IP security solutions
Sargent & Greenleaf® (S&G), a global pioneer in high-security locking solutions with more than 168 years of trusted innovation, has announced its official integration into the ASSA ABLOY Group ®, the world’s foremost provider of access solutions. This milestone marks an exciting new chapter for Sargent & Greenleaf, strengthening the company’s ability to serve customers worldwide while building on the legacy, expertise, and customer relationships that have defined...
February 2026, Mayflex, the distributor of Converged IP Solutions, has further strengthened its external security team with the appointment of Dan Miller, who will focus on the London and South-West. Dan joins Mayflex from Veracity, where he served as the Lead UK Systems Sales Manager. He brings extensive experience from across the security sector, having previously worked as a Senior Security Consultant at Westronics Ltd, supporting a wide range of projects and customer requirements. Strong c...
Allied Universal®, the world’s pioneering security and facility services provider, is one of America’s best workplaces for culture, belonging and community according to Newsweek. The news outlet’s 2025 list of America’s Greatest Workplaces for Culture, Belonging & Community features companies that prioritise culture, foster genuine belonging and build strong communities. Newsweek ranking “This honour is a reflection of the workforce we’ve built on t...
RecFaces, a global developer of ready-made facial recognition software solutions, is pleased to announce its participation in Intersec 2026, one of the world’s pioneering security, safety, and fire protection exhibitions. On January 12-14, 2026, visitors will be able to see the latest versions of RecFaces’ flagship products in action at the Dubai World Trade Centre, where the company will join the stand of its long-standing technology partner, Milestone Systems (S1-H24). Video sur...
Artificial Intelligence Technology Solutions, Inc., a pioneer in AI-driven security and productivity solutions, along with its wholly owned subsidiary, Robotic Assistance Devices Group (RAD-G), now announced that RAD-G has begun invoicing monitoring company clients for SARA™, its proprietary agentic AI platform, marking a decisive shift from pilot programs and proof of concept engagements to live, revenue generating deployments across the remote video monitoring sector. Over the past...
In the modern world of intelligent security, AI cameras and processing units (often called "AI boxes" or "AI servers") are transforming surveillance. They can detect specific behaviours — like someone entering a restricted area, loitering, or a vehicle parking illegally — and send immediate alerts. This represents a significant leap from older systems that merely recorded video for later review. However, a common challenge arises when organisations use devices from multiple manufact...
News
AMAG Technology™ is excited to announce that it has achieved the most rigorous National Protective Security Authority (NPSA) accreditation for its Symmetry Enterprise Access Control software, including the M2150 OSDP panels and cabinets. With more than 50 years of developing security solutions in the UK, AMAG’s achievement of full NPSA accreditation is a natural progression. Moving beyond AACS assurance to the complete NPSA framework, including Cyber Assurance of Physical Security Systems (CAPSS) and AACS, these certifications validate that Symmetry Enterprise with the M2150 OSDP meets the UK government’s most advanced requirements for cyber resilience, physical protection, and operational assurance. M2150 OSDP panels and cabinets NPSA accreditation assures critical infrastructure customers that they are choosing a company and solution aligned with the UK’s most stringent security requirements. AMAG recognises these demands and is proud to have earned NPSA accreditation quickly. AMAG is committed to delivering a sustainable solution, and the accreditation will come standard with Symmetry Enterprise Access Control with M2150 OSDP panels and cabinets. The organisation looks forward to partnering with its industry integrators and partners to bring the solution to the market. AMAG’s commitment “Earning NPSA accreditation demonstrates AMAG’s commitment to delivering trusted, future-ready security solutions that meet advanced national standards,” said AMAG Technology Vice President, Technical Services, Ryan Howarth. “Our customers, particularly those in critical infrastructure, government, and enterprise sectors, can operate with confidence knowing that cyber assurance and physical protection are built into the DNA of every Symmetry Enterprise system we deliver.” External and internal access points The NPSA’s CAPSS standard ensures that cyber defense is deeply integrated into every stage of product development and build processes, safeguarding against evolving digital threats. The most stringent level of AACS goes beyond basic perimeter protection, providing advanced assurance that both external and internal access points are secure against insider threats and sophisticated attacks. Highest security benchmarks “For our customers across EMEA and APAC, this accreditation means fewer barriers to deployment and assurance that their Symmetry Enterprise system meets the highest security benchmarks,” said AMAG Technology Director of Sales EMEA & APAC, James Clark. “It’s another example of how AMAG continues to lead by combining innovation with accountability. This is who we are and what we do.” AMAG Technology will offer an NPSA training program for qualified customers.
American Conference Institute (ACI) is pleased to announce the 16th Annual Forum on Global Encryption, AI, Cloud & Cyber Export Controls, returning with its most advanced and globally focused program yet. This year’s conference will bring together top government officials and senior industry leaders from across the technology, aerospace & defense, semiconductor, cloud, and life sciences sectors for critical updates, compliance strategies, and cross-border insights on the rapidly evolving export control landscape. Future of American AI tech exports New for 2026, attendees can take part in virtual pre-conference workshops designed to strengthen their foundation for the main program, including Upgrading Your Encryption & Advanced Tech Export Compliance Framework and A Deep Dive into Global Export Compliance in the Cloud Throughout the two-day forum, participants will hear cutting-edge briefings on digital sovereignty, cloud sovereignty in Europe, the future of American AI tech exports, and the impact of BIS’s proposed Secure Sharing Framework and the ITA’s American AI Exports Program. Sessions will also explore China’s expanding trade control regime, regional updates from India and the Middle East, and the increasing convergence of export, sanctions, tariff, and ICTS regulations. Virtual technology control plan This year features enhanced interactivity, including a hands-on Go/No-Go diversion and re-export tabletop exercise focused on Southeast Asia, deemed export case studies, a virtual technology control plan walkthrough, and hypothetical scenario drills tackling high-stakes AI, cloud, and cyber compliance dilemmas Attendees will have the opportunity to benchmark with compliance pioneers from Intel, Microsoft, SAP, Cisco, Arm, Cloudflare, Marvell Technology, Skydio, NetApp, TE Connectivity, Renesas Electronics, Core42, and other global innovators.
Hikvision, a world-pioneering manufacturer and supplier of security products and solutions that deliver the ideal combination of high performance and extreme value, now announced the release of its HikCentral Lite (HCL) V1.1.2 all-in-one units. Designed for small and mid-sized businesses (SMBs) and the integrators who support them, the new units combine streamlined deployment, expanded free channels, and a unified software foundation for reliable, everyday security. Newly upgraded platform "Our newly upgraded platform redefines SMB security by eliminating the initial software cost, giving integrators an enterprise-grade solution at competitive prices they can deploy quickly,” said John Xiao, Vice President of Marketing, Hikvision USA. “This new release is entirely focused on driving speed and performance for our partners and end-users, ensuring predictable costs and pain-free scaling." LiteVMS RM, G7, and B1U models The LiteVMS RM, G7, and B1U models arrive preconfigured with HCL V1.1.2, giving integrators a ready-to-deploy system that behaves consistently across sites. Each unit includes an Intel® i7 processor, an integrated managed PoE+ switch, hot-swappable drive bays, TPM 2.0 hardware protection, and storage options from 20 TB to 80 TB. This tuned hardware architecture shortens installation time and reduces service calls by providing a predictable, stable starting point for every project. Set of free included channels HCL V1.1.2 expands its set of free included channels and adds powerful built-in capabilities that help teams work faster, including: Unified video and access control in a single interface High-capacity live view and multi-channel playback People counting and scene analytics Person and vehicle classification Smart VCA search for streamlined investigations Mobile app access for remote visibility Hikvision’s streamlined request workflow For customers looking to accelerate search workflows, HCL V1.1.2 integrates seamlessly with AcuSeek NVRs for rapid natural-language video search and on-device retrieval. AcuSearch further enhances precision filtering. Together, these tools give organisations a clear upgrade path as their needs expand while keeping the same familiar HCL platform. Licensing is simplified through Hikvision’s streamlined request workflow for integrators, and a direct purchase portal is available for end users who need quick, frictionless expansion.
Datalogic, a pioneer in automatic data capture and process automation, will demonstrate how its integrated portfolio is empowering the intelligent store at NRF 2026, thanks to AI-driven integration. Visitors to Booth 6128 will discover how advanced scanning, mobile computing, RFID, and IoT solutions are driving measurable outcomes for retailers: better customer loyalty, more revenue, fewer errors, higher labour efficiency, accelerated in-store productivity, and the creation of seamless customer experiences. All within a sustainable ecosystem. World premiere: Joya Smart & Joya Smart+ series NRF 2026 will mark the exclusive debut of Datalogic's Joya Smart and Joya Smart+—the industry's first self-shopping devices with integrated AI technology. These innovative handheld solutions empower shoppers to scan items as they move through the store, monitor their baskets in real time, and complete payment quickly at self-service kiosks or assisted lanes. By combining customer autonomy with intelligent loss prevention capabilities, Joya Smart addresses retailers' most critical operational concerns while delivering an exceptional shopping experience Reducing errors, shrinking, and preventing losses with AI and RFID Datalogic will showcase how artificial intelligence and RFID technologies are able to protect profit margins without compromising checkout speed, especially in the grocery segment. The Magellan® 9600 and 9900i platforms feature AI-based audit rules that help associates identify common fraud patterns—including miss-scans, ticket switching, and item stacking—in real time, ensuring accuracy at every transaction. In non-food applications, the PowerScan™ 9600 RFID solution captures data from both barcodes and RFID tags, providing real-time movement visibility that supports loss prevention and inventory accuracy. This capability is ideal for item-level tracking in sensitive areas such as checkout lanes, exits, and back rooms. Sustainability-driven innovation: Gryphon 4600 Another major premiere at NRF is the groundbreaking Gryphon™ 4600, a next-generation scanning solution designed with sustainability at its core. Combining enterprise-grade performance with eco-design principles, the Gryphon 4600 features optimised electronic architecture, reduced power consumption, recycled components, and minimal packaging—proving that environmental responsibility and operational excellence go hand in hand. Streamlining store operations with mobile computing Datalogic's complete range of mobile computers - such as the Memor PDA series and Skorpio family - will demonstrate how to manage essential store operations—including stock counting, replenishment, order preparation, and shelf verification—smoothly and efficiently. Paired with partner-powered shelf analytics platforms, these solutions ensure on-shelf availability, reduce lost-sale scenarios, and improve task execution across the shop floor through high-performance scanning and intelligent mobile applications. GS1 Digital Link readiness Datalogic's forward-thinking approach to product development ensures that its entire portfolio—Fixed Retail Scanners, Handheld Scanners, and Mobile Computers—reads every type of symbology, including GS1 Digital Link. This capability enables retailers to offer richer product information and easier access to transparency and traceability features directly at checkout, meeting evolving consumer expectations and regulatory requirements. Centralised intelligence with Datalogic Connect Attendees will experience Datalogic Connect live on the show floor—the company's intelligent IoT cloud platform for centralised device fleet management. Datalogic Connect provides comprehensive visibility of deployed devices, remote configuration, firmware updates, diagnostics, and multi-location monitoring across store networks. Beyond device management, the platform delivers dashboards and operational insights that help retailers monitor checkout performance, device status, inventory movements, and loss-prevention events in real time. This intelligent layer enables faster operational response, improved uptime, and more efficient management of the entire retail ecosystem. Empowering the intelligent store "For over 50 years, Datalogic has provided the retail industry with innovative solutions that deliver measurable value," said Rosario Casillo, Data Capture Product and Solutions Executive Vice President. "At NRF 2026, we're demonstrating how the convergence of AI, IoT, RFID, and sustainable design is transforming retail operations—making stores more efficient, secure, and profitable while enhancing the customer experience." By combining advanced scanning, mobile computing, AI-assisted automation, and centralised device management, Datalogic supports retailers in creating intelligent stores that drive results now and adapt to the challenges of tomorrow. Visit Datalogic at NRF 2026, Booth 6128, to experience these technologies firsthand.
The contract was signed, live at the SPS in Nuremberg, Germany: CADENAS is now the newest member of the Eplan Partner Network. CADENAS Managing Director Terry Jonen and Eplan Managing Director Haluk Menderes signed the new technology partnership agreement on 26 November 2025. The stated goal of the cooperation is the expanded provision of technical device data via the Eplan Data Portal, which will be implemented using a direct interface between the Data Portal and the CADENAS platform 3Dfindit. Connectivity to the CADENAS device During the SPS, Eplan and CADENAS signed a groundbreaking technology partnership that will make it easier for Eplan users to find the right device data. “CADENAS is a strong partner who will help us considerably extend the range of device data available on the Eplan Data Portal with additional, validated content,” says Eplan Managing Director Haluk Menderes. “For our customers, this cooperation is significant. The connectivity to the CADENAS device database expands our quite comprehensive selection of device data with completely new, sometimes very complex configuration data – for instance for the energy sector.” Speaking about the newly sealed deal, CADENAS Managing Director Terry Jonen says, “With the planned connection of 3Dfindit to the Eplan Data Portal, we’re making it easier for engineers to access precise, up-to-date product data and are thereby increasing the added value for our common customers.” Focusing on added value for designers Comprehensive digital device data is indispensable for design engineers. It accelerates project planning and increases efficiency in engineering, making invaluable contributions to greater data consistency. To achieve this, the companies will be developing an interface to the CADENAS portal that users will be able to access via the Eplan Data Portal, meaning directly via the Eplan cloud. Eplan and CADENAS will be working closely together to design the interface, and both companies will be engaging in continued dialogue with component manufacturers. The advantages for users at a glance Eplan users benefit from a significantly expanded range of data on offer, for instance, for complex designs Design engineers will have additional options when selecting device data Data consistency throughout the entire engineering process also increases Depth of data and data consistency Now that the agreement has been signed, the technical implementation is getting started. In the coming months, both partners will set up technical working groups to define the specific measures with a view to gradually expanding the cooperation. The goal is to validate added value for common customers along the value chain. This involves various topics and industries, for instance, the energy sector. For Eplan users, this will mean increased depth of data and data consistency.
Building on earlier research published in October 2025, Zimperium announced that its zLabs team has uncovered a significantly enhanced variant of ClayRat, an Android spyware family first detailed in the technical brief “ClayRat: A New Android Spyware Targeting Russia”. While the original ClayRat strain was able to exfiltrate SMS messages, call logs, notifications, device data, take photos, and send mass SMS or place calls, effectively allowing infected devices to become distribution hubs. The newly observed variant demonstrates a substantial escalation in functionality and stealth. The updated strain abuses both Default SMS privileges and Accessibility Services, enabling it to: Capture lock-screen credentials (PIN, password, or pattern) and automatically unlock the device. Record the screen via the MediaProjection API. Present deceptive overlays (for example, fake system-update prompts) to prevent user detection. Programmatically initiate taps — blocking the user from powering down or uninstalling the malicious app. Generate fake or interactive notifications, then intercept and exfiltrate responses. This expanded functionality enables full device takeover, making ClayRat far more dangerous than the version first reported, especially since victims may no longer detect or easily remove the malware. The updated behaviour also increases the risk to corporate endpoints: compromised devices could leak corporate credentials, MFA codes, or sensitive enterprise data through hijacked SMS, notification flows, or screen captures. Reliant on phishing webpages The malware continues to leverage social engineering at scale. As before, ClayRat masquerades as legitimate, widely used applications and services, including major video and messaging platforms, as well as localised or regional services (for example, certain Russian taxi or parking apps). Distribution remains heavily reliant on phishing webpages and sideloaded APKs, including via cloud-storage platforms such as Dropbox. According to zLabs telemetry, more than 700 unique APKs tied to ClayRat have already been identified in a short time window. BYOD environments “ClayRat’s evolution shows exactly why enterprises need protection that works at the device level, not just network-based,” said Vishnu Pratapagiri, lead researcher at zLabs. “By abusing Accessibility Services and overlay tricks, this variant turns Android devices into fully compromised endpoints and conventional defences may not be enough.” As ClayRat continues to evolve, expanding its spyware, remote-control, and lock-screen manipulation capabilities, enterprises should treat this campaign as a critical reminder: mobile devices, especially in BYOD environments, remain among the most vulnerable entry points for attackers. Zimperium continues to monitor ClayRat and share relevant indicators of compromise with industry partners.


Expert commentary
As city managers, law enforcement agencies, and first responders face mounting pressure to combat crime and respond to emergencies with limited resources, real-time crime centres empowered by a new generation of data-driven technologies are emerging as an effective force multiplier. Real-time crime centres Real-time crime centres (RTCCs) serve as centralised hubs where dedicated personnel leverage pioneering-edge technologies to analyse diverse data streams and provide critical support to law enforcement and emergency operations. These 24/7 facilities are transforming how agencies gather, process, and act upon information, enabling more proactive and efficient policing strategies. The core functions of RTCCs These centres provide officers with unprecedented situational awareness and real-time intelligence At their core, RTCCs are tasked with three primary objectives: enhancing safety, facilitating identification, and supporting apprehension. By integrating data from a wide range of data sources, these centres provide officers with unprecedented situational awareness and real-time intelligence. Integrated data approach This integrated data approach allows RTCCs to alert officers to potential threats, quickly identify suspects, and guide responders during critical incidents. For instance, in the event of a robbery, RTCC operators can rapidly search camera and licence plate data to track suspect vehicles, significantly improving the chances of a swift arrest. According to the Bureau of Justice Assistance at the U.S. Department of Justice, the mission of an RTCC is to centralise a broad range of current and evolving technologies, coordinate sworn and non-sworn human resources, and direct the attention to high-crime areas, active crimes in progress, high-profile or highly recidivistic offenders, and large-scale public events that may require law enforcement presence or response. The technology powering RTCCs The effectiveness of an RTCC hinges on its ability to seamlessly integrate a wide array of technologies: Open Platform Video Technology: At the heart of many crime centres is an open platform video management software (VMS) that serves as the central nervous system, unifying diverse data streams into a cohesive operational picture. By leveraging open APIs and SDKs, the VMS can incorporate a wide range of cameras, sensors, and analytics tools. This data-driven approach to video technology enables seamless alert distribution to both the RTCC and field officers via mobile applications. IP Camera Networks: The eyes of an RTCC, these systems combine fixed, PTZ, multi-sensor, thermal, and other specialty cameras to provide continuous city monitoring. Strategically placed throughout urban areas, cameras offer comprehensive coverage of critical locations such as transportation hubs, commercial districts, and high-crime zones. This network forms the foundation for real-time monitoring and incident response. Sensor Arrays: Beyond visual data, RTCCs employ various sensor technologies. Acoustic sensors can detect sounds such as gunshots, shouts for help, breaking glass, and other sounds instantly alerting officers and cueing nearby cameras. Environmental sensors monitor air quality for gasses, smoke, and other non-visible hazards. Licence Plate Recognition (LPR): LPR systems act as a force multiplier, continuously scanning for vehicles of interest. By generating real-time alerts for stolen or wanted vehicles, these systems significantly enhance the ability to track suspects and recover stolen property, contributing to reduced auto theft rates. Aerial Surveillance: Many RTCCs incorporate drone technology, providing on-demand aerial perspectives of developing situations. This capability is particularly valuable for monitoring large-scale events, assessing natural disasters, supporting operations in hard-to-reach areas, and serving as a powerful first response for crime scene situational awareness. AI-Powered Analytics: At the heart of many RTCC operations are sophisticated AI algorithms that analyse video data in real-time. These systems can identify a range of suspicious activities, from unattended packages to unauthorised intrusions. By rapidly processing vast amounts of video data, they help operators focus on potential threats and anomalies. Geospatial Mapping: To make sense of the influx of data, RTCCs rely on advanced mapping software. These tools visualise events, alerts, and data streams geographically, allowing operators to quickly identify patterns, clusters of activity, and relationships between incidents. Database Integration: RTCCs maintain direct connections to various law enforcement databases, including local, state, and federal resources like the National Crime Information centre (NCIC). This integration allows for rapid background checks and threat assessments, providing crucial context for ongoing operations. Cloud Infrastructure: The scalability and flexibility of cloud computing are revolutionising RTCC capabilities. Cloud and hybrid solutions offer secure, off-site storage and facilitate easy data sharing between agencies. This approach not only reduces initial costs but also allows for incremental upgrades, making advanced RTCC functionality accessible even to agencies with limited budgets. Real-world impact RTCC operators tracked shooting suspects via camera feeds, guiding officers to their location The proliferation of RTCCs across the United States with over 80 centres in operation speaks to their proven effectiveness. Cities that have implemented these high-tech command centres are reporting significant improvements in response times, clearance rates, and overall public safety. Real-time surveillance In Winston-Salem, North Carolina, the local RTCC leverages over 1,300 live video feeds to provide real-time surveillance across the city. This extensive network, combined with gunshot detection technology and licence plate readers, has already demonstrated its value. In a recent incident, RTCC operators were able to track shooting suspects via camera feeds, guiding officers to their location for a quick apprehension. Video analysis by RTCC Similarly, Newport News, Virginia, saw an immediate impact after launching its RTCC in 2021. The centre has played a crucial role in solving homicides caught on video and rapidly closing a series of carjacking cases. These success stories underscore the game-changing potential of RTCCs when it comes to solving crimes and gathering evidence. In Memphis, Tennessee, video analysis by RTCC detectives helped identify a shooter in custody following an incident at a community basketball court even when no witnesses had come forward. Identifying suspects with RTCC Officers and analysts can view street and body camera footage to monitor crowds at parades The Jackson Police Department in Mississippi has seen similar benefits since building an RTCC in 2019, part of a broader effort that included deploying 100 cameras and 271 body cams. Officers and analysts can view street and body camera footage to monitor crowds at parades and other events. During pursuits, the cameras provide extra surveillance, allowing officers to identify suspects or witnesses to help solve crimes. Enhancing crime mitigation and emergency response While RTCCs have proven their worth in responding to active incidents, their true potential lies in proactive crime prevention and enhanced emergency preparedness. By leveraging advanced analytics and integrated data sources, RTCCs are evolving into powerful predictive tools for law enforcement. Pattern recognition algorithms For instance, pattern recognition algorithms can analyse historical crime data alongside real-time video feeds to identify potential hotspots for criminal activity. This allows law enforcement to strategically deploy resources, increasing visible presence in high-risk areas before crimes occur. Similarly, anomaly detection systems can alert RTCC operators to unusual behaviors or suspicious activities, enabling early intervention in potentially dangerous situations. Asset and property protection, automated alerts RTCCs can monitor critical infrastructure, government buildings, and other high-value assets 24/7 Asset and property protection is another area where RTCCs excel. By integrating with access control systems and using AI-powered video analytics, RTCCs can monitor critical infrastructure, government buildings, and other high-value assets 24/7. Automated alerts for perimeter breaches, unauthorised access attempts, or suspicious objects left in restricted areas allow for an immediate response, significantly enhancing security postures. Emergency response and preparedness In terms of emergency response and preparedness, RTCCs serve as vital command and coordination centres during crises. Whether facing natural disasters, major accidents, or other large-scale emergencies, RTCCs provide a centralised hub for information gathering and dissemination. Real-time video streams from affected areas, combined with data from environmental sensors and emergency service communications, allow for rapid situational assessment and coordinated response efforts. Post-incident investigation and analysis RTCCs can also play an active role in post-incident investigation and analysis. The ability to quickly compile and analyse vast amounts of data from multiple sources can significantly accelerate case resolution and help identify patterns to prevent future incidents. As RTCCs continue to evolve, their capacity for integrating diverse data streams and leveraging advanced analytics positions them as indispensable tools in modern law enforcement strategy. The future of technology-driven policing The integration of artificial intelligence and machine learning promises to enhance video analytics As RTCCs continue to evolve, they are likely to incorporate even more advanced technologies. The integration of artificial intelligence and machine learning promises to enhance video analytics capabilities, enabling faster and more accurate threat detection. Additionally, the expanding use of drones, subject to FAA regulations, could provide RTCCs with cost-effective aerial surveillance options. Effective and ethical operations However, the implementation of RTCCs is not without challenges. Agencies must navigate issues of privacy, data security, and community trust. Ongoing training for personnel and careful planning is essential to ensure these centres operate effectively and ethically. Data-driven approach Despite these hurdles, the trend toward technology-driven policing shows no signs of slowing. RTCCs represent a shift from reactive to proactive law enforcement strategies, offering a data-driven approach to crime prevention and response. As these centres become more prevalent, they will play an increasingly vital role in helping agencies maximise their resources and make informed decisions, ultimately contributing to safer communities for all.
