Skip to content
§
§ · build vs buy

Physical Security Information Management Build vs Buy: Genetec, Situator and the Site Count That Decides It

Standardise and buy if you can reach it. One vendor doing access control and video across your whole estate beats an integration layer over a mess, every time, provided migration is realistic inside two budget cycles.

Internal Tools Development architecture and database illustration for Physical Security Information Build vs Buy Guide.
The short answer

Standardise and buy if you can reach it. One vendor doing access control and video across your whole estate beats an integration layer over a mess, every time, provided migration is realistic inside two budget cycles. Build only when the estate changes faster than a vendor engagement cycle, which in practice means you acquire sites regularly and carry four or more head end platforms.

What Genetec, Situator and Vidsys actually do well

Genetec Security Center is a strong unified platform, and if your estate can be migrated onto it, that is usually the right answer and cheaper than integrating around it. It is optimised as the system of record for access control and video, which means its value rises with the share of your estate that runs on it. Milestone XProtect occupies similar ground on the video side, and AMAG Symmetry, Lenel OnGuard and Software House C-CURE 9000 are all serious access platforms with long deployment histories.

Qognify Situator and Vidsys are genuine security information management products, and their real strength is the part homegrown attempts consistently underestimate: situation management. Guided response, step by step procedures, escalation timers and a recorded decision trail are harder to build well than an event feed, and these products have been doing it for years.

So the recommendation first, because it applies to more readers than the alternative. If your estate is small enough or homogeneous enough that migrating to one platform is realistic within two budget cycles, do that. A single vendor handling doors and cameras removes the entire integration problem rather than managing it. And if your estate is mixed but stable, with a modest number of system types and no acquisition pipeline, buy a security information management product and manage a vendor rather than an engineering backlog. That is a legitimate answer and we give it often.

The build conversation only opens when neither of those is true.

Where they stop: the acquired site that speaks a different dialect

An operator sees a forced door alarm at a site in another region at three in the morning. He needs three things: who badged into that area in the last ten minutes, the video covering that door, and the procedure for this alarm at this site. What he has is the alarm text and a phone number for a local facilities manager. The site was acquired four years ago, it runs a platform nobody at head office has credentials for, and its recorder sits behind a site firewall the network team locked down after a review.

That is the normal condition in large estates. The corporate standard exists on paper and the estate is a museum of every vendor and firmware generation acquired over two decades. Head office standardised in a given year, which means the sites bought since then are standardised and the rest are not.

Standards help and do not finish the job. The Open Supervised Device Protocol, now published as an international standard, improved reader communication over the older Wiegand wiring, but the head end platforms still expose events through their own interfaces, database connections, or in some cases nothing you are licensed to use. On the video side, profile support under the ONVIF specifications varies by device and generation, and the recorder still owns the recorded footage and its bookmarking.

Then identity, which is where every question you actually care about breaks. One employee exists as five records with five card numbers in five access systems, plus a directory record, plus a contractor entry with a different spelling. Nobody reconciled them because each site's local record was sufficient. Until you ask who is in this zone now, or which credentials a departed contractor still holds.

Camera to door mapping deserves naming too. In most estates it lives in a drawing. Until it is data, a badge event cannot become an evidence packet.

The arithmetic: per site licensing against per system type connectors

This is where the two models diverge more sharply than in most categories, and the difference is not the sticker price.

A packaged security information management product prices integration per device type and firmware generation, and adding a newly acquired site with an unfamiliar platform is a vendor engagement rather than an internal task. So your cost scales with sites added. Ask for that quote in writing before you compare anything, along with how long the engagement takes, because the elapsed time is often the more expensive half.

A build prices integration per system type, once. In our delivery experience a connector for a new access or video platform costs roughly $12,000 to $30,000 to build, and then costs effectively nothing to point at the eleventh site running the same platform. The first site of a type is expensive and the rest are configuration.

So do the sum on your acquisition pipeline rather than your current estate. Take the per site engagement quote, multiply by the sites you expect to add over three years, and set it against a build amortised across the same period. A first release at $190,000 with year two support at 17 percent works out near $95,000 a year over three years. If you add five or more sites a year and any of them arrive on unfamiliar platforms, the packaged route usually passes that figure by year two.

Stated as a number: the crossover sits at roughly four distinct head end platforms combined with five or more site additions a year, or an estate past about sixty sites where migration to one vendor has already been costed and rejected. Below that, buy.

