In the past, a lock was a physical device with a single function. When located in a smart building, that equivalent doorway is a network endpoint that communicates with elevators, cameras, HVAC systems, and occupancy sensors. As soon as it begins to communicate with those systems, the access control room stops being a hardware choice and becomes a technology choice.
According to Deloitte’s 2021 Smart Building Readiness survey, 69% of firms worldwide anticipate that they will invest more in smart building technology over the following three years. This is not a trend specific to a few particular commercial properties with flagship towers where the access control room has probably been located. It is a widespread trend throughout the commercial real estate, healthcare, education, and government sectors, and the access control choices made currently will need to be those that meet some of the integration requirements that most older platforms were never designed for.
Card-and-Fob Access Wasn’t Built For This
A typical physical access control system was designed with a straightforward model in mind: you issue a credential, you assign it to a door, you check it at the reader, and you’re done. The model assumes that roles are relatively static and door assignments change infrequently. A receptionist gets a key or badge for lobby and front-office access. A facilities technician gets a master key or badge for all mechanical rooms. Once that key or badge is provisioned, nobody touches it again until someone leaves or loses their badge.
Smart buildings blow up that assumption. Suddenly, access needs change hourly, not according to a printed org chart. That contractor may need HVAC room access for an afternoon. A tenant’s cleaning crew may rotate through different floors each night. Meeting rooms get booked and released in real time, and visitor access must track with one-off calendar invites for contractors or business partners. Access should scale with the event until it expires, neither before nor after. Static, single-factor identity simply doesn’t work in an environment where access is meant to be conditional, temporary, and context-aware.
This is not just a minor nuisance. It’s a square peg, round hole problem. Real-time flexibility can’t be bolted on to a system built with the assumption of fixed roles and a list of doors that almost never changes. The card-and-fob model must be rethought from the ground up, not patched.
Migrating Without Ripping Everything Out
Nearly no business can afford a complete overhaul of all their physical security control systems in one budget cycle. The realistic path for most existing buildings is phased migration, running legacy and modern systems side by side until the transition is complete.
That starts with an honest inventory: which readers and controllers still have useful life left, which ones are upgradeable to networked, OSDP-capable hardware, and which need full replacement. It means mapping that hardware roadmap against budget cycles, since most buildings can’t fund a full swap in one fiscal year. And it means designing the target architecture first, so each phase of the upgrade moves toward that end state instead of creating another patchwork of incompatible systems.
Most organizations going through this benefit from bringing in an experienced security partner early, someone who can assess the current infrastructure honestly, design the integrated architecture around open standards, and manage the transition without disrupting daily operations. Firms like AG Security Group work through exactly this kind of assessment and phased rollout with building owners who need a realistic multi-year plan rather than a rushed, disruptive overhaul.
Getting this sequencing wrong is expensive. Getting it right means every dollar spent on upgrades moves the building closer to the architecture it will actually need in five years, rather than solving today’s problem in a way that creates tomorrow’s rework.
The Door is Now Part of the Network
Many security teams are surprised by the fact that in a converged smart building, the door reader shares a network with the BMS, the CCTV platform, and sometimes the corporate IT backbone. This also means that the controller is not simply protecting a door now. Instead, it’s a node that can be explored, exploited, or serve as an entry point into systems completely unrelated to physical entry.
Essentially, this is IT/OT convergence happening right at the door frame. Formerly, the lock was the responsibility of facilities teams, the network belonged to IT, and the guard desk was the responsibility of security guards. In a smart building, all three of these areas intersect at each reader, and none of them can autonomously determine access any longer. A misconfigured access panel that features default admin credentials can’t just be left for the facilities team to deal with, because this is a network vulnerability that appears on the CISO’s risk roster. Organizations that continue to see access management as something that facilities should procure, independently from an IT security evaluation, are inadvertently leaving a blind spot exactly where attackers are likely to exploit it.
Applying Zero Trust to Physical Doors
Zero Trust architecture originated in network security and is based on the concept of never trust, always verify. The same concept can be applied to a locked door or a login interface.
In practice, this means treating every reader as untrusted by default rather than assuming a valid credential equals a valid entry. It means moving toward continuous authorization instead of a single check at the moment of badge-in. A credential that was valid this morning shouldn’t automatically be trusted this evening if the person’s role, location, or threat context has changed.
