The company Genetec, specialized in enterprise physical security software, warns that the growing connection of access control systems with corporate networks, identity management platforms and business applications is transforming their role within organizations. What was traditionally considered a tool to manage who could enter a building is now part of an increasingly broad attack surface, where physical security and cybersecurity converge.
Readers, controllers, credentials, and management software generate and store sensitive information and communicate with other corporate systems. If they are poorly protected, outdated or poorly managed, they can create both digital and physical risks.
Identity and credentials as a priority objective
This evolution coincides with a scenario in which identity and credentials have become a priority target for cybercriminals. In fact, Flashpoint’s Global Threat Intelligence Report 2026 identifies identity exploitation as one of the main vectors of cybercrime and estimates stolen credentials at 3.3 billion during 2025 from 11.1 million infected devices.
In this context, Genetec recommends that physical security systems be subject to the same demands as any other technology connected to the corporate network. Organizations need to know how quickly they can apply updates, whether communications are encrypted, how users are authenticated, what visibility there is into potential vulnerabilities, and how security policies are enforced across locations.
This transformation also requires closer collaboration between physical security and IT. It is no longer enough to know who can access a certain area. Companies need to know who manages the system, how permissions are granted and revoked, when they were last reviewed, and whether these decisions can be audited consistently.
Growth makes it difficult to control permits
The problem is accentuated in organizations with multiple headquarters, acquisitions, contractors, temporary workers or frequent job changes. When different facilities use different procedures to grant credentials, approve applications, or review permits, the risk of losing a comprehensive view of who has access to each facility increases.
As a result, some employees may retain permissions they no longer need, policies may vary unreasonably between locations, and security teams may have difficulty detecting outdated permissions or anomalous behavior.
For this reason, Genetec points to standardization and automation as essential elements to make access management scalable. Role-based models and integration with Human Resources and identity management systems allow permissions to be automatically adjusted to each person’s current responsibilities and avoid maintaining access granted for needs that no longer exist.
Companies need to know who manages the system and how permissions are granted and revoked
“As access control becomes increasingly integrated with corporate networks and identity management platforms, it can no longer be considered an isolated infrastructure. Organizations need to know not only who can open a door, but why they retain that permission, when it was last reviewed and whether that decision can be applied and audited consistently across their facilities,” says Rafael MartÃn, Sales Director Southern Europe at Genetec.
For Genetec, modernizing access control is no longer just about renewing hardware. It also requires establishing clear processes, maintaining continuous supervision, automating permit management and strengthening coordination between physical security, IT, compliance and risk management teams.