What a custom build actually costs

Bands from delivery rather than a market estimate. A focused first release covering connectors for two access control systems and two video platforms, event normalisation, a correlated alarm queue with camera to door mapping, and one response procedure runs $120,000 to $260,000 and ships in 16 to 24 weeks. A full platform adding identity resolution across systems, mapping and situational display, mass notification, guard tour, visitor integration and audit reporting runs $300,000 to $800,000 phased over 10 to 18 months.

Data migration runs 10 to 25 percent of build cost, and in this category it is mostly identity and mapping rather than events. Reconciling person records across five access systems against your directory, and turning camera to door relationships out of drawings into maintained data, is the migration. It is also the highest value work in the project, so treat the cost as investment rather than overhead.

Year two runs 15 to 20 percent of build cost annually. Firmware moves, platforms are replaced site by site, and each change touches a connector.

What pushes you up the band: whether vendors will licence you interface access at all, which is a commercial negotiation that can outlast the engineering. Network and security review cycles inside a large organisation, which are real months rather than weeks. Any control capability beyond read only. Video specifically, because live streaming and recorded retrieval across mixed recorders is materially harder than event ingestion. And geographic spread, which brings residency and retention differences with it.

The four situations where building wins

  • Regulatory fit. Movement data about identified people is personal data in most jurisdictions, video adds to it, and biometrics carry separate rules that differ by country and by state, including statutes such as the Illinois biometric information privacy act. Retention periods per data type and per jurisdiction, least privilege credentials, read only defaults and an audit log of who viewed which footage all become design requirements rather than policy documents. Retrofitting them after a security review typically costs a quarter.
  • Scale economics. Per site integration engagements against an acquisition pipeline. Your cost model should scale with the number of platform types you support, not with the number of buildings you own.
  • A workflow that is your competitive advantage. Response procedures are your security policy, and they are revised after every incident review. If changing a procedure needs a vendor ticket, procedures go stale and operators revert to a laminated card. Versioned, editable procedures owned by your operations team, with each step recorded as completed and by whom, are what turn a post incident review into a timeline rather than a set of recollections.
  • Integration sprawl across three or more systems. Access control, video, visitor management, mass notification, the directory or joiners and leavers process, travel security and internal case management. A security information management product covers the first two well and rarely reaches the rest, which is exactly where your operating picture is incomplete.

How to decide in a week

Monday: pull the last fifty alarms that required an operator to telephone a site. Record how long each took from alarm to first useful evidence. That single metric is the one a build moves first, and having a baseline stops the argument later.

Tuesday: inventory your estate by platform type and firmware generation rather than by site. Most security leaders discover the number of distinct types is smaller than they feared and the number of unsupported generations is larger. Both facts change the decision.

Wednesday: pick one departed contractor from the last six months and try to establish, from the systems alone, which credentials they still hold across the estate. Time it. If it takes more than an hour, identity resolution is your first build phase rather than your third.

Thursday: ask your incumbent or shortlisted vendor two written questions. What does adding a newly acquired site on an unfamiliar platform cost and how long does it take, and who can edit a response procedure, your team or theirs. Keep both replies.

Friday: test any developer on one scenario before money moves. Ask how they would resolve one person appearing as five records across five access systems. If they do not immediately reach for the directory or the joiners and leavers process as the authority, correlation will never be trustworthy and every query you care about depends on it. Then ask how they will pass your security engineering review, and listen for least privilege, segmentation, read only defaults and credential handling in the first answer rather than the fourth.

Then commission a paid discovery phase. At Digital Heroes that ends in a signed product requirements document covering the event model, the identity resolution approach, the connector inventory and the acceptance criteria, and you keep it whether or not we build. Take it to two other firms and the quotes finally compare. We are wrong for you if your estate can realistically be standardised on one vendor, or if you want a central console that can open doors remotely on day one. We fit organisations that want the repository and the infrastructure in their own name from the first commit, so any component can be independently reviewed or penetration tested without asking a supplier's permission, contracted through our India LLP, US LLC or UK LTD so assignment happens under your own law. Over fifty specialists, more than 2,000 delivered projects, and public records on Clutch, Trustpilot, Fiverr Vetted Pro and D-U-N-S.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  2. McKinsey's Developer Velocity research finds best-in-class tools are the top contributor to software business success, yet only about 5% of executives ranked tools among their top-three software enablers, signaling underinvestment in developer tools (this finding originates in McKinsey's Developer Velocity study rather than the linked generative-AI article). Source: McKinsey & Company (2023) →
  3. McKinsey emphasizes that most L&D functions still fail to tie training to business outcomes, recommending organizations track 2-3 business-relevant indicators (such as time-to-proficiency, redeployment into priority roles, or frontline productivity) rather than participation metrics to demonstrate training effectiveness. Source: McKinsey & Company (2025) →
  4. U.S. retailers lost an average of 1.6% of sales to shrink in FY2022 (up from 1.4% the prior year), equating to $112.1 billion in inventory losses - the benchmark case for POS-integrated loss prevention and inventory accuracy. Source: National Retail Federation (NRF) (2023) →
FAQ

Frequently asked questions

How long does a first release take on a mixed estate?

