Unlock the full potential of Wavestore v6.52 -view our launch presentation today and explore the latest innovations in video management.
Mercury's 2026 survey of access control professionals contains a number that should change how you scope your next project: 32% say their controllers are missing cybersecurity features. A year earlier, that figure was 21%.
The controller used to be the dull part of an access control estate. It sat in a cabinet, opened doors and rarely came up in a security review. The survey suggests that is no longer a safe assumption, and that the way integrators evaluate controllers, and the software on top of them, needs to catch up.
Mercury surveyed 561 physical security and cybersecurity professionals globally in early 2026 and published the results in September. Respondents were 50% administrators, 30% partners (integrators, installers, consultants and OEMs) and 20% end users. Mercury makes access control hardware, so read the findings as a vendor-commissioned view of its own market. The direction of travel is still instructive.
The figures that matter most to anyone specifying or supporting an estate:
Read in isolation, each statistic is a separate story. Together they describe a squeeze.
Buyers want more connectivity and more integration. 34% cite IoT integration as a factor in controller decisions, and 41% have already integrated controller data with building occupancy and utilisation programmes. Every new connection widens the surface that has to be secured. At the same time, IT teams are being pulled into physical security decisions, and three quarters of respondents say that coordination is harder than it was.
The cloud numbers deserve particular attention. Demand is rising while reported cloud-enabled deployments are falling. One plausible reading is that organisations are reaching for cloud capability and finding that their existing estate, or their software, cannot deliver it cleanly. The survey does not prove that, so treat it as a question to put to your own clients rather than a conclusion.
Here is the part that gets lost when the conversation turns to controllers: in many estates the hardware is not what holds the capability back. The management software on top of it is.
Open standards on the controller side matter. OSDP, for example, replaced legacy Wiegand readers with encrypted, supervised two-way communication. But a controller with sound security features still sits behind whatever platform manages it. If that platform is closed, you inherit its integration limits, its update cadence and its cost model, whatever the controller can do.
That is the case for an open, unified platform. If your access control, video and data share one architecture built on open interfaces, then interoperability stops being a bolt-on project for each new system. WaveFusion is built on HID/Mercury controllers with an open API architecture, which is why we talk about protecting existing hardware investment rather than replacing it. Where an estate already runs Mercury, the migration route is about changing the management layer, with compatibility confirmed per estate rather than assumed.
The 56% versus 41% gap does not mean every estate should move its door decisions into the cloud. Reliability is still the number one buying criterion, and a door that fails when the internet does is a reliability failure.
The sound approach is hybrid: cloud for intelligence and management, edge for decisions and continuity. Controllers keep making local access decisions through a WAN or cloud outage, while the platform provides centralised management, reporting and integration. WaveFusion is designed around that split, with local decision-making at the edge and cloud hosting for the management layer.
Use the survey as a prompt for a more rigorous evaluation. These are the questions we would put to any vendor, including ourselves:
The survey's respondents are asking for reliability, interoperability and stronger cyber features in the same purchase. Those demands only conflict if the architecture forces a choice. An integrator who can show a client an open platform, controllers that keep working at the edge and a clear answer on cyber hardening is answering the question buyers are already asking.
If you are scoping a project now, start with the controller estate you have, not the one a vendor would like you to buy. If you want to test a platform against the questions above, talk to the Wavestore team.
Do we need to replace our access controllers to close a cybersecurity gap?
Not necessarily. The survey measures missing controller features, but many estates also have gaps in the software layer. Assess both before committing to hardware replacement.
Is cloud-enabled access control the same as cloud-dependent?
No. A well-designed system keeps access decisions at the edge so doors keep working during an outage, and uses the cloud for management and visibility.
Why does interoperability matter for cybersecurity?
Open standards and documented interfaces reduce the custom integration work that tends to introduce weak points, and make it easier to update or replace components independently.
Who should lead the evaluation, IT or physical security?
Both. The survey shows coordination is getting harder, so agree ownership of directory integration, patching and incident response before procurement starts.

Solutions for a world we can't yet see. Discover v6.52 features helping people and businesses.