I get asked this question in one of two forms. The first is from an owner writing a tender who wants to know which platform to specify. The second is from an owner who already has one of them at twelve sites, has just acquired a company running a different one at eight more, and wants to know whether to consolidate. The honest answer to both is that all three run large enterprise estates well, the differences are real, and which differences matter depends on what the estate is for.

What follows is how I read them after fifteen years of designing, auditing, and fixing all three. I hold A&E and channel agreements with vendors in this space so I can reach their engineering resources; none of those agreements pays me anything, and the practice sells no equipment and takes no margin on what gets specified. The independence page says how that works. The opinions below are the ones I would give a client across a table.


The shape of each platform

Genetec Security Center is a unified platform: video, access control, intrusion, and licence plate recognition in one Directory, one client, one audit trail, one set of permissions. Synergis, the access control side, is not a bolt-on; it is the same product. That unification is the whole argument for Genetec, and on estates where the same operators handle video and doors, it is a strong argument. The cost is that you are buying the platform’s way of doing things, and it is a large, opinionated platform with a correspondingly large surface to design, harden, and maintain. The architecture article covers what that surface looks like.

Milestone XProtect is a video management system first and an integration platform second. It is the most open of the three: the widest device support, the most permissive SDK, the largest third-party ecosystem, and the least resistance to being one part of somebody else’s design. Access control is by integration, and there are several good ones, but it is integration rather than unification and the seams show in the operator experience and in the audit trail. Where an owner has a strong access control platform already and wants video that fits around it, Milestone fits.

Avigilon, now under Motorola Solutions, is the most vertically integrated: Avigilon cameras, Avigilon analytics, Avigilon appliances, and Unity as the on-premises VMS, with Alta as the cloud-managed line. The analytics are the point, and they are genuinely good when the cameras are Avigilon’s. The platform is at its best on estates that were designed around it from the start, and at its most awkward when asked to manage a mixed fleet of somebody else’s cameras. The Motorola relationship also gives it a route into public safety radio and command environments the other two do not have.


Where each one wins

DimensionGenetec Security CenterMilestone XProtectAvigilon Unity
Video and access in one systemUnified. One client, one audit trail, one permission model.Integrated. Access control through partners; separate audit trails reconciled after the fact.Integrated. Access control through Avigilon’s own and partner products.
Openness and device supportBroad, with a preference for its own way. Strong on the major camera families.Widest. The ONVIF reference for most camera vendors.Narrowest in practice. Best with Avigilon cameras; workable with the majors.
Multi-site architectureFederation. Mature, well understood, scales to very large estates. Each site keeps its own Directory.Interconnect and federated architecture. Works; requires more design to get the operator experience right across sites.Site families and central management. Cleanest on homogeneous estates.
AnalyticsGood; strongest through partner integrations and its own recent work.Through partners, and there are many.Strongest native analytics, particularly appearance search and classification, on its own cameras.
Licensing shapePer connection, with maintenance. Predictable; grows with the estate.Per device, tiered by edition, with a care plan. Flexible; edition choice matters.Per channel, appliance-led on Unity; subscription on Alta.
Hardening guidanceBest documented. A published hardening guide, a security score in the product, appliances at CIS Level 2.Good. A hardening guide exists and is maintained.Adequate. Appliances ship hardened; the documentation is thinner.
Integrator depth in CanadaDeep, particularly in government, transit, and healthcare.Deep, particularly in enterprise and commercial.Deep in retail, education, and anywhere Motorola already is.
What it costs to run wellHighest. It rewards a dedicated administrator and punishes neglect.Moderate. Simpler to keep healthy; more moving parts at the integration seams.Lowest on a homogeneous estate; rises fast on a mixed one.

The multi-site question specifically

Every enterprise estate ends up federated, whether the platform calls it that or not. Sites have local operators, local network conditions, and local ownership, and the central control room wants to see everything without being responsible for every site’s Archiver. The platforms handle this differently and the difference decides a lot.

Genetec Federation lets each site run its own Directory, with its own administrators and its own database, and presents them to a central Directory as federated entities. The central operators see the cameras and doors; the site keeps control of its system. It scales to hundreds of sites and it survives a site’s WAN link failing, because the site’s system does not need the centre to record. The trade-off is that every site is a full Security Center system, with everything that implies for the databases, the storage, and the hardening, at every site.

