Mergers & Acquisitions
Fime announces the acquisition of Red Alert Labs, taking a further step in its strategy to become a global Digital Trust Provider. The acquisition adds cybersecurity evaluation, certification expertise and compliance automation to Fime’s established capabilities across payments, smart mobility and digital identity. Trust infrastructure As digital ecosystems become increasingly interconnected, trust can no longer be addressed in silos. Payments, digital identities, connected devices...
ASSA ABLOY has acquired Pacific Lock Company, a US padlock and security hardware manufacturer. Expert insight "I am very pleased to welcome PACLOCK to ASSA ABLOY. This acquisition delivers on our strategy to strengthen our position in mature markets through adding complementary products and solutions to our core business,” says Nico Delvaux, President and CEO of ASSA ABLOY. "PACLOCK is recognised for delivering high-quality security products that combine reliability, durability, a...
ZBeta, a pioneer in delivering comprehensive physical security consulting services, announces the launch of its Client Immersion Program, a strategic engagement designed to help organisations align security decisions with business priorities, operational requirements, and long-term goals. Security decisions increasingly have implications across the enterprise, influencing business continuity, operational resilience, regulatory compliance, technology strategy and growth. As organisations adopt n...
Ranger Fire and Security has announced a new partnership with Ulster-based Fire Protection Ireland, bringing the total number of businesses in the Ranger Group to 26. Fire Protection Ireland was established in 2011 and is based in Cavan, Ulster, providing comprehensive fire and security services – covering design, installation and commission – to public and private sector customers across the nation. Smoke ventilation systems The business’s services include fire alarm and ex...
Cybersecurity teams face a difficult reality. Organisations are collecting more security data than ever before, yet many still struggle to detect threats quickly, respond efficiently, or keep pace with increasingly sophisticated attacks. Traditional Security Operations Centre (SOC), once considered the backbone of enterprise defence, are under pressure from alert overload, analyst burnout, and attackers who now use automation and artificial intelligence themselves. As a result, AI-driven SOC is...
Hexaware Technologies, an AI-first digital and IT services company, announces the appointment of Vivek Jetley as CEO Designate. Vivek will join Hexaware and assume the role of CEO on October 28, 2026. The appointment comes at an important moment for Hexaware as the company enters its next phase of accelerated growth with AI reshaping enterprise technology services globally and creating new sources of client demand. Srikrishna Ramakarthikeyan ("Keech") will step down as CEO and as a member of th...
News
IQSIGHT announces the appointment of Michael J. Schulte as Chief Executive Officer, effective September 1, 2026. Michael will lead the global IQSIGHT business and report to Steve Shine, Chairman of IQSIGHT. Michael joins IQSIGHT with more than 30 years of leadership experience across technology, industrial and private equity-backed businesses. Most recently, he served as EVP and President of the Safety Solutions Group at Clarience Technologies and previously as President of Safe Fleet, where he helped drive growth, acquisitions and a successful private equity exit. Earlier, he held senior leadership roles at Atkore International, Danaher Corporation, and Boston Consulting Group. He holds an MBA from Harvard Business School. Successful private equity “Over the past months, we have worked closely with the leadership team to define a clear strategic direction for IQSIGHT and position the business for its next phase of growth. With that foundation in place, this is the right time for Michael to take the helm. Michael has an exceptional track record of driving execution, transforming businesses and delivering results. His leadership style, operational discipline and customer focus make him the ideal person to translate our strategy into action and unlock the full potential of IQSIGHT,” said Steve Shine, Chairman of IQSIGHT. “IQSIGHT has a strong heritage, outstanding people and a compelling strategy. I am excited to join the team and build on the excellent work already underway. Together, we will focus on execution, innovation and creating even greater value for our customers, partners and employees,” Michael Schulte said. Together, Steve Shine and Michael Schulte will build on the strong foundation already in place, ensuring continuity for customers and partners while driving the next phase of growth for IQSIGHT.
Managing access control for a single facility is very different from overseeing dozens of locations across multiple regions. As organisations grow, security teams must manage more access requests, frequent role changes, and compliance across multiple sites. At the same time, access control systems are becoming more connected to identity management platforms, business applications, and corporate networks. Access control was once considered primarily a door-management function, it is now closely connected to identity, cybersecurity, compliance, operational technology and enterprise risk. This shift is particularly relevant in the Middle East, where the continued expansion of smart cities, critical infrastructure and large-scale commercial and government environments is creating more connected and complex security operations. Complex security operations Access control systems generate and store sensitive information, connect to enterprise networks, and often integrate with other business systems. Readers, controllers, credentials, and management software are now part of the same risk conversation as endpoints, networks, cloud services, and identity platforms. If compromised or poorly governed, they can create exposure that is both digital and physical. Organisations want greater visibility into system health, stronger oversight of administrative access, and confidence that vulnerabilities can be addressed before they become larger problems. This includes understanding whether communications are encrypted, how users are authenticated, how quickly software updates can be applied and whether policies are consistently enforced across locations. Well-managed environments “As access control becomes more connected to enterprise networks and business applications, it can no longer be managed in isolation from wider cybersecurity and governance strategies,” said Hassan Makki, Area Sales Director at Genetec Inc. “For organisations across the Middle East, consistent policies, shared visibility and closer collaboration between physical security and IT teams will be essential to managing risk as operations continue to grow and become more interconnected.” As organisations expand, governance often becomes more difficult to maintain. New facilities, acquisitions, contractors, temporary workers, and evolving organisational structures can introduce complexity into even the most well-managed environments. Approving access requests Different locations may use different processes for credentialing employees, approving access requests or reviewing permissions. Security teams may also be managing multiple systems while trying to enforce common policies without a complete view of their operations. Without a clear governance framework, inconsistencies begin to accumulate. Employees may retain access for longer than necessary. Access privileges may vary from one location to another, and security teams may struggle to determine which policies should apply at different locations. Access-related decisions As the number of sites and users grows, manual processes become increasingly difficult to sustain, and the likelihood of errors increases. Standardisation therefore becomes essential to scaling access control effectively. Access control becomes harder to manage consistently without accurate information. Yet many organisations struggle to gain a complete view of permissions, credential activity, and security events across all locations and systems. Access to reliable information helps organisations make better decisions and respond more effectively when issues arise. It also supports collaboration between physical security, IT, compliance, and risk management teams that may all have a stake in access-related decisions. For organisations across the Middle East, clear governance, consistent policies and shared visibility will be essential to scaling access control while managing evolving cyber and physical security risks.
RAD Security, a behavioural cloud native detection and response company, has been named one of 10 finalists for the RSA Conference 2024 Innovation Sandbox contest in recognition of its work empowering engineering and security teams with a custom, behavioural approach to cloud native detection and response. RAD Security will present its technology to a panel of prominent industry judges and a live in-person audience on Monday, May 6 at RSA Conference 2024 in San Francisco. Cloud native detection Since 2005, the RSAC Innovation Sandbox contest has served as a platform for the most promising young cybersecurity companies to showcase their groundbreaking technologies and compete for the title of “Most Innovative Startup.” The competition is widely recognised as a catapult for success as the Top 10 Finalists have collectively celebrated more than 80 acquisitions and received $13.5 billion in investments over the last 18 years. RAD Security will have three minutes to pitch the panel of judges before a question-and-answer round. “We are honoured that RAD Security has been selected as a finalist for the RSA Conference 2024 Innovation Sandbox contest,” said RAD Security CTO and co-founder Jimmy Mesta. “In sharp contrast to one-size-fits-all, legacy CWPP and container detection and response solutions, RAD takes a custom, behavioural approach to cloud native detection and response that can counter evolving threats while sharpening inputs into shift-left and posture management.” Unique good behaviour RAD Security creates behavioural fingerprints of the unique good behaviour to eliminate zero day attacks, apply zero trust principles, and verify your posture in real-time. RAD’s behavioural, cloud native detection and response platform includes real-time KSPM, cloud native Identity Threat Detection and Response (ITDR) and runtime protection. RAD Security provides the ultimate source of truth for cloud breaches, giving you a unique view of what ‘good’ looks like across the areas attackers are targeting today: cloud native infrastructure, identity, and the software supply chain. "In the constantly evolving threat landscape, legacy cloud scanners and runtime point solutions struggle to detect cloud native attacks," said Brooke Motta, CEO and co-founder of RAD Security. "For teams to achieve true resilience against emerging threats, detection and response solutions must evolve their approach beyond signature-based, one-size-fits-all solutions and black box anomaly detection.” Detect cloud native attacks “The submissions for this year’s RSA Conference Innovation Sandbox contest were both dynamic and inspiring. Along with the rest of our entrepreneurial audience, I am excited to see these ideas come to life on stage,” said Linda Gray Martin, Senior Vice President, RSA Conference. “The evolution of global cyber threats is constant and there’s no better place to look for solutions and to help solve these challenges than in our own community.” The RSAC Innovation Sandbox contest kicks off at 10:50 a.m. PT on May 6 and winners will be announced at approximately 1:30 p.m. the same day. The panel of renowned expert judges includes Asheem Chandna, Partner at Greylock; Dorit Dor, Chief Technology Officer at Check Point Software Technologies; Niloofar Howe, Sr. Operating Partner at Energy Impact Partners; Paul Kocher, Independent Researcher; and Nasrin Rezai, SVP & CISO at Verizon. Hugh Thompson, RSAC Executive Chairman and Program Committee Chair of RSA Conference, will return to host the contest. The RAD Security executive team will be in San Francisco all of RSA Conference week. Find out where they’ll be and how to meet the team here.
Arrow Electronics, Inc. announces the appointment of Deidra C. (Dee) Merriwether to the new position of president and chief operating officer, effective Sept. 8, 2026, reporting to William F. Austen, interim chief executive officer. Merriwether will be responsible for leading Arrow’s global business segments and logistics organisations. With this announcement, the company augments its executive team and strengthens succession planning. “We are delighted that Dee is joining Arrow as president and chief operating officer. Her extensive experience in distribution combined with her successful track record leading commercial, operational, and financial teams make her an ideal leader to join Arrow at this time to support our terrific teams driving profitable growth and value creation for stakeholders,” said Steven H. Gunby, chairman of the Arrow board of directors. Optimised performance results Merriwether brings a robust background in broad-based business management and optimised performance results. Before joining Arrow and since 2021, she served as the senior vice president and chief financial officer of W.W. Grainger, Inc. and prior to that as the senior vice president and president, North American sales and services, and other roles of increasing responsibility since 2013. From 2002 to 2013, she held roles of increasing responsibility in general management and finance at Sears Holdings Corporation, departing as chief operating officer, retail formats, in 2013. She started her career as an engineer and production leader at Eli Lilly and Company and gained valuable accounting and mergers and acquisitions experience at PricewaterhouseCoopers International Limited. Corporate responsibility committee “I am thrilled to welcome Dee to Arrow and our executive team. She brings exceptional depth with her more than two decades of substantive distribution, sales channel, operations, and finance experience, with a demonstrated talent for innovation, versatility, leadership, and performance results. Further, she has the qualities we seek in our leaders -- she is humble, approachable, transparent, and driven by purpose and values to deliver results for our suppliers, customers, employees, and investors,” said Austen. Merriwether holds a Master of Business Administration from Indiana University’s Kelley School of Business and a Bachelor of Science degree with a major in chemical engineering from North Carolina Agricultural and Technical State University. She currently serves on the board of Weyerhaeuser Company as an independent director and member of the audit committee and governance & corporate responsibility committee.
SAGE Integration announced the acquisition of Vital Installs and sudoVision Consulting LLC, expanding the company’s capabilities in security integration for commercial customers and government agencies. Vital Installs, with an office in Columbus, Ohio, provides security system solutions, structured cabling, and network installation services designed for performance, reliability, and growth. SudoVision Consulting LLC, out of Charlotte, North Carolina, is an SDVOSB-certified firm focused on delivering advanced technologies and services to commercial and government clients. Complex customer environments “We are thrilled to join the SAGE family. Since day one, our mission has been to deliver exceptional service and trusted solutions to every customer we support. As part of SAGE, we’re excited to expand that commitment, bringing our expertise, innovation, and customer-first approach to an even broader community. The future is bright, and we’re just getting started.” – Omid Jaafari, Founder/Owner, SudoVision Together, these acquisitions strengthen SAGE’s national delivery platform and add complementary expertise in low-voltage systems, future-ready infrastructure, and technology applications. The additions also enhance SAGE’s ability to support complex customer environments where physical security, resilient networks, and emerging technologies increasingly intersect. “Adding Vital Installs and sudoVision Consulting is an important step in our continued growth,” said John Nemorofsky, COO of SAGE Integration. “Their teams bring specialised capabilities that align directly with where our clients’ needs are headed: secure facilities, dependable infrastructure, and smarter technology solutions delivered with speed and precision.” With these additions, SAGE Integration continues to build a broader national security and technology services organisation capable of helping clients protect people, facilities, operations, and critical assets across a wide range of industries.
Gunnebo Group has entered into an agreement to divest the business unit Gunnebo Entrance Control to ASSA ABLOY, the global pioneer in access solutions. Gunnebo Group is a global pioneer in security solutions, offering innovative products and services that protect and control the flow of people and securely safeguard valuables through its two separate business units, Gunnebo Entrance Control and Gunnebo Safe Storage. Focused technology company The transaction marks an important milestone in Gunnebo Group's strategic development. Following completion of the transaction, the group will focus exclusively on Gunnebo Safe Storage, enhancing the global reach and offering with which they serve their customers. Stefan Syren, President and CEO of Gunnebo Group, says: "I am excited about the journey ahead for Entrance Control as part of ASSA ABLOY. Over the past decade, we have transformed Gunnebo from an industrial conglomerate into a focused technology company. The combined team brings innovative products, strong service capabilities and highly skilled talent to the market.” Deepen customer relationships “Altor and Stena Adactum have invested significantly in the business – in our people, new factories, new products, product development, digitalisation and sustainability – with the ambition to build a world-class company. With their continued support, Gunnebo will sharpen its focus on the SecureTech and Safe Storage markets, accelerate innovation, digitalisation and service-based business models, deepen customer relationships and drive customer-led sustainable growth – both organically and through selected acquisitions.” Says Howard Lang, President of Gunnebo Entrance Control: "This is a proud moment for everyone at Gunnebo Entrance Control. We are excited about the opportunities this combination creates for our employees, customers and partners. Bringing together these two organisations with complementary strengths will accelerate innovation, further improve our customer offering, drive future growth and reinforce our position as a leading provider of entrance control solutions. Becoming part of ASSA ABLOY marks the beginning of an exciting new chapter.” The transaction is subject to customary regulatory approvals and is expected to close during the fourth quarter of 2026.


Expert commentary
Acquisitions are often billed as moments of bold opportunity. For senior executives and boards, these deals are about accelerating growth, unlocking synergies, and strengthening competitive advantage. But for the teams responsible for making operations run safely and smoothly — including physical security — acquisitions can feel like controlled chaos. Decisions happen without warning, details are opaque, and the ripple effects of choices made in the boardroom cascade down through every layer of the organisation. Too often, physical security isn’t even in the room where those decisions happen. Beyond access control When security is treated as an afterthought — a cost centre to be rationalised, rather than a strategic enabler — companies expose themselves to risks that go well beyond access control or surveillance coverage. Overlooked integration challenges can compromise the safety of people and property, slow down facility transitions, inflate budgets, and undermine everyone’s confidence in the acquisition deal itself. For seasoned physical security leaders, the imperative is clear: make your program visible, credible, and indispensable before and during acquisition conversations. That means ensuring your voice is represented. Why security visibility matters At first glance, it’s not obvious to some why physical security should rank alongside finance, IT, and legal in the M&A playbook. But consider what’s really at stake:͏ Budget accuracy: If no one accounts for system migrations, access credential re-issuance, or security subject matter expert (SME) travel during due diligence, financial forecasts will be miscalculated. Underestimating these costs by even a small percentage can throw off larger integration budgets. ͏ Technology fit: Acquirers frequently inherit access control, video, and monitoring platforms that don’t align with their standards. Without early planning, companies risk unsupported infrastructure, avoidable downtime, and duplicating expensive features. ͏ People and roles: Security staff redundancies and mismatched responsibilities are often decided hastily, surfacing operational gaps and challenges with morale. ͏ Cultural harmony: Employees at acquired companies can perceive new security measures as heavy-handed or intrusive, jeopardising adoption and compliance. Each of these factors is manageable — but only if you consider them early on in the acquisition and communicate clearly at the decision-making level. Securing a seat at the table Physical security leaders don’t need to wait passively for a seat at the M&A table — they can and should advocate for it. Take practical steps: Identify the M&A committee. This group may go by different names — corporate development team, integration steering group, or even a subcommittee of the board. Pinpoint who leads it and which executives have influence. Make the case for inclusion. Position security not as a compliance hurdle but as a value multiplier. Remind leadership that visibility into risks, costs, and integration timelines reduces surprises, accelerates business continuity, and protects reputation. Bring data, not anecdotes. Prepare a concise playbook: current-state inventories of systems and personnel, cost models for typical integration activities, and sample timelines for cutovers. When executives see that security has done its homework, they’re more likely to view the function as essential. Leverage allies. Partner with your security consultant, along with your facilities, IT, HR and risk management teams who share overlapping interests in safe, seamless operations. Unified advocacy is harder to dismiss than a single voice. By getting on the M&A committee, you ensure your concerns aren’t filtered secondhand or raised too late to influence outcomes. Leading with credibility during acquisitions Visibility is only the first step. Once in the room, security leaders must contribute with authority and clarity. Three practices stand out:͏ Translate security into business impact. Executives don’t respond to jargon about card readers or VMS licenses—they respond to risk, cost, and continuity. Frame every input in terms of: Financial implications, such as “Consolidating platforms will save $X annually, but requires $Y in upfront integration.” Operational implications, such as “Delays in credentialing will stall employee onboarding at three newly merged sites.” Cultural implications, such as “Without a clear change management plan, acquired employees may resist compliance, leading to increased insider risk.”͏ Provide scenarios, not surprises. Acquisitions move fast, but that doesn’t mean you can’t plan. Present modeled scenarios — small target vs. large target, regional vs. global integration — and their associated timelines and costs. This proactive approach demonstrates foresight and earns trust. ͏ Advocate for people, not just systems. In the scramble to integrate technology, companies often forget the human element. Use your platform to ensure that acquired security personnel are evaluated fairly, retrained where possible, and integrated into the new culture. Advocating for people strengthens morale and preserves institutional knowledge. Visibility beyond a single deal For some companies, acquisitions are rare, high-stakes events. For others, they’re a routine growth engine. In either case, physical security leaders should treat M&A as a recurring test of their strategic value. To do this, work with your security consultant to:͏ Document lessons learned from each acquisition, then institutionalise these lessons in playbooks and checklists. ͏ Develop clear security messaging that explains your team’s mission and impact, so executives understand why your presence is non-negotiable. ͏ Commit to realistic timelines for integration work, ensuring leadership sees the discipline and predictability of your function. The goal isn’t just to be consulted during one deal — it’s to become permanently visible in the company’s growth strategy. Don’t be an afterthought In the popular imagination, the “room where it happens” is a place where power dynamics shift and futures are decided. For physical security leaders, being absent from that room during an acquisition means watching others dictate the future of your program, your people, and your company’s security posture. But by proactively seeking visibility — by insisting on a voice in acquisition planning, by bringing data and credibility to the table, and by consistently framing security as a business enabler — you can transform physical security from an afterthought into a recognised pillar of successful acquisitions.
