A Building Incident Is Now a Cyber Incident
Part 7 of the series
The Building Is Now Part of the Attack Surface
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
For many organisations, cyber incidents and building incidents still belong to different worlds.
One is investigated by the SOC.
The other by Facility Management.
One triggers incident response.
The other triggers maintenance.
One is reported to the CISO.
The other to the Head of Real Estate.
That distinction is becoming increasingly dangerous.
Because modern buildings no longer fail only because components break.
They also fail because software fails.
Because identities are compromised.
Because remote access is abused.
Because cloud services become unavailable.
Because attackers intentionally manipulate operational technology.
The incident may still begin in a building.
Its cause is increasingly digital.
The Traditional Incident Model
Enterprise incident response was built around information technology.
Typical scenarios include:
- ransomware,
- phishing,
- data breaches,
- malware,
- identity compromise,
- denial-of-service attacks,
- cloud misconfigurations,
- insider abuse.
Facility management developed a different incident model.
Examples include:
- power failures,
- broken elevators,
- HVAC outages,
- water leaks,
- fire alarms,
- structural damage,
- equipment failure,
- contractor mistakes.
Historically, these categories rarely overlapped.
Today, they often describe different symptoms of the same event.
When Operational Failure Has a Cyber Cause
Imagine a headquarters building where access-control systems suddenly stop responding.
Employees cannot enter.
Visitors remain outside.
Emergency doors switch to contingency mode.
Facility management initially investigates:
- hardware,
- power supply,
- controllers,
- network connectivity.
Hours later, the SOC discovers compromised supplier credentials that were used to alter the access-control configuration remotely.
The operational incident never changed.
Only its cause did.
Without cyber investigation, the organisation might never discover the real reason.
Cyber Incidents No Longer Stay Digital
The cybersecurity community often discusses digital consequences.
Data theft.
Credential compromise.
System downtime.
Buildings introduce physical consequences.
A manipulated building automation system may affect:
- ventilation,
- cooling,
- heating,
- power management,
- environmental monitoring,
- physical access,
- life-safety systems,
- production environments.
The cyber incident becomes an operational incident.
Sometimes within minutes.
The Cost of Misclassification
One of the most expensive mistakes organisations make is classifying incidents too early.
“This is just a technical fault.”
“This is only a maintenance issue.”
“This is an IT problem.”
“This belongs to the supplier.”
Every premature conclusion delays the correct investigation.
A cooling failure might be mechanical.
Or malicious.
An unavailable CCTV system might be hardware failure.
Or ransomware.
An access-control outage may be a software bug.
Or credential abuse.
Classification should be the outcome of investigation—not its starting assumption.
Incident Response Needs New Participants
Traditional cyber incident response teams typically include:
- SOC analysts,
- incident responders,
- IT operations,
- identity specialists,
- legal,
- communications,
- management.
Building-related cyber incidents require additional expertise.
Examples include:
- facility managers,
- building automation engineers,
- corporate security,
- fire safety specialists,
- operational technology engineers,
- maintenance providers,
- external contractors.
No single discipline understands the complete incident.
Modern incident response therefore becomes multidisciplinary by design.
Evidence Exists Outside IT
Digital forensics traditionally focuses on:
- servers,
- endpoints,
- cloud platforms,
- email,
- firewalls,
- identity providers.
Building incidents generate different evidence.
Examples include:
- controller logs,
- access-control events,
- CCTV metadata,
- environmental sensors,
- engineering workstations,
- building automation servers,
- maintenance records,
- contractor activity,
- physical inspection reports.
If incident responders ignore these sources, the investigation remains incomplete.
The Problem With Escalation Paths
Many organisations maintain separate escalation procedures.
Facility management reports internally.
The SOC follows cyber playbooks.
Corporate Security activates physical response.
Business Continuity evaluates operational impact.
The board receives fragmented information.
During a fast-moving incident, fragmentation becomes delay.
The first question should not be:
“Which department owns this incident?”
It should be:
“What capabilities are required to understand it?”
Crisis Management Changes Too
Building incidents have traditionally focused on restoring operations.
Cyber incidents additionally require:
- evidence preservation,
- threat containment,
- regulatory assessment,
- identity analysis,
- supplier investigation,
- legal coordination,
- external reporting.
A compromised building automation platform may simultaneously require:
- emergency maintenance,
- cyber forensics,
- crisis communication,
- supplier management,
- executive decision-making.
The organisation cannot afford separate crisis structures.
Recovery Is More Than Repair
Replacing failed equipment does not necessarily remove cyber risk.
If attackers entered through compromised supplier access, replacing a controller solves nothing.
If identities remain compromised, recovery is incomplete.
If remote maintenance remains unchanged, the attack path still exists.
True recovery requires asking two separate questions.
How do we restore operations?
How do we prevent recurrence?
Both answers are equally important.
Exercises Must Become Realistic
Many organisations test cyber incidents.
Others test evacuation procedures.
Few test both together.
Consider realistic scenarios.
A ransomware attack disables the building management platform.
Access-control systems become unavailable.
Cooling systems require manual operation.
External contractors need emergency access.
The SOC identifies active attacker persistence.
Executive management must decide whether to isolate operational infrastructure.
These are no longer theoretical exercises.
They represent plausible crisis scenarios.
Prepared organisations rehearse them before reality does.
Reporting to Executive Management
Boards increasingly request cyber reporting.
They also request operational resilience reporting.
Those discussions should converge.
Executives should understand:
- which critical buildings depend on connected infrastructure,
- which operational technologies support essential services,
- which suppliers possess privileged remote access,
- which cyber incidents could disrupt physical operations,
- how quickly recovery can realistically occur.
Enterprise resilience cannot be reported through isolated dashboards.
The Regulatory Perspective
Around the world, regulation increasingly reflects this convergence.
Operational resilience.
Critical infrastructure protection.
Cybersecurity.
Supply-chain governance.
Business continuity.
They all recognise the same reality.
Digital compromise increasingly produces physical consequences.
Organisations that continue separating these domains risk creating governance gaps that attackers will eventually exploit.
What Mature Organisations Do Differently
Mature organisations:
- integrate Facility Management into cyber incident response,
- establish shared escalation criteria,
- correlate physical and digital evidence,
- include operational technology in SOC visibility,
- involve suppliers in incident exercises,
- align crisis-management structures,
- document cyber-physical playbooks,
- report integrated resilience metrics to executive management.
Most importantly, they stop asking whether an incident is physical or digital.
They ask whether enterprise resilience is threatened.
Conclusion
The boundary between physical incidents and cyber incidents has disappeared.
A failed controller may be a maintenance problem.
Or the final symptom of a sophisticated intrusion.
A compromised identity may unlock not only systems—but buildings.
An unavailable cloud platform may prevent not only collaboration—but physical access.
The incident itself no longer respects organisational boundaries.
Neither should the response.
Because in connected buildings, operational disruption and cyber compromise are no longer separate stories.
They are different chapters of the same incident.
And organisations that investigate only one chapter rarely understand the entire attack.
Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion