INSIGHTS / ACCESS CONTROL

You paid for the access control system. But do you actually control it?

Encryption can make access credentials substantially harder to copy. But if the customer cannot control, transfer or support the encrypted environment, a security feature can also become a long-term ownership problem.

CREDENTIAL → ENCRYPTION KEY → READER → ACCESS SYSTEM
Encrypted Credential
Who Controls the Key?
Who Can Support the Readers?
What Happens When Providers Change?
THE REAL OWNERSHIP QUESTION

A customer can own every reader, controller and credential—and still discover that practical control of the credential environment sits somewhere else.

Modern encrypted credentials are designed to reduce cloning and unauthorised duplication. That is valuable. The problem begins when the encryption keys, configuration information and transition arrangements are not clearly understood or documented for the customer.

If the relationship with the original provider changes, the organisation may discover that issuing new credentials, changing support providers or expanding the system is not straightforward.

The issue is not whether encryption is good or bad.
The issue is whether encryption has been implemented in a way that protects the organisation while preserving legitimate customer control.
AN ANONYMISED SAFEGUARD EXAMPLE

Approximately 40 readers. Around 1,100 replacement credentials. One difficult ownership question.

Safeguard assisted an organisation that needed to regain practical control of an encrypted access-control credential environment. The immediate work involved approximately 40 readers and around 1,100 replacement credentials.

The review also identified a further 11 buildings where the same credential-governance question needed to be understood. Some older readers could not form part of the recovered environment and required replacement.

The recovery and migration process took approximately six months and required support from the credential manufacturer. The work had to establish what could be retained, what needed to change and how the organisation could move forward without creating unnecessary disruption.

Customer, site and operational details remain deliberately anonymous.

WHAT THE WORK REQUIRED

Recover control without weakening the security objective.

Understand the key environment

Establish how credentials and readers had been secured and what information was available for a controlled transition.

Map compatibility

Identify which readers could remain in service and which older devices could not be carried into the recovered environment.

Plan the migration

Coordinate replacement credentials, reader changes and the order of work so access operation could be maintained.

Document customer control

Make future administration, support and provider transition part of the security outcome rather than an afterthought.

QUESTIONS EVERY CUSTOMER SHOULD ASK

Before approving an encrypted credential solution, understand the exit path as well as the entry path.

Who controls the encryption keys?

Is control held for the customer, and is that arrangement documented?

Can another qualified integrator support it?

What is required if the service relationship changes?

What information will the customer receive?

Confirm documentation, credential formats, reader compatibility and administrative responsibilities.

What happens to older readers?

Understand compatibility and lifecycle implications before issuing a large replacement credential population.

Can the environment expand?

New sites and readers should be able to join the intended credential standard without recreating the ownership problem.

Is the customer protected from lock-in?

Security should be strengthened without making legitimate future support unreasonably dependent on one provider.

Encryption should protect the customer.
It should not separate the customer from control of its own security environment.

SHOULD ENCRYPTION BE AVOIDED?

No. It should be designed and governed properly.

The lesson is not to retreat to weaker credential technology. Properly implemented encryption remains an important protection against credential copying and unauthorised use.

The lesson is to address ownership, documentation, administration, compatibility and provider transition when the system is designed—not years later, when the organisation needs to make a change.

See the anonymised project summary in Our Work →

REVIEW YOUR ACCESS-CONTROL ENVIRONMENT

Do you know who controls the credentials, keys and future support pathway?

Safeguard can review an inherited or existing access-control environment, identify supportability and ownership risks, and help develop a controlled path forward.

Request an access-control review