SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    ASSA ABLOY eCLIQ programmable key access system

    ASSA ABLOY eCLIQ programmable key access system

    Dahua Wi-Fi Pan & Tilt Camera with AI Detection and Smart Dual Light

    Dahua Wi-Fi Pan & Tilt Camera with AI Detection and Smart Dual Light

    Dahua Wireless Alarm Hub 2

    Dahua Wireless Alarm Hub 2

    Hikvision LinkVu integrated security and networking solution for SMB installers

    Hikvision LinkVu integrated security and networking solution for SMB installers

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Gunnebo reveals secure storage At Security Essen 2026
    • Paxton solo: Student housing access control simplified
    • Zero Networks expands Palo Alto integration: AI focus
    • Cribl advances AI SOC with Radiant Tech acquisition
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • Responsible AI adoption starts with governance
    • Solink's AI agents boost efficiency of existing infrastructure with automation
    • How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
    • What is the changing role of intelligence in physical security?
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    Hikvision solution boosts Muçum flood preparedness

    Hikvision solution boosts Muçum flood preparedness

    Carrefour Brazil: Enhanced security with Dahua solutions

    Carrefour Brazil: Enhanced security with Dahua solutions

    El Loa Aerodrome security with Dahua Technology

    El Loa Aerodrome security with Dahua Technology

    Enhance business intelligence with key control systems

    Enhance business intelligence with key control systems

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    Intersec Buenos Aires 2026

    Intersec Buenos Aires 2026

    Securex Caspian 2026

    Securex Caspian 2026

    PACK EXPO Chicago 2026

    PACK EXPO Chicago 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Software House
    • ELATEC USA
    Other Resources
    • eMagazines
    • Videos
    Technology's role in securing banks and financial institutions

    Technology's role in securing banks and financial institutions

    Integrated systems enable critical and compliant security for transportation

    Integrated systems enable critical and compliant security for transportation

    Modernising physical access control

    Modernising physical access control

    Access. Intrusion. One estate.

    Access. Intrusion. One estate.

About us Advertise
  • Securing financial institutions
  • AI special report
  • Cyber security special report
  • 6

Cloud security

  • Home
  • About
  • White papers
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • Videos
Delivering a smart, secure and healthy workplace with cloud
Delivering smart, secure and healthy retail environments with the cloud

Delivering smart, secure and healthy retail environments with the cloud

White paper
What is the cloud? (Can we all agree?)

What is the cloud? (Can we all agree?)

Expert panel
Delivering a smart, secure and healthy workplace with cloud

Delivering a smart, secure and healthy workplace with cloud

White paper
Looking back at 2020: Cloud systems expand in shadow of COVID

Looking back at 2020: Cloud systems expand in shadow of COVID

Editor's opinion
Which security markets are likely to embrace the cloud?

Which security markets are likely to embrace the cloud?

Expert panel

White papers

Securing the modern data centre

Securing the modern data centre

Download
Security technologies promote real-time awareness in K-12 schools

Security technologies promote real-time awareness in K-12 schools

Download
Milestone cloud deployment guide

Milestone cloud deployment guide

Download
Maximising enterprise security systems in the cloud

Maximising enterprise security systems in the cloud

Download
Using artificial intelligence (AI) to automate physical security systems

Using artificial intelligence (AI) to automate physical security systems

Download
A modern guide to data loss prevention

A modern guide to data loss prevention

Download
2025 Trends in video surveillance

2025 Trends in video surveillance

Download
How to lower labour costs when installing video surveillance

How to lower labour costs when installing video surveillance

Download
Total cost of ownership for video surveillance

Total cost of ownership for video surveillance

Download
Guide for HAAS: New choice of SMB security system

Guide for HAAS: New choice of SMB security system

Download
Integrating IT & physical security teams

Integrating IT & physical security teams

Download
Understanding all-in-one solutions

Understanding all-in-one solutions

Download
Top 7 trends to watch in the physical security industry

Top 7 trends to watch in the physical security industry

Download
2024 trends in video surveillance

2024 trends in video surveillance

Download
Securing data centres: Varied technologies and exacting demands

Securing data centres: Varied technologies and exacting demands

Download
View all

News

Netwrix expands AI identity security in Microsoft cloud
Netwrix expands AI identity security in Microsoft cloud

Netwrix, a recognised pioneer in identity and data security, announces new capabilities across Netwrix PingCastle and Netwrix Threat Manager that extend identity security deeper into the Microsoft cloud, including coverage of AI agents. Organisations are deploying AI agents faster than they can govern them. Each agent is an identity holding real permissions inside the enterprise environment, yet most exist outside any inventory, ownership, or review process. Identities needing access A Cloud Security Alliance survey found that fewer than a quarter of organisations have a formally adopted policy for creating or removing the identities their AI systems run on, and more than 16% don't track when a new one is created at all. The consequences are measurable: in its 2026 Data and Identity Security Report, Netwrix found a 43% breach rate among organisations where AI had significantly expanded the number of identities needing access, compared with 11% where it hadn't. Netwrix PingCastle extends its Microsoft Entra ID coverage to 102 risk checks, extending the tool's trusted Active Directory posture assessment into the cloud identity plane. Security teams and administrators can now assess identity risk across both on-premises AD and Entra ID with the same fast, prioritised approach that has made PingCastle a community favourite. Actionable risk insights Netwrix Threat Manager adds new visibility into AI agent identities in Microsoft Entra ID, giving security teams an inventory of the agents operating in their environment and the access they hold. That inventory is the missing foundation for most organisations: the Netwrix report found only 19% of organisations fully govern non-human identities such as service accounts and AI agents. Threat Manager already provides visibility and monitoring for another critical non-human identity category, service accounts, through actionable risk insights, abnormal-behavior detection, and attack context for faster triage; this release extends that coverage to AI agents. Agent-specific threat detection The latest Netwrix Threat Manager release also adds new threat detection for Azure Files, protecting file shares against ransomware, abnormal behaviour, and high-risk changes such as the creation of open access. Agent-specific threat detection is planned for a subsequent release, building on the visibility foundation delivered today. The new capabilities complement Microsoft's native tooling with independent assessment and visibility across the Microsoft identity plane. "Earlier this year, we gave organisations visibility into what AI agents can access. This release goes a layer deeper: which agents exist at all," said Jeff Warren, CPO at Netwrix. "Our research found fewer than one in five organisations fully govern non-human identities, and agents are the fastest-growing category. You can't review access for an identity you don't know you have." Independent posture assessment These releases advance Netwrix's strategy to unify identity and data security. PingCastle's assessment engine already powers more than 200 checks within the company's 1Secure™ platform, reflecting the same independent posture assessment approach now extended deeper into the Microsoft identity plane. Netwrix PingCastle 4.0 and Netwrix Threat Manager 3.3 are available now. To learn more, book a meeting with the Netwrix team.

RAD releases cloud native behavioral detection solution
RAD releases cloud native behavioral detection solution

RAD Security releases the industry’s first behavioural detection and response solution for cloud native environments, as CEO Brooke Motta takes the stage in San Francisco for the RSA Conference Innovation Sandbox. To-date, signature and anomaly-based methods are late and ineffective against cloud native attacks like the recent XZ Backdoor. RAD’s detection and response platform is the first to baseline behaviour through workload fingerprints, detecting cloud native attacks as they happen, while tying in real-time infrastructure and identity context for response prioritisation. Identity context for response prioritisation “As the footprint of cloud native environments continues growing, security teams can no longer rely on signature-based detection that only works after the attack, or false promises from AI and machine learning models based on insufficient samples of cloud attacks. Security teams need to respond to cloud native attacks as they happen, with clear prioritisation across workloads, infrastructure and identity,” explains CTO and Co-Founder, Jimmy Mesta. Today, 70% of teams are using containers in production, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. A recent survey shows that 90% of teams using containers and Kubernetes had an incident in the last year, and a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap. Consistent set of core processes In the weeks following the zero day XZ Backdoor software supply chain attack, cloud native IDS approaches resulted in signatures days and weeks following the attack, and anomaly detection approaches were blind to the set of attackers’ techniques that relied on normal processes. To detect the XZ Backdoor and other zero day attacks, a behavioural profile of the environment would have been required before the attack took place. RAD’s behavioural fingerprints are based on the fact that the majority of cloud native workloads exhibit a consistent set of core processes, programs and files at runtime. Any drift from this core set of behaviours is suspicious. Cloud native technologies RAD fingerprints get critical context from its ITDR and KSPM capabilities to help reduce noise and allow teams to understand the true impact of detections, compared to CSPM and CNAPP vendors that leave teams blind to the real-time changes between cloud native identity, infrastructure, and workloads. The launch of the detection and response platform follows the release of the open source fingerprint standard and Cloud Native Identity Threat Detection & Response (ITDR). Over a dozen companies are using RAD to create fingerprints in their environment, and in the last year alone, RAD Security has seen ARR has grown by 3 times, with a 219% net retention rate and new logos from highly regulated and digitally mature industries such as insurance, banking and media. At the same time, the current and growing importance of cloud native technologies in the security team’s priorities is reflected in 60% growth of customer contract value, with nearly half of new ARR coming from expansion of current customers. LLM-driven analysis New features in this release include: Fingerprints and drift for unique containers: RAD can now create cloud native behavioural workload fingerprints and detect drift for custom containers (versus just open source) at runtime eBPF sensor: RAD is releasing a newly re-configured, custom eBPF sensor to get around the inflexibility and instability inherent in legacy agents. RAD’s agent requires the fewest and most precise permissions, has more flexibility for correlation of data across the environment, and a smaller footprint Response actions: Customers can terminate pods, label pods, and quarantine pods (e.g. prevent network egress from pods) in response to drift detection AI/LLM Categorisation of Drift Events: Drift events are classified into different attacks (if known), based on LLM-driven analysis Workflow manager: Set up automated workflows to choose how to respond to detections from RAD, whether that's to notify to one or more channels, label a pod to enable security teams to further investigate, kill a pod, or quarantine, open a pull request, run Terraform, call an AWS API to change a setting, and more Learn more about behavioural cloud native threat detection and response, meet them in the innovation showcase at the RSAC Innovation Sandbox competition, or reach out to get started creating unique behavioural fingerprints today!

