Category: Command & Control

VMS, PSIM and unified command-and-control platforms that bring multiple security systems into a single operational view.

  • Lockheed Martin Demonstrates AI-Driven Battle Management Prototype for Guam Missile Defense

    Lockheed Martin Demonstrates AI-Driven Battle Management Prototype for Guam Missile Defense

    Lockheed Martin demonstrated a prototype AI-driven battle management system for the Guam Defense System (GDS) on August 26, 2026, showing how artificial intelligence analytics can compress the time it takes to detect, evaluate, and respond to air and missile threats in a simulated Guam operational environment.

    The prototype, called the GDS Battle Manager Suite, networks data from multiple Integrated Air and Missile Defense (IAMD) systems slated for deployment to Guam, including Aegis Guam and the Integrated Battle Command System (IBCS), into a single tactical picture. Powered by Lockheed Martin’s CommandIQ software, the system applies AI analytics to assess incoming tracks and generate fire-direction recommendations for human operators.

    From Request to Demonstration in Under Two Months

    The U.S. Army issued a call for a GDS Battle Manager Suite solution in June 2026. Lockheed Martin was invited to a Phase 2 evaluation at the Army Tactical Systems Integration Laboratory at Fort Bliss, Texas, where the company said its prototype was integrated and met demonstration requirements within 24 hours of arrival on site.

    Traditional IAMD battle management has relied on operators manually correlating information across documents, voice channels, and text messages — a process that is time-consuming and prone to error under the compressed timelines of a missile engagement. By automating that correlation and applying algorithmic shot selection informed by extensive simulation data, Lockheed Martin says the system is designed to give operators machine-speed decision support while helping preserve high-cost interceptor inventories.

    Part of a Broader Command-and-Control Push

    The Guam prototype follows related software-based command-and-control integration work Lockheed Martin performed during the Valiant Shield 2026 exercise, which the company has cited as evidence that capabilities developed across different programs and vendors can be connected rapidly to meet emerging operational requirements — a recurring theme as the Pentagon pushes for faster, more interoperable air and missile defense architectures across the Indo-Pacific.

    Guam’s defense architecture has been a focus of U.S. missile defense investment for several years given the island’s strategic role as a forward operating location. Layering AI-assisted battle management on top of existing sensor and interceptor networks is intended to help defenders manage a more complex and saturated threat picture without proportionally increasing the number of personnel required to operate it.

  • Global Security Operations Center (GSOC) Design: People, Process and Technology

    Global Security Operations Center (GSOC) Design: People, Process and Technology

    A Global Security Operations Center, or GSOC, centralizes monitoring and incident response for organizations with security operations spread across multiple facilities, regions or time zones. Unlike a single-site guard station monitoring local cameras and alarms, a GSOC is built to aggregate video, access control, intrusion detection, travel risk intelligence and often cybersecurity alerting from dozens or hundreds of locations into a unified operating picture, with staff trained to triage and coordinate response regardless of where an incident originates.

    The technology layer that makes this possible is a physical security information management (PSIM) platform, or increasingly a unified security platform that combines video management, access control and analytics natively rather than through a separate integration layer. The core function of this software is normalization: translating alerts and video feeds from potentially dozens of different camera manufacturers, access control panels and alarm systems, often installed at different times by different integrators, into a consistent interface that a GSOC operator can act on without needing to learn each underlying vendor system individually.

    Staffing model and shift structure are as important to GSOC effectiveness as the underlying software. A GSOC covering global operations typically requires 24/7 staffing organized around a “follow the sun” model, with regional teams handing off situational awareness at shift boundaries, or a single centralized team working rotating shifts. The choice affects language coverage, familiarity with regional regulatory and cultural context, and response time to incidents occurring outside a centralized team’s typical working hours; organizations with major operations concentrated in a small number of regions often favor a hybrid model with a smaller follow-the-sun core team supplemented by on-call regional specialists.

    Alert prioritization and workflow design determine whether a GSOC scales effectively as the number of monitored sites grows. Without a structured triage process, a GSOC ingesting alerts from hundreds of facilities can quickly become overwhelmed by nuisance alarms, such as motion-triggered alerts from wildlife or weather rather than genuine intrusions. Mature GSOCs implement tiered alert classification, often informed by analytics that pre-filter video-based alerts before they reach a human operator, and maintain documented standard operating procedures that specify escalation paths, notification requirements and decision authority for different incident categories, from a minor access control malfunction to an active threat requiring law enforcement coordination.

    Integration with business continuity and crisis management functions is increasingly a defining feature of higher-maturity GSOCs. Rather than operating purely as a security monitoring function, many organizations now position their GSOC as the initial point of situational awareness for a broader range of business-impacting events, including severe weather affecting a facility, civil unrest near a location with traveling employees, or a supply chain disruption at a manufacturing site, feeding that awareness into the organization’s broader crisis management and business continuity processes rather than treating physical security monitoring as an isolated function.

    Facility design for a physical GSOC space itself follows established principles: redundant power and network connectivity, video walls sized and positioned for extended-shift ergonomics, and physical security controls for the GSOC space that reflect its role as a high-value target in its own right, since an incident that disables or compromises the GSOC’s own operations removes situational awareness across the entire organization at the moment it may be needed most. Organizations building or upgrading a GSOC increasingly plan for a geographically redundant backup facility or cloud-hosted failover capability, so that a single site outage, whether from a power failure, natural disaster or targeted attack, does not eliminate centralized monitoring capability entirely.

  • Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Crafted URL Can Hijack Administrator Sessions

    CISA published ICS advisory ICSA-26-225-14 on August 13, 2026, disclosing a cross-site scripting vulnerability in Johnson Controls Metasys, a building automation and management platform used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-34491 and rated CWE-79, the flaw carries a CVSS v3 base score of 8.0.

    According to CISA, a low-privilege user can inject a malicious payload into the Metasys web interface through a crafted URL. The payload persists across logins and executes in the browser context of other users who view the affected page, including administrators, which could lead to session hijacking and unauthorized access to building systems. The advisory lists Metasys 12 and 13 as affected in all versions, and Metasys 14 before v14.1.5 and Metasys 15 before v15.0.1.

    Mitigation

    Johnson Controls has released patched versions for the affected Metasys 14 and 15 branches and published mitigation guidance for the platform. CISA recommends operators apply the available updates, restrict Metasys web interface access to trusted networks, and follow standard input-validation and session-management hardening for building management system deployments.

    Sources

  • Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    City Will Phase Out Acoustic Sensors by Year’s End

    The Denver Police Department says it will let its contract for ShotSpotter gunshot-detection technology expire at the end of 2026, ending more than a decade of automated gunfire alerting in the city, according to CBS Colorado and Denver7 reporting on the department’s August 20-21, 2026 announcement. The system uses acoustic sensors mounted on utility poles to detect the sound of gunfire and alert Denver’s 911 dispatch center, often before a human caller reports a shooting. Denverite reported the city’s contract with SoundThinking, the company behind ShotSpotter, is worth roughly $4.7 million and expires at the close of the year.

    Rather than an abrupt shutdown, DPD says it will begin removing sensors from areas generating the fewest alerts first, with most of the network remaining active through the rest of 2026. According to Denver7, the department said it is evaluating “whether a new vendor can provide greater public safety benefits” and plans to launch a bidding process to assess alternative gunshot-detection capabilities while gathering community input on how to reallocate resources. As part of the initial ramp-down, DPD said it will begin phasing out ShotSpotter coverage specifically in the Sun Valley and Park Hill neighborhoods.

    A Decade of Data on Alerts, Arrests and Recovered Firearms

    In its release announcing the change, the department said that from 2020 through June 2026 the program generated 25,217 alerts, leading to 655 arrests and the recovery of 721 firearms, according to CBS Colorado. Officers also located shell-casing evidence tied to 6,672 of those alerts. Denver’s decision comes amid what Denver7 described as broader nationwide scrutiny of police gunshot-detection and surveillance technology, as cities weigh the systems’ operational value against their cost and questions about alert accuracy and community impact that have been raised in other jurisdictions.

    What Happens Next

    City officials have not yet named a preferred replacement vendor or detailed the criteria for the planned bidding process. The wind-down gives Denver several months to evaluate alternative gunshot-detection platforms and to solicit public feedback before the current sensor network is fully retired, according to the reporting from Denver7 and Denverite.

    Sources

  • AI Agents in Security Operations Centers

    AI Agents in Security Operations Centers

    Security operations centers receive events from cameras, access control, intrusion, fire, cyber, intercom and building systems. AI agents are emerging as a software layer for gathering and presenting that context.

    What an AI agent does

    An agent can receive an event, gather context, summarize what happened, suggest a response and, within defined permissions, execute an approved workflow.

    Useful early applications

    Drafting reports, classifying alarms, generating shift summaries, searching procedures and locating related video or access events can reduce repetitive work without automating high-consequence decisions.

    Permissions and human supervision

    Automatically unlocking doors, disabling alarms or changing surveillance configurations creates risk. Sensitive actions should require operator confirmation and clear authorization boundaries.

    Data quality and auditability

    Incorrect names, outdated maps or unsynchronized timestamps can mislead an agent. Recommendations and actions should preserve evidence, uncertainty, user approval and system state.

    The changing SOC interface

    Conversational tools may allow operators to query multiple systems through one layer, but the underlying integrations and source data must remain visible and verifiable.

