zum Inhalt springen

Back to the overview

Cybersecurity of Access Control Systems: NTC Seeks Operators for Security Analyses

Electronic access control systems regulate physical access in office buildings, data centers, hospitals, and at critical infrastructure operators. However, once they are put into operation, they are rarely independently tested for cyber risks. In various analyses, the National Test Institute for Cybersecurity NTC has found that security measures in the communication between readers and controllers need to be improved. The NTC is therefore launching a broader testing initiative and is seeking organizations that would like to have their access control systems tested by the NTC.

Background

Hold a badge up to the reader, a short beep, and the door opens. The process seems routine, yet it’s easy to overlook just how critical it is to security. Modern access control systems are digital, networked systems. However, they are often procured and operated not by the IT department, but by facility management or building operations. As a result, their cybersecurity often falls into a gap between two areas of responsibility.

The findings on dormakaba’s systems, published in January 2026, demonstrate that even systems from established manufacturers can contain substantial vulnerabilities. In its analyses to date—some conducted in collaboration with specialized companies such as Aveniq—the NTC has also repeatedly identified areas for improvement, particularly in the communication between readers and controllers.

 

2026-zutrittssystemen

In Focus: The Connection Between the Reader and the Controller
The actual access decision is not made in the reader, but in the controller or in a higher-level system. In many installations, the connection to these systems is inadequately protected—for three reasons:

Physical exposure: Readers are often located on the exterior of the building and, due to their design, can be removed from the wall in just a few simple steps.

Insecure protocols: Many installations use older or proprietary protocols without encryption or integrity protection. More modern standards such as OSDP (Open Supervised Device Protocol) are only effective if the Secure Channel is enabled and correctly implemented.

Organizational separation: Operational protection against cyber risks typically falls under the purview of IT, but the access control system is procured and operated by building operations.

The relevant threat here is not a mass attack via the Internet, but rather the threat posed by a skilled attacker with a specific target and brief physical access—such as to the cable behind a reader on an unguarded facade. Furthermore, local tampering is not immediately noticeable during operation, as tampered signals often appear as regular access events in the system logs. Such attacks are particularly worthwhile against high-value targets such as data centers, sensitive production environments, research facilities, financial institutions, or operators of critical infrastructure.

What the NTC Tests

The focus is on a clearly defined question: How well is the connection between the reader and the controller protected against eavesdropping and tampering in real-world installations? Since manufacturers’ demo environments rarely correspond to actual field configurations, the NTC aims to test as many products from different manufacturers as possible in real-world configurations, in close consultation with the operator and without disrupting ongoing operations.

Who Can Participate?

The NTC is seeking organizations in Switzerland that operate an electronic access control system, regardless of manufacturer or product. Organizations with heightened security needs are particularly encouraged to participate. Here are some points to help you assess your own situation:

    • Is the connection between the reader and the controller verifiably protected against eavesdropping and tampering (e.g., OSDP with Secure Channel enabled)?
    • Are local tampering attempts made more difficult, detected (tamper protection), and reported to a security monitoring system?
    • Is there a structured, regular exchange of information between IT security and physical security regarding configuration, updates, and risks?
    • Was the system independently audited after commissioning?

    These questions are intended as an initial self-assessment. Participation is possible regardless of the answers.

    What Participants Receive
      • An independent security analysis of the reader-controller interface in your installation.
      • A confidential report with specific, prioritized recommendations.
      • A contribution to Switzerland’s cybersecurity: The findings are incorporated in anonymized form into a sound overall assessment of the risks.
      Confidentiality

      The results of individual assessments are treated confidentially. Participating organizations are named only at their own request. The NTC reports identified vulnerabilities to the affected manufacturers in accordance with the NTC Vulnerability Disclosure Policy. Overarching findings are published in anonymized form.

      Sign up now 

      The NTC is looking for organizations that would like to have their access control systems tested by the National Test Institute for Cybersecurity—with a focus on the reader-controller interface. Those interested should contact us using the form below.