It also means enforcing least privilege segmented across four dimensions: role, zone, time, and threat level. A facilities contractor’s credential should open only the mechanical rooms they’re scheduled to work in, only during their shift window, and should automatically tighten or lock out entirely if the building raises its threat posture. None of this is achievable with static card assignments. It requires software-driven policy that can be updated in real time, which is exactly what cloud-based access control is built for.
Mobile Credentials Solve the Lifecycle Problem, and Create a New One
With traditional card-based systems, one of the most significant problems is the lifecycle gap. If a staff member resigns on a Friday, their badge typically remains active until it’s deactivated on the following Monday, if at all. Similarly, a lost or forgotten access card may continue to offer potential access to a building for several days before the owner is alerted and it’s reported. The reason is simple: for the sake of expediency and simplicity, it’s much easier to invalidate and reissue a single card than it is to trace and collect all of those unreturned ones.
Mobile credentials and cloud-based access control, by contrast, automatically reduce that gap. If provisioning and deprovisioning are linked directly to an HR system, access instantly disappears the moment an employee’s status changes. If a phone is lost or stolen, revocation can automatically render that particular device credential inactive. Security teams get remote lockdown capability across an entire portfolio of buildings from a single console, rather than having to dispatch someone to reprogram panels door by door.
But mobile credentials bring their own set of questions. A compromised phone is a different threat model than a lost card. Employees have legitimate privacy concerns about location tracking tied to their personal devices being used for building access. None of this makes mobile credentials the wrong choice. It just means the conversation has to include device security posture and clear data policies, not just convenience.
Why the Standards Matter More Than the Brand
When security leaders assess access control vendors, they often compare feature lists and prices. But that’s not the right place to start for a smart building. The right question is whether the system is based on open standards or if you are locked into a proprietary ecosystem.
OSDP is important because it establishes encrypted, supervised communication between readers and controllers. This closes the security gap left by the Wiegand-based wiring of older systems. Power over Ethernet is important because it allows you to power and network a reader with a single cable, making it far less invasive to retrofit or add new doors. Open APIs are important because your access control platform will need to integrate with your BMS, your visitor management system, and whatever app your leasing team decides your tenants will use to book time in the building conference room next year.
Choose proprietary, and you’ve locked potential out of your building. Choose open standards and the possibilities remain open as the ecosystems around you continue to adapt.
Integration is Where Security Actually Breaks
If you ask anyone who has experienced a physical security breach leading to a network breach, you’ll often hear a similar version of the same story, it was the front door that held. It was the old controller on a flat network with a default password nobody thought to update after installation.
Legacy door controllers without network segmentation are still at risk of lateral movement into corporate systems. “It’s a door lock” and “if it’s not broke don’t fix it” combines to make the firmware update that never was, and a soft target for adversaries. That’s why network segmentation for physical layer devices, regularly patching firmware, and actively monitoring reader and controller traffic has to become part of the same hygiene regime that applies to any other network endpoint. The more you treat door hardware as somehow different and exempt from IT security protocols, the higher the risk it remains the weakest link.
Access Control as a Tenant Amenity, Not Just a Cost Center
As a commercial real estate owner managing a multi-tenant complex, there’s a business case that’s not obvious when all the talk is about technology: Tenants increasingly judge a building by how easy they can get into it.
Mobile entry managed by a visitor in advance, turnstiles with nothing to touch, visitor flows that eliminate the need for a paper sign-in sheet, these aren’t just nice safety things to have. They’re low-touch amenities that come up in lease renewals and satisfaction surveys. A building that still hands out plastic fobs and has visitors standing at a desk waiting for a badge is competing with buildings that don’t. If the only way you’re thinking about smart access control is as a security line item, you’re missing the retention and leasing aspect that it drives.
The Door is a Software Decision Now
Smart buildings did not just include ease of operation facilities in physical security, they redefined the concept of locks. They are essentially software functioning within a network, taking policy-based decisions in real time. Security heads, facilities management, and IT teams who perceive access control as just another isolated hardware procurement will continue facing incompatible connections and vulnerable corners of their networks. It is the right approach that has building owners shifting from “which lock should we buy” to “what does our access architecture need to support over the next decade.” This question is tough. It’s the one you should find the answer to.