Security manufacturers throw around the term “scalable” a lot these days, but few dive into what scalable really means for modern organisations and their security programs. Achieving true scalability, or as I like to refer to as “expandable with a purpose,” takes planning and coordination from security pioneers alongside the broader organisation. Implementing a flexible strategy is critically important in the age of advancing analytics and intelligence-driven technology. So what exactly do we mean by “scalable”? "Scalable" refers to the capability of a system, process, or technology to handle growth or increased demand without compromising performance, efficiency, or quality. To put it simply, scalability refers to the ability of a solution to expand or adapt to accommodate larger workloads, higher volumes of data, or increased complexity without requiring significant changes to its underlying architecture or design. It’s not enough to create a “fix it and forget it” security program. Not only do the needs of the organisations shift, but growth (or even shrink) is inevitable. How to Approach Growth Pioneers must be prepared to adapt their strategies and approaches to manage security risks For many security pioneers, growth has a trickle-down effect. Expansion through mergers and acquisitions or organic growth, in addition to decreases in facility or employee count, directly impacts the security program. Whether it’s an increase or decrease in size, workload, or scope, these pioneers must be prepared to adapt their strategies and approaches to efficiently manage security risks while maintaining operational efficiency. Here are some ways security pioneers can approach growth: Assess the here and now: Begin by looking at the current state of your security program, including the resources, capabilities, processes, and technology infrastructure. Understanding existing strengths, weaknesses, and areas for improvement can help inform planning for the future. Align with the business: This might be one of the most important considerations to make, but ensuring security pioneers understand the organisation’s growth objectives, priorities, and risk tolerance levels is critical to the success of a security program. The most successful security pioneers will be able to align security strategies with business goals to ensure security investments and planning are enabling the company’s growth initiatives. Invest in scalable solutions: Invest in solutions that offer flexibility and can adapt to the changing needs of the organisation. Closed systems that can’t integrate fully with new technologies will severely limit the security team’s ability to seamlessly manage the security portfolio. Optimize processes: Reviewing security processes and workflows – or investing in a platform that can streamline this for you – can improve efficiency and effectiveness for your security team. Identifying opportunities for automation and standardisation can allow for scaling as business needs change. Collaborate across departments: Preparing for growth initiatives requires extensive communication across departments, including leadership teams, human resources, legal, IT, facilities, and many other stakeholders ensure that security priorities, challenges, and requirements are effectively communicated and integrated. Adopting these approaches helps put security teams in the driver’s seat, effectively managing periods of growth and change without compromising the safety and security of the organisation. Technology considerations As security pioneers navigate investments in new technologies that achieve some of the approaches listed above, such as aligning strategy with business goals, optimising processes, and cross-departmental collaboration, there are several considerations to make. Looking at how technology can support (or even hinder) future growth. For example, when making a buying decision around access control systems, security pioneers must consider the number of users, number of credentials, server requirements, facilities, hardware end points, and software features. As these items are being addressed in an RFP or in conversations with a vendor, security pioneers must ask themselves, “Is there a scenario where my program will outgrow the system’s capabilities in any of these areas?” If so, the answer might be to select a different solution. Security pioneers must consider interoperability. We talk a little about this above, but the importance here cannot be overstated: integration is key. The ability to leverage multiple point solutions, such as access control systems and video surveillance cameras – regardless of manufacturer – provides growing companies with the ability to scale quickly and more efficiently than ever before. Centralising the ability to pull these solutions into a single security operations management platform allows security pioneers a better view of their security programs in a current – and even future – state. Cloud-based solutions can provide the ultimate scalability factor, providing flexibility and accessibility advantages compared to traditional on-premise systems. Cloud-based, or Software-as-a-Service (SaaS) platforms, can easily scale up or down based on changing needs, accommodate distributed environments, and provide remote access and management capabilities, making them well-suited for scalable physical security deployments. Data-driven insights and analytics can drive decision-making beyond security, making technology investments that provide these critical. Automated workflows, event-triggered alerts, and AI-driven analytics can streamline security processes, improve threat detection capabilities, and reduce manual intervention, enabling security teams to manage larger environments more efficiently. Centralised management of technology investments can create cohesion for security teams. Centralised management and monitoring of physical security systems across multiple locations or facilities enables personnel to efficiently oversee and control security operations, access controls, and incident response activities. Being able to manage security in a single platform provides security pioneers with the ability to assess staffing levels, streamline training, allocate resources effectively, and scale to additional sites and/or solutions as needed. Tasked with building a security program that can adapt to the changing needs of the organisation, security pioneers must consider a number of factors when setting strategy. First and foremost, taking a close look at the existing program to identify strengths and weaknesses, then truly assessing the technology and processes in place, is the best way to move forward and future-proof the organisation.
The days of being reactive are over. That’s right, we as an industry, can no longer afford to be reactive. As threats evolve, the need for proactive security is critical. While traditional methods, including physical barriers and security personnel, are still necessary, the future of our approach is built on the backs of emerging technologies. Substantial vulnerabilities As an industry, we’ve operated reactively for decades, it has been common for security teams to address threats only after they occur. The growing risk landscape proves that this approach has significant limitations. Human oversight, delayed responses, and the inability to monitor large areas have exposed substantial vulnerabilities. Emergence of AI AI enables real-time monitoring, advanced data analysis, and more accurate risk detection Times are changing though and it’s largely due to the emergence of AI. AI is revolutionising the security landscape by making technology smarter. It enables real-time monitoring, advanced data analysis, and more accurate risk detection. This ensures a higher level of security and safety, minimising potential incidents' impact while enhancing overall safety. Focus on strategic aspects AI's ability to process vast amounts of data quickly and accurately is, quite frankly, a game-changer. It can identify patterns and anomalies that can provide stakeholders with critical insights to respond in a more prepared manner. By automating routine tasks and highlighting potential issues, AI also allows operators to focus on more complex and strategic aspects of security management, rather than responding to false alarms. The future is AI The future of security lies in AI. The Security Industry Association (SIA) has recognised AI as one of the top security megatrends in 2024. However, the challenge is not adopting AI, it is about effectively using it to enhance security. AI can enhance video surveillance by improving object detection and enabling real-time, informed responses AI systems can easily integrate with existing infrastructures, providing a layered defence that combines traditional methods with more modern technology. For example, AI can enhance video surveillance by improving object detection, reducing false alarms, and enabling real-time, informed responses. This ensures that security measures are adaptive, scalable, and capable of addressing the evolving risk landscape. Don’t react, anticipate One of AI's most significant benefits is its ability to provide proactive insights. AI can predict potential breaches by analysing behaviour patterns and detecting anomalies allowing security pioneers to do something before an event happens. This shift, from reactive to anticipatory measures, marks a significant advancement in asset protection and risk management. AI systems can also continuously analyse data and distinguish between everyday events and real-world threats. It’s AI's continuous learning capabilities that mean the systems can adapt and improve over time to become more accurate and efficient in threat detection and response. Save money, scale on demand Contrary to common belief, adopting AI technologies will not put a security department over budget. It may be surprising, but these solutions offer cost-effective and scalable alternatives to traditional security measures. An initial investment in AI technology can result in substantial long-term savings (and ROI) by reducing the need for physical infrastructure and on-site security personnel. Customisable solutions The ability to scale and customise AI solutions makes them an efficient choice for enhancing perimeter defence AI systems are also inherently scalable and can be tailored to meet the specific needs of different environments. This ensures the system can evolve with emerging threats and technological advancements without requiring a complete system overhaul. The ability to scale and customise AI solutions makes them a practical and efficient choice for enhancing perimeter defence. How’s that for staying within budget? Embrace the possibilities Integrating AI into perimeter security is the future of proactive and intelligent security. As these technologies continue to evolve, we can expect even more refined solutions that are predictive, autonomous, and capable of directly addressing new and emerging threats. We’re experiencing an exhilarating transformation as AI becomes more trusted, precise, and advanced on multiple levels. This evolution is bigger than pilots and small, low-profile deployments. AI in perimeter security For instance, France is preparing to deploy AI-powered video surveillance as it gears up to host the 2024 Olympics, part of its efforts to detect sudden crowd movements, abandoned objects, and suspicious activities. Think about the sheer scale of that project. We’re finally moving forward, and staying one step ahead must be our priority. But this shift requires a significant change in mindset. Are you ready to make the change?