Artificial Intelligence isn’t just a buzzword anymore. It has become part of our lives, and its uses and applications are growing every other day. Even the public sector, which usually is a late adopter of new technologies, has come onboard this new train. Law enforcement, in particular, has seen the advantages different AI technologies can offer to their work and has started to integrate them into their workflow and daily routines. But there is much more to come. Task automation: AI as a workhorse Due to the increasing importance of media files in police investigations, current police cases have an increasing amount of digital files to be analysed. Videos from mobile phones, computer files, sound recordings, voice messages from chat applications…the list is almost endless. But, in contrast to other types of digital files, like documents or PDFs, it is not possible to search directly a certain information in a video. It has to be watched by someone. And that takes an inordinate amount of time for a human being, as there can be hundreds of videos in a case. This is one of the areas where artificial intelligence shines. Modern analytics systems are able to find almost any kind of information in media files due to the improvement of artificial vision, object recognition and face biometrics. It is simply a matter of feeding the hundreds or thousands of media files to a AI analyser, which will work through them and find specific sounds, words, faces, cars, etc. Case of law enforcement On top of that, an analyser does not tire after long work hours and does not make errors What is more, unlike human officers, these systems can work 24/7 which speeds up investigations considerably, as more evidence is found in less time. On top of that, an analyser does not tire after long work hours and does not make errors. This is why police work can be helped greatly by AI Analytics, as it frees police officers to do high value work, instead of endlessly watching videos on a computer of listening to audio recordings, in search of evidence. As soon as the system finds what the officer has specified (a face, name, number plate, object, etc.) it sends an alarm to the officers’ phone, so he or she can take a look and decide what to do with that information. Despite AI being touted as a danger to many workplaces, in the case of law enforcement, it is a valuable tool to help police do more, with more accuracy, and in less time, freeing officers from the repetitive and boring work of checking mountains of evidence in search of clues. The AI Analyser landscape The field of AI analytics is expanding constantly and new types of analysis are being discovered that may be helpful to police or intelligence. The most used analysers today are probably Automatic Licence Plate Recognition (ALPR), object and face recognition. But OCR is equally useful not just for reading documents, but also signs and logos that may appear in pictures or videos, to help identify a location. And for audio (as in interception or surveillance recordings) there is speech-to-text (S2T), translation, Speaker ID, audio fingerprinting (AFP) and natural language processing (NLP) which is able to extract sentiment from what is said. All of these have their application in daily police work and can save time in investigations or make them possible in the first place. But looming on the horizon are new possibilities, which we will discuss later and that are even more powerful. So the field of AI Analytics is, by no means, a closed one. Generative AI in law enforcement LLMs will be an important part in all those tasks related to investigate large sets of documents For the past year, the term “Generative AI” has become part of our general vocabulary, although most of the time we just say ChatGTP, Copilot o similar. The large language models (LLM) use Deep Learning and different AI strategies to, amongst other things, analyse and summarise vast amounts of information, in order to generate a short report with the highlights. This can be of use for Law Enforcement in all those cases that have great amounts of documents that may contain evidence. Again, this is a case like the above, where AI helps speed up operations by doing the grunt work much quicker than any person could. The difference is in the Deep Learning part. The model can be tuned to specific needs (like financial crimes, for example) and will get better over time when dealing with specific sets of documents. Thus, LLMs will be an important part in all those tasks related to investigate large sets of documents during a case. What the future holds As with all technology, it is virtually impossible to predict what the future will hold. Because any breakthrough can upend complete sectors, as demonstrated by ChatGPT not that long ago. However, there are several promising AI technologies in the pipeline, some of which are already being tested and perfect around the world: Behaviour analysis: as facial recognition systems get better and better, they are not only able to recognise faces, but also facial expressions. This means that AI systems could be assisting during interrogations, to evaluate the truthfulness of what is being said. Combined with the analysis of small voice inflections, they can be a non-invasive “lie detector”. Robotics: already in use by many police forces around the world, robots are going to be ever so important. Particularly the autonomous kind, which is able to do missions on its own, without a human behind the controls. This, combined with swarm technology, could be an incredible help in disaster areas, where time is of the essence in locating victims. Predictive policing: thanks to pattern analysis, predictive policing, which has been to the test several times already, will be an important part of police work, to figure out where to send units or concentrate surveillance efforts. In short, AI has much more to offer, and we are going to see and incredible evolution of this technology applied to law enforcement, over the next years.
Security manufacturers throw around the term “scalable” a lot these days, but few dive into what scalable really means for modern organisations and their security programs. Achieving true scalability, or as I like to refer to as “expandable with a purpose,” takes planning and coordination from security pioneers alongside the broader organisation. Implementing a flexible strategy is critically important in the age of advancing analytics and intelligence-driven technology. So what exactly do we mean by “scalable”? "Scalable" refers to the capability of a system, process, or technology to handle growth or increased demand without compromising performance, efficiency, or quality. To put it simply, scalability refers to the ability of a solution to expand or adapt to accommodate larger workloads, higher volumes of data, or increased complexity without requiring significant changes to its underlying architecture or design. It’s not enough to create a “fix it and forget it” security program. Not only do the needs of the organisations shift, but growth (or even shrink) is inevitable. How to Approach Growth Pioneers must be prepared to adapt their strategies and approaches to manage security risks For many security pioneers, growth has a trickle-down effect. Expansion through mergers and acquisitions or organic growth, in addition to decreases in facility or employee count, directly impacts the security program. Whether it’s an increase or decrease in size, workload, or scope, these pioneers must be prepared to adapt their strategies and approaches to efficiently manage security risks while maintaining operational efficiency. Here are some ways security pioneers can approach growth: Assess the here and now: Begin by looking at the current state of your security program, including the resources, capabilities, processes, and technology infrastructure. Understanding existing strengths, weaknesses, and areas for improvement can help inform planning for the future. Align with the business: This might be one of the most important considerations to make, but ensuring security pioneers understand the organisation’s growth objectives, priorities, and risk tolerance levels is critical to the success of a security program. The most successful security pioneers will be able to align security strategies with business goals to ensure security investments and planning are enabling the company’s growth initiatives. Invest in scalable solutions: Invest in solutions that offer flexibility and can adapt to the changing needs of the organisation. Closed systems that can’t integrate fully with new technologies will severely limit the security team’s ability to seamlessly manage the security portfolio. Optimize processes: Reviewing security processes and workflows – or investing in a platform that can streamline this for you – can improve efficiency and effectiveness for your security team. Identifying opportunities for automation and standardisation can allow for scaling as business needs change. Collaborate across departments: Preparing for growth initiatives requires extensive communication across departments, including leadership teams, human resources, legal, IT, facilities, and many other stakeholders ensure that security priorities, challenges, and requirements are effectively communicated and integrated. Adopting these approaches helps put security teams in the driver’s seat, effectively managing periods of growth and change without compromising the safety and security of the organisation. Technology considerations As security pioneers navigate investments in new technologies that achieve some of the approaches listed above, such as aligning strategy with business goals, optimising processes, and cross-departmental collaboration, there are several considerations to make. Looking at how technology can support (or even hinder) future growth. For example, when making a buying decision around access control systems, security pioneers must consider the number of users, number of credentials, server requirements, facilities, hardware end points, and software features. As these items are being addressed in an RFP or in conversations with a vendor, security pioneers must ask themselves, “Is there a scenario where my program will outgrow the system’s capabilities in any of these areas?” If so, the answer might be to select a different solution. Security pioneers must consider interoperability. We talk a little about this above, but the importance here cannot be overstated: integration is key. The ability to leverage multiple point solutions, such as access control systems and video surveillance cameras – regardless of manufacturer – provides growing companies with the ability to scale quickly and more efficiently than ever before. Centralising the ability to pull these solutions into a single security operations management platform allows security pioneers a better view of their security programs in a current – and even future – state. Cloud-based solutions can provide the ultimate scalability factor, providing flexibility and accessibility advantages compared to traditional on-premise systems. Cloud-based, or Software-as-a-Service (SaaS) platforms, can easily scale up or down based on changing needs, accommodate distributed environments, and provide remote access and management capabilities, making them well-suited for scalable physical security deployments. Data-driven insights and analytics can drive decision-making beyond security, making technology investments that provide these critical. Automated workflows, event-triggered alerts, and AI-driven analytics can streamline security processes, improve threat detection capabilities, and reduce manual intervention, enabling security teams to manage larger environments more efficiently. Centralised management of technology investments can create cohesion for security teams. Centralised management and monitoring of physical security systems across multiple locations or facilities enables personnel to efficiently oversee and control security operations, access controls, and incident response activities. Being able to manage security in a single platform provides security pioneers with the ability to assess staffing levels, streamline training, allocate resources effectively, and scale to additional sites and/or solutions as needed. Tasked with building a security program that can adapt to the changing needs of the organisation, security pioneers must consider a number of factors when setting strategy. First and foremost, taking a close look at the existing program to identify strengths and weaknesses, then truly assessing the technology and processes in place, is the best way to move forward and future-proof the organisation.
