- Rhombus VP Diego Oliveira has said physical security should be managed as part of an agency’s IT infrastructure
- Oliveira points to cloud-managed platforms and edge analytics as key shifts for agencies
- Compliance signals for government use include NDAA Section 889-compliant hardware and SOC 2 Type II alignment
Diego Oliveira, vice president of corporate development and strategy at Rhombus, said agencies should stop managing physical security as a separate system and instead treat it as part of their core IT infrastructure.
“My answer is to stop treating physical security as a separate stack. It’s an IT system now and should be held to the same standard,” Oliveira wrote in an article published on Carahsoft.com.
Oliveira noted that devices such as cameras, access control systems, intercoms and sensors once ran on isolated networks managed by facilities teams, but now operate as IT assets on the same network as every other agency system, meaning a compromised device can serve as a pivot point into core infrastructure.
He added that outdated firmware, default credentials and open inbound ports on network video recorders create attack surfaces that adversaries target at scale, and quarterly patching is no longer sufficient given the pace of change.
What Makes a Physical Security Platform Compliant?
Oliveira said a platform’s value depends on whether it can be deployed inside a federal, state or local agency. He pointed to several compliance markers, including hardware aligned with Section 889 of the National Defense Authorization Act, or NDAA, and standards such as SOC 2 Type II, the Health Insurance Portability and Accountability Act, or HIPAA, and the General Data Protection Regulation, or GDPR.
Oliveira added that agencies should look for a contract vehicle-friendly path through an industry partner. He said hardware should arrive already hardened, with a distinct digital certificate assigned to each device, firmware signed and checked prior to installation, and updates applied without manual intervention.
What Shifts Are Reshaping Physical Security for Agencies?
Oliveira identified three changes he said matter most for government agencies:
- Cloud-managed platforms that give agencies a unified view across sites, automatic updates and secure remote access without a VPN for every camera
- Zero trust standards that require hardened hardware, encrypted communications and continuous patching
- Edge analytics that support real-time detection through natural-language and multi-camera search, replacing manual video review














