Security Pros Reported Gaps in Controller Infrastructure

A survey of 561 professionals reveals that aging access control hardware struggles to meet modern cybersecurity standards.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of an industrial circuit board with geometric components, symbolizing the complexity of hardware-level cybersecurity infrastructure.
Mercury Security's recent survey indicates that nearly one-third of security professionals struggle with missing cybersecurity features in aging access control hardware. AI Illustration. Upload story photo >

Live Poll

Do you trust that your organization's security infrastructure is keeping pace with modern cybersecurity threats?

Mercury Security published a global survey finding that 32% of security professionals identified missing cybersecurity features in their current access control controllers. This research highlights the ongoing challenge of securing legacy physical infrastructure as organizations push for cloud connectivity.

Why it matters

The findings underscore a growing friction between the need to maintain existing long-term hardware investments and the increasing complexity of integrating IT and physical security. This tension is forcing organizations to prioritize controller platforms that offer both backward and forward compatibility.

While 78% of professionals view controllers as critical to their strategy, only 41% currently operate cloud-enabled systems. Interoperability remains a top procurement priority for 69% of respondents, as firms begin testing edge computing—distributed data processing closer to the source—in 39% of cases.

The players

Mercury Security

An access control infrastructure provider that tracks industry hardware adoption and security integration trends.

The details

The industry is shifting toward integrating controller data with building occupancy and utilization programs to centralize security management. This transition requires controllers to support complex data handoffs between physical hardware and cloud-based IT services. Most organizations are currently attempting to balance this integration with the necessity of maintaining legacy equipment that lacks modern, encrypted network interfaces.

Timeline

  1. 2025: This year serves as the baseline comparison for reported cybersecurity gaps in controller infrastructure.

  2. September 29, 2026: Mercury Security released the global survey results.

The Tech Race

The findings track the ongoing convergence of Information Technology and Operational Technology as legacy physical security systems struggle to adopt modern network standards. This survey identifies a competitive race among hardware manufacturers to offer the most seamless bridge between existing physical access infrastructure and cloud-native management platforms.

Security administrators and integrators should expect increased pressure to replace legacy controllers that lack basic encryption or cloud-ready interfaces. Organizations will likely pivot procurement toward modular platforms that allow for future feature updates rather than complete hardware overhauls.

The takeaway

The widening gap in security features suggests that hardware longevity is becoming a secondary concern to network-level resilience. Organizations should watch for a shift in procurement requirements toward vendors that guarantee both legacy backward compatibility and future-proof cloud-native architectures.

Further reading

For more on the current state of digital defense in building systems, visit the Cybersecurity section.

Source note: This article includes information reported by Security Info Watch.

Live Poll

Do you trust that your organization's security infrastructure is keeping pace with modern cybersecurity threats?