Security beat
2025 was another impactful year for mergers and acquisitions (M&As) in the security industry, which is undergoing an enormous transformation as global pioneers prioritise specialised technology to drive future growth. The year 2025 has been defined by massive corporate reorganisations, most notably Honeywell and Resideo spinning off core divisions to unlock shareholder value. Simultaneously, an aggressive wave of mergers and acquisitions is reshaping the landscape, with giants like ASSA ABLOY and Motorola Solutions absorbing innovators in AI-driven surveillance, cloud-native access control, and identity management. From residential security shifts to critical infrastructure enhancements, this article will summarise how these strategic moves signal a decisive industry pivot toward integrated and intelligent security ecosystems. Resideo to spin off ADI business Resideo Technologies, Inc. announced its intention to separate its ADI Global Distribution business from its Products & Solutions (P&S) business via a tax-free spin-off to shareholders. The separation is expected to be completed in the second half of 2026. P&S will continue as Resideo, a building products manufacturer of residential controls The goal is to unlock value, enhance operational performance, and improve strategic flexibility for both entities. After the separation, P&S will continue as Resideo, a building products manufacturer of residential controls and sensing solutions. ADI will become an independent public company and remain a global wholesale distributor of low-voltage products, including security and audio-visual solutions. Honeywell separates into three companies There are big changes pending at Honeywell, another global security industry company. Honeywell announced plans to separate its Automation and Aerospace businesses into two independent, publicly traded companies following a comprehensive portfolio evaluation. Combined with the previously announced spin-off of Advanced Materials, this strategy will create three distinct industry pioneers. The Automation and Aerospace separation is targeted for completion in the second half of 2026 as a tax-free transaction for shareholders. The largest portion of Honeywell’s traditional security business (cameras, access control, and fire safety) sits within the Building Automation segment of the new Honeywell Automation company. This unit includes products from recent major acquisitions, such as LenelS2. SimpliSafe’s new chapter SimpliSafe has agreed to be acquired by private equity firm GTCR from Hellman & Friedman SimpliSafe has agreed to be acquired by private equity firm GTCR from Hellman & Friedman, another private equity firm. As the third largest U.S. residential security provider, SimpliSafe will continue under the leadership of the current CEO, while its founders remain significant investors. GTCR, an experienced security industry investor, intends to support the company’s expansion and continued innovation in AI-powered, DIY home protection. This marks a new chapter in SimpliSafe’s mission to provide professional monitoring without long-term contracts. SimpliSafe is GTCR’s fifth investment in the security alarm industry, including prior investments in residential-focused security companies SecurityLink and Protection1, along with commercial-focused security companies HSM and Everon. Motorola grows technology portfolio Motorola Solutions grew its portfolio through acquisitions in 2025. The industry giant strategically expanded its safety and security ecosystem through the acquisition of four specialised technology firms. The company acquired Blue Eye to integrate AI-driven remote video monitoring and 24/7 security operations into its threat detection workflows. To support frontline workers, Motorola added Theatro’s voice-powered communication platform, which complements existing mobile and video technologies. Motorola further bolster its public safety capabilities with the acquisition of RapidDeploy, a cloud-native Next Generation 911 provider that offers real-time caller mapping and data analytics to accelerate emergency responses. Motorola also agreed to acquire InVisit to enhance its Avigilon Alta suite with cloud-based visitor management, streamlining guest registration and blocklist screening for enterprise security. These acquisitions aim to unify detection, communication, and response across various sectors, including retail, healthcare, and critical infrastructure. Allied sells majority stake in AMAG Allied Universal sold a majority stake in AMAG Technology to Shore Rock Partners In December, Allied Universal sold a majority stake in AMAG Technology to Shore Rock Partners. Shore Rock is a growth investor focused on critical infrastructure, with strategic backing from BellTower Partners. Allied Universal will retain a significant minority share. The sale is intended to allow 54-year-old AMAG, which provides integrated access control, identity, guest, and video management solutions, to operate independently from Allied Universal's services-based model for long-term growth. Shore Rock's plan is to invest in advancing AMAG's product line and customer relationships. With this transaction, David Sullivan, AMAG's President, will become CEO. Everon acquires ADT multifamily segment Commercial security provider Everon announced in September that it had entered into a definitive agreement to acquire the business-to-business (B2B) multifamily segment from ADT. This acquisition is a strategic extension that expands Everon's reach in the valuable multifamily market. It will allow the company to offer a more comprehensive portfolio of tailored solutions, including access control, video surveillance, and self-guided tour capabilities. Everon's CEO states that the deal enables them to help property owners and managers increase net operating income and improve operational efficiency. Dormakaba acquires TANlock and Avant-Garde Dormakaba, a global provider of access solutions, acquired TANlock GmbH in July Dormakaba, a global provider of access solutions, acquired TANlock GmbH in July. TANlock is a German firm specialising in innovative high-security access solutions for data centers and other critical infrastructure. The acquisition strengthens Dormakaba’s presence in the data center market. TANlock's intelligent system provides enhanced server cabinet security using electromechanical rack locks and various authentication modules. This solution is scalable, future-proof, and can be integrated into existing IT infrastructures for both retrofits and new installations. Dormakaba also agreed to acquire Indiana-based Avant-Garde Systems Inc. to strengthen its North American entrance control portfolio. This move bolsters Dormakaba’s presence in high-growth sectors like airports and data centers. Acre acquires REKS for AI Recent M&A activity also reflects the growing importance of artificial intelligence. For example, Acre Security acquired REKS, a purpose-built generative AI solution designed to transform access control, allowing professionals to use natural language queries for instant data insights. Integrated into Acre’s cloud-native ecosystem, this AI-powered platform prioritises data privacy while streamlining operations. Led by a new AI Development Team, Acre plans to expand these capabilities into intrusion detection and visitor management. Two acquisitions for Allegion Global security provider Allegion, through one of its subsidiaries, completed the acquisition of ELATEC Global security provider Allegion, through one of its subsidiaries, completed the acquisition of ELATEC, a manufacturer of security and access technology, specialising in RFID credentials and readers solutions designed in Germany and sold globally. ELATEC’s portfolio of readers leverages their internally developed software stack and ensures compatibility with nearly 100 credential types, making the company a pioneer in interoperability, which aligns well with Allegion’s partner-of-choice strategy. Allegion, also through one of its subsidiaries, acquired Brisant Secure Limited, a security hardware provider in the United Kingdom. Senstar acquires Blickfeld for LiDAR sensors Senstar Technologies Corporation has agreed to acquire Blickfeld, a specialist in 3D LiDAR sensors and software. Expected to close in Q1 2026, the acquisition integrates Blickfeld’s hardware into Senstar’s advanced security ecosystem. This strategic move expands Senstar’s addressable market into volume monitoring and traffic applications while enhancing its AI-powered situational awareness capabilities. Following the transaction, Blickfeld will operate largely independently as a subsidiary. ASSA ABLOY continues acquisition spree Global giant ASSA ABLOY was probably the most active company in the M&A market in 2025 Global giant ASSA ABLOY was probably the most active company in the M&A market in 2025, demonstrating aggressive market growth, strategically reinforcing its core business, and expanding its technological footprint across the global security marketplace. The acquisitions delivered on the company's strategy to strengthen its position in mature markets by integrating complementary products and solutions. A major theme for ASSA ABLOY was the enhancement of the door and perimeter security portfolio, particularly in the Americas. This effort included acquiring US-based Metal Products Inc. (MPI) for custom-made hollow metal doors and frames and International Door Products (IDP) for fire-rated steel door frames, both in the fall. Earlier in the year, ASSA ABLOY gained a stronger presence in Central Canada with the addition of Wallace & Wallace and Wallace Perimeter Security, a manufacturer, distributor, and installer of perimeter fencing, door, and gate solutions. The Entrance Systems Division also saw expansion with the acquisition of Belgium’s Kingspan Door Components, a manufacturer of sectional door panels. Furthermore, Door System, a Danish manufacturer of high-quality fire-rated doors, was signed for acquisition in the spring. Cloud-based platform ASSA ABLOY also made significant moves in electronic and access control solutions. Early 2025 saw two key acquisitions: Uhlmann & Zacher, a German supplier of access control handles and knobs, and InVue, a US-based provider of connected asset protection and access control solutions. Reinforcing this segment, SiteOwl, a pioneering cloud-based platform for physical security lifecycle management, was acquired in the summer. The spring acquisition of Pedestal PRO, a US manufacturer of access control pedestals and mounting solutions, further strengthens the electromechanical offerings in the Americas. ASSA ABLOY bolstered its capabilities in remote care technology with Germany’s TeleAlarm Group in late spring. HID Global expands in 2025 HID Global, a subsidiary of ASSA ABLOY, was also active on the M&A front in 2025 HID Global, a