SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
ColumnsSIA Waypoints

Cyber-Physical Security & the Industry: Two Experts Speak

By Kara Klein, Contributing writer, Geoff Kohl, Contributing writer
sia waypoints.png
March 27, 2024

In a constantly evolving cyber-physical security landscape, the security industry, and security integrators in particular, need to prioritize strong cybersecurity and cyber-readiness practices. In this month’s column, the Security Industry Association (SIA) spoke with experts Jim Cooper, chief technology officer at Integrated Security & Communications, and Josh Cummings, executive vice president, technology, at Paladin Technologies — contributors to SIA’s Security Industry Cybersecurity Certification (SICC) program, SICC credential holders and instructors in SIA’s SICC Review Course – to learn about the changing threat landscape and how integrators and the industry at large can improve. 

In terms of the threats and attacks you’ve seen lately, what’s new and what’s changing for people protecting the cybersecurity of physical security systems?

Cooper: I think the biggest threat for physical security systems integrators is that the systems are no longer on an isolated network, or a black box system that nobody has any information about. In the past, a lot of cybersecurity was “security through obscurity” where integrators and manufacturers would try and use nonstandard ports, operate closed source systems, omit crucial steps like vulnerability assessments and ignore the larger cybersecurity threat landscape. The reality is there are a lot of individuals and teams now specifically targeting physical security systems, attacking everything from the card through the reader, panel, network and head end software. There are quite a few videos on YouTube showing detailed attacks and hacks against physical security systems. Tools like Flipper Zero add a gamification element to RFID hacking, making it easy to get into card cloning and fuzzing. Integrators need to design and install every system like it is going to be attacked as soon as the van pulls out of the parking lot.

Cummings: We have to be constantly on our guard. We have seen exploitation of password managers, firmware vulnerabilities and misconfiguration of products, which have all made the news recently in the area of cybersecurity. Cyber is not a box you check, but rather a mindset and a posture that you have to continually work at. It’s a partnership between the integrator, the manufacturer and the customer to deploy, maintain and operate these systems in a secure manner. We also have to realize that there are always going to be new vulnerabilities, and we have to identify them and address them quickly and efficiently. To be able to do that, we have to change from a break-fix mentality to a regular, programmatic approach to managing these systems.

You’re both integrators on the front lines of physical security and cybersecurity. What are the top challenges you’re facing? Where can we improve as an industry?

Cummings: We’ve got to continue to mature as an industry when it comes to cyber. That means we need to replace technology when we can no longer secure it, and we need to focus on secure configurations of the products we sell and deploy. We saw that with the session at Black Hat last year highlighting the vulnerabilities of SIA Open Supervised Device Protocol (OSDP) when not configured properly. We also need to invest in training our people on cybersecurity and how to securely deploy technology. (SIA note: Josh’s comments underscore the importance of implementing OSDP properly. See SIA’s guidance here.)

Cooper: The biggest challenge for the industry is recognizing we are WAY behind on cybersecurity and hardening when compared to a “traditional” IT environment. We are being required to follow customer cybersecurity policies and procedures, rightfully so, and any cybersecurity issues or potential vulnerabilities are being given a lot more attention. As integrators, we need to comply with customer third-party risk assessments, which include not only our internal infrastructure and edge computing devices (tech laptops), but also assessments on the products that we are installing. Customer information security departments can refuse to allow unvetted products on their networks or allow integrators with poor security posture to perform projects. Having a clear understanding of the potential risks an unsecured system can pose to a customer’s network infrastructure, as well as how to mitigate those risks and communicate with the information security team, will be critical to move the industry forward. Also, do your updates! Windows updates on servers and workstations and firmware updates on edge devices are all critical to maintaining the security and stability of a system.


SIA’s next SICC Review Course will be held April 9 during ISC West 2024; learn more about the course and register here.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

KEYWORDS: SIA SIAC

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Kara klein 200x200

As manager of communications at the Security Industry Association (SIA), Kara Klein creates, advances and manages communications and content programs that effectively articulate SIA’s mission and objectives and promote the organization and the security industry. Before her time at SIA, Kara served as director of digital strategy at the National Cyber Security Alliance.

Kohl

Geoff Kohl is the senior director of marketing for the Security Industry Association (SIA). Kohl is responsible for delivering strategic marketing direction to expand the awareness of SIA and its product and service offerings. He serves as the primary researcher and author for the association’s annual trends report, Security Megatrends, and is a regular speaker on trends topics shaping the security industry.


Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    SDM 100 Report
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Video Solutions
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Trends & Industry Issues
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • sia waypoints.png

    Data Privacy & the Security Industry: Experts Speak

    See More
  • Workforce Strategies

    How the Security Industry Aims to Hire More Techs: A Q&A With FAST’s Executive Director

    See More
  • Workforce Strategies

    Security on the RISE, Part 2: Insights From the Industry’s Emerging Leaders

    See More

Events

View AllSubmit An Event
  • November 16, 2011

    Illinois Electronic Security Association meeting

    The day will start with IESA attorney Edward Williams' updated “PERC Nuts & Bolts” seminar that runs from 3:00 p.m. to 5:00 p.m. A social hour begins at 5:00 p.m. followed by a dinner meeting during which the IESA will hold elections for its Executive Board positions and Glen Mowrey, a Security Industry Alarm Coalition (SIAC) Law Enforcement Liaison, will give the keynote speech.
View AllSubmit An Event
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing