Access Control is Obsolete; A Glimpse at Its Future

As enterprise security leaders demand cyber-hardened infrastructure, lower deployment costs, and greater scalability, traditional access control architectures are facing growing scrutiny. This provocative industry perspective argues that the future of access control lies beyond legacy panels, proprietary ecosystems, and decades-old communications protocols—toward IP-native, PoE-powered, software-driven door intelligence.

Key Highlights

  • The security camera industry has reached a functional plateau, with innovations mainly improving interfaces and storage, but not the core camera capabilities.
  • Legacy access control protocols like Wiegand and Prox are outdated, insecure, and hinder industry progress; a shift to IP and OSDP is necessary for scalability and security.
  • Cost considerations, including cabling and hardware, are driving the industry towards PoE and wireless solutions, which can significantly reduce installation expenses.
  • Trust issues in security systems stem from outdated technology, inadequate cybersecurity measures, and internal policies, emphasizing the need for more secure, integrated solutions.
  • Industry resistance to change is fueled by fear of patent infringement, proprietary technology, and the perceived risks of adopting disruptive innovations, but embracing these can lead to significant advancements.

There is a divide in the security industry, maybe you’ve noticed.  Talk of innovation and next-generation systems, and finally, access control.   While this article challenges the access control industry, let’s first look at the security camera.  Internet Protocol (IP) cameras were released in 1996 by Axis Communications.  Some companies, like Pelco, chose in the early 2000s not to innovate around technology, costing the company dearly; a decision they have since reversed.  Today, many of the cameras installed are IP cameras. 

The argument now is, can a camera’s functionality get any better?  We have camera sensors that can see in starlight.  They can take pictures at any frame rate between 1 fps and 120 fps.  Cameras capture anywhere from 1080p (2MP) to 96MP with a single imager.  There is not much more to make a camera better for its function as a camera.  Sure, we can add a better user interface, more computing and storage, and a graphics processing unit (GPU) built into the camera, but the camera's actual function at this point isn't getting any better.  Let’s be honest, we can view other galaxies with a camera now.  Where else can this go?

The Fight for Legacy

On the other side of the spectrum, we have an electronic access control system.  Access control is not sexy.  It does not grab attention until it fails.  Most people view access control as little more than a database of actionable users, with excitement wrapped around peripheries; mobile credentials, biometrics, etc. 

The core technology of access control was originally released in the 1960s and has remained remarkably unchanged since then, with the largest breakthrough being a shift from RS-232/RS-485-based panel communication to IP connectivity.  Granted, boards have evolved since then and expanded to support 1, 2, 4, 8, 16, etc. door counts.  The breakthrough that gets talked about was when “some” access control companies figured out how to license individual doors and not by the next binary number.  Remember the days when you needed the 17th license but had to purchase 32?  For some, those days are still here.  Electronic access control boards still, for the most part, consist of one or more reader ports, two or more inputs, and one or more relays.  For many of the manufacturers' panels, readers, inputs, and output relays are hard-coded to specific functions or devices. 

Really? At this stage in the development process?  Thank you for that headache. 

For a system that, historically, was a software layer on top of an isolated SQL database, is designed to present a credential, validate the credential, and unlock a door; or, upon leaving, validate that a person is exiting and shunt a sensor, so it does not give an alarm.  Yet nuisance alarms are among the most common and troublesome problems for enterprises, so much so that many turn them off or delete them without ever investigating.  Features that made access control innovative in the past have now led to its undoing.

The core technology of access control was originally released in the 1960s and has remained remarkably unchanged since then, with the largest breakthrough being a shift from RS-232/RS-485-based panel communication to IP connectivity. Granted, boards have evolved since then and expanded to support 1, 2, 4, 8, 16, etc. door counts. The breakthrough that gets talked about was when “some” access control companies figured out how to license individual doors and not by the next binary number.

Trust in access control is limited because many still rely on isolation or on technologies proven vulnerable decades ago, yet, as an industry, we are still fighting the legacy mindset.  As an industry, we admonish the trunk slammers, but is that not exactly what we are doing, peddling legacy technology with shiny new stickers?  

The question should be, why?  Access control manufacturers seem to be making futile attempts to stay relevant by answering the following question: how to take market share from HID and Mercury, while keeping their access control systems from being ripped out.  Concerns like who can make a better board or how we can replace or retrofit the “x” brand with the “y” brand.  Here, let’s add Message Queuing Telemetry Transport (MQTT) so this board can talk to that board, or let’s make a new standard so all who use it are “open”, a term that has become synonymous with the kitchen sink. Who can make a better credential (card, fob, mobile credential, etc.)?  These are very good ideas, but they are band-aids at best. 

