Smart buildings are helping organisations operate more efficiently, improve sustainability and gain a clearer picture of how their estates are performing. Yet as building management systems, security platforms and energy infrastructure become more closely linked, the risks associated with that connectivity are also increasing. A cyber incident that starts within a digital system can now have a direct impact on the physical operation of a building. Here, our Senior Technology Consultant, Peter Schwartz, explains why organisations need to take a more joined-up approach to managing cyber-physical risk in connected buildings.
As organisations continue to integrate building management systems, access control, CCTV, environmental monitoring and energy infrastructure, the benefits of connectivity are clear. Shared networks provide greater operational visibility, support remote management and help organisations optimise energy use and building performance.
At the same time, every new connection can introduce another route into the wider environment. Smart buildings therefore need to be treated as operational environments where cybersecurity can directly influence business continuity, rather than simply as technology platforms designed to improve efficiency.
The conversation around smart buildings often focuses on energy savings, occupancy analytics and automation. These capabilities undoubtedly deliver value, but they can also overshadow a fundamental consideration in resilience. As building systems become more connected, organisations must consider what happens if those systems are unavailable or deliberately manipulated.
Unlike traditional cyber incidents, the impact is not always measured by stolen data. A cyber-attack against a building management system can have immediate physical and operational effects. Consider a modern office where the building management system controls heating, ventilation and air conditioning (HVAC), access control and environmental monitoring. If an attacker gains access through a poorly secured connected device and moves into the building management network, they may choose not to steal information at all.
Instead, they could alter HVAC schedules and disable environmental alerts. Temperatures begin rising in communications rooms and equipment spaces, critical systems experience outages and facilities teams lose visibility of alarms and system status. The result is operational disruption and potential equipment damage rather than a conventional data breach.
This is why smart buildings should be viewed as operational environments rather than collections of connected technologies. Cybersecurity is now about maintaining operational continuity as well as protecting information.
Many of the systems that present the greatest cyber-physical risk are not traditionally managed as IT assets. Environmental sensors, smart cameras, access control devices, energy management systems and legacy building management controllers are frequently considered operational technology, meaning they can fall outside conventional cybersecurity reviews.
During procurement, organisations understandably focus on functionality, performance and integration. However, security requirements, patching responsibilities and lifecycle management often receive far less attention. As more connected systems are introduced, these gaps become increasingly significant because vulnerabilities in operational technology can provide a route into wider business systems and operations.
The technology itself is only part of the challenge. Third-party vendors and systems integrators often retain privileged remote access for maintenance and support, making supplier security practices an equally important consideration. The UK Government’s Cyber Security Breaches Survey 2025 highlights the wider governance challenge, reporting that only 14 per cent of businesses formally review the cybersecurity risks associated with their immediate suppliers, while just seven per cent assess risks across their wider supply chain.
Although these figures are not specific to smart buildings, they demonstrate that third-party risk remains an area where many organisations have more work to do. Strong governance, clear contractual accountability and regular security assessments should therefore apply equally to both connected technologies and the organisations responsible for supporting them.
Reducing cyber-physical risk does not require organisations to sacrifice the benefits of integration. Instead, the priority should be integrating systems in a way that improves visibility while maintaining appropriate separation between them.
Effective integration is about ensuring systems can share information securely through appropriate network segmentation, clearly defined trust boundaries, robust identity controls and centralised monitoring. The objective is greater operational awareness and faster incident response rather than building an increasingly large and tightly connected environment.
This approach is reflected in guidance from the National Institute of Standards and Technology (NIST). Its Guide to Operational Technology (OT) Security identifies building automation and physical access control systems as operational technology requiring dedicated cybersecurity controls, recommending measures such as network segmentation, strong identity management and continuous monitoring to reduce operational risk.
Monitoring also plays a critical role because most cyber-physical incidents begin as relatively small anomalies. Unexpected device behaviour, unusual network communications, failed authentication attempts, unauthorised configuration changes or equipment unexpectedly going offline can all indicate an emerging issue. Combining asset visibility, operational telemetry and cybersecurity insights enables organisations to identify problems before they affect building operations. In practical terms, organisations cannot secure what they do not know is there.
As building systems, IT infrastructure and physical security increasingly overlap, organisations also need to rethink how responsibility is managed. Traditional siloed ownership models are becoming increasingly difficult to sustain because operational resilience now depends on multiple disciplines working together.
Facilities teams, IT departments and physical security specialists each bring different expertise, but connected buildings require a shared governance framework that applies cybersecurity policies, risk assessments and incident management processes consistently across both IT and operational technology environments. Shared accountability is essential for protecting connected buildings against increasingly complex operational risks.
For organisations looking to strengthen resilience, the most effective starting point is often the simplest. Establish a complete inventory of connected building systems and devices. Many organisations still do not have a comprehensive understanding of everything connected to their environment. Once that visibility exists, unsupported systems can be identified, unnecessary connectivity removed, vulnerabilities assessed and appropriate monitoring introduced. Improving visibility remains one of the fastest and most cost-effective ways to reduce cyber-physical risk.
As smart building technology becomes more deeply embedded in day-to-day operations, resilience needs to develop at the same pace as connectivity. Cyber-physical security can no longer be treated as the responsibility of facilities, security or IT in isolation, because disruption in one area can quickly create consequences across the wider organisation.
Those best placed to manage this risk will be the organisations that understand exactly what is connected across their estates, define clear ownership for those systems and maintain ongoing visibility of how they are operating. By combining stronger governance, effective monitoring and closer collaboration between facilities, security and IT teams, organisations can continue to benefit from smarter buildings while reducing the operational risks that come with greater connectivity.
To learn more about strengthening the resilience of connected buildings, our team is happy to talk it through. Just fill in the form below and we’ll be in touch.