ASSA ABLOY Opening Solutions - Experts & Thought Leaders

Latest ASSA ABLOY Opening Solutions news & announcements

ASSA ABLOY adds cloud management capability to the Incedo Business access control solution

Incedo access management from ASSA ABLOY Opening Solutions is created for businesses on the move, who need a flexible security solution which grows with them. Now security managers managing an Incedo Business solution can work remotely, too — while maintaining complete control over their building’s access points. Incedo connects security software and hardware within a single, seamless platform. To accommodate the restless change and disruption of modern business life, Incedo enables scaling up or down on demand. And now, new Incedo Business Cloud management keeps security and facility managers in control of their premises from wherever they happen to be right now. Cost-efficient subscription Incedo Business Cloud solves many pressing daily challenges of access management. Managers no longer need to be on-site to handle day-to-day security. Incedo Business Cloud operates securely 24/7 from any PC with an internet connection. Installing the system is easy, with no complex integrations needed. Software updates are regular and automatic, with real-time reports and analytics available with a few clicks. Incedo Business Cloud works out of the box via a cost-efficient subscription service: no more waiting around for engineer callouts. Onboarding is fast and hassle-free. And security managers can feel confident about confidentiality: business and user data are safeguarded with an Information Security Management System certified to ISO/IEC 27001. Cloud-based management Recent report finds 78% of IT decision-makers anticipate growing their reliance on cloud solutions going forward According to the Wireless Access Control Report 2021, over a third of companies now use cloud-based management to power their access control. This proportion is likely to grow in the years ahead, as working practices become ever more mobile and the notion of being ‘at work’ describes a state of being, rather than a specific place. Indeed, another recent report finds 78% of IT decision-makers anticipate growing their reliance on cloud solutions going forward. A cloud solution makes access management easier and more convenient, helping companies to design security administration processes which are streamlined, location-independent and efficient. For any size of organisation, switching to Incedo Business Cloud implements this powerful access control with no high upfront costs and ongoing cost-effectiveness. Managing access control “A cloud software solution makes budgeting more predictable for facility and security managers,” says Kevin Hoare, EAC Product Unit Director at ASSA ABLOY Opening Solutions EMEA. “It removes the need to hire additional in-house IT support and maintenance teams: you know ahead of time how much resource to allocate and can scale infrastructure up or down quickly. The business benefits of ‘managing access rights from anywhere’ drive ever greater demand for cloud solutions within security and beyond.” “Survey data shows the way companies manage access control will continue to be a mixed picture, with both locally hosted and off-site cloud solutions for Access Control as a Service,” he adds. “This is why, when launching our Incedo ecosystem, we give users the choice.” Migration between Incedo’s local and cloud management options is always seamless in any direction, ensuring total flexibility for any business. Appropriate management system Incedo Business Cloud makes access control more efficient for everyone, from installers to end-users Incedo Business Cloud makes access control more efficient for everyone, from installers to end-users. A modular, platform approach makes both procurement and operation simpler. Managers choose the security hardware and credentials they need together with the appropriate management system. Award-winning ASSA ABLOY wireless digital locks and wired ASSA ABLOY wall readers secure the doors. A choice of card and token credentials — or mobile keys on a smartphone — helps users enjoy safe and convenient access to, and movement around, the premises. New Incedo-enabled hardware from ASSA ABLOY and third-party providers will continue to be made available within the evolving Incedo ecosystem. Remote access management Add doors or locations, and switch between local and cloud management, as often as required. Incedo guarantees flexibility and scalability in every direction, to meet security needs today and in the future. “This latest enhancement of our Incedo solution makes comprehensive, real-time, remote access management into a reality. Incedo will keep premises secure and filter access intelligently, to manage the ever-changing movement of people across multiple sites — from anywhere. Your business is not static, and there is no reason why your security should be.” says Stephanie Ordan, VP Digital and Access Solutions at ASSA ABLOY Opening Solutions EMEA. Incedo™ Business Cloud embodies ASSA ABLOY’s vision to create a safer and more open world, keeping everyone on the move together.