subsidiary of ASSA ABLOY, was also active on the M&A front in 2025, aggressively driving the convergence of physical and digital identity solutions and signaling a clear roadmap for security professionals. HID's move to purchase Vancouver-based IDmelon, announced in the autumn of 2025, targets the critical need for robust logical access control. IDmelon’s proprietary software platform transforms everyday identifiers, including existing physical credentials, smartphones, or biometrics, directly into enterprise-level FIDO (Fast IDentity Online) security keys. This approach streamlines an organisation’s transition to phishing-resistant, passwordless multi-factor authentication (MFA) and minimises the need for disruptive changes by integrating physical and digital access into a single, cohesive solution. Safer patient experience Separate from its focus on digital access, HID also bolstered its Identification Technologies Business Area by acquiring the Calmell Group. Calmell is a long-established manufacturer specialising in smart cards, smart paper, and magnetic tickets for the public transportation sector. This addition is expected to expand HID’s footprint and relevance in global public transportation ecosystems, allowing the Barcelona-headquartered firm to leverage HID’s core expertise in digital credentials to drive future-proof solutions for seamless mobility. Also, HID acquired Intelligent Observation to expand its Healthcare Real-Time Location Systems (RTLS) portfolio. Intelligent Observation provides a platform to reduce hospital-acquired infections (HAIs) by tracking hand hygiene compliance. The system uses wearable Near-Field Magnetic Induction (NFMI) devices and a cloud-based SaaS dashboard. This technology records and reports if healthcare workers sanitize appropriately, providing granular compliance data to administrators to enable a safer patient experience.
The practice of executive protection changed forever on Dec. 4, 2024, when UnitedHealthcare CEO Brian Thompson was shot outside a Manhattan, New York, hotel. The shocking event raised awareness in board rooms around the world about the need for, and challenges of, executive protection. Questions followed immediately, including why was the high-level executive not protected? Combination of risk and reward UnitedHealthcare’s stock price has gone down more than 20% since the shooting The event also highlighted what is at stake for companies, extending beyond the safety of executives and impacting many factors, even including a company’s stock price. UnitedHealthcare’s stock price has gone down more than 20% since the shooting, equating to tens of billions of dollars. “Companies are considering the combination of risk and reward like never before when it comes to executive protection,” says Glen Kucera, President of Allied Universal Enhanced Protection Services. “What are the chances this could happen? Before Dec. 4 many thought it was zero. And what are the financial implications for a company if it happens? Executive protection is a small investment to protect against a worst-case scenario.” Evaluation of an executive protection Before the UnitedHealthcare shooting raised awareness, fewer than 50% of executives had protection. But concerns that previously fell on deaf ears now have the full attention of companies, says Kucera. “Boards of directors are having to figure this out,” he adds. “They may not have executive protection, but now they have to do it.” A threat assessment, conducted by a company such as Allied Universal, provides an independent evaluation of a company’s executive protection needs. The assessment evaluates factors such as an executive’s travel habits, the safety of their home, etc. Does the executive need protection 24/7, or just when they travel into more dangerous areas? Risks increase related to corporate earnings Sometimes, cases increase the need for executive protection, such as an internal threat In assessing threats, security professionals also look beyond the individual to consider the safety of a corporate facility, for example. “Is there a visual deterrent, controlling who comes and goes?” asks Kucera. “If there is good security, it all ties together. We do home assessment, facility assessment, route assessment, and travel assessment as needed.” Sometimes, circumstances increase the need for executive protection, such as an internal threat. Timing is a factor, and risks increase related to corporate earnings releases, new product announcements, and corporate layoffs or consolidation. Monitoring social media tracks shifting threats that impact the need for executive protection. UnitedHealthcare shooting “He didn’t have it and probably didn’t think he needed it,” comments Kucera about the UnitedHealthcare executive who was gunned down in the streets of New York City. “He was staying at the hotel across the street and was used to walking down the street every day.” “Sometimes executives want to preserve their privacy and be able to walk down the street,” says Kucera. “Getting protection can be seen as a sign of weakness. Some CEOs in the past have said they just didn’t want it.” However, the UnitedHealthcare shooting raised the stakes of the need for more vigilance. “The bottom line is you have to yet beyond objections and make the investment to protect against a worst-case scenario,” says Kucera. Anti-capitalist sentiment in the general population An internal police bulletin warned of an online hit list naming eight executives and their salaries Threats to executives sometimes arise from anti-capitalist sentiment in the general population about perceived inequalities in wealth and power. Executives provide symbolic targets for anyone who fights the system, and social media has amplified the voices of those who oppose capitalism. For example, a "Most Wanted CEO” card deck seeks to shine a spotlight on "titans of greed." Also, in the aftermath of the UnitedHealthcare shooting, CEO "wanted" posters appeared across New York City, threatening various executives of large companies. An internal police bulletin warned of an online hit list naming eight executives and their salaries. Careful monitoring of social media posts Careful monitoring of social media posts and other sources enables executive protection professionals to analyse data and separate the dangerous threats from the merely negative ones. Sadly, positive support of the UnitedHealthcare shooting was expressed by the 300,000 or so followers of the shooter, who became a celebrity of sorts. A huge outcry of negative sentiment toward the insurance industry led to fear that copycat incidents might occur. “There has been an unprecedented amount of positive support for committing murder,” commented Kucera. Executive protection requests HR executives can be at risk, especially at a time of layoffs or consolidation “Let’s face it, there has been a lot of controversy, from COVID to the Middle East crisis, to the political campaign, and there is negativity on both sides,” says Kucera. “People have opportunities to pick sides, and there is a lot of sentiment going both ways, and there is a small percentage of people who will act aggressively.” Executive protection requests now extend beyond the CEO to include others in the management ranks of companies. Basically, any public-facing executive is at risk, including anyone who makes statements to the press. Human resource (HR) executives can be at risk, especially at a time of layoffs or consolidation. Private information on the Internet Typically, an executive is assigned a single armed operative for protection. The firearm serves primarily as a visual deterrent that hopefully makes a potential perpetrator think twice. “When they plan an event like this, their expectation is that it will be a soft target,” says Kucera. “If there is an officer, it gives them pause.” Controversial or high-profile CEOs are typically protected 24/7, including when they travel with their family. Adding risks is the fact that private information is now posted on the Internet, including where an executive lives and where their children go to school. Internet monitoring Internet monitoring also includes the “dark web,” which includes sometimes dangerous information “We offer social media monitoring, and we advise them to be more careful with what they post,” says Kucera. “We monitor reactions to posts including any that might be threatening. We watch social media carefully if a company announces earnings or a change in their service or product offering.” Internet monitoring also includes the “dark web,” which includes sometimes dangerous information that is intentionally hidden and requires specific software, configurations, or authorisation to access. Own layer of protection Public and government officials can also come under fire in a variety of scenarios. FEMA officials faced threats after the recent floods in the Southeast, for example, among other situations where perceived unfair treatment promotes thoughts of retribution. Although government agencies have their own layer of protection, there are instances when they call on companies such as Allied Universal for additional help. Ad hoc protection for various executives In the aftermath of the UnitedHealthcare shooting, calls to Allied Universal’s Command Centre increased by 600%, reflecting requests for ad hoc protection for various executives. These requests are in addition to the company’s business providing “embedded” operatives that travel with executives all or some of the time. On that side of the business, requests for services are up probably 300%, says Kucera. {##Poll1742194323 - Has the recent increase in violent threats changed your company's view on executive protection?##}
Big news on the mergers and acquisitions (M&A) front is closing out 2024, a year in which several shifts changed the face of the physical security manufacturer community. Announced in December, German giant Bosch Group is selling its Building Technologies division’s product business for security and communications technology to the European investment firm Triton. Bosch division selling to Triton The transaction encompasses three business units – Video, Access and Intrusion, and Communication – and thus the entire product business of Bosch Building Technologies that was offered for sale. All 4,300 associates employed in these units at more than 90 locations worldwide will be taken over. The transaction reflects a growing confidence in the security market among private equity companies such as Triton, Becklar, and Volaris. Sharing best practices Acre Security and Bosch will remain independent, standalone companies under Triton’s ownership Acre Security, previously acquired by Triton, has benefited from Triton’s strategic guidance and expertise, according to the company, which is confident Bosch will experience the same level of support and opportunity to thrive. Acre Security and Bosch will remain independent, standalone companies under Triton’s ownership, but will benefit from the potential to collaborate and share best practices as part of the broader Triton portfolio. Resideo acquires Snap One Earlier in 2024, there were other large M&A transactions. In the spring, Resideo Technologies, Inc., a manufacturer and distributor of technology-driven products and solutions, agreed to acquire Snap One Holdings Corp., a provider of smart-living products, services, and software to professional integrators. The transaction is valued at $1.4 billion, inclusive of net debt. Upon closing, Snap One becomes part of Resideo's ADI Global Distribution business. Honeywell buys Carrier’s Access Solutions In late 2023, Honeywell announced plans to enhance and strengthen its building automation capabilities with the acquisition of Carrier Global Corporation’s Global Access Solutions business for $4.95 billion, in an all-cash transaction. The acquisition, which played out through 2024, includes both hardware and software solutions, adding three respected brands to Honeywell’s portfolio with a focus on life safety and digital access solutions. Acquired brands include LenelS2, commercial and enterprise access solutions; Onity electronic locks; and Supra cloud-based electronic real estate lock boxes. Hirsch reemerges as an iconic brand The Identiv sale was originally announced in April, subject to regulatory approval Identiv announced plans to sell its physical security business and assets to Vitaprotech, the security solutions provider that also acquired British manufacturer, TDSI, in 2019. The Identiv sale was originally announced in April, subject to regulatory approval. As a result of the sale, Hirsch, a global security technology pioneer advancing physical security, video intelligence, cybersecurity, and digital identification solutions, announces the relaunch of its iconic brand and strengthened focus on the industry’s most complete high-security, end-to-end platform. Ease of use security solutions The move seeks to reposition Hirsch as the global pioneer in physical security, video intelligence, and identity solutions, protecting everything from small enterprises to critical national infrastructure. With a 43-year-strong foundation in the industry, Hirsch’s mission has always been empowering a secure, connected world, combining government-grade high security with ease of use. Milestone and Arcules unite Effective July 1, 2024, global video technology company Milestone Systems announced its merger with the cloud-based video surveillance solutions provider, Arcules. Both companies are owned by Japanese multinational Canon Inc. Based in Irvine, Calif., Arcules was spun off from Milestone in 2017. The merger brings together Milestone and Arcules’ best-in-class capabilities within video management software (VMS), video analytics, and video surveillance as a service (VSaaS), providing a complete video technology offering. More M&A stories in 2024 In other M&A moves in 2024, cloud-based workforce management software provider Synerion USA Inc. acquired cloud-based video surveillance and access control solutions platform Qumulex Inc. Also, the global pioneer in airspace awareness and security, Dedrone, became part of the public safety and technology company Axon. The acquisition unites two companies with a shared mission to improve public safety and national security by staying ahead of persistent and escalating threats, enabling faster, more effective responses and ultimately protecting more lives in more places.
Case studies
Security chiefs nationwide are addressing emerging workplace issues of white-collar crime and computer security. Theft, by internal and external perpetrators, has taken on a new and expensive face with the advent of lightweight computers. On site slips, falls and vehicular accidents lead to expensive liability lawsuits. Increasing pressure on the bottom line has led many security chiefs to turn to contract labor, which offers its own set of supervisory challenges. Security magazine stated “At least seven in 10 of their readers use private protection officers…and more than one in three of these respondents say they use more security officers than they did three years ago.” Monitoring equipment temperatures These changes have occurred in an era of economic growth where corporate mergers and acquisitions are commonplace. Over a relatively short period of time, the security chief is likely to see the size and make-up of the buildings and workforce change, dramatically. A new list of threats, increased reliance on contract labour, and rapid changes in scope and responsibilities force security chiefs to demand more of the security systems they use. Client: When David Weihe, Chief of Corporate Security, joined Kentucky Fried Chicken in 1992, he inherited a thirty-five-station guard tour system that was worn out and problematic. Weihe had a large area to protect – two buildings totaling 325,000 square feet on 35 square acres in Louisville, KY. He also had special responsibilities, such as monitoring equipment temperatures. In addition, one of the two KFC buildings lacks a sprinkler system, so fire extinguisher checks are crucial. Largest restaurant system When Weihe joined the company, KFC’s corporate parent was PepsiCo, Inc. In January 1997, PepsiCo, Inc. announced the spin-off of its quick service restaurants – KFC, Taco Bell and Pizza Hut – into an independent restaurant company called TRICON Global Restaurants Inc. TRICON (NYSE: YUM) is the world’s largest restaurant system with nearly 30,000 restaurants. Weihe is now responsible for all of TRICON Global’s corporate locations, including the restaurant support center in Louisville, which employs more than 1,200. The physical sites include two original KFC buildings, which house KFC’s Research and Development unit, a document management center, and another processing facility. He uses 14 contract security officers to maintain a 24/7 presence. Universal product indicator Project: Back in 1992, Weihe knew that he needed a guard tour system that was robust and expandable with state-of-the art data capabilities. Handheld units had to be slim-line, user friendly and tough enough to withstand stand up to constant use by a variety of personnel. The system’s software had to offer fast, comprehensive reports that would help Weihe pinpoint incidents and keep track of every contract employee on every shift and every checkpoint station. Weihe considered several solutions. He rejected systems that required officers to carry multiple pieces of equipment – strips or buttons – because he considered them complicated and difficult to maintain. He also rejected systems based on UPC (universal product indicator) codes because he considered them too fragile. In 1993, and again this year, Weihe chose a Morse Watchman guard tour system. Management patrol software Provider: The Morse Watchman tour guard system is made up of three components: designated checkpoint stations, placed in fixed locations throughout the facilities, a handheld data recorder carried on rounds and uses to check into the key stations and record information; and management patrol software, which converts data recorder information to printable custom reports. Morse Watchman guarantees its checkpoint stations for life. They’re built out of impact-resistant Lexan(r), the material used for professional football helmets. The PowerCheck 3002, which Weihe upgraded to this year, features Auto Pilot, a user selectable option that displays the next station to visit. The system also gives the customer the option of preprogramming up to 99 different incident reports, all of which can be keyed in by officers on tour. Implementation: When the PowerCheck system was ready, training proved simple, thanks to documentation provided by Morse Watchman and the fact that most of the new system’s checkpoint stations were placed in the same locations as the old. Four different tours Using the system’s Auto Pilot feature, Weihe has programmed four different tours, three of which guide officers to stations in specific order. The fourth records tour data in random order. In any given week, Sunday through Saturday, Weihe’s officers run close to 50 tours, which equals 3,000 station checks per week. The new PowerCheck 3002 system can hold up to 8,000 transactions before it must be downloaded. Benefits: It didn’t take long for Weihe’s contract security officers to appreciate the PowerCheck 3002. “They like the fact that the holster used to hold the recorder has got a clip or an arm-band, offering more options for comfort. The recorders are lighter. The key stations are smaller, and the officers are able to record temperatures of coolers, freezers, and other equipment right into the recorder,” Weihe admitted. Providing details of problems In fact, Weihe’s Morse Watchman system has increased the efficiency of the company’s maintenance staff. The maintenance incident report Weihe downloads from the system is essentially a work order, providing details of problems. The system’s ability to record a myriad of incidents helps in other unanticipated ways, such as when contract cleaners don’t put wet floor signs down after mopping up. Weihe expects his officers to record such data, as well as put down a floor sign. If someone complains they have fallen because of a wet floor, Weihe has hard data to prove who is actually responsible. Variety of contract personnel The biggest result of the Morse Watchman system, though, is to help Weihe make sure his contract security officers are on the job, where they should be, when they should be. The effect, Weihe feels, has been to help keep security incidents to a minimum at TRICON Global, because the system helps ensure a security presence that, while not predictable, is predictably strong. Weihe sets a schedule for his officers so those tour patterns are not created. All in all, Weihe is pleased with the Morse Watchman system, and its reliability. His two recorders are used 24/7 by a variety of contract personnel. Weihe said the system’s handheld recorders have proven to be durable. “They have to be severely knocked around to crack the LCD display,” Weihe told. In the past, when a recorder was damaged, Morse Watchman loaned him a free spare, shipped overnight, until his unit had been repaired. Guard tour system Satisfaction: Weihe fits the definition of a satisfied customer. He bought a Morse guard tour system, used it for seven years, then upgraded this year. He’s found the company to be supportive at every turn. “I can say that it has always been extremely pleasant,” Weihe voiced of his communications with Morse Watchman. As for the system itself, Weihe announced, “I haven’t seen one that could beat it, so until I hear even remotely of something, it’s going to be Morse Watchman products.”
