ASSA ABLOY Opening Solutions - Experts & Thought Leaders
White papers from ASSA ABLOY Opening Solutions
Securing the modern data centre
DownloadModernizing access control
DownloadHow biometrics are reshaping security in a connected world
DownloadThe key to unlocking K12 school safety grants
DownloadAccess control system planning phase 2
DownloadAccess control system planning phase 1
DownloadMulti-residential access management and security
DownloadSecuring data centres: Varied technologies and exacting demands
DownloadBoost efficiency and streamline security with integrated access control
DownloadSchool security checklist
DownloadLatest ASSA ABLOY Opening Solutions news & announcements
Incedo access management from ASSA ABLOY Opening Solutions is created for businesses on the move, who need a flexible security solution which grows with them. Now security managers managing an Incedo Business solution can work remotely, too — while maintaining complete control over their building’s access points. Incedo connects security software and hardware within a single, seamless platform. To accommodate the restless change and disruption of modern business life, Incedo enables scaling up or down on demand. And now, new Incedo Business Cloud management keeps security and facility managers in control of their premises from wherever they happen to be right now. Cost-efficient subscription Incedo Business Cloud solves many pressing daily challenges of access management. Managers no longer need to be on-site to handle day-to-day security. Incedo Business Cloud operates securely 24/7 from any PC with an internet connection. Installing the system is easy, with no complex integrations needed. Software updates are regular and automatic, with real-time reports and analytics available with a few clicks. Incedo Business Cloud works out of the box via a cost-efficient subscription service: no more waiting around for engineer callouts. Onboarding is fast and hassle-free. And security managers can feel confident about confidentiality: business and user data are safeguarded with an Information Security Management System certified to ISO/IEC 27001. Cloud-based management Recent report finds 78% of IT decision-makers anticipate growing their reliance on cloud solutions going forward According to the Wireless Access Control Report 2021, over a third of companies now use cloud-based management to power their access control. This proportion is likely to grow in the years ahead, as working practices become ever more mobile and the notion of being ‘at work’ describes a state of being, rather than a specific place. Indeed, another recent report finds 78% of IT decision-makers anticipate growing their reliance on cloud solutions going forward. A cloud solution makes access management easier and more convenient, helping companies to design security administration processes which are streamlined, location-independent and efficient. For any size of organisation, switching to Incedo Business Cloud implements this powerful access control with no high upfront costs and ongoing cost-effectiveness. Managing access control “A cloud software solution makes budgeting more predictable for facility and security managers,” says Kevin Hoare, EAC Product Unit Director at ASSA ABLOY Opening Solutions EMEA. “It removes the need to hire additional in-house IT support and maintenance teams: you know ahead of time how much resource to allocate and can scale infrastructure up or down quickly. The business benefits of ‘managing access rights from anywhere’ drive ever greater demand for cloud solutions within security and beyond.” “Survey data shows the way companies manage access control will continue to be a mixed picture, with both locally hosted and off-site cloud solutions for Access Control as a Service,” he adds. “This is why, when launching our Incedo ecosystem, we give users the choice.” Migration between Incedo’s local and cloud management options is always seamless in any direction, ensuring total flexibility for any business. Appropriate management system Incedo Business Cloud makes access control more efficient for everyone, from installers to end-users Incedo Business Cloud makes access control more efficient for everyone, from installers to end-users. A modular, platform approach makes both procurement and operation simpler. Managers choose the security hardware and credentials they need together with the appropriate management system. Award-winning ASSA ABLOY wireless digital locks and wired ASSA ABLOY wall readers secure the doors. A choice of card and token credentials — or mobile keys on a smartphone — helps users enjoy safe and convenient access to, and movement around, the premises. New Incedo-enabled hardware from ASSA ABLOY and third-party providers will continue to be made available within the evolving Incedo ecosystem. Remote access management Add doors or locations, and switch between local and cloud management, as often as required. Incedo guarantees flexibility and scalability in every direction, to meet security needs today and in the future. “This latest enhancement of our Incedo solution makes comprehensive, real-time, remote access management into a reality. Incedo will keep premises secure and filter access intelligently, to manage the ever-changing movement of people across multiple sites — from anywhere. Your business is not static, and there is no reason why your security should be.” says Stephanie Ordan, VP Digital and Access Solutions at ASSA ABLOY Opening Solutions EMEA. Incedo™ Business Cloud embodies ASSA ABLOY’s vision to create a safer and more open world, keeping everyone on the move together.
