Category: Access Control & Identity

Credentialing, biometrics, smart locks and identity verification technologies that control who can enter a facility.

  • Security 101 Expands Southern California Reach With Silverstrand Technologies Acquisition

    Security 101 Expands Southern California Reach With Silverstrand Technologies Acquisition

    Security 101, a national provider of commercial electronic security solutions, announced on August 26, 2026 that it has acquired Silverstrand Technologies Inc., a San Diego-based systems integrator, according to Security 101’s own announcement and reporting by SDM Magazine and Security Info Watch.

    Strengthening the West Region

    Silverstrand has operated for 19 years, providing video surveillance, access control, structured cabling, wireless networking, sound masking and life safety solutions to commercial, government, hospitality, aviation and institutional clients across Southern California. The acquisition strengthens Security 101’s presence in the San Diego, Orange County, Los Angeles and Riverside markets and folds Silverstrand’s regional team into the company’s West Region operations.

    Local Team Stays in Place

    “Silverstrand is one of Southern California’s most respected technology integrators, with a culture centered on taking care of both employees and customers,” said Greg Daly, CEO of Security 101, in the announcement. “That focus mirrors our own. Bringing this team into the Security 101 organization strengthens our West Region and gives customers access to national resources delivered by the same local team they already trust.” Silverstrand founder Jeremy Johnson will remain with the operation as general manager, continuing to lead the team that built the company’s regional reputation.

    Part of a Broader Consolidation Trend

    The deal is the latest in a wave of consolidation among regional security integrators, as national platforms acquire established local firms to combine deep market relationships with broader technical portfolios and lifecycle support. Security 101, based in West Palm Beach, Florida and founded in 2005, delivers design, installation and maintenance of access control, video surveillance, intrusion detection, visitor management and managed services across healthcare, education, financial and government end markets nationwide.

  • Biometric Access Control Compared: Fingerprint, Iris, Face and Vein Recognition

    Biometric Access Control Compared: Fingerprint, Iris, Face and Vein Recognition

    Biometric access control has moved from a specialist technology into a mainstream option for offices, data centers, airports and critical infrastructure sites. But “biometrics” is not one technology — fingerprint, iris, facial and vein-pattern recognition each rely on different physical traits, different sensors and different deployment trade-offs. Choosing the right modality, or combination of modalities, depends heavily on the environment, the threat model and how the system will be used day to day.

    Fingerprint Recognition

    Fingerprint readers remain the most widely deployed biometric modality because the sensors are inexpensive, compact and familiar to users from consumer smartphones. Most systems capture a digital image of the fingerprint ridge pattern and extract minutiae points — the specific locations where ridges end or split — to build a template for matching, rather than storing the raw image. Fingerprint readers perform well in controlled indoor environments but can struggle with dirty, wet, gloved or worn fingertips, which is a common consideration for industrial and outdoor sites.

    Iris Recognition

    Iris recognition captures the intricate pattern in the colored ring around the pupil using a near-infrared camera, converting the pattern into a mathematical template. Because the iris pattern is highly detailed and stable over a person’s lifetime, iris systems are often used where very high assurance is required, such as border control, data centers and other high-security facilities. Iris cameras typically require the user to look toward the sensor within a defined distance, which makes enrollment and enforcement more deliberate than a simple badge tap.

    Facial Recognition

    Facial recognition systems map geometric features of the face, or increasingly use deep-learning models to generate a numerical embedding of the face, and compare that embedding against enrolled templates. The major advantage of facial recognition for access control is speed and convenience: many systems can identify an authorized person without requiring them to touch a sensor or stop moving, which supports high-traffic entrances and touchless access goals. Accuracy can be affected by lighting conditions, camera angle, face coverings and image quality, and the technology has also drawn regulatory and public scrutiny over data protection and consent, which organizations need to factor into deployment plans.

    Vein Pattern Recognition

    Vein recognition, most commonly implemented as finger-vein or palm-vein scanning, uses near-infrared light to image the pattern of veins beneath the skin’s surface, since deoxygenated blood in veins absorbs infrared light differently than surrounding tissue. Because the vein pattern sits inside the body rather than on an exposed surface, it is difficult to capture or replicate without the cooperation of a live subject, which makes vein recognition attractive for high-security financial and data center environments concerned about spoofing. The trade-off is that vein scanners are typically more expensive than fingerprint or facial recognition hardware and are less commonly integrated into general-purpose access control platforms.

