Understanding cybersecurity in smart buildings

 

When we think about Smart Buildings, we immediately think about their advantages. We think of the efficiencies such connected building technology offers developers, building managers and tenants. Whether it’s about efficiency, long-term value or brand perception, stakeholders will suffer if their building is not ‘smart’. However, do we think about their cyber-security risks?

 
September 1, 2019 PropTech
 

Understanding cybersecurity in smart buildings
 

As our buildings become more complex, with the number of IoT connected devices and cloud services growing exponentially, the threat and chance of cyber-attacks becomes even greater. So, how can we understand these challenges and prevent them from happening in the future?

The Challenges of Smart Buildings

Today’s buildings systems often fall short of effectively managing any potential cyber intrusion. This is a direct result of there being an obvious disconnect between groups managing information technology (IT), who have extensive cyber-security knowledge and the groups managing building operational technology (OT), who have the building management system (BMS) operational knowledge. Previously, BMS required specialised knowledge of systems and protocols and didn’t require access to corporate network resources or the internet. Therefore, the security of a BMS network predominantly relied on obscurity and the lack of external connectivity. However, in this day and age, the evolution of BMS technology has meant that typical BMS control systems now use a combination of OT protocols, including ModBus and BACnet, as well as IT protocols such as HTTP and FTP. This has revolutionised the way smart buildings operate but it has also affected how they can be targeted from a cyber perspective.

The evolution of BMS technology is essentially a gold mine for hackers. Coupled with the disconnect between IT groups and OT groups, the de facto operational model for buildings needs to change. In recent years there have even been hacker communities and research groups that specialise in cyberattacks targeting smart buildings to retract important data. Ultimately, the problem starts with the network of a BMS. This network can be deemed as a way in to the wider IT network of an organisation. Hence, not only does the management system itself become the target but so does the whole company.

The Solution

To mitigate these attacks and realise the full potential of smart buildings, operators and occupiers need to alter how smart building control systems are architected and managed from a cybersecurity perspective. Setting aside organisational barriers and acknowledging the IT/OT disconnect is the critical first step towards implementing and operating cyber secure smart building control systems. Luckily, there has already been strong support in the OT control systems industry to address the security challenges being faced today.

Better yet, industry associations have risen to the need for common OT cyber-security best practices, in particular with the development of the IEC 62443 global set of cyber-security standards. This is set to improve safety, availability, integrity and confi dentiality of systems used for industrial automation and control.

Fundamentally, there are four key ways that organisations can create a secure and operational smart building:

1. Assess and protect legacy OT building control systems

2. Choose IoT devices and vendors that follow a Secure Development Lifecycle approach

3. Implement secure OT building control system architectures

4. Bridge the secure OT building control systems through an IT Security Monitoring Zone

 

The future

The vulnerability of a BMS system working with these two sets of protocols lays on the disconnect between the groups in the IT team, who have the cyber security knowledge and the OT team, who have the operational knowledge. The smarter your building gets and the less these two groups work with each other, the more vulnerable technology will become resulting in the increase of external cyberattacks. Teams need to work together to create a more secure system and organisations must adhere to certain practices to keep their building as secure as possible.

(The author, Ram Venkat, is an Energy Management Professional and Evangelist, and is currently working in the UKI Eco-Building Marketing team, Schneider Electric)

MORE FROM BUILT ENVIRONMENT

Musanadah Appoints Rana Alturki to Drive High-value Growth in Saudi Arabia’s Eastern Province
Musanadah Appoints Rana Alturki to Drive High-value Growth in Saudi Arabia’s Eastern Province

In her most recent role as project manager in specialized contracting, Rana managed strategic partnerships and oversaw complex projects from design development through execution and final handover

June 18, 2026 Saudi Arabia Business
The Single-Partner Advantage: How ENGIE Solutions Is Redefining Infrastructure Operations Across Abu Dhabi's Master-Planned Communities
The Single-Partner Advantage: How ENGIE Solutions Is Redefining Infrastructure Operations Across Abu Dhabi's Master-Planned Communities

In this exclusive Q&A, Khaled Ramadan, Head of Operations for Abu Dhabi Emirate at ENGIE Solutions, makes the case for integrated operations, to ensure predictive asset stewardship managing over 250,000 maintainable assets across more than 150 sites.  

June 18, 2026 UAE IFM
EEG Tackles Regional Water Issues: “Strengthening Water Security in Arid Regions Through Sustainable Resource Management”
EEG Tackles Regional Water Issues: “Strengthening Water Security in Arid Regions Through Sustainable Resource Management”

Dr. Habiba Al Mar’ashi, Co-Founder and Chairperson of EEG, highlighted the growing importance of unity, resilience and sustainability in addressing the complex challenges facing the region and the world

June 18, 2026 UAE Sustainability
6 Construction Choices That Can Make Buildings More Heat-Resilient
6 Construction Choices That Can Make Buildings More Heat-Resilient

The decisions made during planning, design, material selection, and construction directly influence how liveable a building will be for future residents and tenants

June 17, 2026 UAE Sustainability
Al-Futtaim Contracting Awarded Contract for Ultra-Luxury Villa Development at Eden Hills by H&H
Al-Futtaim Contracting Awarded Contract for Ultra-Luxury Villa Development at Eden Hills by H&H

The agreement was signed in the presence of Shahab Lutfi, Chairman of H&H, Miltos Bosinis, CEO of H&H, and Murali S, Managing Director of Al-Futtaim Contracting, marking another milestone in Al-Futtaim Contracting’s growing portfolio of premium residential and lifestyle developments across the UAE

June 16, 2026 UAE Real Estate
When Purpose Meets Practice: How Berkeley Services and Emirates Environmental Group Are Redefining Sustainability in the UAE's Built Environment
When Purpose Meets Practice: How Berkeley Services and Emirates Environmental Group Are Redefining Sustainability in the UAE's Built Environment

In a major step toward a low-carbon future, Berkeley has launched a powerful new module within its CAFM system: the ESG Navigator

June 12, 2026 UAE IFM
Innovo Delivers the Sold-Out Six Senses Palm Jumeirah
Innovo Delivers the Sold-Out Six Senses Palm Jumeirah

Designed in strict alignment with LEED green building certification requirements, Innovo integrated highly energy-efficient systems, optimised water consumption frameworks, and carefully selected sustainable materials to dramatically reduce the development's long-term environmental footprint

June 12, 2026 UAE Business
Emaar's Most Ambitious Masterplan for Dubai: An AED 200 billion Vision to Redefine Urban Living
Emaar's Most Ambitious Masterplan for Dubai: An AED 200 billion Vision to Redefine Urban Living

Designed to accommodate a projected population of nearly 150,000 residents, this development will create a city within a city

June 11, 2026 UAE Real Estate
ALBADDAD Unveils New Botswana City
ALBADDAD Unveils New Botswana City

The UAE-headquartered global group specialising in modular construction, exhibition infrastructure and fast-track delivery, announced the launch of New Botswana City

June 10, 2026 Botswana Real Estate
Designing the Invisible in Hospitality: A Hotel's Future Will Be Defined by Human Behavior, Not Buildings
Designing the Invisible in Hospitality: A Hotel's Future Will Be Defined by Human Behavior, Not Buildings

The traditional definition of a hotel is becoming less relevant because it describes an operational category rather than a human experience

June 10, 2026 UAE Business
 
Subscribe to our newsletter