    Conclusion

    The realistic direction is human-supervised autonomy: agents handle routine correlation and documentation while operators retain judgment and accountability.

  • Unified Security Platforms: Integration vs True Unification

    Unified Security Platforms: Integration vs True Unification

    Security vendors often use integration and unification interchangeably, but they describe different architectures. Integration connects separate products; unification begins with shared data, identity, workflows and administration.

    Traditional integration

    A VMS, access-control system and intrusion platform may remain independent applications that exchange events through APIs or middleware, while retaining separate users, databases and upgrade cycles.

    What true unification changes

    A unified platform can provide one operator interface, common permissions and shared event handling across video, access, alarms and other systems.

    Operational benefits and data model

    Shared workflows can reduce training and speed response. The deeper distinction is whether identity and event objects are genuinely shared or merely displayed together.

    Vendor dependence and best-of-breed systems

    Unification may increase dependence on one vendor. Buyers should examine open APIs, third-party device support and export options. Specialized sites may still justify best-of-breed subsystems.

    Cybersecurity and migration

    A unified platform can simplify identity and patching but also concentrates risk. Many enterprises should migrate gradually through federation or integration as legacy systems reach end of life.

    Conclusion

    A single dashboard is not proof of unification. The correct architecture depends on scale, legacy investment, specialized requirements and long-term platform strategy.

  • VMS, PSIM and Command & Control Systems Explained

    VMS, PSIM and Command & Control Systems Explained

    Understand how VMS, PSIM, alarm management, GIS, sensor fusion and security operations center platforms turn security data into operator decisions.

    Security technology produces events faster than people can interpret them. Cameras create video and metadata, access systems create credential events, perimeter sensors create alarms, fire systems create life-safety signals and building systems add another layer of operational data. Command-and-control software exists to turn that flow into a manageable picture.

    VMS: video first

    A Video Management System is primarily designed to manage video. It connects cameras, controls streams and recording, manages users, displays live and recorded video, and increasingly hosts analytics and integrations. For many sites, the VMS is the main operator interface because visual verification is central to incident response.

    Modern VMS platforms often integrate access control, intercom and analytics, but the depth of those integrations varies. A system that can display an access alarm is not necessarily a full access-control platform.

    PSIM: process and integration first

    Physical Security Information Management was developed to aggregate events from multiple security systems and guide operators through consistent procedures. A PSIM may sit above VMS, access control, intrusion, fire interfaces, GIS and other systems. The key value is not simply showing everything on one screen; it is correlating events, applying rules and creating an auditable response workflow.

    For example, a perimeter radar detection might automatically cue a PTZ camera, display the target on a map, check nearby access-control states and present the operator with a response procedure. That is more useful than five independent alarms arriving in five applications.

    Command & control

    The term command and control is broader. In critical infrastructure or public-safety environments, the platform may combine security, operational technology, communications, mapping, incident management and external data. The design goal is shared situational awareness and coordinated action.

    Alarm management and prioritization

    A common failure in security operations centers is alarm overload. If low-priority technical faults are presented with the same urgency as a confirmed intrusion, operators lose attention. Good alarm management applies severity, confidence, location, time, dependencies and escalation rules.

    Sensor fusion goes further by combining evidence. A single radar track may be interesting; a radar track plus thermal detection plus a fence vibration event is more compelling. Fusion logic should be transparent enough for operators to understand why the system raised priority.

    Interoperability and metadata

    ONVIF Profile M standardizes metadata and events for analytics applications and can help move structured information between compatible systems. Standardized event data matters because automation depends on software understanding not just a video stream, but what the system believes happened.

    GIS and maps

    Maps are particularly useful for large campuses, airports, borders and energy sites. Spatial context allows operators to see where alarms occur relative to gates, cameras, patrols and assets. Good GIS integration should support action, not just decoration.

    How to choose the right layer

    A small site may need only VMS plus integrated access control. A larger enterprise may benefit from a unified security platform. A critical-infrastructure operator with many legacy systems may need PSIM or a broader command-and-control layer.

    The key questions are operational: how many systems must operators use, which events need correlation, what workflows must be enforced, how incidents are escalated and what evidence is required afterward.

    FAQ

    Is PSIM the same as VMS? No. VMS is video-centric; PSIM is typically multi-system and workflow-centric, though modern platforms increasingly overlap.

    What is sensor fusion? It is the combination of signals or events from multiple sensors to improve confidence or context.

    Does one interface guarantee integration? No. True integration should be evaluated at the data, control and workflow levels.

    Verification note

    Avoid claiming a “single pane of glass” unless a tested integration actually supports the required control functions, not just event display. This article describes general architecture, not vendor-specific performance claims.