Understanding the risks of being hacked through your tech and building systems

The Savills Blog

Understanding the risks of being hacked through your tech and building systems

Connected buildings offer many advantages, but increased technology increases the risk of being hacked.

Modern buildings rely on an ecosystem of connected technologies. Building management systems, access controls, energy monitoring platforms, and tenant usage and maintenance apps all generate valuable data and improve operational efficiency. However, every connected system adds an "attack surface": a potential entry point that could be hacked by a malicious actor. This could result in data being stolen or compromised, being exposed to ransomware, or, on a practical level, a loss of control over lifts, HVAC or lighting systems.  

 

The growing threat

As buildings become ever smarter and more connected, cybersecurity’s evolved from being largely just an IT consideration: it’s now a property management, operational resilience and business risk issue.

This change has been accelerated by AI, which has given on the one hand (by offering powerful threat detection and system monitoring tools) but taken on the other (allowing attackers to automate activities, identify vulnerabilities and scale operations more effectively, advancing attack speed and sophistication).

Another challenge is visibility. Responsibility for building technology is increasingly shared between owners, managing agents, facilities teams, and suppliers. Often no one has a complete picture of every device, application or access point within a building or portfolio. Legacy systems add another layer of complexity, particularly where modern networks are plugged into older infrastructure without ensuring everything is integrated and meets today's security requirements.

 

Minimising the risk

Practical steps can reduce exposure, including aligning a cyber risk framework with the wider organisation’s or building’s resilience arrangements. Unmanaged systems, forgotten devices and poor user training all create vulnerabilities. Regular audits and asset inventories should inform a risk log or register to enable a full understanding and identify these before they become problem; this should be an active management and control tool.

Linking back to the risk log, strong access controls are crucial. Examples include multifactor authentication, clearly defined user permissions and the prompt removal of access rights when roles change or systems become redundant. As buildings become even more connected, Wi-Fi and data communications systems should also be segregated from corporate IT networks, limiting the ‘contagion’ of a breach of one system affecting others.

Third-party suppliers represent another critical area. Building owners and occupiers should ensure vendors maintain robust cybersecurity standards, apply software updates promptly and clearly define access arrangements through service-level agreements. Vigilance doesn’t stop at the building boundary; resilience depends on the strength of the entire supply chain.

Finally, as part of the risk management framework, prepare for the worst. Robust incident management procedures are required, including regular testing aligned to business continuity plans. Where possible, additional cyber insurance cover could also limit some of the financial impact and provide additional resources to improve responses and recovery. 

 

Occupiers consider cybersecurity alongside operational performance

In a world of smart buildings and connected systems, one weak link can create a serious breach. Cybersecurity is consequently becoming a key component of building quality and value considered by landlords and occupiers, alongside factors such as sustainability, compliance and operational performance. Cybersecurity and a risk management framework should be embedded into building design, procurement and operations from the outset, rather than after vulnerabilities emerge. Buildings that can demonstrate strong governance across both physical and digital systems are likely to be better positioned for the long-term. 

Recommended articles