What’s difficult is that some of the access control manufacturers know it.  For example, a VP of product at an access control manufacturer recently stated that “the status quo is no longer good enough.”  That limiting mindset seems to be at the heart of most access control manufacturers, when the status quo is never good enough.   Here’s a novel idea: instead of trying so hard to keep customers through proprietary systems designed as traps, give them a reason to stay.  For some, the answer is to suck less; yes, I said it.  Maybe the product was rushed to market or is marred by years of technical debt; the product does not function optimally. 

Maybe it's just better support for the integrator and the end user.  For others, this will require removing the bloat and kludgy aspects of the software.  “Maybe it’s time for genuine innovation, rather than simply matching your competitor’s features,” says Brett Zelnio, Principal Consultant with Stratified Logic Group and co-thinker on this article. The access control industry is the only segment within the security industry where innovation can stall, sometimes for years or decades, and no other company will overtake it.  Those brands that do innovate get to talk about it for years, as it may be years before their next innovation.  Compare that to a camera manufacturer that fails to innovate: 50 other companies release their “x brand killer” within a year. 

While opportunity is knocking, why are we not tackling issues like 125 kHz Prox and Wiegand, which are being perpetuated as “security” solutions?  Opinion time: Prox, as a technology, is not going away because it has many applications beyond security.  For the security industry, 125 kHz Prox is the tech that just will not die, despite most respected security practitioners calling for its demise.  As an industry striving to provide true security, we must design away from it.  For those selling Prox, an end-user license agreement (EULA) is long overdue and states that if you use Prox, all liability falls solely on the end-user. 

Watch how fast Prox goes away.  Integrators who install Wiegand readers should be required to complete a similar EULA with the distributor.  Wiegand’s lifespan will likely drop dramatically.  Wiegand has a migration path to Open Supervised Device Protocol (OSDP), a bidirectional secure RS-485 communication protocol between the panel and peripherals.  However, many installers are still unaware or untrained on OSDP.  So are manufacturers. 

The Security Industry Association (SIA) holds educational OSDP bootcamps throughout the year, welcoming integrators, manufacturers, and end-user customers.  However, access control manufacturers are still part of the problem.  Many of them promote OSDP-compliant technologies and household access control names, yet they are not.   One of the OSDP validators noted that many manufacturers who say they are compliant still have significant work to do to make their OSDP-compliant devices actually secure.  A good place to find those products that are OSDP verified is on SIA’s website at https://www.securityindustry.org/industry-standards/open-supervised-device-protocol/sia-osdp-verified/sia-osdp-verified-products/. It’s sad that one of the best innovations that the access control industry has come from low-voltage cabling companies, who created the composite cable to bundle all of the necessary door cabling into one jacketed “banana cable” to make installation easier. 

Systems of Trust

The reality is that security systems have caused a trust problem.  One of many reasons security systems are air-gapped from production networks is that they do not meet the enterprise network standards.  Panels may communicate via IP connectivity, but the peripheries do not.  They are not monitored in the same way, and the checks and balances within access control monitoring systems are typically inadequate for companies that value their cybersecurity.  Admittedly, access control is not the only reason security systems are air-gapped from production networks.  Often, this relates to internal policies on system ownership and ongoing maintenance, such as cyberhardening, firmware updates, password changes, and more. 

Who do enterprises trust when it comes to technology?  Security? Typically, not.  We still have limited budgets for gates, guards, and guns.  We are the insurance policy that every enterprise hopes never to have to use, because that would mean they have made front-page news (for those who read newspapers).  Also, we really have not given them a reason to trust us.  Sure, we are the security industry, the people who keep assets and people safe.  But that is not enough. 

On any enterprise’s company ledger sheet, security is a liability.  Security costs money; it rarely makes money, although it has proven valuable in bringing business intelligence to organizational stakeholders.  The enterprise must have trust in its IT infrastructure networks.  In the hyperconnected world we live in, IT infrastructure networks are the lifeblood of the enterprise.  They support the heart of the business and its profitability.  It’s not uncommon for a corporate entity to spend 10 times or more on network and network security than they spend on their entire security program. 

The infosec requirements and the potential liability for noncompliance make most companies tremble.  They are looking for IPv6 connectivity, 802.1x port authentication with certificate injection, Transport Layer Security (TLS) 1.3, Trusted Platform Module (TPM) secure element, secure boot, signed firmware, Single Sign On (SSO) compliance, ISO27001 and/or SOC2 compliance, UL/ULC/CE certifications, AES-256, zero-trust, air-gapped, redundant with high availability, industry or geographic compliance – Data Privacy (GDPR, CCPA), Biometric (BIPA/CUBI), AI (EU AI Act), and more.  All the while, the access control industry is still trying to determine if Prox and Wiegand should still be implemented.  Cybersecure solutions compared to systems with known vulnerabilities.

