11 Questions for Evaluating Security Technology at GSX 2026
Walking the GSX show floor provides an opportunity to see hundreds of security technology offerings in a very short time. The challenge isn’t finding interesting products. It’s determining which ones can meaningfully improve your security operations and fit into the larger technology and organizational environment in which they must function.
That requires looking beyond features.
Today’s security technologies increasingly operate as parts of larger systems of systems. AI-enabled products can provide new forms of detection, analysis and situational awareness. Specialized products can add capabilities to existing systems without requiring their replacement. Integration can combine technologies into greater capability, while orchestration can establish how technologies, information, people and workflows function together to achieve operational objectives.
At the same time, acquiring and deploying technology does not automatically make an organization ready to put it fully to work. Operational readiness, supportability, cybersecurity, privacy, governance and lifecycle management all affect the value ultimately obtained.
With those perspectives in mind, here are some questions worth taking onto the GSX show floor.
AI delivers the greatest value when it helps security teams make sense of information, communicate shared understanding and translate decisions into consistent action.Questions to ask
1. OPERATIONAL VALUE. What specifically will your solution enable our security organization to do more effectively that we cannot do — or cannot do well — today?
Product demonstrations naturally focus on features and functionality. Bring the conversation back to operational improvement. Ask what changes for security personnel, security operations and the organization when the technology is put to work.
2. RISK SCENARIOS. What specific security risk scenarios does your solution address, and how does it change detection, assessment, response or recovery for those scenarios?
A useful answer should go beyond listing product functions. Ask what happens today without the capability, what happens with it, and how the difference improves the security outcome.
3. OPERATIONAL READINESS. What must we have in place — people, processes, training, configuration, information and assigned responsibilities — to put this technology fully to work?
Technology deployment and technology operationalization are not the same thing. A successful installation can still fall short of its potential if the organization isn’t prepared to operate and sustain the resulting capabilities.
For more on this distinction, see my recent SecurityInfoWatch article, “Operationalizing Security Technologies.”
4. ORGANIZATIONAL CAPABILITY. What sustainable organizational security capability will this technology help us establish or improve?
Look beyond what the product itself can do. Consider what the organization will become capable of doing consistently because the technology, people, processes and information have been put together effectively.
5. NATIVE INTEROPERABILITY. What other technologies does your solution interoperate with natively, and what information and functions can they exchange without custom integration work?
A specialized product doesn’t have to be an isolated product. A Natively Interoperable Point Solution can provide highly specialized functionality while being designed from the outset to participate in a larger multi-vendor technology environment.
Ask what works out of the box, what requires configuration, and what requires middleware, custom development or professional services. Don’t stop at “We have an API.”
6. ORCHESTRATION. How can your technology participate in coordinated workflows involving other technologies, information and people?
Can events or information from the product trigger actions in other systems? Can other systems trigger actions in this one? Ask the vendor to describe a complete operational workflow rather than simply naming systems with which the product integrates.
Integration combines systems into greater capability. Orchestration establishes how technologies, information, people and workflows function together to achieve operational objectives.
For more on that distinction, see “Why Orchestration is the Next Step Beyond Integration.”
7. EXISTING SYSTEM VALUE. How can your solution add capabilities to technologies we already have rather than requiring their replacement?
Many organizations have substantial investments in deployed physical security technology. New technology should be evaluated not only for what it can replace, but also for what additional capabilities it can bring to what is already there.
This question can be especially important when evaluating specialized AI analytics, identity and access technologies, sensing technologies, cloud services and other focused offerings.
8. OPERATIONAL SUPPORTABILITY. How easily can our staff and integrator configure, monitor, troubleshoot and recover the solution?
Ask to see the audit trails, event logs and diagnostic tools available for troubleshooting. For integrations, can you determine whether information was sent, received and acted upon as intended? Can configurations be backed up and restored? Can a known-good configuration be recovered after a failure or problematic change?
Also ask: Do you have a publicly available product knowledge base that I can examine? Look for configuration, integration, cybersecurity, troubleshooting and lifecycle-management guidance.
An integration isn’t fully supportable if you can’t readily determine what happened when it doesn’t work as expected.
9. AI OPERATIONAL IMPACT AND GOVERNANCE. Where AI is involved, what does it actually improve, and what must we do to govern its use?
Ask what AI improves: detection, situational awareness, decision-making, response time, operator workload, reporting or some other operational outcome. Then ask who develops and maintains the AI models, how updates are validated, what information the AI uses, and what human oversight is required.
The important question isn’t simply, “Does it use AI?” It is what the AI contributes and what responsibilities come with using it.
10. CYBERSECURITY, PRIVACY AND DATA GOVERNANCE. What protections and controls are built into the product, and what responsibilities remain with us?
Ask about identity and access controls, encryption, digital certificates, security updates, vulnerability management and product security documentation. For systems that collect, analyze, retain or exchange sensitive information, ask what privacy controls are available and how data retention, access, sharing and deletion can be governed.
Don’t settle for “Our product is secure” or “We support privacy.” Ask to see the controls and documentation.
11. LIFECYCLE AND SCALE. What will it take to manage and sustain this technology across our intended deployment over its useful life?
Ask how devices and applications are inventoried, configured, monitored, updated and supported at scale. How are firmware and software updates handled? How long will cybersecurity patches and product support be provided? What happens as the deployment grows from a pilot to dozens, hundreds or thousands of devices, users or sites?
A technology that is easy to demonstrate or pilot may be very different to own at enterprise scale.
gettyimages2192055374Look beyond the product
GSX exhibitors have limited time to demonstrate increasingly capable technologies, so naturally their presentations focus on what their products can do. Your job is to consider something larger: what can your organization accomplish with them?
That means looking beyond individual products to operational readiness, organizational capabilities, interoperability, integration, orchestration, supportability and lifecycle management.
The show floor is also a particularly good place to ask vendors to show rather than tell. Ask to see the audit trail. Ask to see the knowledge base. Ask to see the privacy controls. Ask how an integration is configured. Ask what happens when it fails. Ask for an example of a multi-system workflow.
The answers can reveal much more than a feature list.
Most importantly, don’t evaluate a technology only as the product you see demonstrated in the booth. Evaluate how effectively it can become part of the security capabilities your organization needs to establish, operate and sustain.
About the Author
Ray Bernard, PSP, CHS-IIIRay Bernard, PSP, CHS-III
Ray Bernard, PSP, CHS-III, is the principal consultant for Ray Bernard Consulting Services (RBCS), a firm that provides security consulting services for public and private facilities (www.go-rbcs.com). In 2018 IFSEC Global listed Ray as #12 in the world’s top 30 Security Thought Leaders. He is the author of the Elsevier book Security Technology Convergence Insights available on Amazon. Ray has recently released an insightful downloadable eBook titled, Future-Ready Network Design for Physical Security Systems, available in English and Spanish.
Follow him on LinkedIn: www.linkedin.com/in/raybernard.
Follow him on Twitter: @RayBernardRBCS.
