News & Events

Controllers Are Now Critical: What Integrators Should Ask About Cyber and Interoperability

Unlock the full potential of Wavestore v6.52 -view our launch presentation today and explore the latest innovations in video management.

VIEW PRESENTATION

Mercury's 2026 survey of access control professionals contains a number that should change how you scope your next project: 32% say their controllers are missing cybersecurity features. A year earlier, that figure was 21%.

The controller used to be the dull part of an access control estate. It sat in a cabinet, opened doors and rarely came up in a security review. The survey suggests that is no longer a safe assumption, and that the way integrators evaluate controllers, and the software on top of them, needs to catch up.

What the survey found

Mercury surveyed 561 physical security and cybersecurity professionals globally in early 2026 and published the results in September. Respondents were 50% administrators, 30% partners (integrators, installers, consultants and OEMs) and 20% end users. Mercury makes access control hardware, so read the findings as a vendor-commissioned view of its own market. The direction of travel is still instructive.

The figures that matter most to anyone specifying or supporting an estate:

  • Cyber gaps are widening. 32% report missing controller cybersecurity features, up 11 points from 21% in 2025.
  • Interoperability is a buying requirement. 69% call it critical in controller procurement, and 82% say backward and forward compatibility matters for future planning.
  • Cloud is wanted more than it is deployed. 56% weigh cloud connectivity as a top purchase driver, up from 50%. Only 41% say their controllers are cloud-enabled, down from 52%.
  • Coordination is getting harder. 74% say cybersecurity and IT coordination has become more complex over the past three years.
  • Reliability still leads. 57% rank reliability and uptime first when choosing controllers, although that is down from 63% in 2025. Cost-effectiveness (34%) and cybersecurity features (30%) follow.

Why these numbers belong together

Read in isolation, each statistic is a separate story. Together they describe a squeeze.

Buyers want more connectivity and more integration. 34% cite IoT integration as a factor in controller decisions, and 41% have already integrated controller data with building occupancy and utilisation programmes. Every new connection widens the surface that has to be secured. At the same time, IT teams are being pulled into physical security decisions, and three quarters of respondents say that coordination is harder than it was.

The cloud numbers deserve particular attention. Demand is rising while reported cloud-enabled deployments are falling. One plausible reading is that organisations are reaching for cloud capability and finding that their existing estate, or their software, cannot deliver it cleanly. The survey does not prove that, so treat it as a question to put to your own clients rather than a conclusion.

The software layer is where the gap usually sits

Here is the part that gets lost when the conversation turns to controllers: in many estates the hardware is not what holds the capability back. The management software on top of it is.

Open standards on the controller side matter. OSDP, for example, replaced legacy Wiegand readers with encrypted, supervised two-way communication. But a controller with sound security features still sits behind whatever platform manages it. If that platform is closed, you inherit its integration limits, its update cadence and its cost model, whatever the controller can do.

That is the case for an open, unified platform. If your access control, video and data share one architecture built on open interfaces, then interoperability stops being a bolt-on project for each new system. WaveFusion is built on HID/Mercury controllers with an open API architecture, which is why we talk about protecting existing hardware investment rather than replacing it. Where an estate already runs Mercury, the migration route is about changing the management layer, with compatibility confirmed per estate rather than assumed.

Edge resilience and cloud are not opposites

The 56% versus 41% gap does not mean every estate should move its door decisions into the cloud. Reliability is still the number one buying criterion, and a door that fails when the internet does is a reliability failure.

The sound approach is hybrid: cloud for intelligence and management, edge for decisions and continuity. Controllers keep making local access decisions through a WAN or cloud outage, while the platform provides centralised management, reporting and integration. WaveFusion is designed around that split, with local decision-making at the edge and cloud hosting for the management layer.

Questions to ask before you specify

Use the survey as a prompt for a more rigorous evaluation. These are the questions we would put to any vendor, including ourselves:

  1. What happens when the WAN drops? Ask for a physical disconnection test, not a slide. Our platform evaluation framework makes this the first test for a reason.
  2. Which cybersecurity features does the controller support, and which does the platform add? Get the answer in writing, with the firmware and software versions it applies to.
  3. Which open standards are in use end to end? Reader communications, transport encryption and directory integration should all be named, not implied.
  4. How is the platform itself hardened? Look at the operating system, encryption of data in transit and at rest, authentication and who can access the system remotely. Our security overview sets out what we do, and releases such as WaveView v6.52 show it is an ongoing job.
  5. What is the exit route? Confirm in writing how video data, cameras and controllers are handled if you ever change platform.
  6. How will IT and security share ownership? Directory integration, role separation and audit trails are what make the 74% coordination problem manageable.

What this means for integrators

The survey's respondents are asking for reliability, interoperability and stronger cyber features in the same purchase. Those demands only conflict if the architecture forces a choice. An integrator who can show a client an open platform, controllers that keep working at the edge and a clear answer on cyber hardening is answering the question buyers are already asking.

If you are scoping a project now, start with the controller estate you have, not the one a vendor would like you to buy. If you want to test a platform against the questions above, talk to the Wavestore team.

Frequently asked questions

Do we need to replace our access controllers to close a cybersecurity gap?
‍
Not necessarily. The survey measures missing controller features, but many estates also have gaps in the software layer. Assess both before committing to hardware replacement.

Is cloud-enabled access control the same as cloud-dependent?
‍
No. A well-designed system keeps access decisions at the edge so doors keep working during an outage, and uses the cloud for management and visibility.

Why does interoperability matter for cybersecurity?
‍
Open standards and documented interfaces reduce the custom integration work that tends to introduce weak points, and make it easier to update or replace components independently.

Who should lead the evaluation, IT or physical security?
‍
Both. The survey shows coordination is getting harder, so agree ownership of directory integration, patching and incident response before procurement starts.

Source

Further reading

A group of five diverse business professionals smiling and engaging in a lively meeting around a table with laptops.

View Wavestore v6.52 presentation

Solutions for a world we can't yet see. Discover v6.52 features helping people and businesses.