RAD Security unveils AI-powered incident investigation
RAD Security unveils AI-powered incident investigation

RAD Security takes the stage as a finalist in the Black Hat Startup Spotlight Competition, it unveils the first-ever AI-powered incident investigation capability for behavioural detection and response. Today, cloud security is based almost exclusively on signature-based detections, which are notorious for burdening security teams with false positives. RAD Security is the first to combine AI-powered incident investigation with behavioural, signature-less detections, to significantly reduce false positives and provide much-needed relief for overburdened security teams. Signature-focused approach “By definition, signatures are stateless, making investigations based on the signature-focused approach inaccurate and tedious,” says CTO and Co-Founder Jimmy Mesta. “By adding AI-powered investigations to behavioural detection, which is already a step ahead of signature-based detection in accuracy, security teams can quickly get light years ahead in the accurate assessment of incidents.” RAD’s behavioural approach and AI-powered investigations result in the lowering of false positives on their own; but by putting these two capabilities together, RAD enables security teams to achieve a multiplier effect. The enhanced accuracy of behavioural methods versus signature-based methods is easily demonstrated using multiple examples of attack tactics like reverse shells, access to sensitive data, and a Sudo CVE. Behavioural drift event In these examples, while signatures can be easily bypassed by avoiding the exact parameters, they are detected by RAD’s behavioural solution. By the same token, a behavioural drift event is not always a malicious event, so the addition of the AI investigation capability ensures additional accuracy. AI is particularly suited for looking across large sets of data and quick contextualisation, making it a natural investigation tool and engine to analyse benign versus malicious drift. Throughout the history of cyber security, and most famously in the endpoint and network security markets, signatures have eventually been replaced by behavioural methods in response to an evolving threat landscape. Today, the cloud security category is nearly entirely composed of signature-based approaches with runtime security and Cloud Workload Protection (CWPP) that are standalone or part of a broader Cloud Native Application Protection Platform (CNAPP). Cloud native environments In sharp contrast to signature-based CNAPPs, or posture-focused Cloud Security Posture Management (CSPM), RAD Security’s Cloud Detection and Response (CDR) solution creates behavioural baselines of unique good behaviour to detect zero day attacks, enriching detections with real-time identity and infrastructure context that inform response actions. More and more, detection and response is being accomplished by fewer and fewer dedicated people, with 22% of security professionals reporting recent layoffs at their company. The workforce reductions are an even more acute pain in cloud security, with 65% of cybersecurity and infosecurity professionals claiming burnout due to skill gaps. Even though a full 95% of IT decision makers feel their team has been negatively impacted by the cloud security skills gap, cloud native adoption continues, and analysts predict that, by 2025, 95% of new applications will be built using cloud native workloads. Zero days like the XZ Backdoor are now a regular occurrence, making detection and response in cloud native environments more important than ever. Signatureless cloud detection RAD Security has introduced multiple new features to help security teams adopt new innovation that will help them address these alarming trends and emerging threats: Amazon EKS Add-on: RAD Security is now available as an Amazon EKS Add-on in the AWS Marketplace for Containers. This means customers can now provision the real-time KSPM and runtime features of the RAD platform directly from EKS, for real-time visibility into their Kubernetes risk as well as signatureless cloud detection and response. Automated AI-Powered Investigation: RAD Security uses LLMs to quickly analyse multiple behavioral detections and determine whether an incident is malicious or benign, including real-time infrastructure and identity context. Findings Centre: All incidents are now available in an easy to navigate console, making detection and investigation easier and quicker. RAD Open Source Catalogue: New version details and new open source images have now been added to the RAD Catalogue, detailing the changes in behavioural fingerprints over time and bolstering the behavioural workload fingerprint standard. Schedule a meeting with the RAD Security team at the Black Hat Conference this week to discuss improving detection accuracy for attacks in your cloud environments. The team will be exhibiting at booth #219 in Startup City, and at 4:45PM EST they will be presenting at the Innovators and Investors Summit as one of the four finalists in the Startup Spotlight competition.

Acalvio deception guardrails secure AI with honey decoys
Acalvio deception guardrails secure AI with honey decoys

Acalvio Technologies, the pioneer in autonomous cyber deception technology, announces the launch of Deception Guardrails, a groundbreaking preemptive defence capability designed specifically to secure AI agents. The new capability addresses a critical gap in agentic AI security: traditional guardrails primarily focus on inputs and outputs and provide limited visibility into agent behaviour after compromise. Deception Guardrails introduce proactive tripwires that detect, deceive, disrupt, and deny malicious agent activity before enterprise systems are impacted. Adopting agentic AI systems As enterprises rapidly adopt agentic AI systems capable of autonomous reasoning and task execution via tools and APIs, the attack surface has fundamentally shifted. Recent incidents involving AI agents have highlighted how quickly compromised agents can exploit credentials, tools, and external systems in ways that evade traditional guardrails. Most AI guardrails primarily focus on controlling and filtering agent inputs and outputs, leaving security teams blind once an attacker bypasses them. "Reactive guardrails are designed to keep well-behaved AI systems on the road, but they do nothing to stop a hijacked agent driven by a malicious actor," said Ram Varadarajan, CEO at Acalvio. "With our patent-pending Deception Guardrails, we are moving the industry from reactive filtering to preemptive defence. If an AI agent goes rogue or its infrastructure is manipulated, our deceptive assets rapidly detect the misalignment, feed the attacker fabricated data, and alert the SOC before real enterprise assets are compromised." Perfecting deception technologies The urgency of addressing agentic AI threats was underscored by the recent Hugging Face incident. A briefing, authored by top cyber authorities from the Cloud Security Alliance, SANS, and RSAC, issued a clear recommendation for deception, "Because agents cannot easily tell valid credentials or systems from honeypots, deploy fake identities, credentials, package registries, datasets, honey APIs, and honey clusters to slow attackers and generate high-confidence indicators." "Acalvio has spent years perfecting deception technologies to detect sophisticated attackers inside enterprise environments. Extending those same principles to AI agents is a natural and compelling evolution. By embedding deceptive assets directly into agent workflows and surrounding AI infrastructure with decoys, organisations gain a powerful new layer of detection that complements existing AI safety and governance controls," said Lawrence Pingree, Head of Research at Software Analyst Cyber Research. Detecting compromised agents Beyond detecting compromised agents, Deception Guardrails provide high-confidence early warnings that help security teams reduce AI risk and respond before business-critical systems are affected. Acalvio’s Deception Guardrails natively extend the company's award-winning ShadowPlex platform, combining agentic deception and AI-infrastructure honeytokens and decoys, with comprehensive enterprise deception across on-premises and cloud environments. Key features of Deception Guardrails include: Full-Spectrum Enterprise Coverage: An extensive set of honeytokens and decoys deployed across on-premises and cloud environments. This comprehensive enterprise deception ensures that any misalignment or unauthorised lateral movement by internal AI agents against enterprise infrastructure is rapidly detected. Agentic Deception: Deploys highly credible honeytokens and honey skills in the files and configuration surfaces that AI agents read as operational context. If a compromised agent attempts to access or utilise these tools, high-fidelity alerts are triggered. Decoy AI Infrastructure: Surrounds the AI ecosystem with a deceptive reality, including decoy MCP (Model Context Protocol) servers, decoy RAG (Retrieval-Augmented Generation) systems, and decoy AI agents. Real-time Misalignment Detection: Identifies malicious manipulation, jailbreak behavior, and prompt injections in real-time by monitoring interactions with deceptive guardrails, neutralising threats before they can pivot to production environments. Enterprise-scale deployment As organisations move from AI experimentation to enterprise-scale deployment, Deception Guardrails provide the visibility and pre-emptive defence required to manage agentic risk without slowing innovation. To learn more about cyber deception, visit the Acalvio team at Black Hat USA, at Booth #8606, AI Zone. Attendees are encouraged to visit the booth for a live demonstration of Deception Guardrails against agentic attacks.

View all

Expert commentary

Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity

The sheer volume of smart locks, lock management systems, connected readers and an increasing array of Internet of Things (IoT) devices complicates the issuance and management of certificates that are foundational to establishing trust between a device and the credential used to access it. That’s why more companies are turning to PKIaaS for IoT devices. But there’s another reason to consider PKIaaS: the rise of quantum computing. Secure digital communications Gartner predicts that the pace of quantum computing will render asymmetric cryptography systems PKI certificates form the backbone of secure digital communications, but Gartner predicts that the pace of quantum computing will render asymmetric cryptography systems unsafe by 2029 and could render all current cryptography unsafe by 2034. As with any software implementation, there are pitfalls to avoid, including vendors that use proprietary technology that’s incompatible with other systems and “gotcha” pricing tactics where a slight increase in certificate usage triggers a massive increase in pricing. However, the time to implement PKIaaS is now. Physical security faces growing cyber threats Although ransomware attacks directly on computing infrastructure dominate business headlines, physical security systems are also under threat. An HID survey of over 1,200 security professionals, end-users and executives shows that 75% reported threats to their physical security systems in the past year, as these systems are more tightly integrated with company IT networks. Until recently, most physical access control systems (PACS) were proprietary and worked only on the specific systems they were designed to interact with. However, the movement toward open supervised device protocol (OSDP) revolutionised the field, allowing companies to integrate and control devices from different vendors while improving compatibility and security. PACS and IoT devices  PKIaaS makes sense as the number of digital certificates needed to power PACS and IoT devices As a result, 40% of companies plan to either update or change access control systems in the next year, with 21% emphasising the need for open standards like OSDP to both improve interoperability and future-proof their systems. When asked about reasons for a proposed upgrade, more than half cited convenience, while another 40% sought to improve their overall security posture. PKIaaS makes sense as the number of digital certificates needed to power PACS and IoT devices continues to increase, promoting security and reducing manual processes related to tracking certificates. Regulatory compliance demands automation and agility Companies also face increased regulatory pressures regarding technology in general — and certificates in particular. The European Union’s Cyber Resilience Act sets mandatory cybersecurity standards for manufacturers and retailers, covering the planning, design, development and maintenance of products throughout the entire value chain. Certain high-risk products must undergo third-party evaluation by an authorised body before being approved for sale in the EU. EU Cybersecurity Act shows a unified certificate framework for ICT products, services and processes More specifically, the EU Cybersecurity Act establishes a unified certification framework for information and communications technology (ICT) products, services and processes. Businesses operating in the EU will benefit from a “certify once, recognised everywhere” approach, meaning that approved ICT offerings will be accepted across all EU member states. Given the global nature of PACS, these regulations likely will impact companies well beyond the EU, much like the general data protection regulation on websites has. These changes, when considered together with rapid advancements in quantum computing, underscore the need for a unified certification solution such as PKIaaS to handle increased — and increasingly complex — certificate compliance. A path to PKI modernisation Modernising PKI through a PKIaaS model doesn’t have to be difficult. With a clear and phased approach, most organisations can transition smoothly while reducing risk and improving efficiency. It starts with a quick assessment of current certificate usage to understand where certificates are issued, how they’re renewed and any gaps in coverage. From there, it's about defining what you need and selecting a trusted partner. Look for a solution that integrates well with your existing systems, supports automation and scales as your needs grow. In terms of partners, not all PKIaaS vendors are the same. Look for one with a strong security track record and predictable pricing, which will simplify both onboarding and long-term management. When it comes to vetting vendors, ask the following questions: Is the solution scalable? The trend toward future-proof installations has never been greater. As the number of certificates increases, any PKIaaS solution must be able to grow in concert. How will pricing change as certificate volume grows? Some solutions are priced in tiers by the number of certificates. If a company exceeds that maximum by even a single certificate, it owes not only the price difference between tiers, but it will also be expected to pay for that tier the following year, which can bring a significant financial surprise. How are CAs accessed and stored? Look for companies that can provide long-term offline secure storage of certificates that can also track when CA keys are accessed. What support is included in the PKIaaS? Specifically ask vendors about up-front costs for implementation and onboarding to get a real apples-to-apples comparison among partners. Step-by-step replacement of manual processes A pragmatic approach allows corps to move quickly and confidently from legacy PKI to a scalable Once a vendor in place, start with a focused rollout, e.g., automating certificate renewals for internal systems or a specific business unit. Once the pilot is complete, expand automation with a step-by-step replacement of manual processes to limit operational disruptions. Finally, as PKIaaS becomes embedded in day-to-day operations, it’s important to align it with broader security governance. Establishing regular reporting and clear policies, as well as future-proofing for quantum-safe cryptography to ensure long-term resilience and compliance without adding complexity. This phased, pragmatic approach allows organisations to move quickly and confidently from legacy PKI to a scalable, secure and future-ready solution. A necessary upgrade According to an analyst report, manual certificate management can cost organisations up to $2.5 million annually in labour and outage-related expenses. While automation reduces these costs by up to 65%, the real challenge in IoT environments lies in managing scale. With device lifecycles often spanning decades and certificate volumes reaching millions — especially across distributed, resource-constrained endpoints — manual PKI processes and legacy infrastructure simply can't keep up. The convergence of regulatory mandates, quantum computing threats and rising cyber risks to connected physical systems makes scalable, cloud-based PKIaaS not just a strategic advantage, but a foundational requirement for secure IoT deployments.

Scalable security storage: From SD cards to hybrid cloud solutions
Scalable security storage: From SD cards to hybrid cloud solutions

Where and how to store security camera footage usually depends on the scale of the video surveillance project, the way you are using to record the video and how long you want to keep the recordings. If there are only few IP cameras, say 2~3 IP cameras for example, and you don’t need to keep the recordings for the month, usually using SD card which is installed in the camera is enough. Video management software A VMS provides a unified platform to manage all cameras and record footage onto centralised local storage servers If there are more than four cameras, even up to 128 cameras, NVR or CVR become the practical choice for managing and storing recordings reliably. However, if there are hundreds or thousands cameras, which need to managed and recorded, in this way video management software with centralised recording storage becomes essential. A VMS provides a unified platform to manage all cameras and record footage onto centralised local storage servers. S3-compatible cloud platforms Critically, if the VMS supports the S3 object storage protocol, users gain the flexibility to store recordings on S3-compatible cloud platforms (public or private), offering significant hardware cost savings and enhanced scalability. For such demanding environments, selecting a VMS built on an open platform architecture is strongly advised, ensuring the system can expand infinitely to meet future project growth. Video surveillance management system Users can seamlessly add subordinate servers (or disk groups like IPSAN/NAS), disk arrays, and network bandwidth Take the video surveillance management system SVMS Pro as an example. Its foundation is an open 1+N stackable architecture, enabling unlimited expansion of recording storage servers. Users can seamlessly add subordinate servers (or disk groups like IPSAN/NAS), disk arrays, and network bandwidth.  This achieves extended recording durations and boosted storage performance while maintaining system stability during sustained operation (assuming environmental requirements are met). Key architectural advantages Each centralised storage module based on a Linux OS, supports up to 200 front-end video channels per server. Its N+1 stackable expansion capability utilises a distributed architecture, forming clusters of storage servers. Scaling the project involves simply adding subordinate storage modules – no modifications to existing deployments are required. Seamless S3 object storage integration Furthermore, SVMS Pro features deep integration of the S3 object storage protocol Furthermore, SVMS Pro features deep integration of the S3 object storage protocol. This allows seamless connection to major public cloud services like Alibaba Cloud OSS, Tencent Cloud COS, and Amazon S3 cloud, as well as private S3-compatible object storage solutions. This integration delivers truly limitless capacity expansion, leveraging the inherent elasticity of the cloud to effortlessly accommodate petabyte-scale video growth. Dual insurance: Multi-layered data protection The critical value of security data comes with inherent risks; losing video footage can lead to immeasurable losses. To mitigate these risks comprehensively, SVMS Pro innovates with its "Local + Cloud" Dual-Backup mechanism, leveraging S3 features to build multiple security layers: Real-Time Dual-Writing: Recordings are first written to the local disk (acting as a cache buffer). Upon local persistence, data is simultaneously replicated to cloud-based S3 storage, guaranteeing instant failover if either node fails. Smart Hot/Cold Tiering: Frequently accessed ("hot") data remains on high-performance local storage, while historical footage is automatically archived to low-cost cloud tiers, optimising storage expenses. Cross-Regional Disaster Recovery: Utilising the multi-replica and cross-region replication features of carrier-grade S3 storage inherently protects against physical disasters like earthquakes or fires. Additionally, the platform ensures comprehensive data protection through integrity verification and encrypted transmission, safeguarding data integrity and confidentiality across its entire lifecycle – from storage and transmission to access. Conclusion In essence, selecting the optimal storage solution for security footage hinges on a fundamental understanding of scalability requirements, retention needs, and data protection imperatives. As surveillance deployments grow from a few cameras to enterprise-scale systems, the underlying architecture must evolve: Localised storage (SD cards/NVRs) suffices for limited scope and short retention. Centralised VMS platforms become essential for unified management at scale, with open, modular architectures providing critical future-proofing for expansion. S3 object storage integration represents a paradigm shift, decoupling storage capacity from physical hardware and enabling truly elastic, cost-efficient scaling – both on-premises and in the cloud. Ultimately, successful large-scale video surveillance storage relies on architecting for flexibility, embedding data protection intrinsically, and strategically leveraging object storage protocols to balance performance, cost, and resilience – principles essential for safeguarding critical security data now and in the future.

Beyond the cloud: How Edge AI and containerisation will reshape physical security
Beyond the cloud: How Edge AI and containerisation will reshape physical security

The physical security industry has been in love with the cloud for quite some time. And understandably so. The promise of instant scalability, centralised access, and simplified maintenance is hard to ignore, especially in an era of remote work and distributed facilities. But reality is catching up to the hype. For many, especially those dealing with video surveillance at scale, the cloud is no longer the catch-all solution it once seemed. Rising costs, bandwidth limitations, and latency issues are exposing its shortcomings. And the more resolution increases, from HD to 4K and beyond, the heavier that burden becomes. Modern security cameras This is where edge computing, specifically AI-enabled edge processing available in modern security cameras, starts to look less like an option and more like a necessity. But it’s not just about adding intelligence to cameras. It’s about how that intelligence is deployed, scaled, and maintained. This leads us to containerisation and tools such as Docker, which are a revolutionary piece of the puzzle. When cloud isn't enough Cloud analytics for video sounds great in theory: stream everything to the cloud Let’s start with a basic issue. Cloud analytics for video sounds great in theory: stream everything to the cloud, let powerful servers do the thinking, then serve up results to end-users in real time. However, in practice, this model can break down quickly for many end-users. Raw video is heavy. A single 4K camera streaming 24/7 can generate terabytes of data per month. Multiply that by hundreds or thousands of cameras, and the bandwidth and storage costs become unsustainable. Then there’s latency. If AI needs to detect a person entering a restricted area or identify a licence plate in motion, seconds count. Routing video to a cloud server for analysis and waiting for a response can introduce delays. Adding in concerns about uptime, such as what happens if the internet connection goes down, it becomes clear why relying exclusively on the cloud creates friction for mission-critical deployments. The edge advantage Edge processing turns that model on its head. Instead of sending everything out for analysis, edge-enabled cameras do the heavy lifting on-site. AI algorithms run directly on the device, interpreting what they see in real time. They generate metadata—lightweight descriptions of events, objects, or behaviors—rather than raw video. This metadata can be used to trigger alerts, inform decisions, or guide further review. The benefits are obvious: latency drops, bandwidth use plummets, and storage becomes more efficient. Edge processing solves many cloud deployment issues by keeping the compute where the data is generated, on the device. This frees the cloud up to do what it’s best at: providing scalable and centralised access to important footage. But where does the edge go from here? How do we evolve these powerful IoT devices to deliver even more situational awareness? Enter Docker: An app store for Edge AI They package an app along with everything it needs to run: the code, settings, libraries, and tools This is where the concept of containerisation and open development platforms like Docker comes in. Let’s start with an analogy that is helpful for understanding containers. Imagine you're getting ready for a trip. Rather than hoping your hotel has everything you need, you pack a suitcase with all your essentials: clothes, toiletries, chargers, maybe even snacks.  When you arrive at your destination, you open the suitcase and you’re ready to go. You don’t need to borrow anything or adjust to whatever the hotel has, since you’ve brought your own reliable setup. Containers in software work the same way. They package an app along with everything it needs to run: the code, settings, libraries, and tools. This means the application behaves exactly the same, whether it’s running on a developer’s laptop, on the edge in an IoT device, or in the cloud. Security camera with a powerful edge processor There’s no last-minute scrambling to make it compatible with the environment it lands in, because it’s self-contained, portable, and consistent. Just like a well-packed suitcase simplifies travel, containers simplify software deployment. They make applications faster to start, easier to manage, and more predictable, no matter where they’re used.  For a security camera with a powerful edge processor, it’s like giving the camera its own specialised toolkit that can be swapped out or upgraded without touching the rest of the system. It also means you can run multiple AI applications on a single camera, each in its own isolated environment. Integrators and end-users These applications don’t interfere with each other and can be updated independently Want to add fall detection to a healthcare facility’s camera network? Just deploy the analytics in a container. Need to monitor loading docks for pallet counts at a warehouse? Spin up a different container. These applications don’t interfere with each other and can be updated independently.  As a developer, if you use an open container platform like Docker, any system that supports Docker can utilise your software. This removes the need to do expensive custom work for each partner and ecosystem. This is one reason Docker containers are tried and true in the larger IT space and are just starting to get traction in the security sector. Docker also makes this scalable. Developers can build AI tools once and push them out to hundreds or thousands of devices. Integrators and end-users can customise deployments without being locked into proprietary ecosystems. And because containers isolate applications from core system functions, security risks are minimised. Metadata, not megabytes Traditional video analytics systems often require full video streams to be processed One of the most underappreciated aspects of this method is the way it redefines data flow. Traditional video analytics systems often require full video streams to be processed in centralised servers, either on-premises or in the cloud. This model is brittle and costly, and it’s also unnecessary. Most of the time, users aren’t interested in every frame. They’re looking for specific events. Edge AI enables cameras to generate metadata about what they see: “Vehicle detected at 4:02 PM,” “Person loitering at entrance,” “Package removed from shelf.” This metadata can be transmitted instantly with minimal bandwidth. Video can still be recorded locally or in the cloud, but only accessed when needed. This dramatically reduces network load and allows the cloud to be used more strategically: for remote access, long-term archiving, or large-scale data aggregation, without being overwhelmed by volume. Building smarter systems, together A single camera can run analytics from multiple third parties, all within a secure, containerised framework An equally important aspect of containerisation is how it opens up the ecosystem. Traditional security systems are often built as closed solutions. Everything—from the cameras to the software to the analytics—comes from a single vendor. While this simplifies procurement, it limits innovation and flexibility. Docker flips that model. Because it’s an open, well-established standard, developers from any background can create applications for edge devices. Integrators can mix and match tools to meet unique customer needs. A single camera can run analytics from multiple third parties, all within a secure, containerised framework. This is a profound shift. Security cameras stop being fixed-function appliances and become software-defined platforms. And like any good platform, their value increases with the range of tools available. Hybrid: The realistic future So, where does this leave the cloud? It is still essential, but in a more specialised role. The most robust, future-proof architectures will be hybrid: edge-first and cloud-supported. Real-time detection and decision-making happen locally, where speed and uptime matter most. The cloud handles oversight, coordination, and data warehousing. Real-time detection and decision-making happen locally, where speed and uptime matter most This hybrid model is especially useful for organisations with complex deployments. A manufacturing plant might retain video locally for 30 days but push older footage to the cloud to meet retention requirements. A retail chain might analyse customer flow on-site but aggregate trend data in the cloud for HQ-level insight. Hybrid gives organisations the flexibility to optimise cost, compliance, and performance. Regulatory realities It’s also worth noting that not every organisation can, or should, store data in the cloud. Privacy regulations like GDPR in Europe or similar laws elsewhere require strict control over where data is stored. In many cases, sensitive footage must remain in-country. Edge and hybrid models can make compliance easier by minimising unnecessary data movement. Conclusion: Smart security starts at the edge The next wave of innovation in physical security won’t come from bigger cloud servers or faster internet connections. It will come from smarter edge devices, with cameras and sensors that don’t just record, but understand and classify events. And the foundation for that intelligence isn’t just AI, but how that AI is deployed. Containerisation via platforms like Docker is unlocking new levels of flexibility, security, and scalability for the physical security industry. By embracing open standards, supporting modular applications, and rethinking how data flows through the system, physical security professionals can build solutions that are not only more effective but also more sustainable, secure, and adaptable. The cloud still has its place. But the edge is essential to the future for real-time intelligence, mission-critical uptime, and cost-effective deployment.