Milestone’s answer is Interconnect for remote sites and its federated architecture for larger ones. Both work. The design effort is in making the central operator’s experience consistent, because the central site sees remote cameras through an integration layer rather than natively, and features like bookmarks, permissions, and audit do not always cross the boundary the way an operator expects. On estates with a strong central control room and lightly staffed sites, that design effort is worth doing once. On estates where every site is a control room, Genetec’s model fits more naturally.

Avigilon groups servers into site families with central management, which is clean and easy to administer when every site runs Avigilon appliances and Avigilon cameras. It is the least flexible of the three at the boundary, and an estate that has grown by acquisition, with a different vendor at each acquired site, is the case where I would not put it in the centre.


The security posture of the security system

This is the part of the comparison that owners under-weight and that I weight heavily, because the video system is now an IT system on the corporate network and it is assessed as one. All three vendors publish hardening guidance. Genetec’s is the most complete and the most operationalised: a hardening guide that tracks the release, a security score in Config Tool that tells the administrator what is not done, and appliances that ship at CIS Level 2. Milestone’s guide is thorough and maintained. Avigilon’s appliances ship hardened and the documentation for doing the same on your own servers is thinner.

What matters more than the guide is whether the integrator followed it, and on that the platforms are equal: I find the same gaps on all three, and they are the gaps in the hardening guide on this site. A platform with excellent hardening documentation that was deployed by an integrator who did not read it is less secure than a platform with adequate documentation deployed by one who did. Specify the hardening in the tender, as a deliverable with evidence, and the platform choice matters less.


Licensing, honestly

I am not going to quote numbers, because they change, they are negotiated, and the list price is not what anyone pays at scale. The shapes matter more than the figures.

Genetec’s per-connection model with an annual maintenance agreement is predictable and it grows linearly with the estate. The maintenance agreement is not optional in practice; a system without it cannot upgrade, and the version rules mean a system that stops upgrading eventually cannot be upgraded at all without a multi-step migration.

Milestone’s per-device model is tiered by edition, and the edition decision is where owners get it wrong: buying Professional+ for an estate that will need Corporate’s federation two years later is an expensive correction. Buy the edition for the estate in year three.

Avigilon’s Unity licensing is per channel and often bundled with appliances, which makes it easy to buy and harder to compare. Alta is subscription, which is a different conversation about operating versus capital budgets that finance will want to have before the security team does.


Consolidate, or federate the difference

For the owner with twelve sites on one platform and eight acquired sites on another: do not consolidate on day one. Every one of these platforms can present video from the others through integration, and a year of running both, federated to a central view, tells you which one the operators reach for, which one the integrators in your regions actually know, and which one the incident reports come from. Then consolidate, with evidence, onto the one that earned it. Rip-and-replace at acquisition is how owners end up with the wrong platform at twenty sites instead of the wrong one at eight.


The decision, in the order I would ask the questions

  1. Do the same operators handle video and doors, and does the audit trail need to show both in one place? If yes, Genetec, and the rest of the questions are about whether anything rules it out.
  2. Is there an access control platform that is staying, and is it good? If yes, Milestone fits around it with the least friction.
  3. Is the camera fleet going to be Avigilon, and are the analytics the reason for the project? If yes, Avigilon, and design the estate to stay homogeneous.
  4. Who will run it? A dedicated administrator makes Genetec sing. A generalist IT team keeps Milestone healthy with less effort. An estate with no one to run it should be on appliances, whichever vendor’s.
  5. Who will integrate and support it in the regions the sites are in? The best platform with no competent integrator within three hours of the site is the wrong platform.
  6. What does the hardening deliverable look like in the tender? If the answer is “the integrator’s standard practice,” the platform choice is the least of the risks.

If the answers point in different directions, that is the normal case and it is what a pre-purchase design review is for. If they point at one platform and the tender is specifying a different one because of a relationship, that is worth a conversation before the tender closes rather than after the contract is signed.

And whichever platform it is, the estate will be healthy in year three only if someone checks. The Genetec, Milestone, and Avigilon health checks exist because the failure modes are the same on all three, and they are almost never the platform’s fault.

References

  1. Security Center Enterprise Best PracticesSecurity Center 5.14
    Genetec TechDocstechdocs.genetec.com
  2. Security Center Hardening GuideSecurity Center 5.14
    Genetec TechDocstechdocs.genetec.com
  3. NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) SecurityRev 3
    NISTcsrc.nist.gov
  4. Product lifecycle management
    Genetecgenetec.com

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.