Security Professionals Reported Controller Vulnerabilities
A new industry survey highlights growing cybersecurity gaps and complex IT coordination needs for access control systems.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust that your organization's security infrastructure is keeping pace with modern cybersecurity threats?
A global survey by Mercury Security found that 32% of security professionals identified missing cybersecurity features in their current access control controllers. As organizations integrate controllers with broader building systems, 74% of respondents report that IT coordination has become increasingly complex.
Why it matters
The findings underscore a significant tension between maintaining legacy security investments and the rising demand for cloud connectivity and advanced features like facial recognition. As organizations modernize, the failure of existing hardware to meet contemporary cybersecurity standards poses a persistent risk to facility infrastructure.
The survey of 561 professionals revealed that 78% of respondents consider controllers critical to their security strategy, while 69% prioritize interoperability. Currently, 41% of respondents utilize cloud-enabled controllers, and 39% are exploring or have already adopted edge computing.
The players
Mercury Security
This organization is a provider of access control hardware and software that tracks infrastructure trends through industry-wide research.
The details
Security administrators and integrators are increasingly required to link controller data with building occupancy and utilization programs, driving a demand for platforms that offer greater flexibility. Organizations are currently prioritizing hardware that provides backward and forward compatibility to future-proof their security operations.
Timeline
2025 served as the baseline year for reporting missing cybersecurity features.
2026 marks the year the survey was conducted and the report published.
The Tech Race
This data reflects a pivotal transition in the tech race for building security, where legacy, siloed controllers are being outpaced by demands for cloud connectivity and edge computing integration. The industry is currently moving away from hardware-exclusive deployments toward versatile, software-defined ecosystems that prioritize long-term interoperability.
For users and system administrators, these gaps mean that existing building access points may be vulnerable to network-based attacks until hardware is replaced or patched. As IT teams assume more control over physical security, businesses can expect longer procurement cycles as interoperability testing becomes a standard requirement.
The takeaway
Organizations should perform a thorough audit of their existing controller firmware to identify potential security gaps before integrating new cloud features. Prioritizing platforms with proven backward and forward compatibility remains the most effective strategy for mitigating infrastructure obsolescence.
Further reading
For broader context on current defense strategies, visit the Cybersecurity section.
Live Poll
Do you trust that your organization's security infrastructure is keeping pace with modern cybersecurity threats?







