A company we assessed had a tidy access control system with a well-maintained cardholder database. It also had a box of thirty unassigned spare cards in a drawer, twelve active badges belonging to people who had left, and readers wired with Wiegand on the outside face of the building, where the cable could be reached with a screwdriver. The system produced convincing reports. It did not control access.
Access control is an identity problem that happens to involve doors. Treated as a facilities purchase, it drifts out of step with who actually works at the company. Treated as part of identity, it stays accurate on its own.
Credentials and the reader link
Two weaknesses account for most of what we find. The first is the credential itself: 125 kHz proximity cards and MIFARE Classic offer no real cryptographic protection, and cheap handheld cloners copy them in seconds without the holder noticing. Replacing them with DESFire EV3 or an equivalent removes an entire category of attack for the price of new cards and, sometimes, new readers.
The second is the link between reader and controller. Wiegand carries the card number in clear with no authentication, on wiring that frequently runs through the unsecured side of the door. OSDP with Secure Channel encrypts that connection and reports tampering or disconnection. Migration can be staged, since many readers support both, and we prioritise perimeter and high-value doors first.
Mobile credentials on phones are a reasonable option where the population is largely employees with company devices, and they simplify issuing and revoking. They are less suitable where you must admit contractors and visitors who will not install anything.
Joining access control to identity
The most valuable integration is the least visible one. When the access system reads its population from the same directory as everything else, an employee’s departure removes their badge automatically at the same moment it disables their accounts. Nobody has to remember. Access reviews can then treat “who can open the data centre door” as one more question alongside “who can reach the finance system”, answered from a single review rather than two disconnected ones.
This also fixes visitor and contractor handling, which is where controls usually leak. Time-limited credentials that expire automatically are far more reliable than an intention to collect a card back at the end of a project.
Doors, rules and emergencies
A door schedule states, for each door, who may pass, at which times, and what happens when power fails or the fire alarm activates. Escape routes must release; secure rooms may not. Getting this wrong is a life-safety matter, so it is agreed in writing and verified against fire regulations rather than inherited from a default setting.
Higher-security areas can use anti-passback to prevent a card being handed back through a door, interlocks so two doors cannot be open at once, or two-person rules for sensitive rooms. These are worth applying selectively, where the risk justifies the friction.
Evidence
Every door event is logged, and that log is the reason auditors take the system seriously. ISO 27001 and NIS2 both expect physical access to controlled areas to be restricted and reviewable, and a complete event history answers those questions directly. Door logs are also personal data, so retention is defined and access to the log is itself controlled.
Combined with camera footage, door events become genuinely useful: an alarm at a specific reader at a specific second points straight to the relevant clip instead of an afternoon of searching.
Who this is for
This suits organisations running an ageing badge system nobody fully trusts, companies subject to ISO 27001 or NIS2 that must evidence physical controls, sites where an audit has flagged former employees holding valid credentials, and anyone planning an office move who would rather design this once than inherit it.
We handle the technical design, the credential and protocol decisions, the identity integration and the compliance evidence. Where national regulation requires a licensed security company to install the physical equipment, we work with one while remaining responsible for the design and the systems it depends on.
Outcomes
Leavers lose building access the day they leave, without anybody remembering to arrange it. Credentials cannot be cloned from a pocket. When an auditor asks who could enter a given room last quarter, the answer is a report rather than an investigation.