If you still think of a CCTV camera as “just a camera”, you’re already behind.
That was one of the more pointed themes to emerge in a recent conversation with Andrew Elvish, Vice President of Marketing at Genetec, following the release of the Genetec 2026 State of Physical Security Report — the sixth in the annual series. The report itself began as a pandemic-era project in 2020, and has since grown into a substantial temperature check on the industry’s priorities and pain points. This year, Genetec embarked upon the report hoping for 5,800 survey responses and ended up with almost 8,000, with particularly strong participation from the Asia-Pacific region.
So what are those 8,000 voices telling us?
The Vanishing Line Between “Cyber” and “Physical”
The most obvious trend is also the most inconvenient: the boundary between digital threats and physical threats is disappearing. Connected systems have turned the average security ecosystem into an IoT network — and that changes the rules.
Elvish’s blunt reminder is worth repeating: modern IP cameras have IP addresses. They’re “little computers” hanging from ceilings and poles, generating network traffic because that’s how video is transported across an IP environment. Treat them like dumb optics and you’ll secure them like dumb optics — which is to say, poorly.
The catch is that attackers often don’t care about your camera footage. They care about what the camera gives them: network access. Elvish’s “dollars to donuts” wager is that if you haven’t secured your cameras, you probably haven’t secured your network — and once an attacker is in, lateral movement and data exfiltration are the real payday. That’s when fines, outages, and executive job losses enter the story.
Procurement Can Be a Threat Vector
One of the more uncomfortable points in the discussion was that the biggest culprit isn’t always technology — it’s process. Specifically, procurement.
Purchasing departments are trained to chase “best product, lowest price,” and in doing so they can optimise straight past vendor risk assessments, cybersecurity track records, and the kinds of questions that would prevent weak devices from being introduced into critical environments. The result can be cheap kit with expensive consequences.
It’s Not Just About Stopping Attacks — It’s About Proving You Acted
The report also reinforces a shift in expectations: security is increasingly being asked to demonstrate action, not just take it.
A simple example: camera integrity monitoring. Yes, it helps detect deliberate tampering — a shifted camera, a spray-painted lens, the Hollywood-style “funny games.” But it also catches the more common reality: a forklift driver stacks a pallet in exactly the wrong place and accidentally blinds a camera. In either case, the real value comes from what happens next.
Elvish points to the workflow layer: trigger the alert, create a ticket, send it to floor managers, track remediation, and then — crucially — show governance, risk and compliance (GRC) stakeholders that action was taken quickly. That’s where physical security stops being a room full of screens and starts looking like organisational resilience.
Humans Remain the Soft Underbelly
When the conversation turned to phishing, ransomware, credential compromise and device hacking, Elvish didn’t hesitate on what creates the greatest real-world impact: people.
Humans are still the weakest link. We get tired. We get tricked. We click when we shouldn’t. And across the report’s respondents, education rises as the priority — alongside core cyber hygiene like MFA and hardware keys.
It’s not glamorous, but it’s real: a trained person who pauses before clicking can be more valuable than another shiny control nobody understands.
AI: The Difference Between “Innovation” and “Press Release”
AI is the other major thread — and it’s the one most at risk of being treated like a novelty.
Elvish’s feels that a lot of AI innovation in physical security right now is “innovation via press release.” The warning isn’t that AI is fake; it’s that professionals can get excited about technology and forget the only question that matters: what outcome are you trying to achieve?
Where AI shines, he argues, is in investigations — the needle-in-a-haystack work humans are frankly awful at doing for hours on end. Done properly, intelligent automation can collapse investigation timeframes from five to eight hours down to 10–15 minutes by letting operators click on an object or person and have the system rapidly trace when it appeared, where it moved, and what else it touched across an estate of cameras.
The caveat is important: Genetec is “allergic to black boxes.” If the system can’t be understood, it can’t be audited — and if it can’t be audited, it becomes very hard to defend in an investigation.
Responsible AI Means Audit Trails, Not Marketing
That leads to the other brake on AI adoption: defensibility.
Elvish makes the case that when evaluating vendors, end users should demand a clear, published set of Responsible AI principles. Then come the hard questions: where did the training data come from, how was it collected, does it comply with local regulations, who can access it, and what audit trails exist to prove provenance?
Privacy laws are tightening. Compliance expectations are rising. Frameworks and scrutiny are coming whether we like it or not. In that environment, “because the vendor said so” is not a strategy.
And, as I noted in the interview, end users also need to stop hoarding data “just because they can.” Collect what’s mission critical — because every extra piece of data you store is another piece of data you can lose.
In 2026, physical security is no longer merely reactive. It’s increasingly technical, increasingly accountable, and increasingly expected to show its work — not just do it.
The full 2026 State of Physical Security Report is available as a free download from www.genetec.com







