Enterprise security systems — service, repair, programming and support

Repairing versus replacing a security system

Replacement gets proposed far more often than it is warranted, usually in response to a single symptom that nobody diagnosed.

The pattern is familiar. Doors misbehave, a vendor attends twice, parts are swapped, the behaviour continues, and the third visit produces a quote to replace the system. Sometimes that is the right answer. Often the actual fault was a power supply under-sized for the load it was given four years ago, and the new system will inherit the same supply and the same problem.

The useful first question is not repair or replace. It is: which specific component failed, how was that determined, and what is the evidence. A vendor who cannot answer that has not diagnosed anything, and a replacement quote based on an undiagnosed system is a guess with a large number attached.

What actually forces replacement

Three conditions genuinely end the life of a system. Everything else is negotiable.

Parts are gone. Not discontinued, gone. A controller that is still available refurbished, and for which board-level repair is possible, is a system you can keep running. A controller with no new stock, no refurbished stock and no repair path means every future failure is an emergency with an unbounded downtime, because the replacement part does not exist at any price. That is a risk position, not a maintenance position.

The head end cannot run on a supported platform. An access-control or video application whose newest supported release requires an operating system that no longer receives security updates is a problem that grows on its own. IT will eventually be told to remove it from the network, and that decision will not be scheduled around your budget cycle. If the application vendor has no release that runs on a current server OS and current database engine, the application is finished regardless of how well it works today.

The credential technology has to change. If the decision has been taken to move off 125 kHz proximity credentials, the reader population and the credential population both change, and that is the real project. The panel may or may not need to change with it. Do not let a credential migration be sold as a system replacement without checking whether the existing controllers support the new reader interface.

What is worth keeping, almost always

The most valuable asset in an installed access-control system is not the electronics. It is the cable, the pathways and the door hardware. Those represent the cost that cannot be avoided by choosing a different manufacturer, and in an occupied building they represent disruption that cannot be scheduled away.

That said, reuse has to be verified rather than assumed. Older reader runs on four-conductor cable will carry Wiegand fine and will not carry OSDP reliably, because OSDP is RS-485 and RS-485 has topology rules: a daisy chain with termination at the two physical ends, one shield ground, and a bounded total length. A home-run star topology that has worked for a decade of Wiegand becomes a set of unterminated stubs the moment it is asked to carry a multi-drop bus. Verify the cable type, the topology and the run lengths before committing to reuse. That check is a day of work and it removes the largest single source of overrun on these projects.

Enclosures, backboxes, conduit fill, locking hardware, door position switches and request-to-exit devices are usually reusable, subject to condition. Power supplies are frequently reusable and frequently under-sized, which is a different question worth answering separately.

Three paths, honestly compared

The phased path is the one most often overlooked, and it is usually the right answer for a system that is functional but ageing.

Repair in placePhased replacementFull replacement
Best whenA specific component failed and parts existSystem works but parts or software support are endingParts gone, or platform unsupportable
Field wiringUntouchedVerified once, reused where it qualifiesVerified, reused where possible
Operational disruptionPer door, hoursPer door group, planned windowsWhole site, extended window or parallel run
Credential impactNoneCan be sequenced separately from the panelsUsually forced to coincide
RollbackTrivialPer group, back to the previous head endDifficult once the old head end is decommissioned
Risk concentrationLowSpread across several windowsConcentrated in one window
Main failure modeTreating a symptom, not the causeRunning two head ends longer than plannedDiscovering the field wiring at cutover

Phased replacement means keeping the field hardware and swapping the head end, or keeping the head end and swapping controllers a group at a time. Both are viable and both require that the interim state is supported.

Questions to put to whoever is proposing the work

Ask which component failed and what measurement identified it. Ask whether the manufacturer still supplies the part, and if not, whether repair or refurbished stock exists. Ask what the newest supported release of the head-end software requires in terms of operating system, database engine and controller firmware, and whether the existing controllers can reach that firmware level. Ask what happens to the existing credentials.

Then ask the one that separates diagnosis from parts-swapping: if the same fault recurs after the work, what is the next thing you would check. An answer to that question means somebody has a model of the system. No answer means the last three visits were guesses and the fourth will be too.

Where the answer does come back as replacement, the planning work is covered in planning a legacy controller migration. Where the answer is that the platform simply needs to move to a supported version, see preparing for a Genetec or C•CURE upgrade.

Get an independent read before committing

Skyfal Security does not sell panels, cameras or licences, so the assessment is not a route to a hardware sale.


Working through a similar problem?

Describe the platform and what the system is doing. Please do not include passwords, IP addresses, credentials or facility drawings.