Category: Access Control & Identity

Credentialing, biometrics, smart locks and identity verification technologies that control who can enter a facility.

  • Two-Person Integrity: Dual Authorization Access Control for High-Consequence Areas

    Two-Person Integrity: Dual Authorization Access Control for High-Consequence Areas

    For most secured spaces, the security question is simply who should be allowed in. For a narrower category of high-consequence areas — pharmaceutical controlled-substance vaults, cash-handling rooms, weapons storage, sensitive server rooms, certain industrial control rooms — the more important question is whether any single individual should ever be able to gain access alone at all. Two-person integrity (2PI) access control exists to enforce that no single person can act unilaterally in these spaces.

    The Core Principle

    Two-person integrity requires two separately authorized, distinct individuals to be simultaneously present to gain and maintain access to a controlled area, rather than one person’s credential being sufficient on its own. The underlying goal isn’t distrust of any specific individual; it’s structural risk reduction — removing the possibility that a single compromised credential, a single coerced employee, or a single person acting alone can result in unauthorized access to the most consequence-sensitive spaces in a facility.

    How It’s Implemented

    The most common implementation requires two independent, valid credential presentations within a defined time window before an access control system will unlock a controlled door, with the system explicitly rejecting a second scan from the same credential to prevent a single person defeating the control by badging twice. More rigorous implementations pair this with biometric verification for each individual, video confirmation that two distinct people are actually present, and logging that records both individuals’ identities against the access event, not just the fact that “two-person” access occurred.

    Handling the Exit Side

    Two-person integrity is often designed asymmetrically: exit typically doesn’t require the same dual authorization as entry, both because life-safety egress requirements generally take precedence and because the security concern is usually about who can initiate access to the controlled area, not who can leave it. Facilities implementing 2PI need to explicitly define this asymmetry rather than assuming it, since an overly rigid two-person requirement on egress can itself become a life-safety problem during an emergency.

    Where It Breaks Down in Practice

    The most common practical failure of two-person integrity isn’t a technology gap but a workflow one: when staffing is tight, employees under pressure to get a task done sometimes badge a colleague in and then leave, defeating the “simultaneous presence” requirement the control depends on. Facilities that rely on 2PI for genuinely high-consequence areas need staffing models and monitoring that make the control practically sustainable, not just technically correct on paper.

    Conclusion

    Two-person integrity is one of the more demanding access control patterns to implement well, because it depends as much on staffing discipline and monitoring as on the underlying credential technology. For the narrow set of areas where the consequence of a single unauthorized entry is severe enough to justify the operational overhead, it remains one of the more effective structural controls available — but only when the workflow around it is designed as carefully as the access control logic itself.

  • DHS Opens $440.7 Million Governmentwide Competition for Biometric Capture Devices

    DHS Opens $440.7 Million Governmentwide Competition for Biometric Capture Devices

    The Department of Homeland Security has opened bidding on a five-year, $440.7 million multiple-award IDIQ contract (solicitation 70RDA126R00000001) to standardize procurement of biometric capture devices — fingerprint, facial, iris, palmprint and multimodal systems — across DHS components and other federal agencies including the Departments of State and Justice, Washington Technology reported.

    The contract vehicle is intended to replace fragmented, one-off purchasing historically used by DHS’s Office of Biometric Identity Management. Proposals are due September 18, 2026.

    Why it matters: A single large, standardized federal contract vehicle for biometric hardware procurement gives vendors a much larger and more predictable addressable market than the agency-by-agency purchasing it replaces, and is likely to influence which biometric hardware standards and interoperability requirements become de facto norms across other government biometric deployments.

    Source: Washington Technology, September 11, 2026, corroborated by FedScoop and ID Tech Wire.

  • Anti-Tailgating and Mantrap Systems: Stopping Piggybacking at Secure Entrances

    Anti-Tailgating and Mantrap Systems: Stopping Piggybacking at Secure Entrances

    Tailgating, sometimes called piggybacking, happens when an unauthorized person follows an authorized person through a secured door before it closes and locks, quietly defeating an access control system without ever presenting a credential. It remains one of the most common real-world ways access control gets bypassed, largely because it exploits ordinary politeness rather than a technical flaw.

    Detection Versus Prevention

    Anti-tailgating technology falls into two broad categories: detection systems that sense a violation and alert security staff after the fact, and prevention systems that physically stop the second person from entering at all. Detection approaches include infrared or thermal sensors mounted above a doorway that count how many people pass through per credential swipe, and video analytics that visually track individuals entering a controlled space. These systems are lower cost and easier to retrofit into existing doorways, but they rely on a human response to an alarm rather than stopping the intrusion outright.

    How Mantraps Physically Prevent Piggybacking

    A mantrap, also called an interlocking vestibule, is a small enclosed space with two doors that are never both unlocked at the same time: a person must pass through the first door, have it lock behind them, and only then can the second door open, typically after a sensor confirms only one person is present in the vestibule. This makes it physically impossible for a second, uncredentialed person to slip through alongside an authorized individual, which is why mantraps are standard in the highest-security environments, including data centers, pharmaceutical facilities, and secure government spaces.

    Sensor Technology Inside the Vestibule

    Modern mantraps typically use overhead infrared beams, weight-sensing floor plates, or 3D depth sensors to verify occupancy before releasing the second door, since simple beam sensors alone can sometimes be fooled by unusual body positions or objects carried through the space. Some higher-security installations also require a second credential check or biometric verification at the interior door, adding an additional layer beyond simple occupancy counting.

    FAQ

    What is the difference between a mantrap and an airlock-style vestibule? The terms are often used interchangeably in security contexts; both describe a two-door interlocking space where only one door can be open or unlocked at a time.

    Can mantraps handle wheelchairs or large deliveries? Many facilities install a separate, staff-monitored accessible or delivery entrance alongside a mantrap, since the enclosed vestibule space can be too small for wheelchairs, carts or bulky equipment.

    Are camera-based tailgating detection systems as effective as mantraps? Detection-based systems are useful for lower-risk areas and can flag violations for review, but they do not physically prevent an intrusion the way a mantrap does, which is why the highest-security spaces typically use mantraps rather than detection alone.

  • Turnstiles and Pedestrian Access Barriers: Types and How to Choose

    Turnstiles and Pedestrian Access Barriers: Types and How to Choose

    Turnstiles are one of the oldest access control technologies still in widespread use, and for good reason: paired with a card reader or biometric scanner, a turnstile physically enforces that only one person passes per valid credential, something a door alone cannot guarantee. Choosing the right type is a balance between throughput, security level and how a site wants to present itself to visitors.

    Waist-Height Turnstiles for High Throughput

    Waist-height turnstiles, the tripod or drop-arm style common in stadiums, transit stations and office lobbies, prioritize speed, letting large numbers of people pass quickly while still enforcing single-person entry per credential. Their tradeoff is security level: a determined person can climb or vault over a waist-height barrier, which is why they are typically paired with a security guard or camera coverage rather than deployed as a standalone security measure in high-risk environments.

    Full-Height Turnstiles for Higher Security

    Full-height turnstiles, which resemble a rotating cage extending from floor to ceiling, physically prevent climbing over or crawling under, making them the standard choice for unstaffed perimeter entrances at data centers, utilities and other facilities where an unauthorized entry cannot rely on a guard noticing in time. The tradeoff is throughput and cost: full-height units process people more slowly and take up significantly more space and budget than waist-height alternatives.

    Optical and Sensor-Based Lanes

    A newer category, optical turnstiles or speed lanes, uses infrared sensors rather than physical arms to detect unauthorized passage, sounding an alarm or triggering a barrier only when someone attempts to pass without a valid credential or follows too closely behind an authorized person. These systems offer a more open, modern appearance favored in corporate lobbies, but they generally rely on integration with video analytics or a staffed reception desk to respond to detected violations rather than physically stopping them outright.

    Matching the Barrier to the Risk

    Security consultants typically select turnstile type based on the consequence of an unauthorized entry, the expected volume of legitimate traffic, and whether the location has staff present to respond to an alarm. A single site often uses different turnstile types at different entrances, for example optical lanes at a staffed main lobby and full-height turnstiles at an unstaffed rear or loading-area entrance.

    FAQ

    Can turnstiles alone stop tailgating? Waist-height and optical turnstiles reduce tailgating but do not fully prevent a determined person from following closely behind an authorized individual; full-height turnstiles and mantrap-style systems provide stronger physical prevention.

    Are full-height turnstiles required for data centers? Not universally required by code, but they are a common industry best practice for unstaffed high-security entrances where climbing over a barrier must be physically prevented rather than just detected.

    Do optical turnstiles work with mobile credentials? Yes, most modern optical turnstile systems integrate with the same card, mobile or biometric credential readers used elsewhere in a facility’s access control system.

  • Survey Finds Most Americans Believe Building Security Hasn’t Improved Since 9/11

    Survey Finds Most Americans Believe Building Security Hasn’t Improved Since 9/11

    A new YouGov survey commissioned by access-control vendor Alcatraz and reported by SecurityInfoWatch found that 79% of Americans do not believe physical building security has meaningfully improved in the 25 years since the September 11, 2001 attacks, and 73% called upgrading security technology at least somewhat urgent.

    Alcatraz tied the findings to a string of recent tailgating-related security breaches at Harvard, UCLA, 30 Rockefeller Center and the Empire State Building, arguing that standard badge-based access systems do not reliably detect a second, unauthorized person following an authorized badge-holder through a controlled door.

