As smart cards have become increasingly prevalent in electronic access control systems, this paperinvestigates an implementation at a national institution, which uses a smart card with publicly known weaknesses.The main outcome is a set of recommendations which can be used for securing electronic access control systemsagainst the discovered flaws of this work: The implementation did not follow guidelines from the manufacturer of thecards, the content of the restricted sector was printed onto each card, and in-house services with inherent securityflaws were built around the cards, but not maintained. These flaws meant that the civil registration number of anyemployee at the institution could be revealed. Additionally, the flaws allowed for changing the PIN code of any cardin the system.