Sensor Access Strengthens GuardPoint 10 Cybersecurity Through Comprehensive Platform Assessment

Sensor Access Technology has completed a comprehensive cybersecurity assessment of its GP10 access control platform. The assessment examined the system end to end, identified realistic attack paths and resulted in all critical-severity findings being resolved directly within the product.

Domains assessed end to end

%

Identified critical issues resolved in post

Track remediation model

As access control systems become increasingly connected to IT networks, databases, mobile applications, video platforms and third-party systems, cybersecurity is now an essential part of physical security design. To ensure GuardPoint10 continues to meet the security expectations of modern deployments, Sensor Access carried out a full assessment covering the platform from source code through to a live customer-style installation, with a focus on reproducible, real-world vulnerabilities rather than theoretical risks.

Testing covered eight key areas of the GuardPoint10 environment:

  • Application source code
  • GuardPoint10 server and third-party API
  • Operator desktop client
  • Windows services and file permissions
  • SQL Server database
  • Network communications and TLS encryption
  • Third-party software libraries
  • Version-control history

This end-to-end approach allowed the assessment to consider how the individual components interact as part of a complete access control deployment.

Industry-standard tools were used for source-code analysis, dependency scanning, API testing, desktop-client review, Windows service auditing, database assessment, encryption testing and secret detection. A Software Bill of Materials was also generated to provide visibility of the third-party components used within the platform.

Critical findings resolved within the product

All critical-severity issues identified during the assessment have been resolved directly within the GuardPoint10 code.

Improvements introduced as part of the remediation work include:

  • Reduced privileges for GuardPoint10 Windows services
  • Stronger protection of application files and configuration directories
  • Improved authentication and token validation
  • Certificate verification between GuardPoint10 components
  • Modern TLS encryption for system communications
  • Updated third-party libraries
  • Hardened installation defaults
  • Improved SQL login auditing and password-policy enforcement
  • Code signing for application binaries

These changes are incorporated into the GuardPoint10 installer, meaning customers receive the relevant product-level improvements when upgrading without needing to implement each correction manually.

Clear guidance for production deployments

Cybersecurity also depends on how a system is designed, configured and maintained within the customer’s environment.

For this reason, Sensor Access has adopted a two-track remediation model. Product-level matters are corrected within the GuardPoint10 software, while environment-specific decisions are addressed through a companion hardening guide.

The guide provides practical recommendations covering areas such as:

    • Least-privilege SQL account configuration
    • Data-at-rest encryption using technologies such as TDE or BitLocker
    • Application allowlisting through AppLocker or Windows Defender Application Control
    • Backup and recovery planning
    • Optional network-layer encryption using IPsec

    This gives consultants, installers and end users a documented route from an installer-default configuration towards a production-grade deployment suited to the individual building and its security requirements.

    Where this leaves GP10

    All critical-severity issues identified in this assessment have been resolved in code, closing the realistic "first-day" attack paths we found. Remaining items are scheduled for an upcoming release or documented as customer-configurable hardening. A Software Bill of Materials is generated on penetration test; the assessment is designed to be reproducible and is re-run against new releases, and an independent external penetration test is planned to validate these results.

    Critical Paths Closed

    All critical-severity findings identified were resolved in the product code.

    Guided Hardening

    The Companion Hardening Guide helps take an install towards production grade.

    Self-Service Hardening

    Customers can follow the guide themselves with clear, plain English, steps

    Continuously Verified

    The toolchain is re-run against new releases of GuardPoint10.

    Ships by Default

    Customers receive the fixes automatically on upgrade, no action needed.

    External Validation Planned

    An independent penetration test will confirm the results

    Detailed technical findings are managed in accordance with Sensor Access Technology’s responsible-disclosure policy and may be shared with customers where appropriate.

    To discuss GuardPoint10 cybersecurity, system design or deployment requirements, contact Sensor Access Technology at sales@sensoraccesscontrol.com or call +44 (0)1273 242 355.

    After something specific?

    Our Access Control Solutions

    Quick Links

    Follow Us

    My cart
    Your cart is empty.

    Looks like you haven't made a choice yet.