The shift from entry control to risk control is mostly a shift in posture. Entry control asks a binary question at the door: grant or deny and does nothing with the metadata contained in the answer. Risk control asks what the accumulated answers reveal. A credential used at two sites 400 miles apart within the same hour. A contractor whose after-hours entries have quietly tripled over a quarter. A cluster of denied reads on one door the week before a resignation. None of these trips is a traditional alarm, because no single event is a violation. The signal lies in the analysis of the aggregate data your PACS system happily generates continuously.
Practitioners already know the canonical anomalies: tailgating, after-hours access, repeated denials, impossible travel. What changes when you treat PACS as an intelligence source and analyze the data in real time is that it stops being incidents you investigate after the fact and becomes indicators you monitor continuously. Badge data becomes a leading signal for insider risk, a corroborating layer for investigations, and an occupancy feed for everything from emergency mustering to real-estate decisions. The data was always there; what is new is the ability to mine it effectively.
This is also where physical and cyber have a reason to talk. Converged, unified security operations are the clear direction of travel, and identity is the connective tissue. A badge-in with no corresponding network login, or a network session from a user the PACS says is nowhere in the building, is the kind of contradiction that neither team can see on its own. Feeding access events into the same correlation layer as endpoint, identity, and network telemetry turns a pile of door logs into a prioritized risk picture and cuts the alert fatigue that comes from watching dozens of disconnected systems.
Even better, realizing this does not require ripping anything out or changing what is already in place. It requires treating PACS data as a managed asset rather than a byproduct: retaining events long enough to establish a baseline, normalizing them so they can be correlated with other sources, and getting them out of the access-control console and into wherever your team actually does analysis. It means defining the questions worth asking: what does normal look like for this population, this door, this hour. Doing this before an incident forces the question, which already puts you miles ahead.
Vendors are moving this way, slowly. Analytics, behavioral baselining, and AI-assisted anomaly detection are mostly arriving outside of PACS platforms and in other tools. But tooling is not a strategy. The differentiator is whether a security leader has decided that accessing data is part of the organization’s risk intelligence, or whether it remains a log that exists only to be subpoenaed after the fact.
The door is one of the most disciplined sensors most organizations own. It is deployed everywhere people are, it runs continuously, and it ties every observation to an identity. It is time to stop asking only one question. The teams that make that shift will not be buying a new capability so much as finally using one they have paid for all along.