Earlier quoted context omitted.
I care a lot more about my life (or my car's catalytic converter, which was stolen off my car in my work parking lot before they inatalled a gate for the lot) than any of my work-related IT credentials. Health and safety threats are a much bigger deal to people than nebulous, difficult to exploit threats to IP.
Except the turnstiles and swipe cards do almost nothing against an active shooter situation. But missing in this discussion is a risk and consequence analysis. If the risk is armed attackers, do something that targets that. For physical theft, target that. Likewise IT risks. The core problem is that risks were not being identified (systematically or in response to expert feedback) and prioritised. Incidentally, the s…
Or the person who wrote the article just wasn't involved in that loop, or otherwise disagreed on what threat models mattered.