Securing the weakest link with ICT

Neil Foster, Sales Director, Northern Europe for Integrated Control Technology (ICT) examines hidden weaknesses in access control…..
ICT - securitybuyer.com

Share this article:

Neil Foster, Sales Director, Northern Europe for Integrated Control Technology (ICT) examines hidden weaknesses in access control, from legacy credentials to insecure protocols 

Many organisations still rely on 125kHz proximity cards despite their known vulnerability to cloning. Why does this legacy technology persist, and what immediate risks does it introduce?

It is indeed surprising to see how many companies and organisations are still using a technology known for its lack of security. It defeats the purpose of having an access security system if the credentials used to operate it are so weak. 125kHz cards can be cloned in a few seconds using devices sold by main online and high street retailers for less than 20 pounds. But cloning cards is not always done malevolently, it could be done naively by a company to give access to new employees or visitors. Copying an authorised access card means another employee or a total stranger can impersonate an authorised person and access a building or site with all the risks, it implies on assets and intellectual property protection and people safety. 

The main reasons for organisations to carry on using them is the lack of understanding of the technology’s vulnerability and, also, the cost and possible inconvenience to upgrade the system in place. 

If an organisation has hundreds or thousands of users, the practicalities of replacing the whole fleet of access cards or tags while still operating, can seem complex. End-users can also be reluctant to invest in replacing their legacy systems, however, with the correctly planned phased migration of credentials and readers this can be budgeted for and make the transition easier than anticipated.  

Mobile credentials offer convenience but create new exposure points, including sharing between devices. What controls and encryption standards should organisations insist on to prevent misuse or credential proliferation?

Mobile credentials are a very convenient way to give access to users, especially in education, or multitenancy environments where they could be part of an app, allowing other privileges, such as booking common areas, giving passes to visitors etc. 

As mentioned above, credentials could be a weak part of a system and it is no different for mobile credentials. The communication between the app holding the mobile credential and the readers should be encrypted and authenticated. Using AES 256 encryption should be the norm as it helps prevent cloning or eavesdropping. In addition to secure communication between App and readers, an additional authentication could be added such as a PIN on the reader, for instance.  

The access of a mobile credential on multiple devices should be carefully assessed and managed.  

As Mobile credentials are sent electronically, it is important to have a strong identity proofing during enrolment and a clear policy of lifecycle management, like a rapid revocation if the phone is lost or stolen, or if a visitor has a temporary access. 

Wiegand continues to appear in active deployments despite its security limitations. What practical security and operational gains do organisations achieve by migrating to OSDP or RS-485, and how should they approach this transition?

The Wiegand interface is simple to use and widely compatible, which still makes it appealing. A lot for external devices, can be easily added to a controller, using simple and low-cost cabling, and generates a trigger to open a gate, a door etc. It is a one-way communication, there is no encryption or authentication, and no device supervision. So, while it can used easily for a wide arrange of applications, it is not secure and should only be used for small and low risk sites. 

The RS-485 and OSDP (Open Supervised Device Protocol) protocols provide both an encrypted, secure two-way communication with device management. The RS-485 is unique and locked to the manufacturer bringing high security to a site, with as downside, a lack of flexibility if the users want to use third-party readers. 

OSDP (Open Supervised Device Protocol) offers both openness and security and it allows to use any other OSDP compatible devices.  

Organisations should approach the transition to OSDP by identifying the security risk of using Wiegand and start with the areas of the site or building with the highest risk. They will have to replace the Wiegand cabling with shielding twisted pair rated for RS-485 and ensure that existing readers, controllers, expanders support OSDP.  

 Read the full article here. 

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top