Editor's note:Chris Barns is Vice President of the Real Estate Consulting division at R&K Solutions. The views expressed in this article are solely those of the author.

The daily operations of smart buildings—from lighting to security systems—are increasingly reliant on IoT technology. However, the convenience brought by this high level of connectivity also means an expanded cyber threat surface. According to a report released by CrowdStrike, more than 30 hostile cyber operations were recorded in 2023; and a blog post by Asimily noted that cyberattacks in 2024 affected hundreds of thousands of IoT devices. While these interconnected systems enhance operational efficiency, they also create vulnerabilities that cybercriminals can exploit.

The consequences of cybersecurity incidents in smart buildings can be far-reaching, leading not only to operational disruptions and financial losses but also to potential physical safety risks. Facility managers must confront these challenges head-on to protect building assets and the safety of occupants.

When devices such as security cameras, thermostats, and access control systems are designed with convenience as a priority, the integration process often overlooks security flaws. Weak passwords, unpatched software vulnerabilities, and outdated firmware are common entry points exploited by cybercriminals. Once inside the network, attackers can move laterally across interconnected systems and may even gain control of building control systems such as heating, ventilation, and air conditioning (HVAC). In fact, many of the earliest IoT attacks targeted HVAC systems.

R&K
Chris Barns
Image source: R&K Solutions

In 2013, a cyberattack on retail giant Target led to the exposure of millions of customer data records. According to the U.S. Senate Commerce Committee, attackers gained entry through a compromised account belonging to an HVAC vendor. The financial impact of the incident was enormous, and it also exposed deep-seated issues in third-party risk management and the severe challenges of securing complex supply chains in a highly interconnected environment.

In 2016, a lesser-known attack occurred in Finland. Attackers exploited vulnerabilities in the automation control system of a smart building, causing system failures that left residents of two residential buildings without heating and hot water during winter.

A more recent case is the cyberattack on a U.S. water treatment plant in 2021. Attackers exploited vulnerabilities in the plant's supervisory control and data acquisition (SCADA) system, and after breaching it, tampered with chemical levels in the water, posing a potential threat to public health.

Potential Impact

Cybersecurity vulnerabilities in smart buildings can impact operations, safety, finances, and reputation. Once building operational systems are compromised, critical functions such as HVAC or lighting may fail, resulting in significant downtime and financial losses.

In extreme cases, the loss of functionality in critical systems such as HVAC, elevators, or security controls can directly threaten the safety of occupants. For example, unauthorized access to fire suppression or access control systems could have fatal consequences.

Data breaches in smart buildings can also expose sensitive information such as tenant details and operational data. The financial impact includes both direct costs like regulatory fines and indirect losses such as business attrition and reputational damage.

For property managers and owners, the reputational damage from a data breach can lead to decreased tenant trust, reduced property value, and increased difficulty in future leasing. Public perception of the brand can also be severely affected, as breaches are often interpreted as systemic failures in security and privacy management. This reputational loss often exceeds direct financial losses and can hinder long-term business growth.

Best Practices

Securing smart buildings requires a multi-layered defense strategy, with the first priority being the establishment of a rigorous software update and patch management schedule. This foundational measure ensures that all IoT devices and systems are protected against known vulnerabilities. At the same time, strengthening vendor and contractor management is equally critical, including vetting third parties, implementing strict access controls, and continuously monitoring their activities to prevent intrusions from external sources.

Employee training is another cornerstone of cybersecurity. Conduct regular training sessions to teach employees how to recognize threats such as phishing, manage passwords properly, and adhere to security protocols. Given that human error is a primary cause of security breaches, a security-aware and vigilant workforce is one of the best defenses against cyber threats.

Finally, adopting a zero-trust security model can further enhance protection. This model assumes that no entity, whether inside or outside the network, should be trusted until it has been rigorously verified before gaining access. This approach is particularly effective in addressing the IoT security challenges of smart buildings, ensuring that even trusted sources are subject to scrutiny.

Proactive measures such as regular updates, strict vendor management, network segmentation, and comprehensive employee training can significantly reduce the likelihood of security breaches. As smart buildings continue to evolve, staying abreast of cybersecurity trends and anticipating threats is essential to protecting both digital and physical assets.

Cybersecurity is a critical component of a broader information assurance strategy. This strategy not only encompasses preventing malicious intrusions but also ensures the accuracy and availability of data for authorized users. Expertise in information assurance can help facility managers effectively navigate the risks associated with new smart building technologies while enjoying their benefits.