When it comes to balancing visibility and spending, Security Incident Event Managment (SIEM) licencing models can be somewhat restrictive—something a multinational, born in the cloud technology company was becoming painfully aware of. The organisation wanted to improve its security posture by ingesting more data feeds into its SIEM. However, its cybersecurity team found itself hampered by licence limitations and prevented from feeding in more data by licence utilisation caps. Faced with excessive additional licencing costs, the company needed an alternative solution that would optimise the ingestion of data, reduce licence usage, and boost visibility across its environment—without breaking the bank. Enter Cribl Looking for the best solution to achieve their data goals, the company reached out to cybersecurity company RiverSafe for advice. Given its ability to optimise, route and enrich data, Cribl was chosen as a possible fit, and RiverSafe began a proof of concept to investigate the potential impact the product could have on the company’s data streams. “We chose four data sources, and deliberately chose some of our most volumetric data sources. We had a success criterion in mind, and that was to send all these data sources to our SIEM environment via Cribl and see what kind of reduction we could get from a percentage perspective,” the head of security programme management said. “It’s seemed to be a very good product and much needed in the marketplace. There are many organisations like us who have the same kind of challenges and the same use case issues, whereby they don’t have the budget or inclination to spend more and more money on their SIEM.” Instant data ingestion reduction After a successful proof-of-concept, the company opted to implement Cribl Stream. “I know (Cribl Stream) and I knew its capability, so I had an inkling as to what the reduction rate could potentially be. What really surprised me was how easy it was to reduce the data feeds into the SIEM. I was really shocked at how seamless it was to introduce a layer like Cribl to assist with the data optimisation and reduction.” After implementing Cribl Stream as an optimisation layer, the company reduced the amount of data being fed into its SIEM from around 750GB to 450GB. “We were able to reduce our data ingest by about 40%, which matched our original success criteria around the percentage we hoped to reduce the data ingestion by. More importantly, what we were reducing were largely blank fields and null values, content that didn’t feed into our detection rules. We’re able to gain this headroom and cost savings without sacrificing visibility or increasing risk.” Streamlining data ingestion An additional benefit the company experienced post-implementation was streamlined data ingestion. By pointing data through Cribl, the company is able to cherry-pick the data that’s sent to its SIEM, simplifying the onboarding process for new data feeds. “Once we’ve pointed the data to Cribl, we’re able to pick and choose what data we send into the SIEM and what data we don’t. That’s made it a lot more efficient in terms of the way we onboard data, and it’s enabled us to be a lot more granular with the data that we ingest into our SIEM.” Greater scalability With the reduction in data ingestion levels, the company is less likely to run into issues due to SIEM licencing limitations. By employing Cribl to help manage its data, the company hopes to benefit from greater scalability and agility in the future. “Going forward, we’ll have scalability from a visibility and coverage perspective without being constrained by a SIEM licence.” This flexibility is just one of the wide-reaching benefits that the company has experienced since implementing Cribl, and one that’s made a major difference to its operations. “Cribl gives you the flexibility to reduce data ingest, but also the flexibility to be agile and to move your data sources from one environment to another without much configuration. It’s given us the capability to be less rigid in our architecture; that’s been the biggest impact for us.” Significant cost savings Having cut data ingestion by 40% with Cribl Stream, the company is free to load more data feeds into its SIEM without the need to purchase additional licencing capacity. This has not only allowed the company to increase visibility across its digital environment, but also cut down on licencing costs. “Now that we’ve got Cribl in our architecture, we have the ability to ingest more data feeds without having to buy additional licencing—that’s already saved us money. If we didn’t have Cribl, that additional cost would have been between £120,000 and £150,000 per year, on top of what we’re already paying today for our SIEM.” As well as reducing spending on SIEM licencing, the company has been able to cut costs in other areas. “We’re completely in the cloud, so we’re charged for data that we retain for a longer period. Now that we have Cribl, we can send the data that we want to retain to a cheaper storage solution. And with Cribl Replay and Cribl Search, we still have the ability to easily search that data should we need it for audits or incident investigation. That gives us a cost benefit and more flexibility in the long run.” Smarter resource utilisation Cribl is also helping the company put its valuable resources to better use by cutting down on manual data management tasks. Previously, its team had to configure multiple destinations when data was ingested. With Cribl, data from various locations can be ingested once and pointed to numerous locations around the business, eliminating the need for system and platform owners to configure multiple endpoints. FTE effort to implement a data feed “Normally, it would’ve taken us about two days of FTE effort to implement a data feed into Splunk or a similar destination. Since the introduction of Cribl, we’ve cut that down to half a day because now we only need to configure to send to Cribl and Cribl takes care of translating the data into the ideal format for other destinations.” This reduction in time and labour adds up to additional cost savings too. Now, the company can send just the data that’s relevant to a particular end user, rather than shipping the entire data set. This has helped save money on licencing, infrastructure/compute, processing, and effort. “Because we’re a cloud-native organisation, processing costs money—if we’re able to save on that, then we are definitely winning from a cost perspective.”
The client, a pioneering Oil and Gas company, had formed a large central IT capability after many years of mergers and acquisitions. The team had an established on-premise capability, but it was made up of multiple siloed teams and disjointed processes. The company had been progressing a modernising cloud-first approach but had duplicated the organisational and process-based model they had on-premise during the process. Business-focused development teams The resulting cloud offering improved provision times from 4-6 months to 4-6 weeks but there were still huge inefficiencies that were limiting the ability of business-focused development teams to deliver value quickly. The head of the trading division product development teams asked RiverSafe to provide a secure, resilient, consistent and scalable solution that would empower developers in their business segment. Customer requirements The customer requirements were: To be able to provision our own ‘infrastructure’ without relying on handoffs to multiple teams. To accelerate the infrastructure process. “We want hosting of services in minutes not weeks.” To improve our time to market for our products. To minimise downtime. To be able to experiment. All of this with higher levels of embedded security, higher quality and higher resilience. The solution RiverSafe was engaged to help resolve these frustrations and pain points through the implementation of a DevOps approach. They started by value-streaming the existing process, creating automation to replace manual processes, and sizing the application estate to determine what their application needs were. They chose a kubernetes cluster as our target architecture. In this instance, Openshift was the best fit for their needs as most of the existing application estate uses RedHat products. They worked in two teams – one building the ‘platform’, one building a pipeline that could deploy assets into the platform in a secure manner. The platform team The container platform team delivered a platform that had high availability embedded. This provided the capability to significantly reduce downtime by allowing Kubernetes and the terraform modules to scale up and down nodes, pods, and routes automatically based on events occurring within and outside the cluster. Chaos testing was embedded to ensure that previously catastrophic events could be created to ensure service architecture could accommodate these failures within the stated non-functional requirements. The pipeline team In the previous working model, developers were using various tools, leading to a lack of control, and making the overall management of the process very difficult. To resolve these issues, the pipeline team delivered a reference Continuous Integration & Continuous Delivery (CICD) pipeline. This included all the DevOps best practices and ensured fully automated build and deployment flow through environments to production, including security scans, testing and automated change processes. New users with a new pipeline With this pipeline, developers can quickly and easily provision services and components for their applications in just seconds (rather than weeks). Developers have the assurance that they are consistently delivering compliant and tested code which has undergone stringent security scanning at each stage of the process. The team also worked to automate the automation. They built a self-service process to allow new users with a new pipeline along with automatic onboarding to all of the DevOps tool chain. This includes accounts and permissions allocated within the container cluster stored in a secrets vault. Where this process for onboarding new teams and users used to take four weeks it now took 30 minutes. Initial proof of concept and implemented changes This new approach is repeatable and consistent and ensures that new team members and projects have the tools they need right from the start, without unnecessary delays or wait times. It also means that if changes to a particular tool are needed, these can be rolled out to all existing teams with minimal impact on project timelines. With each of these solutions, we started with an initial proof of concept and implemented changes in a small area, iterated to make sure we improved, and then rolled out to the wider business, improving all the time. The outcome The impact on the business of these changes has already been huge. The previous time wasted for developers to get the tools and provisions they needed has been eliminated with infrastructure able to be spun up in seconds and new developers able to start building code in under 30 minutes (as opposed to several weeks). Over the course of the project, this has meant a saving of more than 25,000 engineering days to date. The standardisation has meant that managing the software delivery process has become much easier. Prior to the introduction there were numerous support requests to the tools and platform teams due to software build issues. We provide well-documented standards and, as everyone was working on the same pattern, the technology transfer across the organisation was vastly improved. Impacting container platforms and tooling As a result, all of these support requests stopped and the teams could focus on the operational incidents impacting container platforms and tooling. Currently, 735 services have been onboarded, which spanned 56 projects and 1074 repos. The pattern was applied to 1608 pipelines and those pipelines were run 235,000 times. But key for the business has been the cost savings, which so far have amounted to over £17m over a three-year period. And are still increasing as this is rolled out further within the business.
In the wake of a significant merger between two major telecommunications companies, the client, a newly formed telecom giant was looking to unify and modernise security operations across the entire organisation. The merged entity needed to increase asset visibility for its critical business operations, reduce the sprawl of security tooling, and unify its systems. Additionally, the company was looking to improve its overall monitoring capabilities while addressing a substantial amount of technical debt that had accumulated both pre- and post-merger. This transformation would not only optimise operations but also ensure continued compliance with industry regulations. Recognising the complexity of this project, the client decided to bring on RiverSafe due to the specialised expertise and experience with SOC and SIEM transformation projects. The solution The programme of work began with a series of collaborative workshops, fostering a deep understanding of the company’s vision for its future security landscape. During this discovery stage, the RiverSafe team uncovered 12 legacy SIEMs existing within the organisation. They began by consolidating a major cloud-based security platform, evolving it from three separate instances to a single, unified platform. This consolidation included integrating cutting-edge single sign-on capabilities, incorporating new data sources, and seamlessly migrating existing data parsers, dashboards, and lookups. Data management and routing To enhance data management and routing, RiverSafe implemented Cribl, a sophisticated data streaming platform. This allowed for efficient routing of data feeds to multiple destinations and enabled complex data transformation operations, providing the telecom company with greater flexibility and control over its data. The RiverSafe team further identified an opportunity to optimise the existing SIEM infrastructure and devised a strategic plan to consolidate operations onto two robust platforms: a cloud-based security operations platform for general use, and an on-premises SIEM solution to meet specific regulatory compliance requirements. The outcome The impact of this transformation was substantial. By optimising its SIEM platforms, the telecom company significantly improved its operational efficiency and security visibility. The streamlined infrastructure opened up new avenues for automation and data enrichment, further enhancing the company’s security capabilities. The implementation of the data streaming solution not only improved data routing efficiency but also led to substantial cost savings in licensing fees. Beyond these immediate benefits, the transformation laid the groundwork for future innovations through increased automation potential. It also further strengthened the company’s compliance with industry regulations and enhanced its overall security posture and monitoring capabilities.
The client, a pioneering oil and gas corporation, faced significant challenges in knowledge management. The software engineering function struggled with locating the right documentation across multiple platforms such as ADO Repo, Confluence, SharePoint, and others. This fragmented system created delays and inefficiencies, with engineers spending valuable time searching for answers rather than focusing on delivery. Slow Access to Technical Information The sheer volume of documentation, continuously growing, compounded the problem. Onboarding tools for cloud services Onboarding tools for cloud services was also cumbersome, often dependent on a “hero culture” where finding the right person for help was the norm. This led to frequent meetings, wasted time, and a negative engineering experience, significantly slowing down workflows. RiverSafe was brought in to improve the engineer experience and increase velocity by enabling engineers to complete tasks more efficiently, reduce reliance on individual knowledge holders, and minimise time spent searching for outdated or misplaced documentation. The solution AI-enabled knowledge discovery They introduced an engineering portal powered by AI and natural language processing (NLP). Using a closed-domain RAG model, this portal introduced a ChatGPT-style interface where engineers could engage in natural language conversations to query documentation and receive consolidated answers, dramatically reducing the time spent locating information. The portal’s capabilities include rich content support such as diagrams, graphs, videos, and even in-platform automation for tasks like tool onboarding, further streamlining processes. The platform draws from multiple high-quality content repositories, creating a unified search experience across ADO Repo, Confluence, Internal document management systems, SharePoint, and more. Crucially, they implemented near-real-time monitoring for key model metrics, ensuring that each user’s question and answer interactions delivers unparalleled accuracy and relevance. This guarantees that the portal continuously provides genuine value through its responses. Recognising the challenges posed by response degradation and hallucinations in AI-driven systems, they have developed a set of innovative solutions designed to optimise each interaction’s impact. The outcome Eliminating wasted time and accelerating software delivery The portal has transformed the way engineers work, saving significant time and boosting efficiency across the board. One engineer commented, “I’ve been here for 15 years, and this is the best product for software delivery in our organisation. Previously, it could take me 2 weeks just to find out how to build a cloud environment. Now I get the answer straight away.” Key outcomes Time and Cost Savings: Engineers now save between 45 minutes and 10 days when searching for technical solutions. The portal has saved the organisation 68,000 engineering hours annually, equating to over £4 million in cost savings within the first year. Improved Document Quality: The platform collects and analyses data on the usefulness and quality of documents. This feedback loop ensures that outdated or low-quality documents are flagged for improvement, keeping the knowledge base relevant and focused on high-value content. High-Fidelity Responses: Engineers receive immediate, detailed responses with links to relevant documentation, images, videos, and graphs. This reduces reliance on outdated information and significantly improves the quality of software delivery. Onboarding and Automation: Engineers can complete tasks directly within the platform, such as onboarding new tools, without needing to switch between systems, further streamlining workflows. User feedback and performance data The portal continues to gather user feedback and performance data, ensuring that it remains an invaluable tool for the organisation, consistently improving the engineer experience and accelerating software delivery. The organisation has also engaged NeuroLogik to build on these successes. NeuroLogik specialises in providing deep insights into entire codebases, ensuring that engineers can easily locate and reuse existing code across the organisation, further enhancing efficiency and reducing duplication of effort.
A major UK retailer known for its quality clothing, home products, and premium food offerings recently migrated their SIEM platform to Microsoft Sentinel, which was integrated with other Microsoft security tools, including Defender. Over the months, multiple configurations had been built up, creating complexity within the system. The alert overload problem After the migration, the SOC (Security Operations Center) team became overwhelmed by a flood of alerts—many of which were false positives. This not only drained their resources but also weakened their security posture, as the team couldn’t thoroughly investigate the flood of alerts. RiverSafe’s solution: Optimising configurations RiverSafe was brought in to address this issue and guide the leading UK retailer on reviewing Microsoft Defender configurations and fine-tuning the Microsoft Sentinel queries. The consultant conducted a thorough review of the existing configurations and provided actionable recommendations to the SOC team. Some changes were straightforward and implemented quickly, while others required collaboration with multiple teams across the organisation—something the SOC team had issues in getting implemented over a few months. Facilitating communication for effective implementation The consultant facilitated communication between the SOC team and other departments, providing detailed documentation and clear explanations of why these changes were necessary. By bridging this gap, they ensured the required changes were finally actioned and documented with high standards. Key impacts Within a few weeks, they achieved the changes the SOC team had been pushing for over the few months, fostering better collaboration between the networking and security teams. Alerts were reduced by 62%, significantly improving team efficiency by cutting out noisy, recurring alerts. The improved configurations enhanced the company’s overall security posture, allowing the SOC team to focus on real threats and respond more effectively.


Round table discussion
Future-proofing your skillset is about embracing continuous learning and developing a versatile set of competencies that remain valuable regardless of technological shifts or industry changes. In the security marketplace, it is not about predicting the exact jobs of the future, but rather equipping yourself to adapt and thrive in the uncertain security landscape. But where to begin? The emerging technology shifts in the security industry provide clues, such as the growing importance of cybersecurity and artificial intelligence (AI). We asked our Expert Panel Roundtable: How can physical security professionals “future-proof” their skillsets to prepare for emerging technologies?
Technology can be a powerful tool, but it can also be misused. Ethical principles help ensure that technology is used in a way that minimises risks and avoids causing harm to people or society. Issues could include factors such as data privacy and algorithmic bias of certain technologies. As the security industry embraces advanced and evolving technologies, we asked this week’s Expert Panel Roundtable: What are the biggest ethical considerations of using emerging technologies in physical security?
As the new year dawns, it's a good time for the security industry to look ahead to 2024. We asked this week's Expert Panel Roundtable: What will be the biggest surprise for security in the year ahead?
Security technologies promote real-time awareness in K-12 schools
Download
Technology's role in securing banks and financial institutions
Download
Integrated systems enable critical and compliant security for transportation
Download
Modernising physical access control
Download
Access. Intrusion. One estate.
Download
