INSIGHTS / ACCESS CONTROL
You paid for the access control system. But do you actually control it?
Encryption can make access credentials substantially harder to copy. But if the customer cannot control, transfer or support the encrypted environment, a security feature can also become a long-term ownership problem.
A customer can own every reader, controller and credential—and still discover that practical control of the credential environment sits somewhere else.
Modern encrypted credentials are designed to reduce cloning and unauthorised duplication. That is valuable. The problem begins when the encryption keys, configuration information and transition arrangements are not clearly understood or documented for the customer.
If the relationship with the original provider changes, the organisation may discover that issuing new credentials, changing support providers or expanding the system is not straightforward.
The issue is whether encryption has been implemented in a way that protects the organisation while preserving legitimate customer control.
Approximately 40 readers. Around 1,100 replacement credentials. One difficult ownership question.
Safeguard assisted an organisation that needed to regain practical control of an encrypted access-control credential environment. The immediate work involved approximately 40 readers and around 1,100 replacement credentials.
The review also identified a further 11 buildings where the same credential-governance question needed to be understood. Some older readers could not form part of the recovered environment and required replacement.
The recovery and migration process took approximately six months and required support from the credential manufacturer. The work had to establish what could be retained, what needed to change and how the organisation could move forward without creating unnecessary disruption.
Customer, site and operational details remain deliberately anonymous.
Recover control without weakening the security objective.
Understand the key environment
Establish how credentials and readers had been secured and what information was available for a controlled transition.
Map compatibility
Identify which readers could remain in service and which older devices could not be carried into the recovered environment.
Plan the migration
Coordinate replacement credentials, reader changes and the order of work so access operation could be maintained.
Document customer control
Make future administration, support and provider transition part of the security outcome rather than an afterthought.
QUESTIONS EVERY CUSTOMER SHOULD ASK
Before approving an encrypted credential solution, understand the exit path as well as the entry path.
Who controls the encryption keys?
Is control held for the customer, and is that arrangement documented?
Can another qualified integrator support it?
What is required if the service relationship changes?
What information will the customer receive?
Confirm documentation, credential formats, reader compatibility and administrative responsibilities.
What happens to older readers?
Understand compatibility and lifecycle implications before issuing a large replacement credential population.
Can the environment expand?
New sites and readers should be able to join the intended credential standard without recreating the ownership problem.
Is the customer protected from lock-in?
Security should be strengthened without making legitimate future support unreasonably dependent on one provider.
Encryption should protect the customer.
It should not separate the customer from control of its own security environment.
No. It should be designed and governed properly.
The lesson is not to retreat to weaker credential technology. Properly implemented encryption remains an important protection against credential copying and unauthorised use.
The lesson is to address ownership, documentation, administration, compatibility and provider transition when the system is designed—not years later, when the organisation needs to make a change.
REVIEW YOUR ACCESS-CONTROL ENVIRONMENT
Do you know who controls the credentials, keys and future support pathway?
Safeguard can review an inherited or existing access-control environment, identify supportability and ownership risks, and help develop a controlled path forward.
Request an access-control review