Never used this product but it may be worth looking into.
http://www.mactech.com/articles/mactech/Vol.23/23.01/2301FocusReview/index.html (NetScreen-5GT)
At least your can set higher security zones for each SSID.
By all means you can go Cisco, run the 1200ap's in standalone mode, but like you said you would have to have compatible controller/switch.
Are you happy to go to the domestic range?
www.tomizone.com is a "out of the box" solution. Uses domestic hardware such as dlink to provide a hotspot as well as a internal network.