Nearly 30 years ago, my biggest security worry at the bank was often whether a teller remembered to change a videotape. Now physical security runs on the same network as everything else the institution depends on, and that shift has quietly redefined what the job actually is.
Physical security became cybersecurity, one device at a time
Physical security in banking didn't suddenly become a cyber risk overnight. It happened gradually, one camera, one controller, and one connection at a time. There weren’t any announcements or memos declaring that the security officer's job now included firmware and network segmentation. The technology changed, and our responsibilities changed with it. Most of us were already living through that shift before we fully realized where it was taking us.
I've spent close to 30 years in bank security, long enough to watch that whole process unfold from the inside. And I keep coming back to one question, because I think it's the one every physical security leader in banking needs to sit with right now: if physical security technology is now part of the cyber risk environment, how should physical security leaders change the way they work?
The day I asked for a computer
Picture me, a brand-new college grad walking into a bank in 1998 to start my first real job as a security officer, ready to conquer the world. What I wasn't ready for was my manager's response when I asked for a computer.
"What do you need that for? Use a typewriter!"
I assumed he was joking—he wasn't. There was just one small problem with his plan: I had never touched a typewriter in my life.
Somehow, I survived without one for a while, but not long after I became the bank’s second employee to be given a “modern computer.” A beige tower connected to a huge CRT monitor so deep it looked like it could double as furniture, the kind that took two people to move and left a permanent dent in whatever desk it sat on. I felt like I'd been handed the keys to the future. In hindsight, I'd barely opened the door.
Because the rest of my world was still delightfully analog, our cameras were wired by coaxial cable into multiplexers, feeding video onto time-lapse recorders that hissed and clicked away in a back closet somewhere. Every morning, a teller would pull the tape, scrawl a label on it in Sharpie, and file it away, hoping nobody would ever actually need to watch it. Our alarm panels dialed out over plain old telephone lines, the same technology your grandparents used to call in a pizza order. And access control? Keys, PINs, maybe a proximity card if your bank was fancy. That was the whole system.
Back then, my biggest concern with a time-lapse recorder was whether someone had remembered to change the tape, not whether the recorder had an unpatched vulnerability. At the time, I didn't realize I was watching the beginning of a shift that would eventually change what it meant to be responsible for physical security.
When cameras became computers
The convergence of physical and cybersecurity in banking didn't arrive as a single event. It unfolded one technology at a time. Analog cameras became network cameras. Standalone systems became software platforms. Access control, intercoms, sensors, and video management systems all found their way onto the network. Cloud, analytics, APIs, and remote access slowly worked their way into physical security too, and before long, security technology had become part of the same infrastructure IT was already managing.
Today, a camera is actually a specialized computer that happens to perform a security function. This distinction matters more than most people give it credit for.
I want to be clear about something, though: physical security professionals don't need to become cybersecurity experts. I never did, and I don't think that's the bar anyone should be reaching for. But we do need to understand our share of the cyber risk associated with the technology we select, deploy, and manage every day. Somewhere along this path, the question stopped being whether physical security contributed to cyber risk. It’s become: what are we going to do about it?
Our security devices are now part of the cyber attack surface
Here's what's actually changing for security leaders in banking. Network cameras, access control controllers, intercoms, sensors, video management servers, and every other connected security device are now part of the bank's technology infrastructure. They're running software and connecting to the enterprise network, requiring the same kind of ongoing attention we give other technology. This means we must keep firmware current, address vulnerabilities, and consider the entire lifecycle of the device. In other words, these devices need to be part of how a bank thinks about cyber risk.
Physical security technology isn’t somehow uniquely dangerous. But too many institutions still treat connected devices like the standalone hardware they bought 20 or 30 years ago, when a camera really was just a camera and nothing more. Anything plugged into the network today belongs in the institution's cyber resilience strategy, no exceptions carved out for physical security.
Replacing old technology isn't the same thing as managing cyber risk, either. A brand-new device can become just as vulnerable as an old one if no one is responsible for updating, monitoring, or supporting it through its life. And the stakes are real. In 2024, the average cost of a financial-sector data breach was $6.08 million, 22% above the global average, making banking the second-costliest industry for breaches. This is a number physical security teams can no longer treat as someone else's problem.
The first step is talking to your cyber team
Purchasing new technology isn’t the fix. Progress starts with conversations, which should happen well before any new system hits the RFP stage.
Physical security teams should be talking regularly with cybersecurity, IT, risk management, system integrators, and even the manufacturers behind the technology itself. None of this requires reorganizing the institution or standing up a new department. It does require showing up and asking good questions.
Here are a few I'd bring to the table:
"Do you have visibility into our connected security devices?"
Compare inventories and clarify which devices are connected, where they're deployed, what they're running, who owns them, and how they're being monitored and maintained.
"How should we manage firmware and software updates?"
Agree on how your team will identify, test, approve, and roll out vulnerabilities and updates.
"Are our physical security devices included in vulnerability monitoring?"
Determine whether these endpoints receive the same visibility as the rest of the network.
"How should we handle a vulnerability affecting a security device?"
Decide who will evaluate the risk, who will be notified, and who will make the call on remediation.
"What happens if one of these systems is involved in an incident?"
Map out who can isolate a device, who will contact the manufacturer, and how physical security, cyber, IT, and incident response will coordinate when something goes wrong.
Convergence begins with shared visibility, honest communication, and a common understanding of where the risk actually lives. There’s no need to overhaul your org chart.
Think beyond the purchase
These conversations should persist into purchasing discussions, helping shape how physical security leaders evaluate technology in the first place.
Image quality, features, hardware specs, and price still matter—I'm not suggesting you ignore them. But they can't take up the whole conversation.
It’s also important to ask:
- How does the manufacturer support firmware updates?
- Does the manufacturer have a documented vulnerability disclosure process?
- What cybersecurity protections are actually built into the device?
- What authentication and encryption capabilities does the device support?
- Can the technology be securely managed throughout its expected lifecycle?
Nobody buys a new phone assuming the security story ends the moment they take it out of the box. Physical security tech deserves that same mindset because the most cyber-resilient purchase is the one your team can actually manage securely for years after the invoice is paid, not simply the newest or shiniest option on the table.
Four things I'd do now
Cyber resilience is a continuous practice that takes consistency and collaboration. If I were starting fresh today, here's where I'd focus first:
- Put physical security and cyber on the same calendar: Set up regular conversations with cyber, IT, and risk teams to establish shared visibility and make better decisions together.
- Review what's actually running: Start with an honest inventory of software versions, firmware levels, supported operating systems, devices nearing end of life, known vulnerabilities, and any systems that no longer meet your institution's standards.
- Make updates part of the routine: Don't let firmware management become a once-a-year scramble. Work with cybersecurity, manufacturers, and integrators to build a documented process that monitors updates, assesses vulnerabilities, tests changes, deploys fixes, and tracks lifecycle status over time.
- Understand who owns patching: Don’t assume IT is updating your cameras and access control devices just because they’re on the network. Confirm who monitors security advisories, who evaluates new releases, and who deploys patches. As devices and threats evolve, everyone involved needs to understand their responsibilities and when to act.
Your next step is simple: give physical security a voice in the cyber risk conversation, and keep it going.
Cybersecurity—it’s a team sport
Cybersecurity Awareness Month is a great time to move this conversation forward, because awareness can't stop at the IT department's door. Too much of a bank's security infrastructure now lives on the network for that to make sense anymore.
Physical security leaders aren’t expected to become cybersecurity specialists, but they should clearly understand that technology is part of the IT infrastructure and part of the cyber threat surface. Cyber teams, similarly, don't need to take over physical security, but they need shared visibility and responsibility.
The goal isn't for everyone to play the same position. It's for everyone to understand the play.
30 years later, we're playing a different game
Back in 1998, my technology concerns were typewriters, CRT monitors, time-lapse recorders, and whether someone remembered to change the tape. These concerns have now evolved into intelligent, network-connected devices, software, analytics, cloud platforms, and cybersecurity conversations—the kind of issues that would never have crossed my desk back then, mostly because "my desk" didn't have a network connection.
Physical security is still physical security. What's changed is the technology we use to do the job, and that shift has redefined what it means to be responsible for it. The badge reader is still a badge reader. It just happens to live on the same network as everything else now.
Banking security's next chapter belongs to physical security and cybersecurity teams working from the same playbook—protecting the institution, its customers, and the trust banking has always depended on.