At the same time, however, increasing connectivity is creating new cybersecurity risks, making the protection of digital infrastructure a critical issue for the real estate sector.
As Paul Tostevin and Tim Spencer of Savills point out, modern buildings now rely on a broad ecosystem of interconnected technologies. Systems such as Building Management Systems (BMS), energy monitoring platforms, tenant applications and maintenance systems generate substantial volumes of data and enhance operational efficiency.
However, every newly connected technology also adds another potential entry point for a cyberattack.
A successful attack can result in anything from data theft or breaches and ransomware to, at a practical level, the loss of control over critical building functions, including elevators, lighting and heating, ventilation and air-conditioning (HVAC) systems.
As buildings become increasingly “smart” and interconnected, cybersecurity is no longer solely an IT department issue.
It is now directly linked to property management, business resilience and overall business risk. The development of artificial intelligence is reinforcing this trend. On the one hand, AI offers new tools for threat detection and system monitoring. On the other, it can be exploited by attackers to automate attacks, identify vulnerabilities and accelerate malicious activities.
As a result, the greater the digitalisation of buildings, the greater the need for systematic management of digital risks.
The Challenge of Limited Visibility
One of the most significant challenges for property owners and managers is that they often lack a complete picture of all connected systems. According to Savills, responsibility for a building’s technology may be shared among owners, property management companies, facility management teams and external suppliers. As a result, there may be no single mechanism recording every device, application and access point within a building or across an entire property portfolio.
Older systems create additional challenges. Connecting modern networks to legacy infrastructure can create security gaps, particularly where no comprehensive assessment has been conducted to determine whether all systems are adequately integrated and protected.
How Risks Can Be Mitigated
Addressing cyber risks in buildings requires an organised approach rather than a series of isolated measures. A first step is to integrate the cyber risk framework into the broader risk management and business resilience framework of an organisation or building.
A systematic inventory of all systems and devices connected to the network is essential. Regular audits and up-to-date inventories can identify forgotten devices, unmanaged systems and other vulnerabilities.
The findings should be recorded in an active risk register, which should serve not merely as a record but as a tool for continuous risk management and oversight.
Access Control Is Critical
Particular importance should be placed on controlling access to systems. Measures such as multi-factor authentication (MFA), clearly defined user permissions and the immediate removal of access when an employee changes roles or a system is no longer in use can significantly reduce exposure.
At the same time, building Wi-Fi and data communications systems should, where feasible, be segregated from corporate IT networks. This separation reduces the risk that a breach of one system could spread to other critical systems within the organisation.
Suppliers Are a Critical Link
A significant part of the risk also lies outside the building itself. Owners and tenants work with a large number of third-party providers for the operation, maintenance and support of their systems. For this reason, they should ensure that suppliers maintain adequate cybersecurity standards, implement necessary software updates in a timely manner and operate under clearly defined access protocols.
Relevant requirements can also be incorporated into service agreements so that each party’s responsibilities are clearly defined. The resilience of a “smart” building therefore does not stop at the boundaries of the property but also depends on the security of the entire supply and technology chain.
Preparing for the Worst-Case Scenario
Prevention alone is not enough. Building owners and managers should also have cybersecurity incident response plans in place. Incident management procedures should be tested regularly and integrated with broader business continuity plans.
In this context, additional cyber insurance, where available and appropriate, can help mitigate part of the financial impact of an attack and provide additional resources for response and recovery.
Cybersecurity Becomes Part of Property Value
The evolution of “smart” buildings is gradually changing the criteria used to assess a property. Cybersecurity is emerging as a factor that owners and tenants are increasingly considering alongside sustainability, regulatory compliance and operational performance.
For property owners, this means that cybersecurity cannot be treated as an issue to be addressed only after a vulnerability emerges. Instead, it should be incorporated from the outset into building design, technology procurement and day-to-day operations.