    Why it matters: The survey is vendor-commissioned research, and its framing understandably favors the sponsor’s tailgating-detection technology. But the underlying data point — persistent public skepticism about physical security investment a quarter-century after 9/11 — lands as the industry heads into GSX 2026, where access-control vendors are expected to lean heavily on anti-tailgating and mantrap messaging.

    Source: SecurityInfoWatch.com, September 10, 2026.

  • Access Control Cybersecurity: Hardening Controllers, Readers and Credentials

    Access Control Cybersecurity: Hardening Controllers, Readers and Credentials

    Access control systems were once treated as purely physical hardware: a card reader, a controller board and a locked door. Today most systems run over IP networks, store credential databases, and expose management interfaces, which means they carry the same categories of cybersecurity risk as any other networked infrastructure, alongside the physical risk of an unlocked door.

    Controllers Are Endpoints, Not Just Hardware

    Access control panels and controllers are, functionally, small networked computers, and vulnerabilities in their firmware or management interfaces can let an attacker unlock doors, disable alarms, or extract stored credential data without ever touching the building. Recently disclosed flaws in access control and device management platforms have shown that missing authentication or hard-coded credentials in these systems can hand an attacker root-level control, underscoring why manufacturers and integrators treat firmware update discipline and network segmentation as security-critical rather than optional maintenance.

    Weak Credential Technology Is Still Common

    Despite years of known weaknesses, many sites still rely on older low-frequency proximity cards and legacy Wiegand wiring between readers and controllers, both of which can be cloned or intercepted with inexpensive, widely available equipment. Modern smart cards and mobile credentials using encrypted protocols close much of this gap, but only if a site has actually migrated its readers, controllers and credentials together; a modern reader paired with an unencrypted legacy card format, or vice versa, can leave the original vulnerability largely intact.

    Network Segmentation and Monitoring

    Best practice increasingly places access control controllers on a segmented network separate from general office IT traffic, limiting what an attacker who compromises one system can reach from the other. Pairing that segmentation with logging and monitoring of controller and management-software activity helps detect unusual behavior, such as after-hours credential changes or unexpected firmware update attempts, before it results in an unauthorized physical entry.

    FAQ

    Can a cyberattack on access control lead to a physical break-in? Yes. If an attacker gains control of an access control system’s management interface, they may be able to unlock doors, add unauthorized credentials, or disable alarms, translating a network compromise directly into physical access.

    Are older proximity cards insecure? Many legacy low-frequency proximity card formats can be cloned with low-cost, readily available equipment, which is why organizations are increasingly migrating to encrypted smart card or mobile credential technology.

    Should access control systems be on the same network as office computers? Security best practice generally recommends network segmentation, keeping access control controllers and servers on a separate network segment from general office IT traffic to limit the blast radius of a compromise on either side.

  • Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security Launches S4 I/O Module Family to Modernize Access Control Infrastructure

    Mercury Security, an HID brand and a longtime supplier of open-architecture access control hardware, has launched its Mercury S4 I/O Module family, a new generation of intelligent modules designed to help organizations expand and modernize physical access control systems built on existing Mercury infrastructure.

    More Capacity, Built-In Cryptographic Headroom

    According to Mercury, the S4 family delivers six times the memory and eight times the storage of prior-generation modules, along with support for post-quantum cryptography aimed at hardening access control communications against future cryptographic threats to critical infrastructure. The modules are built for forward and backward compatibility, letting integrators add doors, readers and other security devices to existing Mercury intelligent controllers without replacing them, while increasing door density and reducing the physical footprint of the resulting installation.

    Responding to Longer Infrastructure Lifecycles

    The company said its ongoing research into access control professionals’ priorities identified sustained emphasis on cybersecurity and data protection standards, alongside a need for hardware that supports both forward and backward compatibility as organizations plan access control investments over longer timeframes. The Mercury S4 I/O Modules are available now through Mercury’s OEM partner network, extending an open-architecture platform the company has developed since its founding in 1992.

  • 153 Million Driver’s License Scans Offered on Dark Web, Likely Tied to IDScan.net

    153 Million Driver’s License Scans Offered on Dark Web, Likely Tied to IDScan.net

    A threat actor began offering digital scans of more than 153 million U.S. and Canadian driver’s licenses on the dark web this week, in what investigative journalist Brian Krebs has linked to a likely breach at identity-verification firm IDScan.net.

    A Large, Verified Identity Document Cache

    The documents surfaced on an identity-theft service called Nexus, while a threat actor simultaneously promoted the same data on a Russian-language cybercrime forum, claiming to hold identification documents for more than 170 million individuals. According to Krebs, a blank search on Nexus returned approximately 153 million driver’s license results, of which only around 1.1 million were Canadian, alongside more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.

