Johnson Controls, Inc.
20 Mar 2026
Summary is AI-generated, newsdesk-reviewed
  • Modernise legacy systems by adopting integrated, data-driven ecosystems with open architecture.
  • Ensure system scalability and resilience using encrypted communication and cloud topology.
  • Employ predictive analytics to enhance security system modernisation.

Editor Introduction

Modernising a legacy physical security system requires a transition from isolated, hardware-dependent silos to an integrated, data-driven ecosystem. This transition involves shifting toward open architecture and encrypted communication to ensure long-term scalability and resilience. Other elements to facilitate upgrading a legacy system include leveraging cloud and hybrid topologies and ultimately moving toward more predictive analytics. Our Expert Panelists offer plenty of ideas for making the transition. We asked our Expert Panel Roundtable: What are today's best practices to transform and modernise legacy systems?


Fredrik Nilsson Axis Communications

Technological advancements, expanding use cases, and growing integration needs continue to impact a wide range of industries, and leveraging existing systems for new capabilities and insights is a key element of security modernisation. Even without major hardware updates, organisations can leverage data from existing systems to inform and enhance their digital transformation, resilience, and business intelligence needs. Today’s IP cameras can detect unusual activity, recognise patterns, and trigger real-time alerts, supporting activities ranging from basic surveillance to behavioral analytics—but not all organisations are currently taking advantage of their full capabilities. While safety and security remain primary drivers of video surveillance use, a growing number of organisations are now leveraging their video solutions for operations and business purposes, turning their existing devices into a multifaceted platform capable of providing actionable intelligence and value generation.

To effectively modernise legacy systems, the most strategic approach is adopting cloud-based, open platform solutions. Rather than ripping and replacing a business’s entire security infrastructure, an open platform enables companies to integrate modern cloud capabilities with their existing cameras and hardware, maximising investments while unlocking new value. This integrated approach enables faster access to cutting-edge innovations, such as AI-powered video analytics, which legacy systems often cannot support on their own. This strategy is essential for futureproofing; it ensures that your security solution remains flexible enough to adapt to future technological advancements without being tethered to obsolete proprietary hardware. Ultimately, an open platform solution provides a streamlined on-ramp to future innovations, bridging the gap between existing infrastructure and the intelligent, scalable potential of the cloud.

Kevin Woodworth Johnson Controls, Inc.

Across home security or commercial building management, end-users are not only looking for standalone security systems but connected, future-ready interfaces that can integrate with other building functions. Security systems will increasingly become part of a comprehensive, responsive ecosystem that links with environmental safety systems such as flood and fire detection, as well as smart home platforms. With over 84% of homeowners owning at least one smart home device within their home, new systems should be ready for the expectation of security systems to seamlessly integrate into broader technology ecosystems. Meeting this new wave of demand requires introducing systems designed for interoperability. Rather than replacing systems when innovation advances, integrators must look towards hardware platforms that support ongoing software updates as ecosystems grow, new devices are added, and users expect more data-led insights. By delivering interoperability in security devices, integrators can create robust and scalable system interconnectivity that transforms the user experience.

If you were fortunate enough to have made the decision five, 10 or 15 years ago to build your security infrastructure on open standards, you are in a fundamentally different position than most — your system has been quietly future-proofing itself all along. For everyone else, the good news is that interoperability is still the right framework for modernisation, even when starting from a more constrained position. With systems that rely on open standards, technology decisions are no longer tied to a single manufacturer's upgrade timeline or available integrations. Systems can grow as needs change, with options from multiple vendors for each upgrade or addition. Making interoperability your primary criteria when evaluating new technology protects existing investments while keeping the door open for whatever comes next.

Sam Smith Salient Systems

Modernising legacy systems is not just about replacing old technology, it is about having a plan that keeps your environment from falling behind in the first place. The organisations I see having the most success start by focusing on what they are trying to accomplish operationally, whether that is improving efficiency, strengthening overall security and IT security practices, or making systems easier for teams to actually use day-to-day. One of the biggest lessons we see is that modernisation cannot be treated as a one-time upgrade. When organisations do not plan for ongoing updates and lifecycle management, systems slowly become harder and more expensive to improve, and eventually transformation feels overwhelming instead of manageable. Staying current also puts organisations in a much better position to adopt emerging technologies and quickly support changes in the market or new initiatives driven by leadership. A phased approach tends to work best, allowing teams to modernise over time without disrupting operations. Prioritising platforms built around open architecture and flexible cloud or hybrid deployments helps organisations stay adaptable and ready for whatever comes next.

Ray May Parker Group, Inc.