View all

Security beat

GSX 2025 highlights security's rapid shift to smart solutions
GSX 2025 highlights security's rapid shift to smart solutions

There was high-level energy at GSX 2025, befitting an industry undergoing massive change. Artificial intelligence (AI) was everywhere, but not so much in the booth signage. Rather, AI has made its way beyond marketing claims and solidly into the core of the products themselves. There were hundreds of examples of how AI is changing how security systems operate, all for the better. Clearly on display at GSX 2025 was an industry in the midst of metamorphosis.  Deep integration of AI My conversations with companies across the security ecosystem revealed an industry heavily focused on leveraging advanced technologies like AI and the cloud to address increasingly complex global and localised threats. Several key themes emerged at the Global Security Exchange (GSX), sponsored by ASIS International, held Sept. 29–Oct. 1 at the Ernest N. Morial Convention Centre in New Orleans, La. Themes I heard repeated throughout the show floor included deep integration of AI, the ongoing shift toward cloud-based and hybrid architectures, and a sharp focus on modernising security systems to meet current challenges. AI and intelligent automation transform security The use of GenAI is moving beyond simple search functions into real-time decision support Companies are integrating AI and intelligent technologies to enhance analytics, streamline incident response, and improve internal efficiency. The use of Generative AI (GenAI) is moving beyond simple search functions into real-time decision support. For example, Bosch Video Systems introduced a "second tier" to its video analytics capabilities by combining highly sensitive edge detection with GenAI models in the cloud. For example, in visual gun detection, edge analytics might flag a potential gun (yellow), but the cloud-based GenAI then quickly reviews and confirms the threat (red), helping to filter out false alarms. Bosch is also using GenAI for more open-ended searches, such as a "Where's Waldo" application demonstrated at their booth. GenAI-powered system  Eagle Eye Networks says they are focused on helping integrators "organise the AI chaos” through their cloud-based video platform. Their precision person and vehicle detection capabilities work across multiple cameras. Motorola Solutions introduced Inform, an AI-assisted incident response solution designed to bring clarity to the "noise" and help security teams respond to complex threats. They also offer Avigilon Visual Alerts, an on-prem GenAI-powered system that expands the natural language interface. AI internally to improve processes The Body Workforce Mini protects frontline workers and businesses "amid rising violence and theft." The Axon Body Workforce Mini, a small “computer with a lens” for non-police applications, is AI-capable and can perform real-time translations, automated report writing, and summarisation, and can even act as a personal assistant by incorporating company policies. All those functions are built into a lightweight body-worn camera designed to safeguard frontline workers in retail and healthcare verticals. The Body Workforce Mini protects frontline workers and businesses "amid rising violence and theft." Beyond products, integration company Everon is using AI internally to improve processes, such as handling commoditised tasks, which they expect will result in better customer satisfaction. Everon wants to be known as a premier service provider and will be introducing new services in the video realm. AI-powered search and continuous system upgrades Genetec prefers the term Intelligent Automation (IA), instead of AI, to describe its empathetic interface, which can "know" what additional information a security professional needs when they click on an image, for example. Genetec says the advantages of the cloud include AI-powered search and continuous system upgrades. Their Security Centre SaaS has had a fast and successful launch. It enables cloud-based systems with local storage.  Genetec also highlighted the Cloudlink 210, a cloud-managed appliance designed to unify physical security operations that can be simply plugged in without involving IT staff. They call it a “headless appliance.” Cloud migration and the push for hybrid systems Hanwha debuted OnCAFE (Cloud Access for Everyone), a new cloud-based access control product The industry continues its strategic march toward the cloud, often through hybrid applications that blend on-prem strength with cloud flexibility. Acre's access control is described as "cloud-first technology," and they continue to focus on cloud solutions, incorporating AI. To help customers transition, they offer the "Bridge," a migration tool that allows systems to communicate throughout the move. At the same time, they are continuing to develop and enhance their core on-prem products – DNA Fusion and AccessIt!. Adding access control to supplement their video product line, Hanwha debuted OnCAFE (Cloud Access for Everyone), a new cloud-based access control product. The goal is to provide “access control that is easy;” It works alongside their OnCloud direct-to-cloud VMS as a Service platform. Future of video management The future of video management is increasingly hybrid. Milestone recently completed a three-year process of updating XProtect and building for the future of hybrid applications. At GSX, they showcased how their XProtect Evidence Manager seeks to "democratise evidence management" by collecting video, cell phone data, notes, and other metadata related to a case for easy sharing and prosecution. Also, Milestone’s “app centre” enables additional features to enhance XProtect without involving integration.  Milestone is also focusing on "Metadata Ingest," which collects and aggregates data from various manufacturers (including Genetec, Motorola, and Exacq) for use by AI. Strategic modernisation and open integration Convergint and Genetec collaborated on a "2026 Technology Modernisation Outlook" white paper A key theme for the future is the shift toward open systems and strategic modernisation, enabling security professionals to better utilise new technology. Convergint and Genetec collaborated on a "2026 Technology Modernisation Outlook" white paper, arguing that dealers and end-users need to think more strategically when buying technology. They predict that "2026 will be the year of modernisation," with tangible results including unified intelligence, flexible deployment, and lower total cost of ownership. The call for open standards and architecture was also strong. What AI needs from open systems Johnson Controls noted that cloud, AI, and open standards are its three big focus areas. Their C-CURE IQ 3.10 is gaining adoption as it unifies access and video. OpenEye is seeking to address the "AI disruption anxiety" in the industry, focusing on what AI needs from open systems. The emphasis is on the value of a Model Context Protocol (MCP), an open standard and framework to enable AI systems to integrate and share data with external tools and sources. Addressing shifting global and local threats Allied Universal's "World Security Report 2025" highlights a risen focus on executive protection Companies unveiled solutions targeted at new security concerns, particularly the rising threat of violence, theft, and misinformation. Allied Universal's "World Security Report 2025" highlights an increased focus on executive protection and cites the rise of misinformation and disinformation as the number two threat. They noted that macro trends around instability and the political and social environment are driving security threats globally. To combat physical threats, Shooter Detection Systems introduced a new outdoor sensor, which is now generally available after a favourable feedback period that included an apprehension in one municipality. The company notes the unique challenge of developing technology for a "non-cooperative" threat like a person with a gun, in contrast to most security technologies that are "cooperative" and depend on user compliance. Implementation of integrated security Flock Safety is expanding its focus beyond licence plate readers into solutions for retail, with a new initiative to automate and streamline investigative processes, which are often manual. The company also showcased "drones as automated security guards," which can be deployed within 90 seconds to provide "eyes" on a site and enhance safety. The system works on its own network and is firewalled away from the city system A tour of the City of New Orleans' Real Time Crime Centre (RTCC), hosted by Axis Communications, demonstrated a mature implementation of integrated security. The RTCC uses Axis cameras, Genetec VMS, and is tied to a Motorola Solutions Command Centre to enhance efficiency and effectiveness, operating independently of the police department. They measure success in terms of valuable hours saved in an investigation or even when an event is happening. The system works on its own network and is firewalled away from the city system. Rapidly changing industry on display The GSX 2025 highlights an industry that is moving toward more intelligent and integrated solutions. The investment in AI is shifting security from reactive monitoring to proactive, automated assistance. Throughout the show floor, the continued embrace of hybrid cloud architectures, coupled with an emphasis on open standards and modernisation roadmaps, suggests a security ecosystem built for agility and future growth.  These trends, and the GSX show itself, collectively underscore the industry's commitment to delivering scalable, next-generation solutions for a changing threat landscape.