Sixteen to twenty four weeks covering two access systems and two video platforms in one region. The schedule risk is rarely software. It is obtaining vendor interface access on commercial terms, getting network paths approved by security engineering, and finding credentials for sites whose original integrator has left the market. Treat those three as workstreams with named owners from week one rather than as assumptions in a plan.

Who owns the code if an agency builds our security platform?

You should own the repository, the cloud and on premise infrastructure, and the unrestricted right to hire another firm, settled in writing before kickoff. In a security context that is more than commercial hygiene: you should be able to have any component independently reviewed or penetration tested without needing a supplier's permission. At Digital Heroes the client owns everything from the first commit.

Should the central console be able to open doors remotely?

Start read only and treat control as a separate capability with its own approval. A console that can act across an entire estate is a much larger risk conversation and it will slow your security review considerably, while an observation and escalation system delivers most of the operational value immediately. If control is added later it should carry its own authorisation model and its own audit trail rather than inheriting operator permissions.

What happens if a site's original integrator has gone out of business?

You inherit a platform with no admin credentials, no documentation and no support path, which is common enough in acquired estates to plan for rather than react to. Options are a credential recovery engagement with the manufacturer, a read only database connection where licensing permits, or scheduling that site for replacement. Identify these sites in week one, because they set your true integration timeline.

Can we keep Genetec and build only the layer above it?

Yes, and that hybrid is common. Keep the unified platform as the system of record wherever your estate already runs on it, and build the correlation, identity resolution and response procedure layer that spans it and everything else. That scopes smaller than a replacement, avoids rebuilding video handling that already works, and leaves you free to migrate more sites onto the platform over time.

Is a custom build worth it for an estate of twenty sites?

Usually not. At that size, either standardise on one vendor over two budget cycles or buy a security information management product and manage the vendor relationship. The build case is driven by change rate rather than size: an estate of twenty stable sites is a buying decision, while an estate of twenty that grows by six acquisitions a year on unfamiliar platforms is not.

What is the difference between a video management system and a PSIM?

A video management system owns cameras, recording and playback for its own devices. A security information management layer sits above multiple systems, normalises their events into one model, correlates across them, and guides an operator through a response procedure. The distinction matters because vendors increasingly market unified platforms as covering both, and their integration depth with competing systems varies a great deal.

How do you resolve one employee having five different card numbers?

With an identity resolution layer that maps person records across systems to a single subject, sourced from your directory or joiners and leavers process rather than from the access platforms, each of which believes its own record is authoritative. Without it, questions like where is this person now, or which credentials does a departed contractor still hold, cannot be answered reliably at all.

What privacy work has to happen before the architecture is fixed?

Retention periods per data type and per jurisdiction, access controls, and audit logging of who viewed which footage, all agreed with privacy counsel rather than added afterwards. Residency rules directly shape where data can be stored, which is an architectural decision rather than a configuration one. Any use of biometric identification needs separate legal review, because the rules vary sharply by country and by state.

Who is a custom build wrong for in physical security?

Organisations that can realistically standardise on one vendor, estates that are mixed but stable with no acquisition pipeline, and any security function without engineering capability it can hire or retain. It is also wrong if nobody will own the response procedure content, because that content is your policy rather than a software feature and it goes stale within a year if unowned.

What does an internal tool cost for a small business with 20 to 50 employees?

Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.

Can a custom internal tool connect to QuickBooks, Salesforce, and the other software we already use?

Yes, and integrations are usually the strongest argument for going custom instead of chaining tools together with Zapier. QuickBooks, Salesforce, Shopify, Stripe, Slack, and Google Workspace all have mature APIs, and each integration typically adds $1,500 to $5,000 to a Digital Heroes build depending on how much two-way syncing you need. The honest caveat is legacy industry software without an API, which may need file-based imports instead of a live connection, so list every system in the first conversation.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

Should I hire a freelancer or an agency for my software project?

A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.

How do I vet a development agency for an internal tools project?

Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply