Physical security platforms now depend on cloud services, identities, APIs and remote access, requiring security teams to understand the cyber risks behind connected systems today.
Ask a security manager to describe an access control system and the answer will usually begin with doors, readers and cards. Ask the IT department about the same system and the answer sounds different: a server, a database, hundreds of user accounts, several open network ports and a maintenance contract with a supplier that connects remotely to keep everything running.
Both answers are accurate. Only one of them tends to appear on the security risk register.
That gap matters because the physical security estate has quietly become an IT estate. Access control platforms run in the cloud. Credentials live on phones. Cameras stream to video management systems on corporate networks and require patching like any other server. Visitor management systems collect personal data and display it at reception. Guard workforce platforms track patrols through mobile devices.
Control rooms increasingly depend on APIs that exchange information between systems bought years apart from different suppliers.
This does not make physical security professionals responsible for every aspect of cyber security. It does make them responsible for systems that carry cyber risk. That is a different job from the one many physical security teams were originally trained to perform.
Convergence on site
The convergence is rarely dramatic. It appears through small, ordinary decisions.
An installer requests a remote access account to support the system outside working hours, and the account is granted permanently rather than for the duration of the work. A camera firmware update is deferred because the site cannot accept an outage during trading hours, then deferred again and eventually forgotten. An HR platform is integrated with access control so new starters receive badges automatically, but nobody establishes what will happen to the connection when the HR platform is replaced. A contractor returns a card within an hour of leaving, while the contractor’s login to the management console remains active two years later.
Each example represents a decision that a physical security team makes, influences or fails to question. Addressing these risks does not require deep technical knowledge. It requires somebody in the room who recognises that the question exists and knows who must answer it.
Cyber skills that matter
There is a reasonable concern that developing cyber skills means learning to write code or configure firewalls. For most physical security roles, it does not. The useful capability is narrower: holding an informed conversation with IT, a supplier and a client about how a security system is connected, administered and recovered.
Some of the related areas are:
Identity and access. Every system has accounts, and those accounts need the same lifecycle discipline that badges have always required. Who can create an operator? Who approves access? What happens on the day somebody leaves? A leaver process that reclaims a card but not a console login is only half a process.
Privileged and shared accounts. Administrative accounts can change permissions, disable alarms, alter schedules and delete audit records. When engineers share an account, or retain the default password used during commissioning, there is no reliable way to attribute an action to an individual. That matters most when attribution is the purpose of the system.
Patching and lifecycle. Controllers, cameras and intercoms are computers with operating systems and support horizons. Record when each device stops receiving security updates in the same asset schedule used for planned replacement. Equipment can remain mechanically sound while falling out of software support. That should be a conscious risk decision, not an accidental one.
Vendor remote access. Many organisations rely on suppliers to connect remotely and diagnose faults. Ask whether that access is time-limited, individually attributable, logged and disabled when the contract ends. This remains one of the controls most frequently handled poorly.
Integrations and APIs. When two systems communicate, something is normally holding a credential that permits the exchange. Somebody should know what that credential is, what it can do, where it is stored and who is responsible for rotating it. ‘The integrator set it up’ is not an answer that survives an incident review.
Logging and escalation. Access control systems produce rich audit trails that may remain unread until an incident occurs, by which time the retention period may have expired. Decide what is retained and for how long. More importantly, decide whom to call at 2 a.m. when the system becomes unreachable and nobody yet knows whether the cause is a network failure, a supplier issue or a cyber incident.
Ownership cannot be shared
Connected security systems often sit between organisational boundaries. The security manager owns the operational requirement. IT controls the network and identity services. An installer commissions the equipment. A software provider operates the cloud platform. A facilities team may hold the budget. Everyone owns a portion of the system, which can mean nobody owns the complete risk.
The answer is not to make one team responsible for everything. It is to name a business owner for each system and document the supporting responsibilities. The owner should know where the system is hosted, which supplier can access it, who approves privileged accounts, who schedules patches, how backups are tested and who leads recovery. IT should define the technical controls and escalation route. Suppliers should provide support dates, access records and clear notification procedures. Physical security should confirm that the controls still support operational needs, including emergency access and continuity during an outage.
Change control is another shared responsibility that needs a clear decision maker. A routine network change, certificate renewal or software upgrade can interrupt badge processing, camera recording or alarm delivery even when no device has physically failed. Before a significant change, teams should identify the affected security functions, agree a maintenance window, confirm a rollback plan and test the service from the operator’s point of view. A technically successful change is not successful if guards cannot receive alarms or staff cannot enter the building.
These responsibilities should be agreed before commissioning. Trying to establish ownership after an alarm platform or access control service has failed wastes the time needed for containment and recovery.
A career opportunity
The regulatory direction makes this more concrete. The Terrorism (Protection of Premises) Act 2025, commonly known as Martyn’s Law, received Royal Assent on 3 April 2025.
Duty holders will need accurate procedures, clear responsibilities and controlled records. Enhanced duty premises and qualifying events will have additional documentation requirements. Keeping that material current and protected is an information management responsibility as well as a protective security responsibility.
Separately, the Cyber Security and Resilience (Network and Information Systems) Bill has completed its Commons stages and is being considered by the House of Lords. Among other measures, it would bring certain managed service providers within the regulatory framework. Suppliers that remotely manage security technology should therefore examine whether their particular services could fall within scope rather than assume that all remote maintenance is treated in the same way.
Client due-diligence questions are already moving in this direction. Security providers may be asked how they manage privileged credentials, control supplier access, protect operational records and escalate suspected compromise. Clear, evidence-based answers can strengthen a provider’s position during procurement and contract review.
The licensing regime has accepted the broader principle that competence requires renewal. Refresher training became mandatory for door supervisor and security guard licence renewals on 1 April 2025 and for close protection renewals on 1 April 2026. Terror threat awareness forms part of that training.
Cyber literacy belongs in the same continuing-development cycle. For anyone developing a career in security, this creates a practical opportunity. Professionals who can understand what an integration does, identify the operational consequences of a technical failure and translate between an IT director, an installer and an operations team are likely to become increasingly valuable.
Choosing useful training
Favour courses that teach principles that can be applied across manufacturers. Vendor certification has a place, but it generally teaches one supplier’s platform rather than the thinking behind secure administration. Recognised foundation material provides a better starting point.
The National Cyber Security Centre publishes free introductory training and guidance, while the Cyber Essentials control set offers a short framework and shared vocabulary for discussions with IT colleagues. NPSA and ProtectUK also provide protective security guidance without charge, and professional bodies can support structured continuing professional development.
Treat any course marketed as making somebody cyber qualified in one day with suspicion. It is equally mistaken to assume that every physical security professional needs a full cyber security qualification. The realistic goal is enough knowledge to ask useful questions, recognise a poor answer and escalate to the right specialist. That can be developed through a few months of deliberate learning reinforced by involvement in real system reviews.
In conclusion
None of this requires a new department. It extends the same habits of ownership, documentation and rehearsal that the profession already applies to keys, patrols and incident response to the connected systems sitting behind them.
The lock on the door has not changed much. Almost everything behind it has.
Vishnu Gatla
Senior Application Security and Infrastructure Consultant
