SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia

Trusted identity cuts across physical and logical systems

Thu, 27th Aug 2026 (Today)
Anthony Caruana
ANTHONY CARUANA Interview Editor

The line between physical and logical security has dissolved. Identity is the fabric that unifies access to physical environments, systems and data. Organisations face an unprecedented level of risk with physical and digital access and the rise of remote work converging with increasingly sophisticated cyber threats.

Trusted identities for people, places and things are a critical element for minimising the risk of malicious incursions. That extends to temporary credentials such as those issued to visitors and contractors. Historically, different identities were handled in different systems. And if an employee worked between different sites, it was common to have multiple swipe cards or fobs for each location. Coupled with multiple logins for disparate applications, this creates two issues.

It is an administrative challenge to onboard and offboard people as there are multiple systems to manage. And, from a security perspective, the threat surface is vastly expanded as there are more credentials to potentially exploit to launch an attack.

Ramesh Songukrishnasamy, the Senior Vice President and Chief Technology Officer at HID, explained.

"Identity was primarily a security function that ensured the right person had access to the right building, applications or system. But today it's much more fundamental to how organisations operate. Every critical system depends on answering a fundamental question – who or what is requesting access and should we trust that request."

Songukrishnasamy said security is undermined if an organisation cannot reliably control who physically enters a sensitive environment. But he added that securing a building isn't enough if a compromised digital credential provides access to critical systems.

"Physical and digital identity can no longer be considered separate disciplines," he said. "Identity is the trust layer that connects people, devices, systems, data and applications. It's a passport for an enterprise."

Organisations have been chasing the idea of a single trusted identity for many years, but it has proved an elusive goal. Like many long journeys, reaching a single trusted identity starts by taking a first step. Songukrishnasamy said modernisation doesn't mean automatically ripping out and replacing everything. Doing this at scale is unlikely to be economically and operationally possible or realistic.

"The better approach is to create an architecture that allows organisations to modernise progressively. It starts with understanding where the risks are and starting there. And use open standards and build interoperability into your identity architecture," he said.

The approach Songukrishnasamy advocates begins by continuing to leverage existing infrastructure that remains secure while progressively upgrading to newer capabilities.

"It's like the renovation work that happens in large airports. You continue to operate while some part of that building is getting upgraded and then you move along as the upgrade or renovation continues."

It's critical, he added, to look holistically at the cost benefit. It may be tempting to work around a legacy system but that can create silos. That can result in investing in solutions to overcome shortcomings that result in benefits being eroded over time.

A strong focus on open standards and interoperability are a key. Songukrishnasamy said there's no specific technology or solution that can satisfy the changing needs.

"It's hard to predict what kind of identity mechanism, or physical or digital access system will satisfy your business needs five or ten years from now. The best approach is to have a robust identity-based architecture that is flexible and can evolve as the technology and risk changes. Invest in systems that are interoperable. Look for an ecosystem where identity becomes the common fabric that cuts across multiple systems."

Sitting next to security is privacy. When a single platform governs physical and logical security, it can create a honeypot for potential attackers. This is why Songukrishnasamy said it is important to only capture what is minimally required. With a single unified identity fabric, it's possible to reduce the amount of data that is captured as there is only one set of access information.

A single trusted identity is a necessity. A physical and digital access fabric enables organisations to reduce administrative overhead and minimise the attack surface. A strategy based on starting with the highest‑risk areas, leveraging existing secure systems and adopting open standards that enable interoperability allows organisations to balance cost, operational continuity, and the need to counter evolving threats. Identity is the backbone of safe and efficient operations.

HID will demonstrate the latest in identity and access technologies at the Security Exhibition and Conference in Sydney from 2-4 September 2026.