Control rooms across industries rely on diverse technologies — new and old — to ensure operational continuity and efficiency. This is especially true in the security industry. However, most organisations have portfolios built on legacy technologies they cannot afford to rip and replace in favor of more modern alternatives. In these situations, teams can modernise their operations by bridging the gap between AV and IT silos. In practice, the best approach begins with deciding how to extend the life of legacy tools while connecting them into a unified ecosystem. Organisations should adopt solutions that bring the AV and IT worlds together over IP networks, enabling the seamless flow of data and allowing operators to see all sources in one place without replacing every legacy device immediately. These solutions can capture, route, record, and distribute high-resolution video and audio over IP. This provides control rooms with a consistent interface for real-time viewing and review, simplifying workflows and supporting shared situational awareness across teams.

Successfully modernising legacy systems and processes requires thoughtful planning, focused execution, and organisational change management throughout. On the planning and execution side of the transformation, the key is to identify and prioritise which improvements will generate the most value for the organisation, break those improvements down into smaller increments, then sensibly leverage tools, including AI, to meaningfully enhance delivery. This reduces exposure to issues such as security, downtime, delays, and poor-quality results. However, the measurable value an organisation will receive from transforming legacy systems is only as great as its culture and processes allow. As the saying goes, “culture eats strategy for breakfast” every day of the week. The most valuable modernisation will first be driven through real organisational change, where internal management teams wholly embrace a digital transformation mindset.

Modernising legacy access control systems requires a strategic balance between security, interoperability, and long-term flexibility. A fundamental best practice is moving away from closed, proprietary architectures toward open, standards-based platforms. Open protocols such as OSDP enable greater interoperability. Cybersecurity must be strengthened at every layer of the infrastructure. Legacy systems were not designed to address today’s threat landscape, so modernisation should include strong encryption, secure communications protocols and hardware designed to protect cryptographic keys. Door readers incorporating secure element hardware, where keys are stored in tamper-resistant chips rather than general memory, significantly reduce the risk of cloning or key extraction attacks. Security should be embedded by design, not added retrospectively. Future-readiness is equally important. Even if organisations are not immediately deploying mobile credentials, selecting readers and platforms that support BLE ensures a smoother transition to smartphone access later. Similarly, cloud-enabled management tools can improve scalability, remote administration, and lifecycle management. Access control systems typically remain in place maximum for 10–15 years and facilities cannot simply shut down during replacement. Multi-technology readers and credentials allow organisations to upgrade in stages, maintaining operational continuity while progressively modernising infrastructure.

Matthew Fabian Genetec, Inc.

Before making changes, organisations should be clear on what they want to accomplish: Is the goal to speed up investigations, improve incident response, streamline operations, strengthen cybersecurity, or meet new compliance requirements? Clear objectives guide smarter technology decisions. Start with your goals and select technology that helps you meet them. The next step is a practical assessment of technology and deployment options. Bring stakeholders to the table from the beginning. Physical security, IT, compliance, and operations teams have different priorities. IT may care most about automated updates and cyber resilience, while compliance may focus on privacy controls and audit trails. Early alignment makes adoption smoother. Finally, consider future goals and plans. Adopting open platforms provides flexibility to introduce new devices, cloud services, and capabilities over time, protecting existing investments while making changes easier to manage.

Chris Hugman System Surveyor

Modernising legacy security systems begins with clarity. Organisations often pursue upgrades without a full understanding of existing infrastructure, resulting in delays, budget overruns, and unnecessary risk. Establishing a living, digital as-built that reflects real-world conditions and evolves alongside the system creates a reliable foundation for informed decisions. Collaboration is equally essential. Because physical security projects now involve integrators, consultants, IT teams, and end users across distributed environments, utilising tools that facilitate real-time communication and collaboration reduces friction, accelerates approvals, and makes sure every stakeholder has a seat at the table. To streamline future modernisation efforts, it’s vital that system documentation progresses beyond handwritten notes and static drawings. By deploying an intelligent site survey and system design software, teams can capture feedback in the field, visualise design options, and automate documentation throughout the project lifecycle—keeping modernisation efforts traceable and repeatable. Ultimately, modernisation is less about replacing legacy infrastructure and more about improving visibility, coordination, and documentation across the board so systems can evolve confidently over time.