Security beat
For all the emphasis on cloud systems and centralised servers at ISC West, a lot of innovation in security video systems is happening at the edge. New advancements inside video cameras are boosting capabilities at the edge, from advancements in processing power to artificial intelligence (AI) and machine learning (ML) algorithms that can now be deployed directly on the cameras or edge devices. Advancements in AI algorithms The progress of video systems becoming smarter at the edge is driven by the need for real-time insights, lower latency, bandwidth efficiency, enhanced privacy, and improved reliability. Advancements in edge computing hardware and AI algorithms are enabling a range of intelligent video applications across various industries, including physical security. Smarter functionality at the edge is a benefit of new computer systems-on-chips (SoCs) that are driving new heights of performance for today’s cameras. Axis Communications’ ARTPEC-9 Axis Communications’ new ARTPEC-9 SoC offers advanced video compression to reduce bandwidth Axis Communication’s new ARTPEC-9 system-on-chip (SoC) offers advanced video compression to reduce bandwidth and storage needs. With a low bitrate, the SoC helps deliver high-quality imaging with outstanding forensic detail. ARTPEC-9 also offers enhanced deep learning capabilities to allow users to leverage the latest video analytics and accelerate the implementation of AI technology. Axis maintains control over all aspects of the chip’s development to ensure high quality and cybersecurity. Among the benefits of ARTPEC-9 are better AI and deep learning, better image quality, better cybersecurity, and AV1 license-free video compression (see below). Hanwha Vision’s Wisenet 9 Hanwha Vision has launched Wisenet 9, its most advanced AI-powered System on Chip (SoC). Wisenet 9’s enhanced edge AI capabilities increase performance as the volume and complexity of security threats demand real-time, accurate analysis. By elevating edge-device performance, AI empowers systems to quickly analyse vast amounts of video data and discern crucial patterns and anomalies. A key differentiator driving Wisenet 9 is deployment of two Neural Processing Units (NPUs), which improve performance three-fold compared to Wisenet 7, the previous SoC generation. While one NPU handles image processing, the other focuses on object detection and advanced analytics. This dual NPU concept was introduced to ensure video quality and analytics have independent resources, thus preventing one function from impacting the performance of the other. The latest from Ambarella Ambarella is a supplier of edge AI systems-on-chips to multiple video camera manufacturers Off the ISC West trade show floor in a nearby meeting room, semiconductor company Ambarella demonstrated how it will continue to push the envelope of what is possible with generative AI at the edge. Ambarella is a supplier of edge AI systems-on-chips to multiple video camera manufacturers and recently achieved the milestone of 30 million cumulative units shipped. The demonstrations highlight Ambarella’s ability to enable scalable, high-performance reasoning and vision AI applications across its ultra-efficient, edge-inference CVflow 3.0 AI SoC portfolio. The company’s DeepSeek GenAI models run on three different price/performance levels of its SoC portfolio. In addition to advancements in GenAI processing at the edge, Ambarella integrates image processing, encoding and system-level functions into all its AI SoCs. New standard for video encoding: AV1 AV1 compression is a next-generation video coding technology that offers significant improvements in compression efficiency and video quality, especially at lower bitrates. Its royalty-free nature positions it as a crucial codec for the future of internet video. AV1 compression is a next-generation video coding technology. Axis Communication’s ARTPEC-9 chip now supports the AV1 video encoding standard. By embracing this standard, which is new to the physical security market although it was introduced in 2018, Axis sets the stage for AV1 compression to eventually become the industry standard, replacing H.264 and H.265. Network video transmission AV1 is an open-source, license-free coding format designed mainly for efficient network video transmission AV1 is an open-source, license-free coding format designed specifically for efficient network video transmission. It delivers high-quality video at low bitrates, reducing bandwidth consumption and storage costs. The codec was developed by the Alliance for Open Media (AOM), a nonprofit organisation founded in 2015 by Google, Intel, Amazon, Microsoft, Netflix, and Mozilla (among others), to provide open-standard, next-gen video coding technology. AV1 is ideal for cloud solutions—making streaming applications more robust, scalable, and capable of delivering real-time insights. Now the ARTPEC-9 chipset brings these benefits to the surveillance industry, and AV1 is currently supported by AXIS Camera Station. Providers of major video management solutions (VMS) such as Genetec and Milestone will be adding support for AV1, with further developments already underway. More intelligence at the edge Intelligence inside video cameras comes from the processing power and algorithms that enable them to perform tasks beyond simply capturing and recording images. This "intelligence" allows cameras to analyse the video stream in real-time, identify objects, detect events, and make decisions or provide alerts based on what they "see." New and improved SoCs are driving performance improvements at the edge. The increasing power of embedded processors and advancements in AI are continuously expanding the capabilities of intelligent video cameras.
AI has the potential to enhance the usability of traditionally complex access control and physical security systems. The application of AI (artificial intelligence) within access control is still relatively new, but rapid advancements in generative AI are already transforming how security systems operate. acre security is driving the deployment of generative AI in access control through its acquisition of REKS earlier this year. REKS is a purpose-built generative AI solution designed specifically for acre’s access control platform. Unlike generic AI tools, REKS understands both system and security-specific terminology, allowing users to ask natural-language questions like, “Show me all access denied events at a specific location,” and receive instant results. AI workflows and AI agents “We're starting to see how AI workflows and AI agents, that leverage language models, can potentially be used in conjunction with access control to create new, automated processes around false alarm reduction, system configuration, report generation, data analysis, threat detection, and in-system customer support,” says Adam Groom, Director of Business Development, AI Development Team, acre security. “We expect AI-driven capabilities to evolve rapidly, but the full range of benefits will depend on continued development and real-world application,” he adds. Integrate AI-driven capabilities acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions The best way to think of REKS is as an acre access control expert you can talk to, says Groom. “As AI adoption grows in security, REKS will expand its capabilities, making access control more usable and more efficient.” Groom says acre’s ability to integrate AI-driven capabilities across the company’s product portfolio positions the company as a pioneer in next-generation physical security. “These features will add long-term value by enhancing usability and operational insights across various segments,” says Groom. “Work is already under way to incorporate REKS into acre access control, and we’ll evaluate other integration opportunities in the future.” REKS' AI capabilities According to acre, REKS simplifies daily operations, automating routine tasks, and delivering real-time, actionable intelligence. With REKS' AI capabilities, users can interact with the system to retrieve more detailed insights and actionable information from their acre access control system. “This eliminates the need for complex reports, navigating drop-down menus, or manually reviewing logs,” says Groom. “It significantly enhances efficiency and usability for security professionals.” Enhancing productivity and customer satisfaction Key concern is ensuring that system configuration, enactment, and servicing remain within their scope For integrators, the key concern is ensuring that system configuration, implementation, and servicing remain within their scope of expertise. With REKS, that doesn’t change — but the process becomes significantly faster and more efficient. Instead of manually configuring every panel, input, and output — a traditionally time-consuming task — REKS enables integrators to use natural language commands to streamline setup and adjustments, says Groom. This eliminates tedious steps and dramatically improves operational efficiency, allowing integrators to deploy and fine-tune systems with greater speed and accuracy, ultimately enhancing both productivity and customer satisfaction, he adds. Cloud-enabled ecosystems “We are committed to helping organisations modernise their security infrastructure by transitioning from legacy systems to cloud-enabled ecosystems at their own pace — ensuring minimal disruption while maximising value,” says Groom. “By integrating AI-driven capabilities, we enhance usability and deliver deeper operational insights across all segments.” “Security’s future isn’t about forcing change — it’s about empowering choice,” adds Groom. “Whether staying on-prem, migrating to the cloud, or adopting a hybrid model, we plan to provide a seamless, zero-disruption transition, prioritising interoperability, automation, and security at every stage.” Generic AI tools AI must be purpose-built for security applications because security demands precision, reliability, and context-aware decision-making, which only focused AI offerings like REKS bring to the table, says Groom. In contrast, generic AI tools, like ChatGPT, are designed to perform a wide variety of tasks, like how humans can learn and do many different things. Instead, purpose-built AI is built to do just one specific function. “REKS adds specially designed artificial intelligence to our access control solutions to enhance both intelligence gathering and the user experience,” says Groom. New applications in access control The integration of generative AI into acre's access control platforms and their broader portfolio A new AI development team will lead AI initiatives at acre, driving the integration of generative AI into acre's access control platforms and their broader portfolio. This team will seek to push boundaries in applying AI to new applications in access control, intrusion detection, and beyond, empowering security professionals to interact with their systems in a smarter, more intuitive way. But don’t worry, AI will not take the human element out of security entirely. AI human capabilities “The reality is that AI will improve upon human capabilities because it is a versatile tool that supports and strengthens security operations, not a replacement for human decision-making,” comments Groom. “It helps operators process large amounts of data quickly and detect patterns that might be missed otherwise.” Rather than removing the human element, AI allows security teams to work more efficiently by automating repetitive tasks and providing actionable data, enabling professionals to focus on critical responsibilities. {##Poll1743085396 - What is the biggest challenge you face with your current access control system?##}
