Networked Access Control and System Integration

Access control moved onto the network for the same reasons CCTV did: one cable per door, central management, and the ability to see the whole estate from one place. It brought the same consequences. The system now has the strengths and the weaknesses of the network it sits on, and it has become something that can be attacked remotely.

What changes with IP controllers

A networked controller sits on the LAN and talks to management software rather than existing as an island at the door. That makes routine work far easier - a leaver is disabled once and the change is live everywhere, and audit trails from every door land in one place.

It also means the door’s behaviour when the network drops becomes a design decision rather than an accident. Controllers should hold their credential database locally and keep making correct decisions offline, syncing when the connection returns. A system that fails open or fails closed the moment a switch reboots was specified badly.

Power over Ethernet at the door removes a separate power run, but the budget arithmetic from CCTV applies here too, and magnetic locks in particular draw continuously rather than in bursts.

Cloud or on-premise

Hosted access control removes the server, the patching and the backup problem, and gives remote administration without exposing anything directly. The trade-offs are a subscription cost, a dependency on the vendor continuing to operate, and questions about where the data sits and who can reach it - which matter more when the data includes biometric templates.

On-premise keeps everything under your control and answers those questions cleanly, at the cost of someone actually having to maintain it. An on-premise server that nobody has patched in three years is worse than a hosted system, not better.

Either way, ask what happens to the door if the management layer disappears entirely. The answer should be that doors keep working on their local database.

Integration with CCTV and intruder alarms

The useful integrations are the ones that save time during an investigation or prevent an avoidable alarm.

  • Access events linked to video. A badge presentation stamped against footage turns a search through hours of recording into a single click.
  • Door forced and door held alarms. The access system already knows the door state, so it can raise an event the intruder panel would otherwise miss entirely.
  • Set and unset the intruder system from the access system. The last valid exit arms the alarm, the first valid entry disarms it. Removes a common cause of false alarms.
  • Roll call. Knowing who badged in and has not badged out is genuinely useful during an evacuation, provided the data is trustworthy.

Integration adds dependency. Every link between two systems is a thing that can break, and a design that quietly stops working when one vendor updates their software is a liability. Confirm what each system does when the other is unavailable.

Securing the system itself

An access control system is a database of who can enter your building and when. It deserves the treatment any other sensitive system gets.

  • Its own network segment, not the general office LAN
  • Default credentials changed on controllers, readers and management software
  • Firmware updates as a scheduled task, not a response to an incident
  • Administrative access limited and logged
  • Remote access through a controlled route, never by exposing the controller to the internet

The physical side matters as much. A controller mounted on the unsecured side of the door it protects undoes everything above it.

Training

The Access Control and IP Networks bundle covers both the access control system and the networking it depends on. For the broader security range, see BH Courses security training.

For the underlying components, see access control fundamentals.