At GSX 2026 in Atlanta, Xtract One CEO Peter Evans took the stage to make a case the physical security industry needed to hear. The session, How to Measure True Physical Security ROI, was a direct challenge to the way the industry has been evaluating security technology for decades, and why the numbers vendors lead with are often telling only part of the story.
Evans opened by noting something he’d observed on the GSX show floor that morning. A colleague from a physical barrier company, the kind that makes fences and vehicle mitigation systems, told him to stop by the booth. “We’ve got AI now,” the colleague said. When Evans asked what that meant for a fence company, the answer was candid: the marketing team thought sprinkling AI over everything would drive more booth traffic.
It was a small moment that made a larger point. “That sort of speaks to some of the fundamental problems we have as an industry,” Evans told the audience. “We’re sprinkling buzzwords on things without really understanding what’s the point and what are the true outcomes we’re looking for.”
The Vanity Metric Doesn’t Prove Much
Evans used miles per gallon as his entry point into the core argument. Everyone looks at fuel economy when buying a car. Almost nobody tracks their actual consumption over the years they own it. It’s a number that makes comparison easy and makes purchasing decisions feel rational. And then there’s the disclaimer: your mileage may vary.
“What if you’ve got a Prius and you’re pulling a boat up a ten degree incline?” Evans asked. “Your mileage is going to vary a lot.”
The same dynamic, he argued, plays out constantly in physical security. The industry has settled on metrics that are easy to communicate and easy to compare, without asking whether those numbers actually reflect what a security program is delivering. In weapons detection, that number is 3,000 people per hour. It’s a single data point measured at a single moment in the entry journey, and it tells you almost nothing about whether the program is working.
“3,000 people per hour is measuring a line on the floor,” Evans said. “But your security experience doesn’t start and stop at that line. It starts when you’re leaving your car and it doesn’t finish until you leave the venue.”
The Denominator Matters
As an applied mathematics graduate, Evans made the case that the most important factor in any security equation is the denominator. Vendors publish interception numbers, weapons caught, threats stopped, items seized, and those numbers feel significant in isolation. But without the denominator, they’re meaningless.
If a hospital reports catching 200 weapons last year, that sounds like a security program working. But the question that number doesn’t answer is: out of how many? How many individuals moved through that entrance over the course of the year, and what percentage of the weapons statistically present in that population did the program actually catch? A 200-weapon interception count against 500,000 annual visitors tells a very different story than the same number against 50,000.
“A single data point does not define an outcome,” Evans said. “You never know if it’s trending up or trending down, whether things are improving or getting worse, or whether the data point is even meaningful to what you’re actually trying to do.”
Slow Is Smooth. Smooth Is Fast.
Evans described Xtract One’s work with the British Museum in London as an illustration of what happens when an organization steps back from vanity metrics and defines its actual priorities. The museum faces genuine and recurring security threats. Its courtyard fills with thousands of visitors from around the world every morning before doors open. Every week it deals with the reality of being a high-profile target.
The museum made a counterintuitive decision. It reduced its security staffing, chose different technology, and redesigned its concept of operations around a principle Evans summarized from the Formula 1 world: slow is smooth, smooth is fast. The result was four times the ingress speed and three times the weapons caught compared to the previous approach.
“It came down to understanding what their priorities and metrics were,” Evans said. “They looked at the combination of outcomes they needed, not a single daily metric.”
Mean Time to Secure
The session introduced Mean Time to Secure as the metric Evans believes the industry should be measuring instead. MTTS equals Mean Time to Detect plus Mean Time to Resolve. Primary screening plus secondary screening. The complete picture of how long it takes one individual to move from joining the queue to clearing security entirely.
“Think about this from an outcomes perspective,” Evans told the audience. “Mean Time to Secure is the true metric of the guest journey. Not the one the vendor thinks is going to convince you they’re the best solution.”
The metric captures what throughput numbers miss: what happens after an alert fires, how long secondary screening takes, whether staff have the information they need to resolve an alert quickly, and what the cumulative effect of alert volume is on a security team managing thousands of interactions over a four-hour event window.
What to Do With This
Evans closed with a challenge to every operator in the room. When a vendor presents a single metric, ask the deeper questions. When someone claims a 97% detection rate, ask what the testing conditions were, what sensitivity setting was used, and what population profile was screened. When a hospital publishes a weapons interception count, ask what the denominator is.
“If you’re an operator and you’re being presented a daily metric, go deeper,” he said. “Think about the context around these things and all the different data points that go into understanding the full picture.”
The full session from GSX 2026 is available on YouTube.
Watch the full session here: