Selected Projects & Evidence · Enterprise Security Program

Physical Security Governance & Access-Control Modernization

Restored trust in a legacy physical-access environment, developed a risk-based modernization strategy, and led a two-plus-month migration to an integrated platform with expanded surveillance, tiered access, mobile credentials, stronger governance, and a business case designed to recover installation costs through operating savings.

Physical SecurityAccess ControlVerkadaRisk AssessmentNIST 800-53Project Leadership
← Back to Selected Projects & EvidencePublic case study · Sensitive physical-security details omitted

Overview

When I assumed responsibility for the organization’s physical-security systems, the immediate challenge was not simply aging technology. The underlying access-control data could not be trusted. More than 1,700 badge records remained active even though the legitimate active badge-holder population was approximately 220, and some records did not accurately correspond to the people carrying the credentials.

I first restored control of the existing environment by cleaning the credential population and correcting data. I then assessed the limitations of the legacy access-control and surveillance environment, evaluated alternatives, developed the business case for modernization, and led the migration to a more capable integrated platform.

1,700+Active legacy badge records inherited before access-data remediation.
~220Approximate legitimate active badge-holder population at the start of remediation.
~2×Approximate camera coverage enabled by the modernization while adding integrated access capabilities.

Business Context

The existing environment relied on Datawatch for both a limited set of cameras and physical badging. Access points were concentrated around the lobby and elevator areas, while the surveillance footprint left important operational spaces without reliable visibility.

Real events demonstrated that those blind spots mattered. An altercation between staff members highlighted gaps in internal coverage. In a separate incident over the Thanksgiving period, unauthorized individuals entered a ground-floor space and remained there for approximately five days without detection. No damage was caused, but the event exposed a significant weakness in the organization’s ability to detect and investigate activity inside the facility.

Modernization principle

Technology selection followed remediation and risk assessment. The objective was not simply to replace cameras and badges; it was to create trustworthy physical identities, risk-based visibility, controlled access, testable procedures, and sustainable operating economics.

Restore Trust Before Modernizing

The first priority was to make the existing access-control data reliable enough to govern. I disabled badges that had not been used for more than three months and cleaned the underlying records so that active credentials could be associated with legitimate badge holders.

This established a trustworthy baseline for the subsequent migration. It also reduced the risk of carrying stale, incorrectly attributed, or unnecessary access forward into the replacement environment.

My Role

I led the effort from initial remediation through technology assessment, business justification, implementation, and operational governance. This included cleaning the inherited credential environment, identifying security gaps, evaluating alternatives, recommending the replacement platform, coordinating the migration, and establishing procedures for ongoing operation and assurance.

The implementation itself required substantial coordination. The switchover took more than two months, and technicians needed escorted physical access to controlled areas. I coordinated that work and spent nights and weekends supporting installation activity so the project could move forward without weakening building security during the transition.

Technology Selection & Business Case

Verkada was selected because the platform could materially increase capability while improving lifecycle economics. The proposed environment could approximately double camera coverage, integrate badge administration with Active Directory, support more sophisticated physical-access groups, and add capabilities such as mobile credentials and enhanced video analytics.

Security investment with an economic case

Projected operating savings were sufficient to offset the installation investment in approximately 4.x years, while the organization gained substantially broader surveillance and access-control capabilities.

Modernized Access Control

Identity Integration

  • Integrated badge administration with Active Directory.
  • Improved the relationship between employee identity and physical-access authorization.
  • Built the new environment from a cleaned and validated credential baseline.

Tiered Access

  • Created access groups with different physical-access entitlements.
  • Supported garage parking, after-hours elevator access, and access limited to authorized spaces.
  • Extended the model as tenants were added to the building.

Mobile Credentials

  • Enabled employees to use a phone as an access credential in addition to a physical badge.
  • Provided greater flexibility without abandoning conventional badge access.

Operating Procedures

  • Cleaned up procedures for employees who forgot or needed temporary badges.
  • Established clearer processes around guest and temporary physical access.
  • Reduced dependence on informal exceptions.

Risk-Based Surveillance Expansion

The legacy camera footprint covered the three elevators, the main lobby, and elevator lobbies across several occupied floors. The modernization expanded coverage based on observed risk and known blind spots rather than simply replacing existing cameras one-for-one.

Additional coverage was introduced in staff spaces and other operational areas, including IT storage and mail-handling areas. The expanded design addressed places where prior incidents or asset concentration demonstrated a need for better detection and investigative visibility.

Governance & Control Assurance

NIST-Aligned Documentation

Created a System Security Plan for the physical-security environment using the organization’s NIST SP 800-53 control framework, bringing the system into the same governance discipline used for other security capabilities.

Quarterly Recovery Test

Established a recurring Zendesk ticket every quarter requiring a test footage save and retrieval, validating that recorded evidence could actually be preserved and recovered when needed.

Administrative Access

Defined who was authorized to access the physical-security platform rather than allowing system access to develop informally.

Footage Governance

Established authority for approving distribution of surveillance footage outside the organization, creating accountability around sensitive physical-security evidence.

Results

Trustworthy credential environment

Reduced a highly inflated legacy badge population to a controlled baseline aligned with the legitimate user population before migration.

Broader detection capability

Approximately doubled surveillance coverage and directed new cameras toward demonstrated operational blind spots and higher-value areas.

More precise physical access

Introduced tiered access for employees and tenants, supporting distinctions such as parking, after-hours elevator use, and access to specific authorized areas.

Sustainable control operation

Combined documented governance, recurring evidence-retrieval testing, defined administrative authority, and lifecycle cost savings with the technology deployment.

Executive Takeaway

The project began with a basic governance problem: the organization could not confidently trust who its active physical credentials belonged to. Correcting that problem exposed the opportunity to rethink the entire physical-security environment.

By combining data remediation, incident-driven risk assessment, technology evaluation, financial analysis, implementation leadership, identity integration, and recurring control testing, the modernization turned physical security from a collection of cameras and badges into a governed enterprise security capability.