HID highlights digital transformation, futureproofing among access trends
HID highlights digital transformation, futureproofing among access trends

Multiple technology trends are transforming the physical access control market. There is a fundamental shift away from physical cards and keys toward digital identities — mobile credentials, digital wallets, biometrics, and cloud-native access platforms. These next generation access solutions are radically reshaping how buildings operate, protect staff, and perform functionally. At the same time, AI and analytics solutions are being layered onto these physical access control systems to support predictive threat detection and behavioural insights. Access data itself is becoming an asset for sustainability, space optimisation, and smart building initiatives. Risk, impact operations and experience The annual HID Global Security and Identity Trends Report highlights these and other issues The annual HID Global Security and Identity Trends Report highlights these and other issues. The survey cites improving user convenience as a priority for nearly half of organisations, while 41% are focused on simplifying administration, and 28% struggle with system integration. These are not theoretical challenges, they are day‑to‑day friction points that add cost, increase risk, impact operations and experience, and, of course, must be addressed. HID Global’s commercial focus HID Global’s commercial focus is to help organisations digitise their access control — with mobile identities, biometrics, and cloud platforms — and then to use the data to deliver more value. “We are turning access control from an operational cost into a software-driven asset that improves efficiency, supports Environmental, Social, and Governance (ESG) goals and even creates new revenue opportunities,” says Steven Commander, HID Global’s Head of Consultant Relations. The impact of digital transformation Digital transformation is the method of moving access control from hardware and physical credentials Digital transformation is in the process of moving access control from hardware and physical credentials to a software-driven, integrated experience. The transformation strengthens security while also improving user convenience — transforming the “pavement to the desk” journey. HID enables this shift through mobile credentials, biometrics, cloud-native platforms, and solutions that allow third-party applications to run on door hardware. “This helps customers turn access data into operational and commercial outcomes, while also improving the overall user experience,” says Commander.  Digital transformation in access control is not focused on chasing the latest trends. Rather, transformation is about turning software, data and integration into outcomes that matter to customers, says HID. “Security becomes stronger and more adaptive,” says Commander. “Operations become simpler and more cost‑effective. Experiences become seamless and consistent. Sustainability moves from ambition to action. And the financial case becomes clearer as efficiencies are banked and new value streams emerge.” The challenge of futureproofing with long lifecycles Given that physical security technologies will be in place for 15 to 20 years, it is important to plan for how systems can evolve over time. Considering how rapidly security threats, compliance standards, and user expectations change, 15 to 20 years is a long time. The decisions made at the beginning of a system’s lifecycle can either limit flexibility later (which will be costly) or enable long-term adaptability. Support for open standards such as Open Supervised Device Protocol (OSDP) is therefore important Choosing products and platforms that are open, interoperable, and designed for updates can enable future-proof projects. Support for open standards such as Open Supervised Device Protocol (OSDP) is therefore important.  In addition, systems built on open controller platforms — such as Mercury — enable organisations to switch software providers or expand functionality without replacing core door hardware. Architectural openness is key to system lifecycles and maximising the return on investment (ROI) from a chosen solution. Digital credentials and mobile access Flexibility and upgradeability should also be top of mind when it comes to endpoints like access control readers. While RFID cards are still commonplace, there is a clear trend toward digital credentials and mobile access. Readers that support both allow organisations to transition at their own pace, without committing to a full system overhaul. A long system lifecycle does not mean technology should remain static. Security, particularly cybersecurity, demands more frequent updates. Technologies that support firmware upgrades in the field extend the value of a deployment while helping organisations keep pace with emerging threats. In that sense, lifecycle thinking is not just about longevity — it’s about maintaining resilience and readiness over time. Applying biometrics and mobile identities Biometrics is becoming mainstream as a credential alternative, strengthening security without adding friction Biometrics is becoming mainstream as a credential alternative, strengthening security without adding friction. Many organisations are now deploying biometrics to support fast, seamless access journeys, with adoption already around 39% in access control according to HID’s recent research.  In addition, 80% of organisations surveyed expect to deploy mobile identities within the next five years. Full technology integration enables tap‑to‑access without opening an app; the user journey becomes faster, safer, and more convenient. “It is where the industry is headed and we are at the vanguard of this,” says Commander.    Ongoing challenge of cybersecurity At HID Global, cybersecurity is embedded into everything, from corporate processes and development practices to the solutions they bring to market. “Our approach ensures that customers can strengthen their overall security posture, not only by deploying secure products but by benefitting from HID’s commitment to the highest industry standards,” says Commander. HID holds multiple globally recognised certifications, including ISO 27001, ISO 14298, SOC Type 2 and CSA STAR, which demonstrate their robust information security and cloud security practices. In addition, HID’s SEOS® secure chipset is independently SEAL-certified, providing one of the most advanced levels of protection available on the market today. “Ultimately, this means organisations are not just purchasing isolated secure products; they are implementing solutions developed and delivered within a comprehensive, cybersecure framework,” says Commander. “When deployed according to best practices, HID solutions enable customers to achieve the highest levels of resilience against evolving physical and cyber threats.” Developing green and sustainable solutions A huge amount of waste is generated from the manufacture of plastic RFID access cards Digital credentials align with the sustainable solutions that everyone wants. A huge amount of waste is generated from the manufacture of plastic RFID access cards. Over 550 million access cards are sold annually. This creates 2,700 tons of plastic waste and 11,400 tons of carbon, based on a PVC card weighing 5 grams.  Therefore, digital credentials self-evidently reduce the reliance on plastic cards (helping reduce carbon emissions by up to 75% according to HID’s research), while leveraging access control system data supports energy optimisation by shutting down or reducing systems in unused spaces. Energy use and CO₂ emissions can be cut dramatically, showing how access systems can contribute to sustainability goals and green building certification. What is the latest in smart buildings? Smart buildings increasingly rely on mobile access control as the backbone for digital services. Real-time access data enables new services such as automated room bookings, HVAC control, lift/elevator calling, e-bike hiring, and so on. Smart buildings increasingly rely on mobile access control as the backbone for digital services The financial upside is clear; smart, digitally transformed buildings can deliver around 8% higher yields per square foot versus traditional office space. Operational savings accrue from reduced administration, the removal of card production and shipping, and lighter IT support. This creates a value cycle — better experiences drive adoption, adoption fuels monetisation, and monetisation funds further improvements. Achieving technology impact in the real world One standout project is One Bangkok – a $3.9 billion mixed used development in Thailand – which demonstrates the scale of what can be achieved when access control data is used for optimisation, particularly when it comes to monitoring facilities usage and occupier behaviours. By switching lights off or lowering the temperature in unused rooms, for example, the One Bangkok building demonstrates this potential with a 22% reduction in energy consumption, saving 17,000 MWh and 9,000 tons of CO₂ annually.  Sustainability is a key factor in contributing to how properties are valued. And sustainability extends far beyond digital credentials having a lower environmental impact than plastic cards.  Buildings with recognised sustainability certifications often command rental premiums of around 6%, and three‑quarters of security decision‑makers now consider environmental impact in their procurement assessments.

ISC West update: New SoCs inside cameras drive intelligence at the edge
ISC West update: New SoCs inside cameras drive intelligence at the edge

