Minimising the risk
Practical steps can reduce exposure, including aligning a cyber risk framework with the wider organisation’s or building’s resilience arrangements. Unmanaged systems, forgotten devices and poor user training all create vulnerabilities. Regular audits and asset inventories should inform a risk log or register to enable a full understanding and identify these before they become problem; this should be an active management and control tool.
Linking back to the risk log, strong access controls are crucial. Examples include multifactor authentication, clearly defined user permissions and the prompt removal of access rights when roles change or systems become redundant. As buildings become even more connected, Wi-Fi and data communications systems should also be segregated from corporate IT networks, limiting the ‘contagion’ of a breach of one system affecting others.
Third-party suppliers represent another critical area. Building owners and occupiers should ensure vendors maintain robust cybersecurity standards, apply software updates promptly and clearly define access arrangements through service-level agreements. Vigilance doesn’t stop at the building boundary; resilience depends on the strength of the entire supply chain.
Finally, as part of the risk management framework, prepare for the worst. Robust incident management procedures are required, including regular testing aligned to business continuity plans. Where possible, additional cyber insurance cover could also limit some of the financial impact and provide additional resources to improve responses and recovery.