    Choosing the Right Modality

    In practice, the choice between modalities usually comes down to a handful of operational questions: How much throughput does the entrance need to support? Will users wear gloves, masks or personal protective equipment on site? Is the environment indoors and climate-controlled, or exposed to dirt, moisture and temperature swings? And what level of assurance does the asset being protected actually require? Many organizations end up deploying more than one modality across a site — for example, facial recognition for high-traffic general entrances and iris or vein recognition for a smaller number of high-security zones such as server rooms or vaults.

    Privacy and Data Protection Considerations

    Because biometric data is permanently tied to an individual and cannot be reset the way a password or badge can, organizations deploying any of these modalities need a clear policy for how templates are stored, encrypted, and eventually deleted, along with a legal basis for collecting biometric data that satisfies applicable regional privacy laws. Storing a mathematical template rather than a raw image, and keeping that template on a secure local device rather than in a shared cloud database, are common practices for reducing the impact of a potential breach.

  • Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    Report: Security Leaders Overconfident on Authentication Even as Modernization Stalls

    A new report from rf IDEAS and Wavelynx has found that most security leaders believe their organizations are more advanced than industry peers on authentication, even though barely a quarter describe their systems as largely modernized, according to the 2026 State of Authentication Modernization Report published August 31, 2026.

    Key Findings

    The survey of 500 IT and security leaders at mid-sized to enterprise organizations found 93% believe their authentication and security maturity outpaces their industry peers, yet only 24% said their systems are largely modernized and 53% have not significantly updated authentication systems in at least three years. While 78% called modernization a high priority for the next 12 months, only 72% of managers closer to day-to-day execution agreed it was a high priority, and 27% cited unclear return on investment as a barrier. Among organizations that do prioritize the work, 55% plan to allocate at least $500,000 to it, but credential and authentication upgrades ranked eighth among security initiatives overall, behind higher-profile priorities.

    Why It Matters

    Forty percent of respondents estimated that a breach involving unauthorized access would cost their organization less than $1 million, well below the $4.4 million global average cost of a data breach reported for 2025. rf IDEAS and Wavelynx said the gap between confidence and readiness underscores the need to treat physical and logical access control as a single modernization effort rather than two separate budgets.

  • LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass Adds Mobile Smart Scanner and Expanded SaaS Monitoring to Business Security Suite

    LastPass rolled out a series of product updates on August 31, 2026 aimed at credential and access management, including what the company describes as the industry’s first Mobile Smart Scanner and expanded SaaS Monitoring capabilities for its Business Max customers, according to the company’s announcement carried by Security Info Watch.

    What’s New

    The Mobile Smart Scanner lets users scan passwords from printed lists, screenshots and handwritten notes through the LastPass Mobile app and convert them into encrypted, autofill-ready credentials. Persistent Monitoring, now fully released across all browser extensions, keeps SaaS visibility active through a permanent browser-extension connection even when a user is signed out of LastPass, and administrators can now set more granular SaaS Protect usage rules for specific users or groups. LastPass also completed its move from a Legacy Admin Console to a single Unified Admin Console, introduced a company-wide sign-up link for Teams, Business and Business Max customers, and is shifting Dark Web Monitoring for consumer accounts to automatic enrollment. The company said it passed independent SOC 2 and ISO 27001/27701 audits with zero findings for a second consecutive year.

    Why It Matters

    LastPass tied the updates to IBM’s 2026 Cost of a Data Breach Report, which found AI-driven attacks rose 56% year over year and added roughly $1 million to average breach costs, with 92% of organizations hit by AI-related breaches lacking adequate AI access controls. The emphasis on visibility and credential hygiene mirrors a broader push across the industry to close the kind of access gaps that groups exploit in AI-assisted phishing and credential-theft campaigns.

  • Keenfinity Splits Intrusion and Access Control Units Into Radionix and MiCOS

    Keenfinity Splits Intrusion and Access Control Units Into Radionix and MiCOS

    Keenfinity Group is separating its former Intrusion & Access portfolio into two dedicated subsidiaries effective September 1, 2026, with Radionix taking over intrusion alarm systems and MiCOS concentrating exclusively on access control, the company confirmed to Security Info Watch on August 31, 2026.

    New Leadership Structure

    Phil Dutoy, who joined Keenfinity in 2025 and previously worked on the company’s transformation strategy following its carve-out from Bosch, becomes CEO of Radionix. Gregor Schlechtriem, who had led the combined Intrusion & Access business through the Radionix brand launch, moves to lead MiCOS exclusively. Both companies remain wholly owned Keenfinity subsidiaries pursuing separate go-to-market strategies, and Keenfinity said the change will not alter existing product lines: Radionix continues to build on Bosch intrusion technology, while Bosch-branded access control products continue under the same development and support teams.

    Two Legacy Brands, Two Focused Businesses

    Radionix, formally launched at GSX 2025, builds on nearly six decades of intrusion-system heritage and includes the G Series platform that integrates intrusion detection, access control and fire alarm functions. MiCOS revives a brand with more than four decades of access control history and will operate out of Eindhoven, Netherlands, with a development center in Aachen, Germany. Keenfinity became an independent company on July 1, 2025, after Triton completed its acquisition of Bosch’s security and communications technology business.

    Why It Matters

    The split gives each business room to compete more directly in increasingly specialized markets, following a broader industry pattern of vendors separating access control strategy from intrusion detection as buyers demand deeper feature depth in each category rather than a single generalist product line.

  • PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    PSG and Mercury Security Partner to Extend Zero Trust to Physical Security’s Far Edge

    Prometheus Security Group Global (PSG) announced a technology partnership with Mercury Security on August 27, 2026, aimed at extending Zero Trust principles down to the field-device level of physical security systems, according to the companies’ announcement and independent reporting from Security Systems News.

    Combining Access Hardware With Edge Authentication

    The partnership pairs Mercury’s open-architecture access-control hardware platform with PSG’s patented technology for embedding cryptographic identity, authentication and verification directly into far-edge field devices, including door readers, sensors and cameras. PSG describes the goal as moving physical security systems away from assumed, unverified inputs toward authenticated and cryptographically verified data starting at the point where it is generated, rather than only securing the network layer above it.

    Why Now

    The move extends a Zero Trust architecture approach that IT security teams have used for years, in which every device and request is continuously authenticated rather than implicitly trusted once inside a network perimeter, into physical and operational technology environments. PSG has previously supplied Zero Trust physical security technology to U.S. Air Force, Navy and Department of Energy programs, and has positioned far-edge authentication as a way to close a gap security researchers have flagged in converging IT and physical access control systems, where edge hardware has often remained a weaker link than the software managing it.

    What It Means for Integrators

    For organizations running Mercury-based access control, the partnership is intended to let them add cryptographic device-level verification without replacing existing access-control investments, addressing a common friction point in critical-infrastructure and high-security environments where wholesale hardware replacement is often impractical.

  • TDSi by Hirsch Releases GARDiS 3.3 Access Control Software Update With New Intruder Integration and Credential Model

    TDSi by Hirsch Releases GARDiS 3.3 Access Control Software Update With New Intruder Integration and Credential Model

    Integrated access control manufacturer TDSi by Hirsch has released GARDiS version 3.3, a major update to its access control software platform introducing new intruder-detection integrations, a redesigned credential model and expanded security and data-governance controls, according to Security Info Watch.

    A Unified Credential Model

    The centerpiece of the release is a redesigned credential model built around a universal “Card or Fob” type that works across virtually all reader and card technologies, removing the need for administrators to manually select and match credential types to specific decode formats. Existing credentials are migrated automatically during the upgrade process and can be verified before changes take effect. Biometric credentials and IP lock whitelisting are included within the same unified approach, simplifying what has traditionally been one of the more error-prone parts of access control administration.

    Expanded Security and Governance Controls

    GARDiS 3.3 adds configurable password rules, banned-word lists and automatic account lockout to strengthen login security, alongside new event-dashboard permissions that control which users can view live and archived security events. Organization-based filtering further restricts user access to information tied only to the people they are authorized to manage — a feature aimed at larger, multi-tenant or multi-site deployments where over-broad visibility has historically been a governance concern. Saved reports can now be kept private to their creator or explicitly shared with designated colleagues, giving administrators finer control over sensitive operational data.

    Ajax Cloud Integration for Intruder Detection

    The release also introduces new intruder-system integration with Ajax Cloud, allowing GARDiS to incorporate intrusion-detection alerts alongside access control events within a single management interface. Combining access control and intrusion alarm data in one platform reflects a broader industry trend toward converged physical security management, where operators increasingly expect a single pane of glass rather than separate systems for access, video and intrusion detection.

  • Video Intercom and Communication Systems: The Missing Link in Modern Access Control

    Video Intercom and Communication Systems: The Missing Link in Modern Access Control

    Video intercom systems sit at the point where access control, video surveillance, and building communication converge. A visitor at a door is simultaneously a video subject, an access-control event, and a two-way audio interaction — and modern IP-based intercoms are designed to treat all three as a single, integrated workflow rather than three separate systems bolted together.