ASSA ABLOY Opening Solutions EMEA launches Incedo™ Business access management solution

The world is constantly changing, with people, data and goods moving more fluidly than ever before. The security solution needs to move with it. New Incedo Business connects all security software and hardware within one platform. One can easily scale it up or down, based on one’s needs, to keep people moving and business growing. Together. People need different access times and entry points, and the access and security requirements change day to day – so, a static solution is no longer an option. Instead, a single, all-encompassing security platform should deliver connectivity, convenience and simplicity, keeping one’s premises secure and filtering access to manage the ever-changing movement of people. This is where Incedo Business comes in: a new solution for all types of premises, handling security while leaving one free to focus on growing the business. Incedo ensures employees, customers and goods are where they need to be. Incedo makes life and tasks easier and more efficient for everyone, from installers to end users. Facility managers enjoy more control and flexibility than they ever thought possible - maximising return on investment, with Incedo Business able to scale quickly when needed. System administrators can do more within available budgets: initiating, cancelling or amending access profiles, and monitoring movement around their site in real time. Building users, meanwhile, get the individual access times and entry permissions they need. They can move freely without compromising the security of other people and equipment. Integrators can upgrade connected technologies and systems quickly, minimising risk and meeting customers’ raised expectations of modern technology. Installers no longer need to wrestle with incompatible systems: easy interoperability is built into Incedo, meaning no more delays or unnecessary complexity. With Incedo’s modular platform approach, one simply chooses the security hardware and credentials one needs and the appropriate management system option. One can set exactly who can access which doors, and when, from the user-friendly Incedo Business software interface. When Incedo Business launches, one can pick the most suitable options from a growing range of Incedo-enabled security and access control hardware. Road-tested, award-winning ASSA ABLOY wireless digital locks and wired ASSA ABLOY wall readers secure all interior and exterior doors.  Also already available, a choice of card and token credentials helps users enjoy safe and convenient access to, and movement around, the premises. Incedo mobile keys add the flexibility to open doors with a smartphone. Incedo’s system management options, Lite, Plus and Cloud, scale from entry level up to cloud-based administration. One can manage multiple sites and third-party integrations, including security solutions like CCTV. Scale up and down, add or remove hardware and credentials on demand, or switch system management options, all within a single environment. Migration between Lite, Plus and Cloud options is always seamless in any direction, ensuring total flexibility for the business. Incedo moves with you, today and in the future However your business moves, an Incedo system moves along. Having a flexible platform, able to adapt as the organisation changes, reduces total cost of ownership: one never needs to retrain staff or start over from scratch. New Incedo-enabled hardware from ASSA ABLOY and third-party providers will continue to be connected to, and made available within, the evolving Incedo platform. One picks the hardware and software configuration one wants, and can change one’s mind as often as one likes. Incedo guarantees flexibility and scalability in every way, to meet the security needs today and in the future. And because the security and operational challenges at a university, small hotel or hospital are not the same as those faced by a public building or corporate HQ, the Incedo ecosystem will introduce new, advanced user interfaces for the specific industry. “Incedo Business transforms the experience of using and managing a building. It is also the seed from which our revolutionary Incedo ecosystem will grow in the months and years ahead,” says Stephanie Ordan, VP Digital and Access Solutions at ASSA ABLOY Opening Solutions EMEA. “A future where doors are smarter, connectivity and movement are seamless, and access management is genuinely intelligent. This is our vision for Incedo and for those who will be using it.” Incedo™ Business embodies ASSA ABLOY’s vision to create a safer and more open world, keeping everyone on the move. Together. To learn more and download a free solution guide, visit https://campaigns.assaabloyopeningsolutions.eu/Incedo-business

