access Consultants, creating modern, experience-...
Footer Logo
© 2026 The Access Control Collective.
All Rights Reserved.
Privacy Policy Terms of Use

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.