SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Cybersecurity gap widens in access control controllers

Cybersecurity gap widens in access control controllers

Fri, 2nd Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Mercury Security has published research showing a widening cybersecurity gap in physical access control controller infrastructure. The survey also found that more organisations now view controllers as important to long-term access control strategy.

Based on responses from 561 physical security and cybersecurity professionals worldwide, the findings point to growing pressure on controller systems from cybersecurity demands, cloud adoption, interoperability requirements and new uses of artificial intelligence. Respondents included access control administrators, systems integrators, installers and end users.

Some 78% of respondents consider the controller important or critical to their physical access control system strategy, up from 72% a year earlier. The increase suggests controllers are being treated less as standalone hardware purchases and more as strategic parts of broader security infrastructure.

Cybersecurity emerged as one of the clearest weak points in current installations. Some 32% of respondents said cybersecurity features are missing from their existing controller systems, up from 21% in the previous survey.

At the same time, 74% said cybersecurity and IT coordination have become more complex to manage, while 86% said their organisations actively work to keep up with changing cybersecurity and data protection standards. The figures suggest many security teams are adapting policy and practice even when the underlying infrastructure has not kept pace.

"Organisations recognize the cybersecurity risks facing connected access control systems, but the infrastructure in place isn't always keeping pace," said Steve Lucas, Vice President of Sales at Mercury Security.

Interoperability also ranked highly in procurement and planning decisions. The survey found that 69% of respondents identified interoperability as a critical factor when buying controllers, while 82% said backward and forward compatibility matters in future infrastructure planning.

That points to a preference for gradual upgrades rather than wholesale replacement. For many organisations, the challenge is to modernise while continuing to use installed systems and avoiding disruptive changes across the wider security estate.

Mobile credentials are part of that shift. Half of respondents said they are already using or planning to adopt mobile solutions, while 46% ranked mobile credential integration among the trends influencing controller purchasing decisions.

Cloud gap

Cloud connectivity is becoming more important, but adoption remains uneven. The share of respondents citing cloud connectivity as a leading factor in controller purchases rose to 56%, from 50% the previous year.

Yet only 41% said their controllers are currently cloud-enabled, and 26% said cloud enablement is missing from existing systems. The data suggests demand for cloud-linked access control is growing faster than some installed infrastructure can support.

That matters because cloud-based management is increasingly tied to broader operating models, including remote administration, software updates and integration with other business systems. Where cloud support is absent, organisations may face limits on how far they can extend or connect their access control environment.

AI pressure

The survey also pointed to growing interest in AI-related functions that place heavier demands on controller infrastructure. Behavioural analysis and anomaly detection rose to 56% from 44%, while facial recognition was cited by 60% of respondents and predictive security and threat prevention by 50%.

These applications can place greater demands on systems in areas such as processing, storage, connectivity, integration design and cybersecurity controls. As a result, controller choice is becoming more closely tied to whether an organisation expects to add advanced analytics or other data-intensive tools later.

More than 39% of respondents said they are exploring or have adopted edge computing within their security environments. Another 41% said they have integrated controller data with building occupancy and utilisation programmes, indicating that controller information is being used for purposes beyond managing doors and entry points.

That broader role helps explain why controller planning is becoming more strategic. Rather than choosing equipment solely for current operational needs, buyers are increasingly weighing whether a platform can support future integration with adjacent systems across buildings, workplace management and security operations.

Lucas said organisations are also trying to avoid writing off earlier investments as they upgrade. "As they look to modernize, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next."