Prior1 & KentixONE: Advanced security for data centers

Prior1, a provider of modular IT infrastructure solutions, develops container data centers to meet the highest security and energy efficiency standards. Their containers require optimum protection against both physical threats and environmental risks. To provide this, Prior1 sought a security solution for their new “IT Container FIX” products which offers seamless monitoring and is flexible, scalable, and meets the requirements of EN 50600 certification. By choosing KentixONE as their central platform, Prior1 identified the comprehensive security solution they need. KentixONE enables the central control and monitoring of all security-relevant devices and sensors in real time. Its central dashboard provides data center managers with an overview and full control of every vital parameter. They can also stay in control while on the move via the KentixONE app, a powerful mobile control center. Comprehensive security solution “By integrating Kentix’s security solutions, we created a state-of-the-art container data center that not only meets the highest security standards but also offers the necessary flexibility for dynamic IT operations,” says Oliver Fronk, Team Coordinator at Prior 1. “This partnership has shown us how innovative technologies and modular systems can optimally support the requirements of digital transformation.” The KentixONE solution protects Prior1 customers against a vast scope of physical and environmental threats. Its seamless networking and intuitive, unified platform enable continuous monitoring and rapid response to incidents – critical to maintaining data integrity and security. Security-relevant events With SmartAccess functionality, Kentix IP wall readers ensure strict access control with two-factor authentication. Every access event is logged; unauthorised attempts immediately trigger an alarm. All data is stored in KentixONE and can be retrieved at any time. In addition, all accesses may be tagged with a short video sequence. Access control and sensor technology combines to create alarm zones which protect against unauthorised intrusion. These zones may be armed and disarmed both manually via access control and automatically. Smart video surveillance integrated within KentixONE detects security-relevant events in real time. Recordings can be called up and live images support the assessment of the situation in any emergency. Indicating critical conditions Powerful integrated SmartMonitoring is enabled via Kentix multisensors which continuously track environmental factors like temperature, humidity, and air quality. An integrated 4-factor early fire detection system detects anomalies which may indicate critical conditions at an early stage. This enables timely action to prevent damage. All external units such as air conditioning and UPS systems are seamlessly integrated and continuously communicate their operating status. Kentix SmartPDUs also monitor current and energy parameters, as well as ambient conditions within the server racks. The integrated residual current measurement (RCM) ensures electrical safety and fire protection, and detects creeping device failures. Anomalies are transmitted to KentixONE in real time so prompt action may be taken. KentixONE provides efficiency indicators such as PUE (Power Usage Effectiveness) and generates an energy report at the end of the month. With the help of KentixONE, then, Prior1 is able to offer customers future-proof infrastructure that combines the highest security and monitoring standards alongside management flexibility and seamless scalability. It is a game-changer for the holistic management of any data center.