    From Analog Buzzers to Networked Endpoints

    Legacy intercoms were closed, point-to-point systems: a door station wired directly to a handset inside. IP video intercoms instead operate as network endpoints, capable of streaming video to a central VMS, triggering access-control credentials, and routing calls to a receptionist, a mobile app, or a remote guard station depending on time of day or staffing. This shift means an intercom call can be answered from anywhere with network access, not just a fixed panel next to the door it serves.

    Integration With Access Control and Visitor Management

    The strongest deployments tie intercom systems directly into access-control platforms so a single interaction — a visitor pressing a call button — can trigger identity verification, log an event, and grant a temporary credential without separate manual steps. Some platforms extend this further into visitor-management systems, allowing a pre-registered guest to be recognized at the door and granted access automatically, with the intercom serving as a fallback for unregistered visitors.

    Where Video Intercoms Add the Most Value

    Multi-tenant residential buildings, corporate lobbies, loading docks, and remote or unstaffed facility entrances see the clearest return: each is a location where someone needs to grant access without being physically present. Cloud-managed intercom platforms let a single remote operator cover multiple sites, reducing the staffing burden of traditional front-desk security while preserving a human decision point at every entry.

    Deployment Considerations

    Bandwidth and power planning matter more for video intercoms than for traditional access readers, since each unit is effectively a camera, microphone, speaker, and access-control endpoint drawing continuous power over Ethernet. Organizations should also plan for redundancy: because intercoms are often the only way a legitimate visitor can request entry, a network outage that takes the intercom offline can inadvertently block access as effectively as a security incident.

  • ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey and Aiphone Launch Integrated Cloud-Based Access Control and Video Intercom Solution

    ProdataKey (PDK) and Aiphone announced on August 26, 2026, a new cloud-based integration designed to unify access control and video intercom management for commercial and multi-tenant properties. The integration connects AiphoneCloud, Aiphone’s cloud-managed intercom platform, with PDK.io, ProdataKey’s mobile-first access control management software.

    “The future of physical security is built on connected, intuitive technologies,” said Dallan Labrum, Executive Vice President of Sales at ProdataKey. “Our integration with Aiphone gives dealers, integrators, and end users a smarter way to manage access control and video intercoms from a unified ecosystem. Together, we’re helping customers improve operational efficiency while delivering a better experience for everyone who enters and manages their buildings.”

    Automatic Tenant Sync Eliminates Duplicate Record-Keeping

    According to the companies, when tenant information is added, updated, or removed in PDK.io, those changes automatically sync to connected Aiphone IXG intercoms, eliminating the need for dealers and property managers to maintain duplicate records or manually coordinate directory updates between two separate systems. Security administrators and property managers can manage both access control and video intercom operations through a single streamlined workflow, which the companies say reduces administrative overhead and helps close security gaps caused by human error in manual record-keeping.

    The launch follows ProdataKey’s earlier preview of the integration at ISC West 2026, where the company showcased new locksets, readers, burglar-panel integrations, and video intercom offerings alongside the incoming Aiphone connection. For multi-tenant and commercial property operators, the combined platform reflects a broader industry shift toward converging previously siloed access control and visitor-verification systems into single-pane-of-glass management, reducing the operational friction that has historically accompanied maintaining separate vendor ecosystems for door access and intercom hardware.

  • Smart Gates and Vehicle Access Control

    Smart Gates and Vehicle Access Control

    Vehicle entrances are among the most complex points in physical security because they combine identity, traffic flow, safety and perimeter control. A modern smart gate must determine who or what is approaching, whether access is authorized and how to move vehicles through the site without creating congestion or unsafe conditions.

    Common technologies include license-plate recognition, RFID tags, mobile credentials, intercoms, loop detectors, radar, barriers, bollards and video analytics. High-security sites may also add under-vehicle inspection or guard verification.

    The most effective systems link the vehicle to an access policy. A recognized plate alone should not automatically be treated as proof of identity in every environment. The system may also verify a driver credential, delivery schedule, visitor record or vehicle classification.

    Video plays a major role in evidence and exception handling. Cameras can document the vehicle, driver lane and surrounding context, while analytics can detect tailgating, wrong-way movement or a vehicle entering a restricted lane.

    Safety must be engineered alongside security. Barrier arms, gates and bollards require presence detection and safe operating logic to avoid collisions. Emergency egress and fire-service access also need dedicated procedures.

    For multi-site organizations, cloud-connected gate management can centralize credentials and audit logs. At critical infrastructure sites, local operation should remain available if connectivity fails.

    Smart vehicle access is therefore not one product but a coordinated system. The strongest designs combine identification, physical barriers, sensors, video and workflow software into one controlled entry process.