📊 Key Data
  • 83% of security professionals rate current interoperability between solutions as fair, poor, or nonexistent.
  • The average cost of a data breach hit $4.45 million in 2023, with nearly half involving stolen credentials.
  • 78% of security breaches involve a physical access component.
🎯 Expert Consensus

Experts would likely conclude that the LEAF Community's End User Committee represents a critical step toward breaking down vendor lock-in, fostering interoperability, and reducing security risks through open standards.

about 13 hours ago
Security's Berlin Wall: How Enterprises Are Tearing Down Vendor Lock-In

Security's Berlin Wall: How Enterprises Are Tearing Down Vendor Lock-In

BROOMFIELD, CO – September 09, 2026 – In a significant move to dismantle the digital walls that have long fragmented the physical security industry, the LEAF Community today announced the formation of its End User Committee. Chaired by Bank of America and featuring security leaders from Anduril, DTCC, IBM, and Red Hat, the new body gives the world's largest organizations a direct hand in shaping a universal standard for access control, a critical step toward ending the costly and restrictive era of vendor lock-in.

For decades, enterprises have been forced to navigate a maze of proprietary systems. A card that opens a door in one building might be useless in another managed by a different vendor's system. This lack of interoperability creates immense friction, inflates costs, and can introduce security vulnerabilities. The LEAF Community, an open, vendor-neutral initiative, aims to solve this by creating a universal standard for physical and mobile credentials. The new committee formalizes a feedback loop, ensuring the standard evolves based on the real-world needs of those who depend on it most.

“None of us are solving these problems in a vacuum — every large enterprise security team is working through the same vendor lock-in and integration headaches,” said Michael Franke, security technology executive at Bank of America and chair of the new committee. “Having a seat on the End User Committee means we're comparing notes with peers instead of finding out the hard way, alone.”

The High Cost of Closed Systems

The problem the committee aims to solve is not trivial. Vendor lock-in has been a persistent and expensive burden on chief security officers and their organizations. When an enterprise commits to a single access control provider, it often becomes dependent on that vendor’s hardware, software, and innovation cycle. Switching providers or integrating a new, more advanced technology from a competitor can be prohibitively expensive and complex, requiring a complete overhaul of existing infrastructure.

This dynamic stifles competition and slows the adoption of innovation. According to one industry report, a staggering 83% of security professionals rate the current level of interoperability between solutions as fair, poor, or nonexistent. This fragmentation carries a steep price. The average cost of a data breach, which can often originate from a physical security lapse, hit $4.45 million in 2023, with nearly half of all breaches involving stolen or compromised credentials. In a world where 78% of security breaches involve a physical access component, relying on outdated or siloed systems is a risk few can afford.

“Physical security leaders are often solving the same problems independently,” noted Matthew Netardus, senior manager of technical security architecture at Anduril and a founding committee member. “A peer committee like this one gives us a structured way to surface those challenges together, apply collective experience to real decisions, and ensure the direction of this technology reflects the requirements of the organizations actually deploying it.”

A Coalition of the Willing

The composition of the LEAF End User Committee underscores the widespread nature of this challenge. The founding members represent a cross-section of the global economy, each with unique and demanding security requirements.

  • Bank of America, as a global financial institution, manages a vast portfolio of physical assets and data centers where security is non-negotiable. Its leadership role signals the financial sector's urgent need for more flexible and resilient security frameworks.
  • Anduril, a defense technology firm specializing in autonomous systems, operates at the cutting edge of security innovation. Its participation brings a perspective focused on integrating disparate sensors and hardware into a unified, AI-powered command system, a goal hampered by closed ecosystems.
  • DTCC (The Depository Trust & Clearing Corporation) provides the post-trade infrastructure for global financial markets, safeguarding trillions of dollars in securities. Its involvement highlights the critical importance of securing essential economic infrastructure against both physical and cyber threats.
  • IBM and Red Hat represent the convergence of IT, cloud infrastructure, and physical security. Their presence on the committee points to the growing need for standards that bridge the digital and physical realms, especially as organizations move toward hybrid cloud environments and integrated identity management.

This coalition isn't just a focus group; it's a powerful collection of consumers who are collectively refusing to accept the status quo. By pooling their experience, these organizations can define a common set of requirements that will compel the market to move toward openness.

The Shifting Landscape of Security Standards

The LEAF Community is part of a broader industry trend toward open standards. For years, initiatives like the Security Industry Association's (SIA) Open Supervised Device Protocol (OSDP) have made progress in standardizing communication between access control panels and peripheral devices like card readers. Similarly, ONVIF has worked to create interoperability for IP-based video and access control products.

Where LEAF aims to carve its unique niche is at the level of the credential itself. The goal is to create a universal digital key—whether on a physical card or a mobile device—that works seamlessly across any LEAF-compliant reader or system, regardless of the manufacturer. This credential-centric approach tackles the problem at its root, promising a future where a single, secure identity can grant access not just to doors, but to everything from IT workstations to vehicle fleets and equipment lockers.

By focusing on a common language for credentials, the LEAF framework allows enterprises to mix and match best-in-class solutions without fear of incompatibility. An organization could use readers from one vendor, an access control panel from another, and a mobile credentialing platform from a third, all working together in a unified ecosystem.

From Vendor Mandates to User-Driven Innovation

The launch of the End User Committee marks a strategic inflection point for the LEAF Community and the industry at large. With a membership that has already grown to over 40 organizations, the initiative has gained significant momentum. Offering free membership to end users further lowers the barrier to entry, encouraging wide participation and ensuring the standard reflects a diverse set of needs.

This user-driven model represents a fundamental power shift. Instead of vendors dictating the terms of integration, the largest consumers of the technology are now in the driver's seat. The committee provides a formal structure for this influence, moving beyond informal complaints to a collaborative process of roadmap development. As Netardus observed, “That kind of feedback loop is rare and worth being part of.”

To further this engagement, the committee is hosting its first in-person event, an End User Breakfast, during the upcoming GSX conference in Atlanta on September 15. The vendor-free gathering is designed to foster open conversation among peers and recruit more enterprises to the cause. By taking its message directly to the industry's premier security event, the LEAF Community is making a clear statement about its intention to build a broad and active coalition.

Ultimately, the success of this initiative will depend on its ability to translate collaboration into tangible, widely adopted technology. However, the formation of this committee, backed by some of the most influential security stakeholders in the world, is the strongest signal yet that the proprietary walls governing physical access control are beginning to crumble.

Topics & Related

Event:
Partnership
Sector:
Cybersecurity

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 49770