IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Mercury Security flags cybersecurity gap in access control

Mercury Security flags cybersecurity gap in access control

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Mercury Security has released research showing a growing cybersecurity gap in physical access control infrastructure, based on a global survey of 561 physical security and cybersecurity professionals.

Its 2026 Trends in Access Controllers Report found that 32% of respondents said cybersecurity features were missing from their current controller systems, up from 21% a year earlier. Meanwhile, 74% said cybersecurity and IT coordination had become more complex to manage.

The findings suggest access controllers are being treated less as standalone hardware and more as part of broader IT and security planning. Among those surveyed, 78% said the controller was important or critical to their physical access control system strategy, up from 72% in 2025.

Respondents also pointed to a gap between modernisation goals and existing infrastructure. While 86% said their organisations actively work to keep up with changing cybersecurity and data protection standards, many said their current systems lack the features needed to support those efforts.

Steve Lucas, Vice President of Sales at Mercury Security, said organisations were struggling to align connected access systems with current risk management demands.

"Organisations recognise the cybersecurity risks facing connected access control systems, but the infrastructure in place isn't always keeping pace," Lucas said.

"As they look to modernise, users also want to protect existing investments. That makes interoperability increasingly important and puts more weight on choosing controller platforms that can address current security requirements while providing the flexibility to support what comes next."

Buying priorities

Interoperability emerged as a major factor in purchasing decisions. The survey found 69% of respondents identified it as critical when buying controllers, while 82% said backward and forward compatibility mattered in future infrastructure planning.

That preference reflects a gradual approach to upgrades rather than wholesale replacement. Organisations appear to be looking for ways to modernise systems while maintaining installed equipment and software links.

Mobile credentials are also shaping procurement decisions. Half of respondents said they already use or plan to adopt mobile solutions, and 46% ranked mobile credential integration among the trends influencing controller purchases.

Cloud gap

Interest in cloud-connected systems is rising faster than deployment. Cloud connectivity was cited by 56% of respondents as a factor influencing controller purchases, up from 50% in 2025.

Yet only 41% said their controllers were currently cloud-enabled, and 26% said cloud enablement was missing from their existing systems. That points to a mismatch between what organisations want from their access control systems and what they currently have in place.

The research also showed that new software-led uses for access control are placing greater demands on controller infrastructure. As systems take on more data, connectivity, and integration tasks, buyers are weighing not only security features but also storage, processing, and system design.

AI pressure

Advanced analytics and automation are adding to that pressure. Behavioural analysis and anomaly detection were cited by 56% of respondents, up from 44% in 2025, while facial recognition was named by 60% and predictive security and threat prevention by 50%.

Those figures suggest controller infrastructure is increasingly being assessed for its ability to support applications beyond traditional door management. More than 39% of respondents said they were exploring or had adopted edge computing in their security environments.

Use cases are also spreading into other building systems. The report found that 41% had integrated controller data with building occupancy and utilisation programs, suggesting access control information is being used more widely across facilities management and operational planning.

The findings indicate that controller selection is becoming a longer-term infrastructure decision, shaped by cybersecurity, interoperability, and readiness for newer forms of software integration. Mercury Security said it has more than 8 million controllers installed worldwide.