The world is constantly changing, with people, data and goods moving more fluidly than ever before. The security solution needs to move with it. New Incedo Business connects all security software and hardware within one platform. One can easily scale it up or down, based on one’s needs, to keep people moving and business growing. Together. People need different access times and entry points, and the access and security requirements change day to day – so, a static solution is no longer an option. Instead, a single, all-encompassing security platform should deliver connectivity, convenience and simplicity, keeping one’s premises secure and filtering access to manage the ever-changing movement of people. This is where Incedo Business comes in: a new solution for all types of premises, handling security while leaving one free to focus on growing the business. Incedo ensures employees, customers and goods are where they need to be. Incedo makes life and tasks easier and more efficient for everyone, from installers to end users. Facility managers enjoy more control and flexibility than they ever thought possible - maximising return on investment, with Incedo Business able to scale quickly when needed. System administrators can do more within available budgets: initiating, cancelling or amending access profiles, and monitoring movement around their site in real time. Building users, meanwhile, get the individual access times and entry permissions they need. They can move freely without compromising the security of other people and equipment. Integrators can upgrade connected technologies and systems quickly, minimising risk and meeting customers’ raised expectations of modern technology. Installers no longer need to wrestle with incompatible systems: easy interoperability is built into Incedo, meaning no more delays or unnecessary complexity. With Incedo’s modular platform approach, one simply chooses the security hardware and credentials one needs and the appropriate management system option. One can set exactly who can access which doors, and when, from the user-friendly Incedo Business software interface. When Incedo Business launches, one can pick the most suitable options from a growing range of Incedo-enabled security and access control hardware. Road-tested, award-winning ASSA ABLOY wireless digital locks and wired ASSA ABLOY wall readers secure all interior and exterior doors. Also already available, a choice of card and token credentials helps users enjoy safe and convenient access to, and movement around, the premises. Incedo mobile keys add the flexibility to open doors with a smartphone. Incedo’s system management options, Lite, Plus and Cloud, scale from entry level up to cloud-based administration. One can manage multiple sites and third-party integrations, including security solutions like CCTV. Scale up and down, add or remove hardware and credentials on demand, or switch system management options, all within a single environment. Migration between Lite, Plus and Cloud options is always seamless in any direction, ensuring total flexibility for the business. Incedo moves with you, today and in the future However your business moves, an Incedo system moves along. Having a flexible platform, able to adapt as the organisation changes, reduces total cost of ownership: one never needs to retrain staff or start over from scratch. New Incedo-enabled hardware from ASSA ABLOY and third-party providers will continue to be connected to, and made available within, the evolving Incedo platform. One picks the hardware and software configuration one wants, and can change one’s mind as often as one likes. Incedo guarantees flexibility and scalability in every way, to meet the security needs today and in the future. And because the security and operational challenges at a university, small hotel or hospital are not the same as those faced by a public building or corporate HQ, the Incedo ecosystem will introduce new, advanced user interfaces for the specific industry. “Incedo Business transforms the experience of using and managing a building. It is also the seed from which our revolutionary Incedo ecosystem will grow in the months and years ahead,” says Stephanie Ordan, VP Digital and Access Solutions at ASSA ABLOY Opening Solutions EMEA. “A future where doors are smarter, connectivity and movement are seamless, and access management is genuinely intelligent. This is our vision for Incedo and for those who will be using it.” Incedo™ Business embodies ASSA ABLOY’s vision to create a safer and more open world, keeping everyone on the move. Together. To learn more and download a free solution guide, visit https://campaigns.assaabloyopeningsolutions.eu/Incedo-business