The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel. The shocking event raised awareness in board rooms around the world about the need for, and challenges of, executive protection. Questions followed immediately, including why was the high-level executive not protected? Combination of risk and reward UnitedHealthcare’s stock price has gone down more than 20% since the shooting The event also highlighted what is at stake for companies, extending beyond the safety of executives and impacting many factors, even including a company’s stock price. UnitedHealthcare’s stock price has gone down more than 20% since the shooting, equating to tens of billions of dollars. “Companies are considering the combination of risk and reward like never before when it comes to executive protection,” says Glen Kucera, President of Allied Universal Enhanced Protection Services. “What are the chances this could happen? Before Dec. 4 many thought it was zero. And what are the financial implications for a company if it happens? Executive protection is a small investment to protect against a worst-case scenario.” Evaluation of an executive protection Before the UnitedHealthcare shooting raised awareness, fewer than 50% of executives had protection. But concerns that previously fell on deaf ears now have the full attention of companies, says Kucera. “Boards of directors are having to figure this out,” he adds. “They may not have executive protection, but now they have to do it.” A threat assessment, conducted by a company such as Allied Universal, provides an independent evaluation of a company’s executive protection needs. The assessment evaluates factors such as an executive’s travel habits, the safety of their home, etc. Does the executive need protection 24/7, or just when they travel into more dangerous areas? Risks increase related to corporate earnings Sometimes, cases increase the need for executive protection, such as an internal threat In assessing threats, security professionals also look beyond the individual to consider the safety of a corporate facility, for example. “Is there a visual deterrent, controlling who comes and goes?” asks Kucera. “If there is good security, it all ties together. We do home assessment, facility assessment, route assessment, and travel assessment as needed.” Sometimes, circumstances increase the need for executive protection, such as an internal threat. Timing is a factor, and risks increase related to corporate earnings releases, new product announcements, and corporate layoffs or consolidation. Monitoring social media tracks shifting threats that impact the need for executive protection. UnitedHealthcare shooting “He didn’t have it and probably didn’t think he needed it,” comments Kucera about the UnitedHealthcare executive who was gunned down in the streets of New York City. “He was staying at the hotel across the street and was used to walking down the street every day.” “Sometimes executives want to preserve their privacy and be able to walk down the street,” says Kucera. “Getting protection can be seen as a sign of weakness. Some CEOs in the past have said they just didn’t want it.” However, the UnitedHealthcare shooting raised the stakes of the need for more vigilance. “The bottom line is you have to yet beyond objections and make the investment to protect against a worst-case scenario,” says Kucera. Anti-capitalist sentiment in the general population An internal police bulletin warned of an online hit list naming eight executives and their salaries Threats to executives sometimes arise from anti-capitalist sentiment in the general population about perceived inequalities in wealth and power. Executives provide symbolic targets for anyone who fights the system, and social media has amplified the voices of those who oppose capitalism. For example, a "Most Wanted CEO” card deck seeks to shine a spotlight on "titans of greed." Also, in the aftermath of the UnitedHealthcare shooting, CEO "wanted" posters appeared across New York City, threatening various executives of large companies. An internal police bulletin warned of an online hit list naming eight executives and their salaries. Careful monitoring of social media posts Careful monitoring of social media posts and other sources enables executive protection professionals to analyse data and separate the dangerous threats from the merely negative ones. Sadly, positive support of the UnitedHealthcare shooting was expressed by the 300,000 or so followers of the shooter, who became a celebrity of sorts. A huge outcry of negative sentiment toward the insurance industry led to fear that copycat incidents might occur. “There has been an unprecedented amount of positive support for committing murder,” commented Kucera. Executive protection requests HR executives can be at risk, especially at a time of layoffs or consolidation “Let’s face it, there has been a lot of controversy, from COVID to the Middle East crisis, to the political campaign, and there is negativity on both sides,” says Kucera. “People have opportunities to pick sides, and there is a lot of sentiment going both ways, and there is a small percentage of people who will act aggressively.” Executive protection requests now extend beyond the CEO to include others in the management ranks of companies. Basically, any public-facing executive is at risk, including anyone who makes statements to the press. Human resource (HR) executives can be at risk, especially at a time of layoffs or consolidation. Private information on the Internet Typically, an executive is assigned a single armed operative for protection. The firearm serves primarily as a visual deterrent that hopefully makes a potential perpetrator think twice. “When they plan an event like this, their expectation is that it will be a soft target,” says Kucera. “If there is an officer, it gives them pause.” Controversial or high-profile CEOs are typically protected 24/7, including when they travel with their family. Adding risks is the fact that private information is now posted on the Internet, including where an executive lives and where their children go to school. Internet monitoring Internet monitoring also includes the “dark web,” which includes sometimes dangerous information “We offer social media monitoring, and we advise them to be more careful with what they post,” says Kucera. “We monitor reactions to posts including any that might be threatening. We watch social media carefully if a company announces earnings or a change in their service or product offering.” Internet monitoring also includes the “dark web,” which includes sometimes dangerous information that is intentionally hidden and requires specific software, configurations, or authorisation to access. Own layer of protection Public and government officials can also come under fire in a variety of scenarios. FEMA officials faced threats after the recent floods in the Southeast, for example, among other situations where perceived unfair treatment promotes thoughts of retribution. Although government agencies have their own layer of protection, there are instances when they call on companies such as Allied Universal for additional help. Ad hoc protection for various executives In the aftermath of the UnitedHealthcare shooting, calls to Allied Universal’s Command Centre increased by 600%, reflecting requests for ad hoc protection for various executives. These requests are in addition to the company’s business providing “embedded” operatives that travel with executives all or some of the time. On that side of the business, requests for services are up probably 300%, says Kucera. {##Poll1742194323 - Has the recent increase in violent threats changed your company's view on executive protection?##}
Case studies
The client, a large telecommunications provider, had teams working across multiple time zones and operated a sprawling and complex IT system. The scale and density of this system made gaining visibility into IT services extremely difficult, leaving the security team blind to what was happening with its IT environment. With little-to-no operations monitoring tools in place to proactively monitor these systems, the team had no visibility on the availability of its IT services or KPIs, such as failure rates, send request times, and response times. This lack of oversight made it difficult for the team to prioritise issues — and nearly impossible for them to find the root cause of any problem. Proactive measures Without the ability to investigate the source of issues, the team was unable to take proactive measures to prevent them from reoccurring, severely impacting service performance. This was not only a problem for IT teams, but also for executives, who lacked the insight into IT business operations that would help them make decisions. The solution The company needed a solution that would map KPIs to critical service components, enabling the operations team to effectively drill down into issues in real time and conduct in-depth investigations to find resolutions. RiverSafe had previously implemented Splunk Enterprise Security for the customer and given the success of the implementation and the positive client feedback on the platform, RiverSafe was again engaged to deploy Splunk’s IT Service Intelligence (ITSI) tool to help it tackle its visibility problem. Data collection metrics Splunk ITSI uses machine learning to analyse existing data and predict future issues. As well as forecasting potential services bottlenecks, it can also troubleshoot problems and help users resolve issues fast. Delivering comprehensive monitoring across the entire IT environment, Splunk ITSI would also give the team full observability of their IT infrastructure. In particular, the engineering team wanted to gather metric data relating to the Kubernetes platform. RiverSafe reconfigured and implemented data collection metrics used elsewhere in the IT environment in Splunk to allow engineers to collate and access this information from different data sources in one place. The outcome: Actionable insights in days, not weeks In less than a week, the RiverSafe team implemented Splunk ITSI and began running monitoring services. With data from existing KPIs already indexed by the Splunk platform, the team are now able to access service insights even faster. These KPIs allow the operations team to identify trends, detect patterns, and proactively address any anomalies that occur before issues arise. Instant visibility with glass table visualisations To enable rapid and proactive issue resolution, RiverSafe implemented custom glass table visualisations in Splunk ITSI. This enables the team to navigate large volumes of data and reduce the time needed to identify and resolve problems. This simple and accessible dashboard gives the team an instant, digestible overview of its web portal performance metrics. These KPIs included the number of open tickets and failed login attempts, memory usage, API call success rates, average response times, and overall health of container services. Event analytics in Splunk ITSI As a result of RiverSafe’s work, the team has been able to centralise events from all its previously siloed solutions into a single interface with Splunk ITSI. The event analytics in Splunk ITSI help to prioritise responses and react more quickly to customers’ infrastructure events, empowering them to provide a better service. This is thanks in part to Splunk ITSI’s ability to identify and filter out false positives from the event management process. Excluding these invalid events reduced the total event volume by 40%, helping operators focus on the events that really matter. With fewer events to process, a single interface to work from, and a streamlined event analytics framework in Splunk ITSI, operators now process events eight minutes faster on average. This boost in efficiency has led to a major improvement in the company’s SLA performance. Best practices for using Splunk ITSI Overall, Splunk ITSI has delivered enhanced operational visibility, meaning the team can locate bottlenecks in workflows quickly and deliver fast recovery and troubleshooting solutions. Along the way, RiverSafe also provided best practices for using Splunk ITSI and recommended the most effective ways to collect data, including proposing an alternative metric type that would save on storage space when collecting logs.