Modernising legacy access systems starts with visibility. Organisations need a clear inventory of their hardware, firmware and software dependencies before making changes. Without that baseline, upgrades become reactive and budgets become unpredictable. From there, define current and future use cases. Access control used to be about opening doors. Today it supports mobile credentials, cloud services, analytics and converged physical-digital identity strategies. Modernisation plans should reflect that expanded role. Interoperability is critical. Most organisations prioritise open platforms and backward and forward compatibility to avoid forced rip-and-replace cycles. Selecting technologies that integrate cleanly with existing infrastructure protects long-term investment and reduces disruption. Futureproofing also requires partners with the right certifications and experience. Choosing the right integration services partner ensures secure configurations, structured migration plans and minimal operational downtime. Modernisation is not a product swap. It is an architectural decision that must balance resilience, cybersecurity, and long-term business value.

Modernising legacy systems starts with respecting the investment customers have already made. Rip-and-replace is rarely practical. The smarter approach is to layer intelligence on top of existing infrastructure. With our X-series cameras, the AI Processing Relay function allows a single AI-enabled device to generate metadata from non-AI cameras, even from other manufacturers. That extends the life of legacy assets while introducing object detection, event classification, and advanced analytics without a forklift upgrade. From there, you modernise the investigation workflow. Active Guard 3.0 adds Generative AI-powered free text search, so operators can query video using natural language instead of fixed filters. That transforms how teams interact with stored footage and reduces time to insight. The best practice is incremental transformation. Add edge intelligence, preserve bandwidth with metadata, and deploy open platforms that integrate with existing VMS environments. Modernisation should enhance what is already in place, not disrupt it.


Editor Summary

When seeking to modernise a physical security system, experts recommend a phased migration rather than a full "rip-and-replace" approach. Layering intelligence and cloud capabilities onto existing infrastructure is an approach that maximises current investments. Key practices include adopting encrypted communication protocols like OSDP, strengthening cybersecurity with secure element hardware, and utilising AI-powered analytics to gain actionable business intelligence from legacy devices. Success ultimately depends on clear operational objectives, collaborative planning across departments, and a culture that embraces ongoing digital transformation.

Johnson Controls, Inc. news

Johnson Controls' AI boosts building efficiency

Johnson Controls, a global pioneer in thermal management, mission-critical building systems, energy efficiency and decarbonisation, announces new AI capabilities in its OpenBlue digital ecosystem to help building owners reduce energy use, automate building operations and cut operating costs. The expanded platform includes: Energy & Comfort Intelligence, an AI-enabled capability that helps optimise how air flows through buildings; an agentic AI assistant; and a new AI-native architecture whe...

Johnson Controls boosts building security with Metasys 16.0

Johnson Controls, a global pioneer in thermal management, mission-critical building systems, energy efficiency and decarbonisation, introduces Metasys 16.0, the latest version of its flagship building automation system with new capabilities designed to help customers reduce downtime risk, strengthen cybersecurity and bring systems online faster across complex environments at a time when building performance is becoming essential to business outcomes. “The environments our customers operat...

The future of physical security on display at ISC West 2026

The security landscape is undergoing a profound transformation, as evidenced by the innovations showcased at the ISC West Expo 2026. From dismantling of silos between physical and digital security to the ongoing transition to cloud and hybrid platforms, much of the discussion on the show floor was familiar, if somehow more urgent than ever. Clearly the industry is moving toward unified, cloud-native, and highly automated ecosystems. In a series of deep-dive meetings and demonstrations at the re...

Johnson Controls, Inc. case studies

Gallagher's SMB boosts beach security at South Maroubra

Keeping beachgoers, swimmers and surfers safe is all in a day’s work for the team at South Maroubra Surf Live Saving Club, and every second counts when an incident unfolds on the water.   One of the most topical issues and threats to those enjoying Australia’s world-renowned beaches is sharks, so for the surf club it made sense to look to smart, new technology to keep those who enjoy the sand and surf safe. Security technology to lifesavers   "Since the club wa...

SwiftConnect integration with Software House C•CURE 9000 access control extends employee badge in Apple wallet to more customers

SwiftConnect, a pioneering provider of connected access enablement, is powering easy, secure, and private access using an iPhone and Apple Watch with the Johnson Controls Software House C•CURE 9000 access control system. The SwiftConnect AccessCloud platform integration with the Software House C•CURE 9000 access control system makes it possible for Software House C•CURE 9000 customers to take advantage of the employee badge in Apple Wallet for physical access. Deployments of emp...

Johnson Controls’ video solution ensures safer school environment

It may sound like a small change, but installing security cameras on a property can significantly impact occupant and visitor behaviour by enabling more accountability. This is notable for environments such as K-12 schools where occupants are younger and more impulsive. Lack of visibility A public school system on the East Coast faced frequent incidents of bullying, vandalism and theft among students as well as the harassment of faculty and staff and was struggling to keep its occupants accou...