// LENEL ONGUARD HEALTH CHECK · HANS STUDY · ONTARIO, CANADA
Lenel OnGuard Health Check
OnGuard estates tend to be old, large, and load-bearing. They were installed when the organisation was smaller, they have absorbed every acquisition and expansion since, and upgrading them is difficult enough that many run several versions behind while everyone hopes nothing changes.
What the Health Check covers
The defining characteristic of OnGuard environments is accumulation. Modules bought for one project, integrations added by successive integrators, cardholder data that has never been cleaned, and a database carrying fifteen years of history. The review follows that shape.
Version and support position
Where the installed version sits against current and against support, and what the upgrade path realistically costs. On this platform that answer is frequently the single most important finding.
Licensing and modules
OnGuard licenses by module and by count. Which modules are licensed, which are actually used, and where the estate has grown past what was bought.
SQL Server and database health
Database sizing, maintenance plans, index and event history growth, archiving strategy, and backup and restore that has been tested. Long-lived OnGuard databases are rarely maintained proportionally to their age.
Controller and panel estate
Firmware consistency across the field, memory and cardholder capacity against the population loaded, downstream device health, and offline behaviour when the server is unreachable.
Cardholder and access levels
Data hygiene at scale, stale records, access level sprawl, and whether the permission model can still be explained by anybody currently employed.
Integrations
Video, intrusion, elevator, visitor management, HR and directory synchronisation. Each one is a dependency, and on older estates several were built by people who have moved on.
Redundancy and continuity
What actually survives a server failure, whether failover has been tested rather than assumed, and what the field does while the head end is unavailable.
Security and hardening
Operator privilege model, service accounts, encryption and certificate posture, audit trail retention against policy, and patch discipline on a system that is often treated as untouchable.
Where OnGuard estates commonly sit
- Several versions behind, because the upgrade is genuinely hard and the system is genuinely critical, so it keeps getting deferred.
- A database nobody has maintained relative to its age, carrying more history than anyone has a policy for.
- Access levels accumulated over a decade, where removing one is riskier than leaving it because nobody knows what it grants.
- Integrations built by departed integrators, undocumented, and only understood by whether they are currently working.
- Redundancy assumed rather than demonstrated, often because testing it would mean taking access control down.
- Treated as untouchable, which is how a critical system ends up unpatched and unexamined for years at a time.
Who this is for
Large organisations where OnGuard controls access to something that matters and where the institutional knowledge about it has thinned out. Healthcare, education, government, critical infrastructure, and enterprise campuses.
Most useful before an upgrade decision, ahead of a budget cycle, after the person who knew the system has left, or when a merger has brought two estates together.
What you receive
The deliverable is a prioritized remediation plan, not a pile of observations you have to triage yourself.
- A findings report organized by severity and by system layer, readable by both the security team and the IT team.
- A clear position on version, licensing and upgrade cost, which on this platform is usually the decision driving everything else.
- Specific, configuration-level recommendations tied to published guidance.
- A working session to walk through the findings and answer what the report raises.
Recommendations do not change based on who is selling. There is no product being steered toward at the end of this.
Scope and pricing
Fixed price, agreed in writing before the work starts. No hourly meter, no scope creep, and no invoice larger than the conversation suggested. Nothing is sold at the end of it either, which is the independence policy.
// Start here
Starter health check
$500
One system, any size
Remote, 90 minutes, live
- Version position against end of life and end of support
- The upgrade path in order, with the traps on it
- Obvious risks visible without a full review
- A straight answer on whether a full health check is worth your money
Credited in full against a full health check booked within 30 days.
// Most common
Health check, single site
$4,500
One site, up to 150 doors
Remote. Remote unit or on site available
- Full review across every layer listed on this page
- Findings report by severity and by system layer
- Configuration-level recommendations tied to published guidance
- Prioritized action list separating now, scheduled, and design-around
- A 90-minute working session to walk it through
// Multi-site
Health check, multi-site
$9,500
Up to 3 sites, up to 500 doors
Remote. Remote unit or on site available
- Everything in the single-site review, across the estate
- Redundancy, failover and database availability reviewed as one system
- Cross-site behaviour checked against what the design assumed
- A 90-minute working session to walk it through
// Larger estates
Enterprise
From $18,000
Beyond 3 sites or 500 doors
Scoped per engagement
- Scoped and priced in writing before anything starts
- Unusual integration, compliance or jurisdictional requirements accommodated
Extend a tier instead of jumping to the next one
Estates rarely land neatly on a boundary. If yours sits just past one, add to the tier below rather than paying for the one above. The rates follow the same slope as the tiers, so extending is never a worse deal than upgrading.
Cameras, doors, readers or controllers beyond the tier allowance. Counted as configured, not as licensed. (per 100)
A further site beyond the tier allowance, reviewed to the same depth and included in the same report. (per site)
Pre-configured appliance shipped to site and returned. See delivery below. (per deployment)
Where physical inspection is required. Travel agreed in writing before it is incurred. (per day, plus travel at cost)
A further 90-minute session, usually for a different audience such as IT, operations or a vendor. (per session)
The findings translated into a short document for a board, council or executive, written to be read by somebody non-technical. (one-off)
Findings inside five business days rather than the standard window. Subject to availability.
How the work is delivered
Screen share, supplied configuration exports, logs and documentation. Most of what a health check examines is visible without anyone travelling, and this is how the majority of engagements run.
A pre-configured unit ships to the site. Somebody on site plugs it into power and network, which takes minutes and needs no technical skill. It provides the access needed to examine the system properly, then ships back. Covers configuration, shipping both directions, and retrieval.
Cheaper and faster than travel for a single site, and it is what makes distance stop mattering. A site in another province costs the same to review as one an hour away.
Where the work genuinely requires being in the room: physical inspection, cabling and rack conditions, commissioning witness, or an environment that cannot be reached remotely. Day rate plus travel at cost, agreed in writing up front and never added afterwards.
What a health check does not include
Listed because an unstated exclusion is what turns a fixed price into an argument at invoice time, and that is the exact failure this practice exists to review other people for.
- Remediation. The report says what to fix; fixing it is a separate engagement or your own team.
- Configuration changes. Nothing is altered on a live system during a review.
- Licence, hardware or software costs, which are yours and are bought direct.
- Vendor support cases, escalations, or dealings with your integrator on your behalf.
- On-site attendance, unless added explicitly.
- Ongoing monitoring or a retainer. A health check is a point-in-time assessment.
Prices are for a Lenel OnGuard environment and are held for 30 days from quotation. Travel, where an on-site day is added, is charged at cost and agreed in writing before it is incurred.
Health checks for other platforms
Same structure and the same fixed pricing across every platform. The layers reviewed differ, because the ways these systems fail differ.
Genetec Security Center →
Architecture, roles and sizing under real load.
C-CURE 9000 →
CrossFire, iSTAR estate, SQL dependency and integrations.
Milestone XProtect →
Edition, Device Pack currency and support entitlement.
Avigilon Unity and Alta →
Which product family you are in, and what that decides.
AXIS Camera Station →
Edge analytics, and the device estate that limits them.
Kantech EntraPass →
Edition ceiling, gateway topology, and controller firmware.
Find out where it actually stands
A system nobody wants to touch is not stable. It is unexamined, and the difference only becomes visible on the day it matters.
Independent of Lenel, Honeywell, and every integrator involved. See the independence policy.