In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organisation. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimise operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialised expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organisation. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimise the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.
The client, a pioneering oil and gas corporation, faced significant challenges in knowledge management. The software engineering function struggled with locating the right documentation across multiple platforms such as ADO Repo, Confluence, SharePoint, and others. This fragmented system created delays and inefficiencies, with engineers spending valuable time searching for answers rather than focusing on delivery. Slow Access to Technical Information The sheer volume of documentation, continuously growing, compounded the problem. Onboarding tools for cloud services Onboarding tools for cloud services was also cumbersome, often dependent on a “hero culture” where finding the right person for help was the norm. This led to frequent meetings, wasted time, and a negative engineering experience, significantly slowing down workflows. RiverSafe was brought in to improve the engineer experience and increase velocity by enabling engineers to complete tasks more efficiently, reduce reliance on individual knowledge holders, and minimise time spent searching for outdated or misplaced documentation. The solution AI-enabled knowledge discovery They introduced an engineering portal powered by AI and natural language processing (NLP). Using a closed-domain RAG model, this portal introduced a ChatGPT-style interface where engineers could engage in natural language conversations to query documentation and receive consolidated answers, dramatically reducing the time spent locating information. The portal’s capabilities include rich content support such as diagrams, graphs, videos, and even in-platform automation for tasks like tool onboarding, further streamlining processes. The platform draws from multiple high-quality content repositories, creating a unified search experience across ADO Repo, Confluence, Internal document management systems, SharePoint, and more. Crucially, they implemented near-real-time monitoring for key model metrics, ensuring that each user’s question and answer interactions delivers unparalleled accuracy and relevance. This guarantees that the portal continuously provides genuine value through its responses. Recognising the challenges posed by response degradation and hallucinations in AI-driven systems, they have developed a set of innovative solutions designed to optimise each interaction’s impact. The outcome Eliminating wasted time and accelerating software delivery The portal has transformed the way engineers work, saving significant time and boosting efficiency across the board. One engineer commented, “I’ve been here for 15 years, and this is the best product for software delivery in our organisation. Previously, it could take me 2 weeks just to find out how to build a cloud environment. Now I get the answer straight away.” Key outcomes Time and Cost Savings: Engineers now save between 45 minutes and 10 days when searching for technical solutions. The portal has saved the organisation 68,000 engineering hours annually, equating to over £4 million in cost savings within the first year. Improved Document Quality: The platform collects and analyses data on the usefulness and quality of documents. This feedback loop ensures that outdated or low-quality documents are flagged for improvement, keeping the knowledge base relevant and focused on high-value content. High-Fidelity Responses: Engineers receive immediate, detailed responses with links to relevant documentation, images, videos, and graphs. This reduces reliance on outdated information and significantly improves the quality of software delivery. Onboarding and Automation: Engineers can complete tasks directly within the platform, such as onboarding new tools, without needing to switch between systems, further streamlining workflows. User feedback and performance data The portal continues to gather user feedback and performance data, ensuring that it remains an invaluable tool for the organisation, consistently improving the engineer experience and accelerating software delivery. The organisation has also engaged NeuroLogik to build on these successes. NeuroLogik specialises in providing deep insights into entire codebases, ensuring that engineers can easily locate and reuse existing code across the organisation, further enhancing efficiency and reducing duplication of effort.
The client, a British media and telecommunications company, was looking to increase operational efficiency, save time spent on identifying and addressing vulnerabilities and reduce risk by increasing visibility across their environment. With multiple security tools in different places, security data was siloed and needed to be accessed separately. This led to long periods of time spent jumping between tools to find data, and a lot of context switching when it came to looking at the results. Developers, security teams and senior directors were forced to search in multiple places for critical, often time-sensitive information about vulnerabilities. Risk of vulnerabilities Not only did this eat into their valuable time, but it also meant they had no overall visibility into the organisation’s security posture. This lack of visibility significantly hampered the development process, as developers struggled to locate and address security issues. In addition, the organisation did not have centralised CI/CDs, instead running different pipelines for individual developers or teams. Combined with poor visibility, this lack of efficiency was causing major frustration for the development team, slowing down development and increasing the risk of vulnerabilities in the code going undetected. The solution RiverSafe was initially brought on board to address the issue of decentralised security data, and help improve operational efficiency. The team’s goal was to allow for the results to be sent directly to the developers without them needing to access and search multiple security platforms to find the information they needed. The RiverSafe team created an integration script for the developers to execute when they were running their pipelines. Once triggered, the script would send a notification to a server that RiverSafe had specifically designed, which collated the identified vulnerabilities and relayed them back to the developers’ pull request. This ensured the development team got the information they needed to improve the security of their code. The next phase: Developing the data insights RiverSafe consultants worked alongside the client’s team to take all the security data that was being collected and, rather than sending it to individual developers’ pull requests, instead created and directed it to a pane-of-glass tool. This tool allows the developers to log in and see their repositories and projects in one place. For management, it allows them to have a complete picture of all the vulnerabilities and what they are impacting, on both individual repositories or a given product. The tool also allows them to build reports and includes a scoring model to give a visual rating so everyone can easily see if their repositories are secure or not. The scoring system, ranging from insecure to excellent sends alerts to let the developers know if their repositories fall below a certain level so they don’t need to continually monitor themselves. The RiverSafe team also provides advice on the steps that should be taken to remediate any identified vulnerabilities. Multiple security operations A key requirement of this tool was that it supported multiple security operations, including SAST (Static Application Security Testing), which would look at code smells and general quality of life, Source Code Analysis (SCA), which would look at which libraries are being used and also Secret Scanning to look for secrets in the code. RiverSafe also wanted to ensure that all of this is serverless on AWS to minimise the time spent on infrastructure maintenance. After launching, RiverSafe continued to work on improving this tool, making quality improvements, performing maintenance, and enhancing the integration via the shell scripts. The outcome The tool now brings together data from over 22,000 code repositories into one centralised place, allowing the client to see all of their security information, what libraries were most common, where the vulnerabilities were, and to start looking for trends. Developers and other stakeholders no longer need to scour multiple locations for vulnerability data, saving the company huge amounts of time and making its development process more efficient. With the bespoke script in place, the data comes to them. This increase in visibility has also led to improvements in response times to zero-day vulnerabilities. Previously, it could take weeks or even months to find all the affected repositories. However, since implementing RiverSafe’s custom tool, the team has been able to locate repositories featuring the vulnerable package immediately and remediate any issues quickly, massively improving their overall security posture. Thanks to this uplift in operational efficiency, the development team is now able to spend more time improving their code. RiverSafe and the client’s team are now working on expanding coverage throughout the organisation, improving analytics and alerting, and centralising CI/CD pipelines.
