THANK YOU FOR SUBSCRIBING



Michael Lawson is Vice President of Security and Loss Prevention officer at Artisans’ Bank and Chairman of the Delaware Association for Bank Security (DABS). As a retired law enforcement professional, he brings decades of experience in physical security, investigations, and risk management. Lawson is a strong advocate for collaboration between financial institutions and law enforcement, focusing on emerging threats, fraud prevention, and the integration of physical and cybersecurity strategies to protect today’s banking environment.
In today’s environment, access control and identity management have moved well beyond the IT department—they sit at the heart of how organizations protect themselves and the people they serve. That shift is especially clear in banking, where institutions are responsible not just for money, but for sensitive data and, ultimately, public confidence.
After two decades in law enforcement and now working in bank security and loss prevention the past fourteen years, I’ve seen how quickly threats evolve. What stands out most is how closely physical and digital risks are now tied together. You can’t effectively manage one without understanding the other, and that reality is pushing security leaders toward more connected, forward-thinking approaches.
A Changing Threat Environment
Banks today face a two-sided challenge. Cyber threats continue to grow, with attackers focusing heavily on identity—stealing credentials, exploiting weak authentication, and finding ways into systems through people rather than technology. At the same time, physical threats haven’t gone away. If anything, they’ve become more complex.
Banks are open, public spaces. Customers walk in every day, often dealing with stressful financial situations. That environment can sometimes escalate quickly. Whether it’s workplace violence or the rare but devastating active shooter event, these risks are real and demand attention.
Taken together, these threats highlight a simple point: security can’t be handled in silos anymore. It’s not just about who logs into a system—it’s also about who enters a building, how they move through it, and how quickly an organization can react if something goes wrong.
Rethinking Access Control
Traditional access control—badges, PINs, locked doors— still plays a role, but it’s no longer enough on its own. What’s needed now is a layered approach that brings physical and digital safeguards together.
From a physical standpoint, access control has to be flexible and situational. Branch design matters. So does visibility into what’s happening in real time. In many past incidents, including active shooter events, gaps like unsecured entry points or delayed communication made situations worse than they needed to be.
On the digital side, the move toward Zero Trust is changing how we think about access. Instead of assuming someone is trustworthy once they’re inside the network, systems now verify continuously. Access is limited to what’s necessary, and activity is monitored closely. That shift reflects a growing understanding that many breaches start with compromised credentials, not external attacks.
Moving Beyond Passwords
If there’s one area where change is happening fast, it’s authentication. Passwords have been the standard for decades, but they’re increasingly seen as a weak link. People reuse them, fall for phishing attempts, or store them in ways that make them easy to steal.
Banks are starting to move in a new direction. Biometrics, secure tokens, and passkeys are becoming more common, offering stronger protection without adding unnecessary friction. Multi-factor authentication is still important, but it’s getting smarter—adapting based on context like location, device, or behavior.
The challenge is getting that balance right. Customers expect security, but they also expect convenience. If logging in becomes too complicated, they get frustrated. If it’s too easy, it becomes risky. The goal is to build systems that work quietly in the background—verifying identity without constantly interrupting the user experience or daily disruption.
Identity as the New Perimeter
In many ways, identity has replaced the traditional security perimeter. With remote work, cloud services, mobile devices, and third-party integrations, there’s no clear “inside” or “outside” anymore. Everything revolves around who is accessing what—and whether they should be.
That creates new challenges. There are more identities to manage than ever before, including not just employees and customers, but also systems, applications, and devices. Regulations continue to tighten, requiring stronger controls and better accountability. At the same time, attackers are getting more advanced, often using automation and AI to probe for weaknesses.
To keep up, banks are investing in smarter tools— behavioral monitoring, identity analytics, and automated response systems that can spot unusual activity and act quickly. The goal is to shift from reacting to threats after the fact to identifying and stopping them in real time.
What Active Shooter Events Teach Us
While identity management is often thought of as a digital issue, some of the most important lessons come from physical security—especially from active shooter incidents.
One of the biggest takeaways from these events is the importance of preparation. People need to know what to do before something happens. Clear communication is critical, as is the ability to act quickly and decisively.
In a bank setting, that means regular training, realistic exercises, and systems that can deliver real-time alerts. It also means having the ability to secure parts of a building immediately—locking down areas or directing people to safety as conditions change.
These situations remind us that security isn’t just about stopping incidents—it’s about managing them effectively when they occur.
Bringing It All Together
The direction banking security is heading is clear: everything is becoming more connected. Physical security, cybersecurity, fraud prevention, and compliance can no longer operate independently. They need to function as part of a single, coordinated effort.
That kind of integration doesn’t happen on its own. It requires strong leadership, ongoing collaboration, and a willingness to adapt. Partnerships between financial institutions and law enforcement are especially important, helping everyone stay informed and respond more effectively to emerging threats.
At the end of the day, access control, authentication, and identity management aren’t just technical concerns— they’re fundamental to maintaining trust. And in banking, trust is everything.
Security today isn’t about building barriers and hoping they hold. It’s about understanding who you’re dealing with, recognizing risk in real time, and being prepared to respond—whatever the situation may be.