smartbuildingmag.com
31
'26
Written on Modified on
Access Control: The New Corporate Attack Surface
Genetec urges the integration of physical security and cybersecurity management to protect corporate identities and networks.
www.genetec.com

Genetec, a global leader in enterprise physical security software, has warned that the growing interconnection of access control systems with corporate networks is transforming their role within organizations. Readers, controllers, and credentials—once limited to managing building entry—are now part of an expanding attack surface. If these systems are outdated, poorly protected, or deficiently managed, they can create critical vulnerabilities that compromise both the physical and digital security of an enterprise.
Identity Exploitation and Cross-Departmental Collaboration
This evolution coincides with the surge in identity exploitation, identified as a primary vector for cybercrime following the theft of 3.3 billion credentials throughout 2025. Genetec recommends that physical security systems be subjected to the exact same policies, encryption standards, and update requirements as any other IT network-connected technology. To scale management securely, the company emphasizes the need to implement role-based permission automation, standardize processes, and foster closer collaboration between physical security, IT, and human resources departments.
Additional Context: Technological Background and Market Dynamics
This section provides technological and market-specific background not explicitly detailed in the original press release.
Traditionally, physical security systems operated on isolated ("air-gapped") networks or closed systems, largely protecting them from external cyberattacks. However, the transition toward smart buildings and the convergence of operational technology (OT) with information technology (IT) have directly connected these peripheral devices to the cloud and corporate databases like Active Directory. Legacy protocols used in many access cards (such as Wiegand) lack advanced encryption, making them susceptible to cloning. By compromising a vulnerable edge device, such as an IP door controller, threat actors can gain an initial foothold, move laterally across the corporate network, and launch ransomware attacks or steal sensitive data. This underscores the urgency of applying Zero Trust architectures even to physical infrastructure.
Edited by Lekshman Ramdas, Induportals editor – adapted by AI.
www.genetec.com