A major UK retailer known for its quality clothing, home products, and premium food offerings recently migrated their SIEM platform to Microsoft Sentinel, which was integrated with other Microsoft security tools, including Defender. Over the months, multiple configurations had been built up, creating complexity within the system. The alert overload problem After the migration, the SOC (Security Operations Center) team became overwhelmed by a flood of alerts—many of which were false positives. This not only drained their resources but also weakened their security posture, as the team couldn’t thoroughly investigate the flood of alerts. RiverSafe’s solution: Optimising configurations RiverSafe was brought in to address this issue and guide the leading UK retailer on reviewing Microsoft Defender configurations and fine-tuning the Microsoft Sentinel queries. The consultant conducted a thorough review of the existing configurations and provided actionable recommendations to the SOC team. Some changes were straightforward and implemented quickly, while others required collaboration with multiple teams across the organisation—something the SOC team had issues in getting implemented over a few months. Facilitating communication for effective implementation The consultant facilitated communication between the SOC team and other departments, providing detailed documentation and clear explanations of why these changes were necessary. By bridging this gap, they ensured the required changes were finally actioned and documented with high standards. Key impacts Within a few weeks, they achieved the changes the SOC team had been pushing for over the few months, fostering better collaboration between the networking and security teams. Alerts were reduced by 62%, significantly improving team efficiency by cutting out noisy, recurring alerts. The improved configurations enhanced the company’s overall security posture, allowing the SOC team to focus on real threats and respond more effectively.
One of the world’s pioneering energy companies embarked on a transformative journey to modernise its development infrastructure with an Internal Developer Platform (IDP). This case study explores how the organisation tackled key challenges to remove barriers, streamline workflows, and improve developer productivity. The challenge The company’s development environment presented several obstacles that impacted team efficiency and overall productivity: Lengthy Provisioning Times: Development resources often took excessive time to provision, leading to delays and bottlenecks. Cumbersome Processes: Resource allocation relied on complex, manual workflows, adding unnecessary friction to the development process. Extended Onboarding: New projects faced onboarding times of 4–6 weeks, delaying time-to-productivity for developers. Inconsistent Practices Across Teams: Varied development practices led to inconsistencies and technical drift from organisational standards. High Cognitive Load: Engineers were required to manage knowledge across multiple domains, increasing their cognitive load. Increased Support Overhead: Complex infrastructure needs led to elevated support requirements, which stretched engineering resources. The solution journey The company engaged RiverSafe to collaborate with its DevOps team on a multi-phased journey toward an automated, developer-friendly platform. Phase 1: OpenShift implementation The initial phase involved adopting OpenShift to simplify cloud operations and establish a unified framework: Pre-Configured Workspaces: Provided developers with pre-configured environments, reducing setup time and manual tasks. Automated Provisioning: Automated the allocation of resources, removing manual paperwork and streamlining workflows. Security and Observability Enhancements: Embedded platform-wide security guardrails and introduced tools for chaos engineering and observability. CI/CD Pipeline Automation: Established automated continuous integration and delivery (CI/CD) pipelines to accelerate deployment cycles. Phase 2: Building the full IDP Building on the OpenShift foundation, the organisation worked on creating a comprehensive IDP designed to: Simplify Deployments: Introduced one-click deployment capabilities to enable rapid iteration and deployment. Enable GitOps and Monitoring: Integrated tools like ArgoCD and Crossplane for GitOps, and Grafana and Loki for real-time monitoring. Streamline Resilience and Testing: Added advanced testing tools, including ChaosMesh for resilience testing and PACT for contract testing. Standardise Development Workflows: Established standardised resource definitions and centralised operational management to ensure consistency. Results to date Quantitative improvements Deployment Time Reduction: Cut deployment times from 2 weeks to 2 minutes, dramatically speeding up the development cycle. Faster Onboarding: Reduced onboarding time from 4–6 weeks to just 30 minutes, enabling new projects to start quickly. Lower Support Overhead: Streamlined processes and automation have significantly reduced support requirements. Qualitative benefits Standardised Developer Experience: Created a more consistent, efficient environment for developers across teams. Reduced Cognitive Load: Engineers can now focus on core development tasks instead of juggling multiple domains. Enhanced Security and Compliance: Automated guardrails ensure compliance and improve security practices.


Round table discussion
Future-proofing your skillset is about embracing continuous learning and developing a versatile set of competencies that remain valuable regardless of technological shifts or industry changes. In the security marketplace, it is not about predicting the exact jobs of the future, but rather equipping yourself to adapt and thrive in the uncertain security landscape. But where to begin? The emerging technology shifts in the security industry provide clues, such as the growing importance of cybersecurity and artificial intelligence (AI). We asked our Expert Panel Roundtable: How can physical security professionals “future-proof” their skillsets to prepare for emerging technologies?
In the physical security marketplace, artificial intelligence (AI) has evolved beyond the novelty phase. The emphasis has now shifted to the more practical aspects of implementing AI technology. That a system implements AI is no longer impressive in and of itself. The question becomes: What can this AI system do for me? How can it improve my physical security stance? We asked our Expert Panel Roundtable: How is artificial intelligence (AI) transforming physical security?
In many cases, architectural design and layout dictate optimal placement of security devices like cameras, access control readers, and sensors. Poor design can lead to blind spots, reduced coverage, and ineffective surveillance. However, planning that involves all the various stakeholders can maximise both security and design elements. We asked this week’s Expert Panel Roundtable: When are building design and physical security systems complementary? When are they at odds?
Products


White papers
Top 7 trends to watch in the physical security industry
Download
Troubleshooting IP video systems
Download
Simple Security Solutions for SMBs
Download
5 question check-up: Test your camera's cybersecurity
Download
How to migrate to an IP-based access control system
Download
Six ways to eliminate costs, risks and disruption to your network
Download
The critical importance of Trusted Execution Environment in access control
Download
Security investments retailers should consider for their 2021 budget
Download
Optimise your business with analytics and AI
DownloadMaking sense of today’s security camera options
Download
How to drive B2B security & operations with smart surveillance
DownloadMaking your surveillance cyber secure
Download
Is access control in the cloud more cost effective?
DownloadWhat are the security technology needs of the hotel sector?
Download
Network Security Redefined: IP-Enabled Access Control
Download

Videos
IP security solutions: Manufacturers & Suppliers
- exacqVision IP security solutions
- Dahua Technology IP security solutions
- Hikvision IP security solutions
- Honeywell Security IP security solutions
- Bosch IP security solutions
- AV Costar IP security solutions
- LILIN IP security solutions
- IDIS IP security solutions
- CIVINTEC IP security solutions
- Vicon IP security solutions
- Pelco IP security solutions
- Axis Communications IP security solutions
- Messoa IP security solutions
- Hanwha Vision IP security solutions
- VIVOTEK IP security solutions
- BCDVideo IP security solutions
- Climax Technology IP security solutions
- eneo IP security solutions
- Avigilon IP security solutions
- Software House IP security solutions
Technology's role in securing banks and financial institutions
Download
Security technologies promote real-time awareness in K-12 schools
Download
Integrated systems enable critical and compliant security for transportation
Download
Modernising physical access control
Download
Access. Intrusion. One estate.
Download
