Thought Leadership
Access Control

Four Gaps Most Lockdown Plans Never Test

Let’s Talk

School safety is now a standing budget line in nearly every state, and the dollars behind it keep climbing. As Acre CEO Kumar Sokka wrote in Campus Security Today, Texas doubled its per-student school safety allotment this year and Michigan committed $321 million in safety grants, real money, well intentioned, and rarely tied to a clear definition of what it's supposed to achieve.

Walk into almost any school in America today and the front entrance looks robust: secured vestibules, controlled entry points, visitor kiosks, camera coverage. And in most cases, it is well handled.

Four problems show up repeatedly when I talk to districts about where their access control actually stands. None of them are solved by which hardware is better on paper. They come down to whether the system holds up when it's actually tested.

Problem 1: Lockdown Procedures That Have Never Been Tested

When I was in school, lockdown practice meant one drill a year: duck under the tables, cover the windows, stay quiet until the all-clear. That's useful for students to know how to do. It was also the entire plan. The only door check was when teachers manually locked their classroom door, nothing was automatic, and nobody tested whether a signal reached the gym or the portable classrooms out back, or how long it actually took to secure the whole campus.

Security has come a long way since then, and most districts have far more sophisticated procedures written down today. Fewer have actually run them end to end, on every door, in every building, under mock conditions before it matters most.

A written procedure is not the same as a fully tested procedure. A procedure that assumes staff will remember which app to open, or that every classroom door actually locks from the inside, or that a signal reaches every building on a distributed campus, is a procedure that has never been stress tested. The gap surfaces at the worst possible time: during an actual lockdown, not during a walkthrough.

Readiness means testing lockdown speed and coverage the same way a fire drill gets tested, regularly, across every building, with a clear measure of what "secured" actually means in seconds, not minutes. There are industry guidelines to assist with these procedures and even mandate that they are tested and documented annually.

Problem 2: Aging Hardware That Opens the Door to Credential Cloning

A lot of the access control hardware still running in schools today is older than the threats it's up against. Legacy proximity cards, many of them using unencrypted low-frequency technology, are vulnerable to credential cloning, copying a card's data with equipment that costs less than a hundred dollars and takes seconds to use. A district running that hardware isn't just overdue for an upgrade. It has a credential system that can be defeated by anyone willing to buy a fifty-dollar reader online.

This isn't a hypothetical risk sitting at the edge of the conversation. It's a known, well-documented vulnerability in exactly the kind of legacy hardware many districts are still running on their oldest buildings, often without realizing it.

Problem 3: Proprietary Infrastructure That Locks Districts In

Aging hardware is one problem. Being locked into a single vendor's proprietary ecosystem to fix it is another. Proprietary systems tie a district to one vendor's pricing, one vendor's roadmap, and one vendor's timeline for addressing known vulnerabilities like the credential cloning problem above. When it's time to migrate away from outdated hardware, proprietary infrastructure usually means a full rip-and-replace, not a phased upgrade.

That single fact shapes everything about how expensive and how slow modernization ends up being. Districts on open platforms can upgrade hardware, credentials, and software independently and competitively. Districts on proprietary platforms are stuck waiting on one vendor to move.

Problem 4: Classrooms That Were Never Actually Secured

The front entrance gets the budget and the attention. Classrooms, the spaces where students actually spend the day, often don't get access control at all. A door that locks only from the outside, a lock a teacher has to remember to engage, or no lock at all beyond whatever came with the building: these are common.

Properly securing the classroom means every classroom door can be locked quickly, ideally from one central command during a lockdown, without relying on a teacher's memory or a maintenance request that's been open for two years.

Where the Fixes Actually Are

None of these four problems get solved by which hardware is better on paper. They come down to whether the system holds up when it's actually tested, and the trends worth paying attention to right now all point the same direction.

Cloud access control gives districts a single view across every building, with centralized lockdown that can secure every door at once instead of relying on staff to lock doors room by room. At the University of Virginia and George Mason University, Acre's cloud-native platform gives administrators real-time visibility into card usage, so lockdowns and threat detection happen from a single view instead of building by building.

Mobile credentials sidestep the cloning problem that plagues legacy proximity cards, since modern mobile credentials use encrypted communication that's dramatically harder to intercept or duplicate than a decades-old prox card. Across UVA, George Mason, and Rockhurst, more than 69,000 students now use a single encrypted credential, card, mobile device, or biometric, for campus access.

Command and control apps turn lockdown from a multi-step manual process into a single action, the difference between a school that can secure a building in under ten seconds and one that's still walking the halls checking doors by hand.

Credential modernization replaces cloneable legacy hardware with credentials built for how threats actually work today. At The Beacon School in the UK, Steve Nesbitt, Head of Networks and Support, put it plainly: "The Acre Access Control System has been invaluable in helping us achieve our goals for site security."

Centralized management means IT and security teams aren't juggling separate systems for separate buildings, separate credential types, or separate lockdown procedures. At Western Kentucky University, the IT team applied the same discipline they'd used to build a campus-wide video program to access control: one platform, clear standards, and automation that keeps roughly 20,000 identities and 600 access-controlled doors in sync with the university's ERP and housing systems. "We really wanted to get into electronic access control, set standards on that, get everybody pointed in the same direction," said Jeppie Sumpter, AVP-IT at WKU.

Modernization without disruption is what makes all of the above realistic for a district that can't do a campus-wide cutover. When Rockhurst University needed to replace aging access control hardware, Acre recommended an open, non-proprietary architecture specifically so the university could integrate with its existing CCTV system and expand over time, rather than starting over. That's the direct answer to Problem 3: proprietary infrastructure forces a rip-and-replace, but an open, phased approach lets a district migrate at its own pace without going dark anywhere in between.

The Question Worth Asking

Before your next procurement conversation, the real question isn't whether a vendor has an impressive front-door demo. It's whether the system underneath has been tested, whether the credentials can be cloned, whether the infrastructure is adequate, and whether every classroom, not just the lobby, is covered.

If you want a structured way to work through those questions, the Education Buyer's Guide walks through a readiness scorecard and the exact questions your board will ask before funding a platform buy.

Lockdown ready isn't a claim. It's a result you can measure, if you've actually tested it and that it is properly deployed.

Let's talk.

Andy Schueller is Director of Sales at Acre Security, where he works with K-12 districts nationwide on access control strategy.