In a sector where budgets are always a focus of attention, delivering concrete returns to every investment is crucial. By digitalising access, healthcare premises – whether large hospitals or small clinics – can benefit from day one. They can improve staff and patient safety; quickly implement more efficient, time-saving workflows; and painlessly meet compliance demands. Healthcare sites always present complex access challenges. They must be welcoming, accessible public spaces. They often occupy large, sprawling areas; unfamiliar faces and first-time visitors are around every single day. At the same time, these premises inevitably have valuable and/or sensitive assets, including confidential data and medicines, which must be secured. Patients, doctors, nurses and support staff must feel safe. In labs and treatment suites, restricted materials and valuable equipment need both security and a compliant system for logging every access event. This has always been healthcare’s ‘business-as-usual’: it is a complex environment for any security manager. Meeting compliance demands Modern hospitals and clinics, however, now face an extra level of challenges – and opportunities. Their access system may benefit from integration with fire detection, CCTV and other building solutions, for example. With so many temporary and contract workers employed on-site, access is in constant motion. It needs to be tailored to specific and very different needs and, equally, revoked when any time-limited tasks are complete. In case of a security breach, rapid investigation is essential. Tracing and logging access to specific areas may also be a legal requirement, especially with new NIS2 regulations introduced for critical infrastructure, which demand proactive “hybrid” cyber/physical security frameworks for many healthcare premises. Relying on manual or siloed systems to complete these tasks could eat up hours or even days for security and even medical staff. Happily, there is a better way to work. Digital access devices The solution is access digitalisation. Digital access devices and credentials help to keep every hospital user safe. Unauthorised access is minimised because unapproved key copies rarely circulate and lost credentials are cancelled with a click. Employees and equipment are safer because more access points may be digitally secured. Issuing contractors and temporary staff with digital or even mobile credentials can further simplify the granting, amending and revoking of site access. Security teams waste less time handing out and collecting keys. Intelligent, intuitive software helps facilities managers stay in control even while they are off-site. Logging access to specific assets or areas becomes quick and simple: a few clicks rather than the laborious process of keeping manual logs up to date. “Access is such an important part of any holistic approach to safety,” says David Moser, SVP and Head of Digital Access Solutions at ASSA ABLOY Opening Solutions EMEIA. “Digitalising access immediately puts powerful tools in the hands of hospital management, delivering tangible daily benefits to meet security challenges head-on, improving efficiency and regulatory compliance at the same time.” Implementing digital access “There’s now a device to extend existing systems with digital control at almost any access point, whatever building solution is in place. Alternatively, we can equip customers with whole solutions to implement digital access from scratch, without invasive installation. So many efficiency and security benefits are within reach.” Below are three of many real-life examples which illustrate the ways healthcare premises have benefited from digital access beyond the most obvious security and safety aspects. By choosing ASSA ABLOY’s Aperio® wireless locks, integrated natively with an ARD access management solution, Centre Hospitalier Métropole Savoie (CHMS) could issue access rights tailored to individual staff and contractors and implement real-time control, helping to boost site safety. Because Aperio locks are wireless, the hospital introduced more layers of security without incurring excessive installation or operating costs, including for sensitive offices and drug stores. Access point functionality at CHMS now includes real-time management logs and remote door opening. Real-time management logs For convenience, staff now carry one credential programmed with their individual tailored permissions. “Having just a single badge, and not having to carry around heavy keys, has been a major advantage for us,” explains Béatrice Dequidt, Health Executive at CHMS. “We have implemented internal HR management procedures, creating badges that are automatically integrated into ARD's operating software,” adds Alain Gestin, CHMS’s IT Systems Architect. Aperio and ARD maintain compatibility of credentials with the French government’s electronic Health Professional Card (CPS), for added staff and management convenience. Personalised access permissions Hospital MAZ, in Zaragoza, also implemented a new ASSA ABLOY digital solution, SMARTair®, with real-time access functionality. Their online wireless access management system saves security managers’ time because they can implement all changes via the central system in real time, without needing to waste time walking through the hospital. Staff convenience is further enhanced: they now carry a smartcard programmed with their personalised access permissions. Custom-made cards double as employee IDs, so 625 staff and approximately 100 contractors only need to carry one. Their ASSA ABLOY system is also mobile access ready, making it easy for the hospital to issue and manage mobile keys in the future without hardware changes. “Digitalisation presents opportunities for healthcare organisations of every size and type to improve security while they also reduce costs ‘hidden’ in daily workflows,” explains David Moser. Convenient secure access Managing physical keys can impact nursing care, as pharmacy managers at Queen Elizabeth Hospital, Birmingham discovered. An older, mechanical system made it difficult for them to keep track of who held the right key. Searching for that person wasted time. They identified a better solution for convenient secure access to controlled medicines: programmable keys. With their CLIQ programmable key access solution, power to digital and electromechanical locks is supplied by a standard battery inside every key, so no wires are required – making it an ideal retrofit solution for hospital doors, cabinets and mobile drug trolleys. Audit trails for locks and padlocks are available on demand: nurse managers can quickly see who has accessed cabinets or drug trolleys. Key access solution “The message from all nursing staff is that patients are getting medicines much easier and in a more timely fashion,” says Inderjit Singh, Chief Pharmacist at QE Birmingham. “For us, the key return on investment is the quality of service we’re providing.” “Our expertise in access, established over decades, enables us to work with customers to get their access ready for what’s ahead,” adds David Moser. “With ASSA ABLOY, they digitalise with confidence.”
Insights & Opinions from thought leaders at ASSA ABLOY Opening Solutions
A lot has been said about door security — from reinforced door frames to locking mechanisms to the door construction — all of which is crucial. But what security measures are in place beyond the perimeter door in case the worst happens and it’s somehow breached? Hopefully, many more levels of access control are in place to prevent, or at least slow down, a perpetrator’s ability to compromise protected assets. Additional interior layers Interior security measures must operate as an integrated, multilayered system that eliminates single points of failure. These inner protections safeguard not only the physical infrastructure but also the operational integrity, confidentiality, and availability of the systems housed within. Beyond simply preventing unauthorised individuals from getting inside, the goal is to create a controlled, monitored, and resilient environment in which every movement, action, and access attempt is verified, logged, and, when necessary, challenged. As modern buildings, data centres, and infrastructure sites host critical functions and potentially sensitive intellectual property, these additional interior layers become essential to protecting both organisations and their proprietary assets. Interior security controls One of the most important interior security controls is granular access segmentation One of the most important interior security controls is granular access segmentation. While a perimeter door may verify an individual’s right to enter the building, the interior should treat every room, cage, and corridor as its own security zone. Role-based access control and strict least-privilege principles should limit personnel to only the areas they absolutely require. For example, a network engineer may need access to routing equipment but not storage racks; a janitorial contractor might be allowed into shared hallways but not any equipment rooms at all. These access restrictions should be enforced using intelligent keys, biometric scanners, mantraps, and, at particularly sensitive locations, two-factor authentication. Segmenting access in this way limits the potential damage from a single compromised badge or insider threat and ensures that a single breach does not cascade into a total facility compromise. Low-light and infrared capabilities Biometric authentication within a building adds a layer of confidence beyond perimeter controls. Technologies such as facial identification help prevent the use of stolen, cloned, or borrowed credentials. These systems complement anti-tailgating measures, such as sally ports or mantraps, which ensure that only one authenticated person passes through at a time. Interior surveillance is another essential measure. High-resolution cameras equipped with low-light and infrared capabilities should cover every hallway, door, rack row, and logistical pathway. Camera feeds must be continuously recorded, and retention policies must align with regulatory requirements. Intelligent video analytics, such as motion pattern recognition and heat mapping, enable the detection of atypical behaviours — such as someone lingering near a cage they are not authorised to access or movement at odd hours. Physical tamper-detection mechanisms Cabinet security provides a vital layer of granularity in the access hierarchy, ensuring that even within secure facilities Integrating surveillance with access control systems creates a strong correlation; when someone successfully passes through a secured door and enters a room, the system can track whether the number of people seen on camera matches the number authenticated, and alert security if a discrepancy occurs. However, it is increasingly important that access control not stop at the room level, because the most sensitive assets are often housed in cabinets, racks, or storage units within already-secured spaces. Cabinet security provides a vital layer of granularity in the access hierarchy, ensuring that even within secure facilities, assets remain protected. Physical tamper-detection mechanisms on racks, cable trays, and server chassis add another dimension: they can detect if a panel is opened, a cable is unplugged, or a device is removed without authorisation. Secure destruction protocols Another internal measure is the use of secure storage and chain-of-custody procedures for any components that contain intellectual property or personally identifiable information. Hard drives, backup media, and even printouts should be stored in locked cabinets accessible only to people with proper clearance. When decommissioning hardware, secure destruction protocols such as shredding or degaussing should be performed in controlled areas and thoroughly logged. Every movement of sensitive equipment should be traceable, from installation through end-of-life disposal. Such processes reduce the risk of data leakage from improperly discarded or undocumented devices. Consequences of improper behaviour Staff should be trained to recognise social engineering attempts, unusual behaviours, and procedural deviations Operational security procedures also contribute significantly to interior protection. Background checks, ongoing employee vetting, and mandatory training ensure that individuals with access to sensitive areas understand their responsibilities and the consequences of improper behaviour. Staff should be trained to recognise social engineering attempts, unusual behaviours, and procedural deviations. Maintaining a strict visitor escort policy prevents non-employees from wandering unobserved. All visitors should wear highly visible identification badges and be monitored continuously by authorised personnel. The building's interior should be treated as a controlled environment at all times, not merely a workspace. Continuous auditing and logging form Continuous auditing and logging form another pillar of interior security. Access logs from intelligent keys, biometrics, video, and environmental systems must be stored securely and evaluated regularly for anomalies. Automated systems can flag irregular patterns, such as repeated attempts to access unauthorised areas or entering rooms at odd hours. Manual audits validate that the access control list remains accurate, that no inactive or former employees retain credentials, and that documentation matches reality on the floor. These logs are indispensable during investigations, compliance assessments, and incident response efforts. Interior security controls Security networks should be isolated from the main IT networks to prevent a cyber incident Finally, redundancy and resiliency must be built into interior security controls. Electrical power for access control, intelligent keys, biometrics, and video systems should be backed by secondary sources, generators, or uninterruptible power supplies. Security networks should be isolated from the main IT networks to prevent a cyber incident from disabling physical protections. The goal is to ensure that interior security remains functional even during outages, disasters, or cyber disruptions. Multilayered approach Together, these additional interior measures create a layered defence that makes a secure building, data centre, or infrastructure site extremely difficult to compromise. Rather than relying on a single barrier at the entrance, the environment becomes an ecosystem of mutually reinforcing controls — physical, operational, digital, and procedural. This multilayered approach allows structures to maintain high levels of protection even as threats evolve, ensuring that the systems inside remain secure, resilient, and trustworthy.
In today’s connected world, attacks are more likely to target digital than physical entry points. From ransomware and firmware tampering to remote hijacking, AI-driven phishing and automated vulnerability discovery, the nature of threats is evolving rapidly, and no industry can afford to neglect them. As our industry has moved from mainly mechanical to increasingly digital solutions, we have long recognised the importance of constantly monitoring and assessing the risks we face. This means not only meeting mandatory regulations but also voluntarily adopting international standards such as ISO 27001, which protects data and systems through a structured and independently audited framework. Today’s fast-changing risk environment is also why the EU introduced the Network and Information Security Directive 2 (NIS2) – to raise the bar for cybersecurity across Europe. But what do measures like NIS2 and the Cyber Resilience Act (CRA) mean in practice? How does the rise of AI fit in? And most importantly, what should our industry be doing to stay secure in such an unpredictable digital landscape? The new regulations Compliance is not just about meeting regulations, it is also a competitive advantage NIS2 is reshaping cybersecurity expectations by setting higher standards to reduce risk, improve transparency, and protect data and services. Alongside it, the CRA introduces mandatory requirements for products with digital components. This makes “secure by design,” regular updates, and compliance checks essential before products can enter the EU market. For companies in our industry, responsibilities now extend well beyond internal systems. Organisations must also ensure that suppliers and service providers comply, with regular risk assessments forming a central part of the process. The consequences of falling short are severe, ranging from significant fines and audits to the potential withdrawal of products from the market. For our customers, the message is clear: security must be built in from the start. Compliance is not just about meeting regulations, it is also a competitive advantage. At ASSA ABLOY Opening Solutions EMEIA, security is part of our DNA. We embed these standards into everything we do, giving customers solutions they can trust to be compliant and resilient. The rise of AI Artificial intelligence is transforming the digital security landscape and it cannot be separated from the regulatory framework shaping our industry. With AI advancing rapidly and new regulations coming into force, we have established a digital compliance framework to stay ahead of the curve and use AI as an enabler for improving security and achieving compliance. On one hand, AI brings powerful benefits, including more intelligent monitoring, faster anomaly detection, and smarter tools for operational efficiency. These capabilities directly support NIS2 and the CRA, particularly in the areas of proactive risk management and incident response. AI and building cybersecurity standards On the other hand, AI introduces new risks. The attack surface is expanding and threats such as deepfakes and smarter phishing create serious threats that regulators are determined to address. Both NIS2 and the CRA emphasise continuous monitoring, transparency and accountability, principles that must now also guide the responsible use of AI. At ASSA ABLOY Opening Solutions EMEIA, we see AI not just as a risk to mitigate, but as a capability to strengthen resilience and trust. That is why we are embedding strong governance practices around AI and building cybersecurity standards into every stage of product development. By doing so, we help our customers align with new regulations while ensuring AI serves as a tool for greater security and confidence. Trust and compliance Beyond our own operations, we are also committed to supporting customers on their compliance journey At ASSA ABLOY Opening Solutions EMEIA, we are taking NIS2, the CRA and the rise of cyber-threats seriously, ensuring compliance and enhancing trust with all our customers. We have reinforced supplier oversight, streamlined incident reporting, and embedded cybersecurity into every stage of product development and lifecycle management. Our teams also conduct ongoing risk assessments and post-incident reviews, ensuring that lessons are learned and improvements are made. By taking these steps, we not only meet regulatory requirements but strengthen the resilience of our supply chain and the trust customers place in us. Beyond our own operations, we are also committed to supporting customers on their compliance journey. Initiatives such as our recently released whitepaper “Enhancing Cyber–Physical Resilience with Digital Access Solutions” and a detailed NIS2 whitepaper developed in Germany last year provide clear, practical guidance. By showing what these regulations mean in practice and how intelligent access solutions can directly support compliance, we aim to make the path forward less complex and more achievable for our customers. Looking ahead The days when security threats to businesses and products were only physical are long passed. Today, we find ourselves in a world where the digital realm poses even more serious and constantly evolving challenges. It is therefore crucial that, as an industry, we take the necessary steps to meet the directives of NIS2 and the CRA and also constantly monitor the rise of AI. Only by doing so can we protect our customers, preserve our reputations, and build the trust that defines true leadership in security.
When it comes to protecting the environment, the security industry has historically been perched on the sidelines. For instance, the amount of electricity that physical security systems use is minimal when compared to the total energy usage in a typical building. However, as awareness of environmental issues has surged, and as some of the "low-hanging fruit" has been harvested, attention has come back to opportunities for additional, if small, savings. The lifecycles of security products are also being more closely examined, including the environmental impact of using plastics and other chemicals. We asked this week's Expert Panel Roundtable: How can the security industry contribute to protecting the environment?
Technology's role in securing banks and financial institutions
DownloadSecurity technologies promote real-time awareness in K-12 schools
DownloadIntegrated systems enable critical and compliant security for transportation
DownloadModernising physical access control
DownloadAccess. Intrusion. One estate.
Download