Missed Opportunities

Why, specifically, is the access control industry fighting over legacy technology?  Here’s a question: Why do we need an access control panel?  IP connectivity is commonplace, supporting Internet of Things (IoT) devices, Power over Ethernet (PoE), digital input/output (DIO), web relays and more.  Access control typically uses IP connectivity to connect panels and peripherals to the internet/intranet.  In most instances, it does not use IP to communicate with endpoints.  Has access control missed the boat?  It sure looks like it.  The panel is not necessary.  Battery-powered IoT devices can operate as a system rather than as individual devices and communicate via IP, LoRaWAN, or other standard protocols.  Yet, the security industry has a panel.  The best we have been able to do is install a PoE panel at the door to communicate with the request-to-exit, door contact, lock, and reader.  Again, why?  Camera manufacturers have already made the move, some going even further by offering IP hubs to power other cameras. Why not have a door instead of a camera?  Many building automation systems have adopted IP as the primary communication protocol.  Traditional analog programmable logic controllers (PLCs) have transitioned to IP-based and even digital logic, effectively removing the PLC entirely.  Legacy still exists here as well, with analog camera systems and serial-communication-based building management, but unlike the access control industry, innovation is being seen and felt.    

Change does not happen overnight, and our first attempt at real change led us from insecure Wiegand to a more secure OSDP protocol.  However, there are two problems with OSDP.  The first is a messaging problem, much like that of the Open Network Video Interface Forum (ONVIF) standards, and the second is that technicians are still trying to figure out how to wire readers correctly using OSDP. 

Most of those same technicians can make an ANSI/TIA 568-B termination after their first day or two on the job; 568-A for those AT&T connections.  OSDP lets us daisy-chain technologies, but passthrough PoE has been around for years as well.  Passthrough PoE is also another word for daisy chaining.  Granted, OSDP has a 4000-foot distance, while the ANSI/TIA 568 standard limits the run to 100 meters (328 feet) for 1GB connectivity.  While other technologies allow greater distances, they do not meet standards and may not be allowed on a job.  While OSDP can go up to 4000 feet, most access control panels can support only two card readers on an OSDP daisy chain, whereas locks and other devices require much shorter distances to avoid voltage drop. 

The access control industry has gone so far as to create a unique standard, OSDP, for us, as a stopgap, not a scalable solution.  Kudos to the team that did that, but why?  IP connectivity offers almost infinite scalability, real-time device supervision, and the ability to segment devices when a problem is detected. 

The Field of Dreams Moment

Why have we not instead created a PoE request-to-exit device that can wire a door contact to the request-to-exit?  Why not have a PoE card reader instead of a biometric reader that requires both PoE and OSDP connectivity?  Why not have a PoE lock (there are a few)?  Any one or multiple of these items could be PoE, PoE+, or PoE++ devices with passthrough PoE to power one or multiple peripherals at a door?  Pull one Cat6 cable to a door to provide power and communication to everything, rather than a composite cable that connects back to 1960s technology. 

Unfortunately, a cursory internet search only turned up a handful of manufacturers who offered traditional electric strikes, mortise, and exit devices powered by PoE. Wonder why that is?  Could it be that these companies have secured the intellectual property around PoE locks?  Could it be they are betting on the future, or simply stifling the industry?  Are these the innovators while the rest of the industry nurses the status quo? 

Compare this to the wireless lockset manufacturers, who offer battery-operated, WiFi-enabled wireless locksets.  While wired PoE locksets are seemingly scarce, wireless handsets are abundant; however, for enterprise clients, battery-powered handsets may not be optimal or permitted.

Still, only a handful of manufacturers offer PoE card readers, including companies that the security industry likes to claim are not security companies.  Hate to say it, but this looks like a Field of Dreams moment; “if you build it, they will come. Feel free to argue with millions and billions of success stories of new companies that have entered the security market.

Costs are King

It will all come down to costs in the end.  For new installations or retrofits, the cost of access control can price the industry out of the market before it even begins. 

To begin with, look at the cost of the composite cable. Plenum-rated composite cable is 6x-8x the cost of a plenum-rated CAT 6A cable.  However, it’s not just the cost of the cable itself; it also includes freight (due to its weight), storage costs, and so on. 

Using only networked devices (wired or wireless) will likely reduce the cost of installing a door, much like IoT sensors reduced costs in the IT industry, thereby increasing the prevalence of these technologies. The end-user is already going to spend money on a door and a lock.  These are table stakes already.  Many enterprise companies are already installing powered locks and transfer hinges for “future doors”.  The door hardware may already be ready for this concept.

