Physical Access Controller Cybersecurity Gaps Widen, Survey Finds
Mercury Security’s 2026 findings show a rise from its 2025 survey in respondents reporting missing controller cybersecurity features.
- By Chelsey Arries
- Sep 29, 2026
Nearly one-third of respondents to a Mercury Security survey said their current access controller systems lack cybersecurity features, up from 21% in 2025.
The 2026 report surveyed 561 physical security and cybersecurity professionals worldwide, including access control administrators, integrators, installers and end users. Thirty-two percent identified missing cybersecurity features, while 74% said coordination between cybersecurity and IT has become more difficult.
Compatibility also figured prominently in purchasing decisions. Sixty-nine percent called interoperability a critical factor when selecting controllers, and 82% said compatibility with older and newer systems matters to future planning.
Interest in cloud connectivity exceeded current deployment: 56% cited it as a purchasing consideration, but 41% said their controllers can connect to cloud services. Another 26% said their existing systems lack that capability.
The survey also found that 41% of respondents have connected access controller data to building occupancy or space-use programs. Mercury said 78% now consider controllers important or critical to their broader physical access control strategy, compared with 72% in 2025.
About the Author
Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.