Insights & Opinions from thought leaders at ASSA ABLOY Opening Solutions

AI and regulation are reshaping the future of building security

There was a time when physical security and cybersecurity occupied two very different worlds. One was concerned with the nuts and bolts of locks, doors and perimeter protection. The other focused on networks, software and digital threats. Today’s modern access control systems – used in everything from offices and hotels to hospitals and data centres – combine the two, fusing mechanical engineering and cloud platforms. That means that a door is no longer simply a physical barrier. Instead, it’s a connected endpoint within a much wider digital ecosystem. And it’s changing expectations across the industry. Increasingly, developers, architects and operators are turning their backs on separate products in favour of integrated access solutions that combine doors, locks, access controls, environmental monitoring and digital management into a single, connected system. A new connected approach to security This change is part of a wider shift in the way that security itself is perceived This change is part of a wider shift in the way that security itself is perceived. Traditionally, physical security was about keeping unauthorised people out. Today, it’s about making sure the right people have the freedom to move within a restricted space. That is particularly important in places such as hospitals, data centres and other critical infrastructure, where security helps protect essential services while minimising disruption. And it’s why our Research & Security Center (R&S) in Berlin, Germany, brings together both disciplines under one roof. Their job is to test products against both physical attacks and cyber threats. Employing unconventional tactics Sometimes, that means employing unconventional tactics, such as using professional lockpickers to test the security and resilience of new physical products. While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just security. Some systems can even use the motion of inserting and turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems. Bridging physical and digital security For instance, great strides have been made recently in terms of biometric authentication However, as everyone knows, digital systems have their own security risks, especially now that artificial intelligence (AI) is part of the emerging threat. This means the cybersecurity team needs to ensure that systems are robust enough to withstand a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behaviour. It’s here that researchers adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities against existing real-world threats while also anticipating what might be around the corner. Mobile-based access control systems For instance, great strides have been made recently in terms of biometric authentication, including facial recognition and fingerprint scanning. Similarly, smartphones are increasingly being used to secure credentials for mobile-based access control systems. But improvements in technology also come with their own risks. For instance, For instance, AI-generated deepfake videos and voices are becoming more convincing, making it easier to trick people into giving access, sharing information or approving actions they should not. And as I alluded to earlier, criminals are now using AI and automated tools to identify weaknesses and exploit them much faster than before, sometimes with little or no human involvement. But it’s also true that it’s being used to bolster defences. Work is currently underway to use AI to analyse data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally. Modern access control Cloud-based platforms allow security teams to issue and revoke credentials remotely Increasingly, the value of modern access control lies not just in the hardware, but in the software that sits behind it. Cloud-based platforms allow security teams to issue and revoke credentials remotely, monitor activity across multiple sites and respond quickly to emerging threats. This makes security a real-time, always-on, continuously managed service rather than a collection of standalone products installed and largely forgotten about. The importance of regulation and compliance This is something that policymakers are aware of. In the European Union, for example, the  EU’s NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance. It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate. Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats. Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world. And by introducing clearer requirements and standards, the CRA will help consumers and organisations identify products with strong security features and configure them more securely from the outset. Security by design Security can no longer be treated as something that is bolted on at the end of the development process In both cases, it is incumbent on vendors not only to meet or exceed these rules and regulations but also to keep customers, the wider industry, and other stakeholders informed about developments. For me, these regulations also reflect a broader shift in thinking. Security can no longer be treated as something that is bolted on at the end of the development process or addressed only after a vulnerability has been identified. Instead, it needs to be considered from the very beginning and maintained throughout a product's lifecycle. For manufacturers, that means continuously assessing risks, testing products against emerging threats and ensuring they remain resilient as technology and the threat landscape evolve. As I said at the beginning, the reason is simple. Today's buildings are no longer just bricks and mortar. They are connected environments where doors, locks, cameras, sensors and access control systems increasingly communicate with one another and with cloud-based platforms. You might want to think about that the next time you walk into a secure building.

What’s behind (perimeter) door #1?

A lot has been said about door security — from reinforced door frames to locking mechanisms to the door construction — all of which is crucial. But what security measures are in place beyond the perimeter door in case the worst happens and it’s somehow breached? Hopefully, many more levels of access control are in place to prevent, or at least slow down, a perpetrator’s ability to compromise protected assets. Additional interior layers Interior security measures must operate as an integrated, multilayered system that eliminates single points of failure. These inner protections safeguard not only the physical infrastructure but also the operational integrity, confidentiality, and availability of the systems housed within. Beyond simply preventing unauthorised individuals from getting inside, the goal is to create a controlled, monitored, and resilient environment in which every movement, action, and access attempt is verified, logged, and, when necessary, challenged. As modern buildings, data centres, and infrastructure sites host critical functions and potentially sensitive intellectual property, these additional interior layers become essential to protecting both organisations and their proprietary assets. Interior security controls One of the most important interior security controls is granular access segmentation One of the most important interior security controls is granular access segmentation. While a perimeter door may verify an individual’s right to enter the building, the interior should treat every room, cage, and corridor as its own security zone. Role-based access control and strict least-privilege principles should limit personnel to only the areas they absolutely require. For example, a network engineer may need access to routing equipment but not storage racks; a janitorial contractor might be allowed into shared hallways but not any equipment rooms at all. These access restrictions should be enforced using intelligent keys, biometric scanners, mantraps, and, at particularly sensitive locations, two-factor authentication. Segmenting access in this way limits the potential damage from a single compromised badge or insider threat and ensures that a single breach does not cascade into a total facility compromise. Low-light and infrared capabilities Biometric authentication within a building adds a layer of confidence beyond perimeter controls. Technologies such as facial identification help prevent the use of stolen, cloned, or borrowed credentials. These systems complement anti-tailgating measures, such as sally ports or mantraps, which ensure that only one authenticated person passes through at a time. Interior surveillance is another essential measure. High-resolution cameras equipped with low-light and infrared capabilities should cover every hallway, door, rack row, and logistical pathway. Camera feeds must be continuously recorded, and retention policies must align with regulatory requirements. Intelligent video analytics, such as motion pattern recognition and heat mapping, enable the detection of atypical behaviours — such as someone lingering near a cage they are not authorised to access or movement at odd hours. Physical tamper-detection mechanisms Cabinet security provides a vital layer of granularity in the access hierarchy, ensuring that even within secure facilities Integrating surveillance with access control systems creates a strong correlation; when someone successfully passes through a secured door and enters a room, the system can track whether the number of people seen on camera matches the number authenticated, and alert security if a discrepancy occurs. However, it is increasingly important that access control not stop at the room level, because the most sensitive assets are often housed in cabinets, racks, or storage units within already-secured spaces. Cabinet security provides a vital layer of granularity in the access hierarchy, ensuring that even within secure facilities, assets remain protected. Physical tamper-detection mechanisms on racks, cable trays, and server chassis add another dimension: they can detect if a panel is opened, a cable is unplugged, or a device is removed without authorisation. Secure destruction protocols Another internal measure is the use of secure storage and chain-of-custody procedures for any components that contain intellectual property or personally identifiable information. Hard drives, backup media, and even printouts should be stored in locked cabinets accessible only to people with proper clearance. When decommissioning hardware, secure destruction protocols such as shredding or degaussing should be performed in controlled areas and thoroughly logged. Every movement of sensitive equipment should be traceable, from installation through end-of-life disposal. Such processes reduce the risk of data leakage from improperly discarded or undocumented devices. Consequences of improper behaviour Staff should be trained to recognise social engineering attempts, unusual behaviours, and procedural deviations Operational security procedures also contribute significantly to interior protection. Background checks, ongoing employee vetting, and mandatory training ensure that individuals with access to sensitive areas understand their responsibilities and the consequences of improper behaviour. Staff should be trained to recognise social engineering attempts, unusual behaviours, and procedural deviations. Maintaining a strict visitor escort policy prevents non-employees from wandering unobserved. All visitors should wear highly visible identification badges and be monitored continuously by authorised personnel. The building's interior should be treated as a controlled environment at all times, not merely a workspace. Continuous auditing and logging form Continuous auditing and logging form another pillar of interior security. Access logs from intelligent keys, biometrics, video, and environmental systems must be stored securely and evaluated regularly for anomalies. Automated systems can flag irregular patterns, such as repeated attempts to access unauthorised areas or entering rooms at odd hours. Manual audits validate that the access control list remains accurate, that no inactive or former employees retain credentials, and that documentation matches reality on the floor. These logs are indispensable during investigations, compliance assessments, and incident response efforts. Interior security controls Security networks should be isolated from the main IT networks to prevent a cyber incident Finally, redundancy and resiliency must be built into interior security controls. Electrical power for access control, intelligent keys, biometrics, and video systems should be backed by secondary sources, generators, or uninterruptible power supplies. Security networks should be isolated from the main IT networks to prevent a cyber incident from disabling physical protections. The goal is to ensure that interior security remains functional even during outages, disasters, or cyber disruptions. Multilayered approach Together, these additional interior measures create a layered defence that makes a secure building, data centre, or infrastructure site extremely difficult to compromise. Rather than relying on a single barrier at the entrance, the environment becomes an ecosystem of mutually reinforcing controls — physical, operational, digital, and procedural. This multilayered approach allows structures to maintain high levels of protection even as threats evolve, ensuring that the systems inside remain secure, resilient, and trustworthy.

Staying secure in today’s digital landscape

In today’s connected world, attacks are more likely to target digital than physical entry points. From ransomware and firmware tampering to remote hijacking, AI-driven phishing and automated vulnerability discovery, the nature of threats is evolving rapidly, and no industry can afford to neglect them. As our industry has moved from mainly mechanical to increasingly digital solutions, we have long recognised the importance of constantly monitoring and assessing the risks we face. This means not only meeting mandatory regulations but also voluntarily adopting international standards such as ISO 27001, which protects data and systems through a structured and independently audited framework. Today’s fast-changing risk environment is also why the EU introduced the Network and Information Security Directive 2 (NIS2) – to raise the bar for cybersecurity across Europe. But what do measures like NIS2 and the Cyber Resilience Act (CRA) mean in practice? How does the rise of AI fit in? And most importantly, what should our industry be doing to stay secure in such an unpredictable digital landscape? The new regulations Compliance is not just about meeting regulations, it is also a competitive advantage NIS2 is reshaping cybersecurity expectations by setting higher standards to reduce risk, improve transparency, and protect data and services. Alongside it, the CRA introduces mandatory requirements for products with digital components. This makes “secure by design,” regular updates, and compliance checks essential before products can enter the EU market. For companies in our industry, responsibilities now extend well beyond internal systems. Organisations must also ensure that suppliers and service providers comply, with regular risk assessments forming a central part of the process. The consequences of falling short are severe, ranging from significant fines and audits to the potential withdrawal of products from the market. For our customers, the message is clear: security must be built in from the start. Compliance is not just about meeting regulations, it is also a competitive advantage. At ASSA ABLOY Opening Solutions EMEIA, security is part of our DNA.  We embed these standards into everything we do, giving customers solutions they can trust to be compliant and resilient.  The rise of AI  Artificial intelligence is transforming the digital security landscape and it cannot be separated from the regulatory framework shaping our industry. With AI advancing rapidly and new regulations coming into force, we have established a digital compliance framework to stay ahead of the curve and use AI as an enabler for improving security and achieving compliance. On one hand, AI brings powerful benefits, including more intelligent monitoring, faster anomaly detection, and smarter tools for operational efficiency. These capabilities directly support NIS2 and the CRA, particularly in the areas of proactive risk management and incident response.  AI and building cybersecurity standards On the other hand, AI introduces new risks. The attack surface is expanding and threats such as deepfakes and smarter phishing create serious threats that regulators are determined to address. Both NIS2 and the CRA emphasise continuous monitoring, transparency and accountability, principles that must now also guide the responsible use of AI.    At ASSA ABLOY Opening Solutions EMEIA, we see AI not just as a risk to mitigate, but as a capability to strengthen resilience and trust. That is why we are embedding strong governance practices around AI and building cybersecurity standards into every stage of product development. By doing so, we help our customers align with new regulations while ensuring AI serves as a tool for greater security and confidence. Trust and compliance Beyond our own operations, we are also committed to supporting customers on their compliance journey At ASSA ABLOY Opening Solutions EMEIA, we are taking NIS2, the CRA and the rise of cyber-threats seriously, ensuring compliance and enhancing trust with all our customers. We have reinforced supplier oversight, streamlined incident reporting, and embedded cybersecurity into every stage of product development and lifecycle management. Our teams also conduct ongoing risk assessments and post-incident reviews, ensuring that lessons are learned and improvements are made. By taking these steps, we not only meet regulatory requirements but strengthen the resilience of our supply chain and the trust customers place in us. Beyond our own operations, we are also committed to supporting customers on their compliance journey. Initiatives such as our recently released whitepaper “Enhancing Cyber–Physical Resilience with Digital Access Solutions” and a detailed NIS2 whitepaper developed in Germany last year provide clear, practical guidance. By showing what these regulations mean in practice and how intelligent access solutions can directly support compliance, we aim to make the path forward less complex and more achievable for our customers. Looking ahead The days when security threats to businesses and products were only physical are long passed. Today, we find ourselves in a world where the digital realm poses even more serious and constantly evolving challenges. It is therefore crucial that, as an industry, we take the necessary steps to meet the directives of NIS2 and the CRA and also constantly monitor the rise of AI. Only by doing so can we protect our customers, preserve our reputations, and build the trust that defines true leadership in security.