    Krebs reported that after confirming his own driver’s license, and those of other individuals, appeared on the platform, he concluded the documents were likely siphoned from IDScan.net, a Louisiana-based identity-verification provider whose services include ID fraud prevention, access management, age verification, ID-activated door locks and mobile ID scanners. The company says it performs more than 21 million verifications per month across more than 20,000 locations for clients spanning automotive, banking, gaming, education, transportation, hospitality, law enforcement, retail and security industries.

    FBI Investigation and Shutdown

    The Nexus platform was taken offline shortly after Krebs published his findings. Separately, the FBI opened an investigation into the suspected IDScan breach after determining that some of the exposed driver’s licenses belonged to its own agents. IDScan.net had not issued a public statement on the incident as of this writing.

    What Organizations Should Take From It

    NCC Group senior adviser Tim Rawlins said the incident underscores that identity systems should be designed on the assumption that identity evidence will eventually be compromised. “A genuine-looking document cannot remain sufficient proof of identity indefinitely,” Rawlins said, adding that organizations should inventory what identity data they hold, establish clear retention and deletion policies, and set contractual requirements with identity vendors covering logging, data segregation, incident notification and independent assurance. He also recommended monitoring for abnormal bulk access to identity systems, including unusual service-account and API activity.

  • Overhead Door Corp. Acquires Motion Access, Expanding Horton’s Pedestrian Access Business

    Overhead Door Corp. Acquires Motion Access, Expanding Horton’s Pedestrian Access Business

    Overhead Door Corp. has acquired the assets of Motion Access, an Elk Grove Village, Illinois-based provider of automatic pedestrian door operators, replacement parts, retrofit solutions and rebuilt equipment. Motion Access will continue operating under its existing name as part of Horton Automatics, the premium access brand within Horton Pedestrian Access Solutions, a division of Overhead Door Corp.

    Strengthening Aftermarket and Service Capacity

    Overhead Door said the deal expands Horton’s aftermarket, service and retrofit capabilities for automatic pedestrian door solutions across North America, adding a company that has built its reputation serving automatic door professionals nationwide.

    “Motion Access has earned a reputation as a trusted provider of automatic entrance solutions, and we are excited to welcome their team into the Horton family,” said Kelly Terry, president and CEO of Overhead Door Corp. “This acquisition strengthens our aftermarket and service capabilities, expands our product offering, and reinforces our commitment to delivering innovative solutions and exceptional support to customers throughout North America.”

    Motion Access owners Joseph Madden, Robert Oakley, Gilbert Valencia and Michael Valencia said in a joint statement that finding the right long-term home for the business was one of the most important decisions they had made as owners, and that joining Horton creates new opportunities for employees and customers.

    Part of a Broader Pedestrian Access Portfolio

    Horton Pedestrian Access Solutions, which also operates the WonDoor brand, runs multiple manufacturing and service locations and works with more than 200 distribution partners across North America. Lewisville, Texas-based Overhead Door Corp., a subsidiary of Tokyo-based Sanwa Holdings Corp., serves more than 4,500 professional distribution partners across residential, commercial, institutional and industrial access markets.

  • Epson and STOPware Partner on On-Demand Color Visitor Badge Printing

    Epson and STOPware Partner on On-Demand Color Visitor Badge Printing

    Epson and visitor management software provider STOPware have announced a partnership integrating Epson’s ColorWorks on-demand color printing technology with STOPware’s PassagePoint platform, allowing organizations to produce full-color, photo-ready visitor badges in real time at sign-in.

    Color as a Security and Workflow Tool

    The integration pairs Epson’s CW-C4000 and CW-C6000 ColorWorks printers with PassagePoint to generate badges featuring visitor photos, color-coded access levels, department or zone identifiers, branding elements, and QR codes or barcodes for check-in, check-out tracking and access control integration.

    According to the companies, color coding helps front-line staff quickly distinguish visitors, contractors, vendors and temporary staff, and can visually flag which building zones a given badge is authorized to access. Full-color photos on the badge itself are also intended to reduce the risk of badge cloning or reuse.

    “We’re seeing firsthand that on-demand, full-color badge printing can help enable safer and faster access decisions, especially in high-traffic environments like hospitals, schools, corporate campuses or government facilities,” said Michael Weitz, product manager for ColorWorks at Epson America.

    Removing Pre-Printed Badge Inventory

    Because badges are printed on demand rather than drawn from pre-printed stock, organizations using the integration no longer need to maintain separate badge inventories or manually restock supplies, and every badge reflects current visit information and access policy.

    “Visitor badges are a frontline tool in ensuring building safety,” said Debbie Pendleton, chief operating officer of STOPware. “By combining ColorWorks color printing technology with STOPware’s platform, organizations gain instantaneous visual clarity and robust identification without slowing down visitor flow.”