For all the emphasis on cloud systems and centralised servers at ISC West, a lot of innovation in security video systems is happening at the edge. New advancements inside video cameras are boosting capabilities at the edge, from advancements in processing power to artificial intelligence (AI) and machine learning (ML) algorithms that can now be deployed directly on the cameras or edge devices. Advancements in AI algorithms The progress of video systems becoming smarter at the edge is driven by the need for real-time insights, lower latency, bandwidth efficiency, enhanced privacy, and improved reliability.  Advancements in edge computing hardware and AI algorithms are enabling a range of intelligent video applications across various industries, including physical security. Smarter functionality at the edge is a benefit of new computer systems-on-chips (SoCs) that are driving new heights of performance for today’s cameras.  Axis Communications’ ARTPEC-9   Axis Communications’ new ARTPEC-9 SoC offers advanced video compression to reduce bandwidth Axis Communication’s new ARTPEC-9 system-on-chip (SoC) offers advanced video compression to reduce bandwidth and storage needs. With a low bitrate, the SoC helps deliver high-quality imaging with outstanding forensic detail. ARTPEC-9 also offers enhanced deep learning capabilities to allow users to leverage the latest video analytics and accelerate the implementation of AI technology. Axis maintains control over all aspects of the chip’s development to ensure high quality and cybersecurity. Among the benefits of ARTPEC-9 are better AI and deep learning, better image quality, better cybersecurity, and AV1 license-free video compression (see below). Hanwha Vision’s Wisenet 9 Hanwha Vision has launched Wisenet 9, its most advanced AI-powered System on Chip (SoC). Wisenet 9’s enhanced edge AI capabilities increase performance as the volume and complexity of security threats demand real-time, accurate analysis. By elevating edge-device performance, AI empowers systems to quickly analyse vast amounts of video data and discern crucial patterns and anomalies. A key differentiator driving Wisenet 9 is deployment of two Neural Processing Units (NPUs), which improve performance three-fold compared to Wisenet 7, the previous SoC generation. While one NPU handles image processing, the other focuses on object detection and advanced analytics. This dual NPU concept was introduced to ensure video quality and analytics have independent resources, thus preventing one function from impacting the performance of the other. The latest from Ambarella Ambarella is a supplier of edge AI systems-on-chips to multiple video camera manufacturers Off the ISC West trade show floor in a nearby meeting room, semiconductor company Ambarella demonstrated how it will continue to push the envelope of what is possible with generative AI at the edge. Ambarella is a supplier of edge AI systems-on-chips to multiple video camera manufacturers and recently achieved the milestone of 30 million cumulative units shipped. The demonstrations highlight Ambarella’s ability to enable scalable, high-performance reasoning and vision AI applications across its ultra-efficient, edge-inference CVflow 3.0 AI SoC portfolio. The company’s DeepSeek GenAI models run on three different price/performance levels of its SoC portfolio. In addition to advancements in GenAI processing at the edge, Ambarella integrates image processing, encoding and system-level functions into all its AI SoCs. New standard for video encoding: AV1 AV1 compression is a next-generation video coding technology that offers significant improvements in compression efficiency and video quality, especially at lower bitrates. Its royalty-free nature positions it as a crucial codec for the future of internet video. AV1 compression is a next-generation video coding technology. Axis Communication’s ARTPEC-9 chip now supports the AV1 video encoding standard. By embracing this standard, which is new to the physical security market although it was introduced in 2018, Axis sets the stage for AV1 compression to eventually become the industry standard, replacing H.264 and H.265. Network video transmission AV1 is an open-source, license-free coding format designed mainly for efficient network video transmission AV1 is an open-source, license-free coding format designed specifically for efficient network video transmission. It delivers high-quality video at low bitrates, reducing bandwidth consumption and storage costs. The codec was developed by the Alliance for Open Media (AOM), a nonprofit organisation founded in 2015 by Google, Intel, Amazon, Microsoft, Netflix, and Mozilla (among others), to provide open-standard, next-gen video coding technology. AV1 is ideal for cloud solutions—making streaming applications more robust, scalable, and capable of delivering real-time insights. Now the ARTPEC-9 chipset brings these benefits to the surveillance industry, and AV1 is currently supported by AXIS Camera Station. Providers of major video management solutions (VMS) such as Genetec and Milestone will be adding support for AV1, with further developments already underway. More intelligence at the edge Intelligence inside video cameras comes from the processing power and algorithms that enable them to perform tasks beyond simply capturing and recording images. This "intelligence" allows cameras to analyse the video stream in real-time, identify objects, detect events, and make decisions or provide alerts based on what they "see." New and improved SoCs are driving performance improvements at the edge. The increasing power of embedded processors and advancements in AI are continuously expanding the capabilities of intelligent video cameras.

View all

Case studies

RiverSafe boosts financial security with Exabeam
RiverSafe boosts financial security with Exabeam

Working in the heavily regulated and frequently targeted financial services industry, the client (a global financial services group) needed to ensure its cybersecurity posture was extremely robust to protect its infrastructure and customer data from threats. The previous threat detection solution posed challenges, notably with a high volume of false positives. Without a robust SIEM tool and relying on less effective UEBA processes, the team recognised the need to fortify its security framework to align with their stringent standards. Another key area of focus was enhancing visibility within their security infrastructure. The existing setup presented an opportunity for improvement in consolidating monitoring capabilities into a unified interface. Additionally, the team wanted to enhance oversight of active directory actions, specifically addressing enumeration attacks, and monitoring the controlled export of company data by internal users. The solution Brought in to increase visibility and reduce overall risk, RiverSafe suggested they implement Exabeam, which would provide the company with all the best-in-class UEBA tools needed. RiverSafe suggested Exabeam due to the platform’s efficient data processing, simple architecture, scalability, and ease of deployment. The off-the-shelf content within Exabeam’s UEBA dashboards and reporting tools offered another key benefit, giving the security team access to data pre-built models and statistics that would allow them to start monitoring and flagging events immediately. Finally, Exabeam’s smart timeline feature that merges all user activity into one stream would address the visibility issue. Security and monitoring purposes With the client ready to implement, RiverSafe deployed Exabeam on their AWS Environment following best practice guidelines. The team mapped out relevant log sources for the system, and onboarded all data streams, filtering and fine-tuning everything to ensure any information being ingested was relevant for security and monitoring purposes. RiverSafe then developed and deployed use cases scoped out in partnership with the client, helping them to get maximum value from their Exabeam implementation. This documentation included custom roles, models and parses, as well as other quality of life improvements, additional search filters, and guidance on maintenance and monitoring techniques. The outcome The client now has an established monitoring workflow for its security team that’s baked into their day-to-day tasks. The team can monitor the entire environment quickly, and has significantly reduced the time it takes to assess threats like phishing and brute force attacks, and investigate unusual internal behaviours. Following RiverSafe’s advice, the client has been able to scale its Exabeam solution by accessing the right hardware required to run the product efficiently. Data loss and maintaining data integrity Noise from the SIEM has been reduced thanks to the optimisation work conducted on log source onboarding. This has resulted in less complexity, fewer false positives, and easier access to the precise information that the team really needs. The security team now has visibility into email, endpoint, active directory, and web activity, and is able to monitor these frequently targeted areas for suspicious events and behaviour. This visibility now also extends to file activity, protecting the company from potential data loss and maintaining data integrity. Managing security data and identifying trigger points Siloes have been eliminated, with security insights now located in a single repository for maximum perceptibility. From server performance to traffic flows, whatever’s happening across its pan-global regions, the security team know about it. Exabeam has equipped the team with a simpler, more effective way of managing security data and identifying trigger points—resulting in a 30% reduction in time spent on threat hunting.

RiverSafe cuts response time by 8 minutes with Splunk ITSI
RiverSafe cuts response time by 8 minutes with Splunk ITSI

The client, a large telecommunications provider, had teams working across multiple time zones and operated a sprawling and complex IT system. The scale and density of this system made gaining visibility into IT services extremely difficult, leaving the security team blind to what was happening with its IT environment. With little-to-no operations monitoring tools in place to proactively monitor these systems, the team had no visibility on the availability of its IT services or KPIs, such as failure rates, send request times, and response times. This lack of oversight made it difficult for the team to prioritise issues — and nearly impossible for them to find the root cause of any problem. Proactive measures Without the ability to investigate the source of issues, the team was unable to take proactive measures to prevent them from reoccurring, severely impacting service performance. This was not only a problem for IT teams, but also for executives, who lacked the insight into IT business operations that would help them make decisions. The solution The company needed a solution that would map KPIs to critical service components, enabling the operations team to effectively drill down into issues in real time and conduct in-depth investigations to find resolutions. RiverSafe had previously implemented Splunk Enterprise Security for the customer and given the success of the implementation and the positive client feedback on the platform, RiverSafe was again engaged to deploy Splunk’s IT Service Intelligence (ITSI) tool to help it tackle its visibility problem. Data collection metrics Splunk ITSI uses machine learning to analyse existing data and predict future issues. As well as forecasting potential services bottlenecks, it can also troubleshoot problems and help users resolve issues fast. Delivering comprehensive monitoring across the entire IT environment, Splunk ITSI would also give the team full observability of their IT infrastructure. In particular, the engineering team wanted to gather metric data relating to the Kubernetes platform. RiverSafe reconfigured and implemented data collection metrics used elsewhere in the IT environment in Splunk to allow engineers to collate and access this information from different data sources in one place. The outcome: Actionable insights in days, not weeks In less than a week, the RiverSafe team implemented Splunk ITSI and began running monitoring services. With data from existing KPIs already indexed by the Splunk platform, the team are now able to access service insights even faster. These KPIs allow the operations team to identify trends, detect patterns, and proactively address any anomalies that occur before issues arise. Instant visibility with glass table visualisations To enable rapid and proactive issue resolution, RiverSafe implemented custom glass table visualisations in Splunk ITSI. This enables the team to navigate large volumes of data and reduce the time needed to identify and resolve problems. This simple and accessible dashboard gives the team an instant, digestible overview of its web portal performance metrics. These KPIs included the number of open tickets and failed login attempts, memory usage, API call success rates, average response times, and overall health of container services. Event analytics in Splunk ITSI As a result of RiverSafe’s work, the team has been able to centralise events from all its previously siloed solutions into a single interface with Splunk ITSI. The event analytics in Splunk ITSI help to prioritise responses and react more quickly to customers’ infrastructure events, empowering them to provide a better service. This is thanks in part to Splunk ITSI’s ability to identify and filter out false positives from the event management process. Excluding these invalid events reduced the total event volume by 40%, helping operators focus on the events that really matter. With fewer events to process, a single interface to work from, and a streamlined event analytics framework in Splunk ITSI, operators now process events eight minutes faster on average. This boost in efficiency has led to a major improvement in the company’s SLA performance. Best practices for using Splunk ITSI Overall, Splunk ITSI has delivered enhanced operational visibility, meaning the team can locate bottlenecks in workflows quickly and deliver fast recovery and troubleshooting solutions. Along the way, RiverSafe also provided best practices for using Splunk ITSI and recommended the most effective ways to collect data, including proposing an alternative metric type that would save on storage space when collecting logs.

RiverSafe unifies telecom giant's security systems
RiverSafe unifies telecom giant's security systems

In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organisation. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimise operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialised expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organisation. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimise the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.

Cybersecurity enhancements with Exabeam fusion SIEM
Cybersecurity enhancements with Exabeam fusion SIEM

With an extensive network of customers spanning the globe, cybersecurity is a primary concern for our client. Protecting extensive infrastructure and customer data requires a robust cybersecurity posture and effective tools, but the team found its SIEM solution lacking. Flooding its security team with an unmanageable number of false positives, the solution was diverting attention away from genuine threats and leaving them vulnerable. A substandard SIEM solution was not the only security issue. With no UEBA platform in place to help detect insider threats and data breaches, the company was faced with a number of gaps and weak spots in its security infrastructure that needed to be addressed. Three key issues The biggest concerns centred around three key issues: A lack of insider threat detection: Without a UEBA solution, the company had difficulty identifying insider threats and anomalous user behaviour within the network. Time spent on manual investigation: Security analysts spent significant amounts of time manually correlating events and investigating incidents, leading to delays in incident response and inefficient use of resources. Alert fatigue: The company’s existing SIEM solution generated a high volume of alerts, making it challenging for analysts to identify genuine threats among the many false positives. The solution The company engaged with RiverSafe to create a bespoke implementation plan that would address its primary issues and properly secure its digital infrastructure. Working in collaboration with the in-house security team, RiverSafe got to grips with existing infrastructure, gathered requirements and outlined the desired outcomes of the project. With all challenges and end goals collated, the RiverSafe team developed a solution that would meet all requirements and eliminate current security weaknesses. The team suggested Exabeam’s Fusion SIEM platform as it addressed the key concerns: Incident management: Delivering streamlined incident management processes by automating the correlation and enrichment of security events, Fusion SIEM equips analysts with actionable insights and real-time alerts. This improved visibility helps analysts hone in on genuine threats more quickly and reduce response times. Behaviour analytics: Tackling the company’s lack of UEBA issue, Exabeam’s advanced machine learning algorithms were configured to establish baseline behaviour for all users and systems. Any deviation from this baseline alerts analysts, enabling them to investigate anomalous activities and potential security issues, including insider threats. Data integration: The platform was integrated with various data sources, including logs from firewalls, servers, applications, and network devices to ensure comprehensive visibility across the organisation’s infrastructure. The outcome The implementation of Exabeam’s Fusion SIEM solution has yielded significant benefits, including: Enhanced threat detection: Exabeam’s behavioural analytics (AA) and machine learning (ML) capabilities have improved the accuracy of threat detection, enabling analysts to identify and respond to security incidents more effectively. Faster incident response: Exabeam’s automated incident enrichment and real-time alerts are helping the security team to respond to incidents promptly, minimising the impact of potential breaches. Reduced alert fatigue: The platform’s next-generation event analysis capabilities have reduced the number of false positives generated, reducing alert fatigue and giving analysts more time to focus on genuine threats. Improved insider threat detection: With its advanced behaviour analytics, Fusion SIEM is enabling the team to detect insider threats by identifying abnormal user activities and deviations from established behavioural patterns.

View all

Round table discussion

Defining zero trust – and how it impacts physical security
Defining zero trust – and how it impacts physical security

Traditional security models protected a perimeter like a castle moat, assuming anyone inside was safe. Zero trust removes that implicit trust entirely, recognising that threats can exist both outside and inside a facility. Zero trust is a routine and accepted concept in cybersecurity. Given the importance of information technology and the increasing convergence of physical and logical security, the tenet is becoming a dominant principle in physical security, too. We asked our Expert Panel Roundtable: Briefly define zero trust and explain how it impacts physical security.

What is the role of ethical hacking in physical security?
What is the role of ethical hacking in physical security?

In the world of cybersecurity, ethical hacking proactively identifies security vulnerabilities before malicious actors (i.e., unethical hackers) can exploit them. By simulating real-world attacks, organisations can strengthen defences, protect sensitive data, and maintain public trust. In the physical security world, ethical hacking can transform cybersecurity of security systems from a reactive struggle into a strategic safeguard. We asked our Expert Panel Roundtable: What is the role of ethical hacking as it relates to physical security?

Which factors are driving the deployment of cloud-based security?
Which factors are driving the deployment of cloud-based security?

The cloud fundamentally changes how organisations acquire and use technology, offering a powerful mix of financial, operational, and strategic advantages that traditional on-premises infrastructure cannot match. Specific to physical security systems, there are additional advantages transforming how technologies and systems are delivered to customers. We asked our Expert Panel Roundtable: Which factors are driving the deployment of cloud-based systems in physical security?

View all

Products

Avigilon VMA-BLU-8P8 subscription-based cloud service platform for security and surveillance

Avigilon VMA-BLU-8P8 subscription-based cloud service platform for security and surveillance

Avigilon APP-RCK-1100 Mounting rack for A1100

Avigilon APP-RCK-1100 Mounting rack for A1100

Avigilon AACC-PWC-USS Power Cables

Avigilon AACC-PWC-USS Power Cables

Avigilon AACC-DRV-12TB Replacement Drives

Avigilon AACC-DRV-12TB Replacement Drives

Avigilon AACC-DRV-08TB Replacement Drives

Avigilon AACC-DRV-08TB Replacement Drives

Avigilon AACC-DRV-04TB Replacement Drives

Avigilon AACC-DRV-04TB Replacement Drives

Avigilon AACC-DRV-16TB Replacement Drives

Avigilon AACC-DRV-16TB Replacement Drives

Avigilon AACC-DRV-20TB Replacement Drives

Avigilon AACC-DRV-20TB Replacement Drives

Avigilon AACC-PWC-IECS Power Cables

Avigilon AACC-PWC-IECS Power Cables

Avigilon AACC-PWC-UKS Single UK Power Cable

Avigilon AACC-PWC-UKS Single UK Power Cable

Avigilon AACC-PWC-EUS Power Cables

Avigilon AACC-PWC-EUS Power Cables

Avigilon APP-1100-48-BT Alta Workstation Cloud Connectors

Avigilon APP-1100-48-BT Alta Workstation Cloud Connectors

Avigilon APP-200-8-DG Alta Workstation Cloud Connectors

Avigilon APP-200-8-DG Alta Workstation Cloud Connectors

Avigilon APP-800-32-DG Alta Workstation Cloud Connectors

Avigilon APP-800-32-DG Alta Workstation Cloud Connectors

Avigilon APP-200-4-SG Alta Workstation Cloud Connectors

Avigilon APP-200-4-SG Alta Workstation Cloud Connectors

View all

Videos

Insta DomainLink Secret™

Insta DomainLink Secret™

VIVOTEK 25th anniversary: Journey through the lens

VIVOTEK 25th anniversary: Journey through the lens

Is the door security and access control compliant?

Is the door security and access control compliant?

SARISA firing tests

SARISA firing tests

View more

Cloud security: Manufacturers & Suppliers

  • Avigilon Cloud security
  • ASSA ABLOY Cloud security
  • Eagle Eye Networks Cloud security

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cloud security
About this page

In-depth coverage of Cloud security, featuring latest news and company announcements, products and solutions and case studies. Read insightful analysis of product, technology and business trends related to Cloud security from security industry experts and thought leaders.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2026, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Technology's role in securing banks and financial institutions
Technology's role in securing banks and financial institutions
Integrated systems enable critical and compliant security for transportation
Integrated systems enable critical and compliant security for transportation
Modernising physical access control
Modernising physical access control
Minimizing storage, maximizing focus
Minimizing storage, maximizing focus
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec