AI and regulation are reshaping the future of building security

Criminals used to rely on lock-picking tools and crowbars to break into buildings. Today’s attackers can cause just as much damage and disruption by using phishing links, malware and sophisticated digital exploits to target products, systems and networks.
The truth is, today’s security challenge isn’t just physical – or cyber – but both. And keeping one step ahead of criminals is a full-time occupation. For those people tasked with researching and developing the latest products, it sometimes means using unconventional tactics, such as using professional lock pickers to test the security and resilience of new products.
SVP & Chief Technology Officer for EMEIA at ASSA ABLOY Opening Solutions.
While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just security.
Latest Videos FromTechRadar
Some systems can even use the motion of turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems.
Used extensively in buildings such as offices, hotels, hospitals and other critical infrastructure, these modern digital access solutions can also connect to cloud-based platforms to manage who can enter buildings and restricted areas.
Bridging physical and digital security
However, digital systems have their own security risks, which means security teams need to anticipate and defend against a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behavior.
This explains why some security personnel have to adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities.
But what is becoming increasingly clear is that physical and digital security systems can no longer be treated as separate entities.
Many security solutions today employ both mechanical and digital technology, which means that resilience – the kind of resilience that keeps data centers safe, for example – depends on understanding how risks move across systems, people and environments.
Embedding resilience into design
That means continuously designing and testing products against existing real-world threats while also anticipating what might be around the corner. That includes building security into every stage of development, especially as technology evolves.
For instance, great strides have been made recently in terms of biometric authentication, including facial recognition and fingerprint scanning. Similarly, smartphones are increasingly being used to secure credentials for mobile-based access control systems.
Work is also currently underway to use artificial intelligence (AI) to analyze data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally.
Using AI tools in a positive way is important because it is also the source of some of the newest and, therefore, most unpredictable challenges. For example, there are now autonomous AI threat chains that can discover and exploit vulnerabilities unilaterally, moving from reconnaissance to exfiltration in record time without any need for human oversight.
The danger posed by cyber criminals has also become more complex due to the growing interconnectivity of digital products and services. In many ways, a world where all hardware and software are interconnected is an efficient and convenient one.
But it is also one where, if bad actors gain access to a single element, they may be able to compromise the whole network.
The importance of regulation and compliance
This is something that the European Union (EU) is actively addressing. For instance, the European Union’s (EU) NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance.
It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate.
Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats.
Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world.
And by introducing clearer requirements and standards, the CRA will help consumers and organizations identify products with strong security features and configure them more securely from the outset.
In both cases, not only is it incumbent on vendors to meet or exceed these rules and regulations, but also to keep customers, the wider industry, and other stakeholders informed about developments.
Not only must businesses contend with the usual challenges from phishing and malware, but the rapid growth of AI has introduced a new and unpredictable dimension to keeping out online criminals. Security – both physical and cyber – has never been more critical than it is today.
We’ve featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit