MERCURY RESEARCH FINDS WIDENING CYBERSECURITY GAP IN ACCESS CONTROL SYSTEMS

TechnologyCybersecurityMERCURY RESEARCH FINDS WIDENING CYBERSECURITY GAP IN ACCESS CONTROL SYSTEMS

Cybersecurity requirements are advancing faster than some physical access control infrastructure can keep up, according to Mercury Security’s 2026 Trends in Access Controllers Report.

Based on a global survey of 561 physical security and cybersecurity professionals, the study found that 32% of respondents say cybersecurity features are missing from their current controller systems, up from 21% in 2025. At the same time, 74% report that cybersecurity and IT coordination have become more complex to manage.

CONTROLLERS TAKE ON A BIGGER SECURITY ROLE

The report found that 78% of respondents now consider the controller important or critical to their physical access control system strategy, compared with 72% in 2025.

As controllers connect more devices, systems, and applications across the security environment, organizations are placing greater emphasis on infrastructure that can address current security requirements while remaining adaptable to future capabilities.

While 86% of respondents say their organizations actively work to stay current with changing cybersecurity and data protection standards, the report suggests that existing controller infrastructure does not always provide the features needed to support those efforts.

“Organizations recognize the cybersecurity risks facing connected access control systems, but the infrastructure in place isn’t always keeping pace,” said Steve Lucas, vice president for sales at Mercury Security.

“As they look to modernize, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next.”

INTEROPERABILITY SHAPES PURCHASING DECISIONS

Interoperability emerged as one of the strongest factors influencing controller procurement.

Around 69% of respondents identified interoperability as critical to purchasing decisions, while 82% said backward and forward compatibility is important to future infrastructure planning.

The findings point to a preference for gradual modernization, allowing organizations to add new capabilities while preserving existing systems and investments rather than replacing entire access-control environments at once.

Mobile credentials are also influencing procurement. Half of respondents said they already use or plan to adopt mobile solutions, while 46% ranked mobile credential integration among the trends driving controller purchases.

CLOUD INTEREST OUTPACES CURRENT DEPLOYMENT

Cloud connectivity is becoming another important consideration.

Around 56% of respondents cited cloud connectivity as a factor influencing controller purchases, up from 50% in 2025. However, only 41% said their controllers are currently cloud-enabled, while 26% reported that cloud enablement is missing from their existing systems.

The gap suggests that interest in cloud-connected access control is growing faster than the installed infrastructure supporting it.

AI ADDS NEW INFRASTRUCTURE DEMANDS

The report also points to increasing demand for more advanced security capabilities.

Behavioral analysis and anomaly detection rose from 44% in 2025 to 56% in 2026. Facial recognition was cited by 60% of respondents, while 50% pointed to predictive security and threat prevention.

As these applications expand, processing power, storage, connectivity, cybersecurity, and systems integration become more important considerations in controller selection.

More than 39% of respondents are also exploring or have already adopted edge computing within their security environments.

ACCESS CONTROL EXTENDS BEYOND THE DOOR

Controllers are also being integrated into applications beyond traditional access management.

The survey found that 41% of respondents have connected controller data with building occupancy and utilization programs, allowing physical access infrastructure to contribute to wider building-management and operational systems.

Taken together, Mercury says the findings show that controller selection is evolving from a straightforward hardware purchase into a longer-term infrastructure decision involving security, compatibility, connectivity, and future technology requirements.

Organizations are increasingly balancing immediate concerns such as reliability and cybersecurity with the need to modernize gradually and integrate with surrounding systems.

More information about Mercury Security and its access control platforms is available through the Mercury Security website.

Related Posts