Eliminating the panel and power supply for either on-premises or cloud connectivity to doors reduces head-end installation costs.  This will not sit well with legacy panel companies or power supply manufacturers, but when a 24-door head-end costing more than $20K is removed from the budget, access control becomes feasible. 

What problems does this solve for the end-user?  This can go two ways.  One, adding more access control as the costs reduce.  Two, the retrofit becomes less of a conversation.  Trying to keep legacy panels that are end-of-life on life support because replacing them is too expensive is a different conversation from replacing just the peripherals.  While most consultants suggest refreshing the access control system every 8-10 years, this helps those 25+-year retrofits move faster. 

The ESG Catalyst

If costs are king, environmental, social, and governance (ESG) goals are their partner.  While some of these goals are internally mandated, others are compliance-driven by government regulation.  Either way, ESG has become a catalyst for change.  We’ve already seen the adoption of mobile credentials in certain verticals because they have furthered ESG objectives. The panel is quickly landing in those crosshairs.  PoE devices require less power than a traditional access control system.  A 24-door system could see as much as a 50% savings in power costs.  While that may not seem like much, for large organizations, it could mean millions in savings each year.  As an industry, we have already seen companies push for new technologies that better align with their ESG goals. 

Speed Bumps or Roadblocks

What is stopping manufacturers?  In a word, fear.  Now, that word is not taken lightly, but that is the primary catalyst for not moving.  Fear of change, fear of rejection, or fear of a lawsuit.  As an industry, we see change as a problem.  It's why when a disruptive technology comes along, we tend to demonize it until everyone else jumps on the bandwagon. 

The industry needs to stop looking at this as a roadblock and view it as what it really is: a speed bump.  The only real roadblock is the one surrounding patented technology.  Retrofits, software development, and physical and cyber vulnerabilities are all speed bumps that require a slow but unwavering approach to implementation. 

The driver for this change is not coming from inside the security industry, obviously.  IT departments have audited the technical debt they own and have decided it's time to get rid of it.  Brett Zelnio explains: “In the absence of a security manager, the IT manager often fills the gap.  When it comes to large capital projects within an enterprise-level organization, it’s not uncommon that the voice of the CIO will garner more influence in the decision-making than the voice of the CSO.” 

Maybe it's time that the security industry offered something equally appealing to both the CSO and the CIO. 

In Closing

Brett Zelnio sums it up nicely: “It shouldn’t go unnoticed that technology companies like Ubiquiti are pushing into the security space.  It’s a short bridge to cross from Identity Access Management (IAM) to Physical Identity Access Management (PIAM).  With the advent of PoE card readers and door-locking hardware, we are entering a new age of access-control system logic.  The access control market, as we know it, is dependent on door controller panels.  As smart door hardware gets smarter and battery power improves, it’s not out of the realm of possibilities to eliminate the hardware middleman that adds high cost to access control infrastructure. 

If system door capacity is no longer restricted by controller boards in the field or the cables pulled to each door, the cost per door plummets.  This thought doesn’t bode well for panel manufacturers or structured cabling suppliers.  Simultaneously, this reduction/elimination of physical hardware/cabling costs presents a massive win for access control software providers. This reduced cost per door associated with adding access control would likely catalyze the broader adoption of access control on enterprise-scale projects.  Software providers would then certainly see higher licensing revenue as enterprise clients could apply access control solutions more widely at a much lower cost.

The access control industry is not known for its innovation.  Sorry, not sorry. 

Retooling existing technologies, sure. Is this a new and radical concept? Maybe. Blasphemous to the legacy industry, absolutely.  Heretical if being honest.  Is it wrong? No, and after polling several access control professionals and security industry leaders who were enthusiastic about this idea, a version of this is in the future of access control; it has to be. 

Is it the intention to step on industry toes? No.  It is meant to be a challenge to the access control industry, to move us past legacy and towards where we should be heading.  Admittedly, it will take some time because it is so different and disruptive in the marketplace.  The fight for legacy will snuff out most companies offering something this unique.  Or they are going to change the world. 

 

About the Author

Jon Polly

Jon Polly

Jon Polly is the Chief Solutions Officer for ProTecht Solutions Partners (www.protechtsolutionspartners.com), , a security technology consulting firm that works with smart cities and corporations to bring business intelligence and public safety through security IoT applications. He has worked as a Project Manager and System Designer for City-Wide surveillance and Transportation camera projects in Raleigh and Charlotte, N.C.; Charleston, S.C.; and Washington, D.C. He is certified in Critical Chain Project Management (IC3PM) by the International Supply Chain Education Alliance (ISCEA). • (704) 759-6837

Sign up for our eNewsletters
Get the latest news and updates