Physical security device fleets run on four independent, recurring cadences:
Each clock is set by a different party for a different reason, and they're not in sync with each other.
The Four Clocks: Deep Dive
Those four owners built the clocks around four entirely different mechanisms. Each is worth examining on its own terms.
Firmware release cycles are set by the device manufacturer's own schedule. This can mean they ship a new build, patch a vulnerability, or retire support for a model, for example. Staying current means someone tracks release notes across every manufacturer, model, and firmware branch in the fleet, then pushes and validates each update, checking each device individually.
A device certificate is valid until a specific date, set at issuance and enforced by whatever system checks it, such as a VMS, an access control panel, or a network authentication service. Tracking expiration across a fleet means someone maintains a list of every certificate, its issuing authority, and its expiration date, then renews and reinstalls each one before that date arrives, one device at a time.
A password rotation policy sets a cadence, 90 days, a quarter, whatever the standard specifies, for every device-admin credential in the fleet. Enforcing that cadence across thousands of controllers, cameras, and access panels means someone needs to track which device is due, log in, rotate the credential, and confirm the change landed, one device at a time.
The audit or regulatory calendar is set externally: by a regulator, a customer contract, or an industry standard, on a fixed timeframe as per the requirement. Passing it means someone can produce, on demand, current evidence for every device in the fleet: firmware version, certificate validity, credential rotation history, accurate as of the audit date rather than the date a spreadsheet was last updated. A handful of devices that missed their cycles is enough to fail the audit regardless of how current the rest of the fleet is, because auditors score every device against the requirement itself.
Two Modes of Failure
Mode one: Firmware and password rotation fail the same way, gradually, one missed cycle at a time. There's no specific state that trips a system, no red flag, and no incident ticket generated. Whatever has accumulated becomes exploitable over time, such as a firmware version old enough to carry a known vulnerability or a credential static long enough to guess, phish, or turn up in a leaked list. Nothing forces the check, so it's usually a vulnerability scan or an audit that surfaces an issue. This tracks with what teams report elsewhere: 73% describe their current tools as reactive rather than proactive, built to respond after something's already wrong rather than catch drift while it's still accumulating (SecuriThings 2026 Physical Security Trends Report).
Mode two: Certificates fail all at once. A certificate is valid until an exact date, and at that date the check that passed the day before fails the next. There’s no interval between the two states and no partial degradation to catch as an early sign. The device that authenticated that morning stops authenticating that afternoon, drops off the network, or gets locked out of the system it was deployed to protect. The first sign is the outage itself.
The audit or regulatory calendar is a different animal altogether. The audit date is often the first moment anyone confirms the fleet's actual state against its required state. The weeks before that date tend to turn into a scramble to catch up on whichever devices fall behind. That scramble is consistent with what teams report: 66% cite competing operational priorities across large device counts as barriers to staying ahead of this kind of maintenance (SecuriThings 2026 Physical Security Trends Report).
Together, this is why the four clocks resist a single fix: two fail invisibly, one fails instantly, and one is the deadline that forces a reckoning with the other three. Each shape hides risk differently, which means each demands a different way of catching it. Doing that across thousands of devices spread across sites, one device checked at a time, is where fleet-scale management breaks down.
The Clock that Gets Outsize Attention and Shouldn’t
The regulatory calendar has a fixed date and immediate consequence so it gets the lion’s share of attention and resources. That imbalance leaves the other three clocks unmanaged. It’s a fallacy to equate passing an audit with firmware, certificates, and credentials actually being current. The gap between "we passed the audit" and "the fleet is actually in sync" is where the real risk sits.
The challenge: Not enough time
Actually closing that distance means keeping all four clocks current year-round rather than sprinting toward a single audit deadline. Manual per-device tracking can't sustain that kind of continuous coverage. Four independent clocks, each with its own owner, its own cadence, its own failure mode, compounds that difficulty. Keeping up with any one of these requires ongoing effort. These aren't one-time tasks that can be crossed off a list. It's no wonder that physical security professionals are grappling with a shortage of time. According to our recent Trends Report, 97% of physical security teams say manual device management is pulling time away from strategic risk work.
Where Automation Changes the Equation
Every clock covered so far shares the same constraint: keeping up with it manually means a person checking, updating, and confirming one device at a time, across a fleet that can run into the thousands. The actual bottleneck is capacity, having enough hands to check every device against every cadence, at the pace all four clocks demand together.
Automation removes that constraint. A system that continuously tracks firmware version, certificate status, and credential age across every device can flag drift the moment it happens and push the fix immediately.
That shift changes what a compliance team's time actually buys. The hours currently going to manual device management, the same hours survey respondents say are pulling focus from strategic risk work, go toward that risk work instead.
Automation solves the capacity problem. What it doesn't solve on its own is sequencing: get the order wrong and you trade one failure mode for another. The Guide to Automating Physical Security Device Management covers where to start, how to build without creating downtime risk, and what separates a real solution from a point fix.