Cybersecurity is often seen as the responsibility of the IT department. IT takes care of passwords, firewalls, updates and system access, while everyone else is expected to follow the rules. Today, this approach is becoming increasingly difficult to maintain.
An organisation’s security environment is no longer limited to computers, servers and cloud services. Video cameras, video management systems, access control equipment, door controllers, smart locks and other physical security solutions are connected to the network. At the same time, people, with their identities, access rights and everyday habits, are part of the same system.
So the question is no longer simply, “How do we protect our IT infrastructure?” The broader question is: how do we manage the risks created by the interaction of people, processes and technology across the organisation?
Security is not one person’s job
Effective information security management can't rely on a single IT or security specialist in the long term. Different people across an organisation see risk from different perspectives. The IT team sees network and system vulnerabilities. Security specialists see physical access and incident risks. HR understands the employee lifecycle - from joining the organisation to leaving it. Business units know which processes and data are critical to day-to-day operations.
Bringing these perspectives together isn't just a theoretical advantage. It helps identify risks that a single department is unlikely to see. For example, when an employee leaves an organisation, their user account may be deactivated in the IT system. But has their access to the office, warehouse, server room or other site been revoked at the same time? It is at these points of intersection that practical security management begins.
Training should reflect real work
Security training can easily become a formal annual exercise. An employee attends a presentation, answers a few questions, and gets back to work. The problem is that security risks are not the same for every role.
For an IT administrator, system accounts, configuration, updates and access rights are critical. For a finance employee, fraudulent emails and payment processes may be more relevant. For security personnel, incident identification, access rights and response are key. Employees who use physical security systems in their daily work also need to know what to do if, for example, an access card is lost or there are signs of unauthorised access.
That is why training based on an organisation’s actual risks and employees’ responsibilities is more useful than one universal programme for everyone.
A security culture needs a simple way to report problems
Even a well-trained employee can make a mistake. What happens afterwards matters more. If people are afraid to report a suspicious email, a lost access card, an unknown person in a restricted area or unusual system behaviour, a minor incident can go unnoticed.
Organisations therefore need a clear and straightforward reporting process. Employees do not need to know whether something is legally classified as an “incident”, “event” or “security breach”. They need to know who to contact and what happens next. Feedback is important too. If employees never see that their reports lead to any changes, their motivation to report problems decreases.
A security culture is not built through posters next to the printer. It is built through how an organisation responds to real situations.
Physical Security Systems Are Part of the Digital Infrastructure
This is one of the most important aspects that is still too often treated separately in security management.
- A video camera is no longer just a camera. It is a network device.
- A VMS is not simply software where a security operator watches cameras. It processes video, user access rights, events and integrations with other systems.
- An access control system is not just a door reader. It processes identity, authorisation and information about who has gained access, when and where.
- An electronic lock, meanwhile, is a physical security element whose operation is increasingly linked to digitally managed access rights.
In its 2025 technical guidance, ENISA addresses physical security, access control and asset management alongside other cybersecurity measures. The guidance specifically emphasises the need to prevent and monitor unauthorised physical access to network and information systems.
This does not mean that every video camera automatically becomes a “cybersecurity system”. It means something more practical - physical security infrastructure needs to be included in the organisation’s overall IT and security risk management.
VMS Security Starts with the System Itself
In video surveillance, attention is often focused on the cameras, but the video management system, user permissions, authentication and system configuration are equally important. Digifort’s latest 7.4.x versions include several cybersecurity-related mechanisms, including the ability to require users to change their password at first login, security configuration for HTTP/RTSP/RTP protocols, TLS 1.2 for email, software code signing and OTP authentication functionality.
However, it is important not to overstate the role of any single product. Even built-in security features cannot replace proper system configuration, updates, user access management and network architecture. A secure VMS depends not only on what the manufacturer has built into the software, but also on how the system is deployed and maintained.
When video surveillance and access control start working together
In larger organisations, the challenge is often not one system, but several systems that are not connected to each other. The camera sees an event. Access control knows which card was used. The intrusion system raises an alarm. The operator then has to piece all this information together.
A unified platform approach can simplify this process. For example, Genetec Security Center SaaS brings video surveillance, access control, intrusion monitoring, communications and other security processes together on one platform. In 2025, Genetec added intrusion management to the platform, while its latest access control capabilities continue to expand the use of hybrid and cloud environments. The practical value here is not simply “more functions in one application”.
It is the ability to connect events. For example, if an access card is used outside a person’s usual access hours, the system can help the operator review the relevant video and other security events. This makes it possible to move from monitoring separate systems to understanding the context of an event.
Identity is another layer of security
From a cybersecurity perspective, access control is not just about asking, “Does the door open?” It is also about how identity is verified and how information is protected between the reader, controller and management system.
Here, the security architecture matters more than just the individual reader or card. A good example is the Genetec Synergis access control solution. In 2025, ANSSI awarded first-level CSPN security certification to Synergis and Synergis Cloud Link. The certification assessment also covered aspects of communication security and protection against logical attacks. The architecture also includes secure I/O modules developed by STid.
In this context, STid should not simply be viewed as a “card reader manufacturer”. Its technology can form part of a broader secure identification and access control chain.
The principle is important: access control security is not just about the security of the door lock. It is the entire chain, from identity to the door controller and management system.
Electronic locks also change how access is managed
The same logic applies to electronic locks. With a mechanical key, access control is largely physical: whoever has the key can open the door. In a digital system, access rights can be managed much more precisely - by person, time, zone or a specific access scenario.
SimonsVoss AX2Go, for example, uses a smartphone as a digital key. Access rights can be assigned and revoked digitally, while AX2Go data transmission is protected with end-to-end encryption. SimonsVoss technical documentation from 2025 continues to define AX2Go as a mobile key solution in which data packets are encrypted end-to-end. This type of solution is particularly relevant where access rights change frequently, for example, for employees, contractors, visitors or temporary users.
Again, technology alone does not solve everything. There needs to be a process that defines when access is granted, who should have it and how quickly it should be revoked.
Not every problem requires a complete system replacement
Improving cybersecurity is sometimes interpreted as a signal that old infrastructure needs to be removed and replaced from scratch. In practice, this is not always necessary.
Many organisations have infrastructure that has been built over different periods of time. Cameras, access control equipment and servers may be from different generations, but they can still be essential to day-to-day operations.
In its 2025 development of Security Center SaaS, Genetec also highlighted the ability to connect existing access control equipment and cameras, including systems that are not cloud-ready, to newer infrastructure rather than necessarily replacing all the hardware.
So the first question should not be “What do we need to replace?” but: What is critical to us, who has access to it, how does the data move, and where is the greatest risk?
Only then can an organisation decide whether it needs to change system configuration, segment the network, strengthen authentication, introduce an integration, update software or replace the technology completely.
Risk assessments should look beyond departmental boundaries
This brings us back to teamwork. A risk assessment involving only IT may miss physical security risks. Likewise, a security team looking only at physical infrastructure may overlook network or identity management issues.
For a practical risk assessment, it is therefore worth involving representatives from IT, information security, physical security, infrastructure and business operations. Depending on the organisation, HR, legal or data protection specialists may also need to be involved.
This approach makes it possible to ask uncomfortable but important questions:
- What happens if the video surveillance server is compromised?
- What happens if an employee’s digital account is deactivated but their physical access remains active?
- What happens if an access credential is lost?
- What happens if the access control system becomes unavailable?
- Can the operator understand what is happening if several security events occur at the same time?
- How quickly can the organisation revoke access rights?
- Which security systems are critical, and which are simply supporting tools?
These are the questions that turn an abstract “cybersecurity policy” into practical security management.
Security is an ongoing process
A security system is not finished on the day it is installed. People change. Infrastructure changes. New integrations are introduced. Software is updated. Business operations evolve. And as a result, risks change too. Security management therefore requires regular reviews, not just an initial risk assessment.
It is important to check not only whether the technology works, but whether it is still configured according to the organisation’s needs:
- whether users have only the access rights they need;
- whether old accounts and access credentials have been deactivated;
- whether software and device firmware are being updated;
- whether system logs and security events are being monitored;
- whether employees know how to report incidents;
- whether there is a clear response plan if a system becomes unavailable or compromised.
This approach also reflects the broader European cybersecurity direction. In its 2025 guidance, ENISA highlights risk management, incident handling, access control, asset management, training, supply chain security and physical security alongside technical measures.
From “IT security” to one security system
In a modern organisation, it is becoming increasingly difficult to draw a clear line between cybersecurity and physical security. An employee’s identity can determine access to both a digital system and a physical space. A video camera is a network device. A VMS is software. An access controller processes digital identity. An electronic lock receives digitally managed access rights. The operator then uses all this information to make decisions about a real-world event.
Security is therefore becoming less about a collection of separate technologies and more about an interconnected system. And technology is only one part of that system. The people using it, the processes by which it is managed, and the organisation’s ability to regularly review whether its security model still reflects the actual risk are just as important. Ultimately, it is not simply about how many security solutions an organisation has.
What matters is understanding how they work together to protect people, infrastructure, data and business processes.
Resources used:
- https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
- https://www.enisa.europa.eu/publications/nis-investments-2025
- https://www.genetec.com/press-center/press-releases/2025/06/genetec-brings-powerful-new-capabilities-to-security-center-saas
- https://www.genetec.com/press-center/press-releases/2025/02/genetec-enhances-security-center-saas-with-the-addition-of-intrusion-management
- https://www.genetec.com/press-center/press-releases/2025/06/genetec-access-control-solutions-receive-first-level-security-certification-from-french-national-cybersecurity-agency
- https://www.genetec.com/press-center/press-releases/2026/05/genetec-receives-qualification-from-the-french-national-cybersecurity-agency
- https://techdocs.genetec.com/r/en-US/SynergisTM-Softwire-Integration-Guide-11.5.3/Supported-secure-I/O-modules-in-Synergis-Softwire-11.5.3
- https://www.genetec.com/products/unified-security/synergis/high-assurance-access-control
- https://www.genetec.com/press-center/press-releases/2025/02/genetec-introduces-cloudlink-210-industrys-first-multi-workload-cloud-managed-appliance
- https://www.genetec.com/press-center/press-releases/2026/03/genetec-enables-enterprise-cloud-modernization-with-new-access-control-capabilities-in-security-center-saas
- Digifort. Release Notes 7.4.1.4. Digifort. 2025.
- https://www.simons-voss.com/en/resources/faqs-about-ax2go.html
- https://www.simons-voss.com/en/Access-control/smartphone-ax2go.html
- https://blog.simons-voss.com/en/news/simonsvoss-introduces-ax2go-mobile-key-for-smartphone-based-access-control/
- https://www.genetec.com/product-releases/stid-io-high-assurance