4 min read

Buildings Under Attack: Why Every CISO Must Prepare for Cyber-Physical Threats

Buildings are no longer passive infrastructure. They are connected cyber-physical systems that combine IT, OT, IoT and AI. This article introduces the emerging attack landscape every CISO should understand before smart buildings become the next major enterprise risk.
Buildings Under Attack: Why Every CISO Must Prepare for Cyber-Physical Threats
Foto by E. Mehler 2026

There was a time when buildings were simply places where business happened.


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


oday they are among the largest distributed computing platforms inside the enterprise.

Every office, warehouse, production site, embassy, logistics hub, laboratory and data center increasingly depends on thousands of interconnected devices that control physical processes. Heating, ventilation, elevators, access control, surveillance, lighting, fire protection, energy management, occupancy optimization and predictive maintenance are all becoming software-defined.

For decades these systems belonged to facility management.

Today they belong on the CISO’s risk register.

Most organizations have invested heavily in securing endpoints, cloud services and identities. Yet the systems that physically enable employees to enter buildings, keep servers cool, provide electricity or control emergency procedures often remain outside the visibility of corporate cybersecurity.

This creates a dangerous illusion.

The organization believes it understands its attack surface while an entire layer of cyber-physical infrastructure remains largely unmanaged from an information security perspective.

This article begins a new series examining why smart buildings have become one of the fastest-growing cybersecurity challenges for enterprise CISOs.


Buildings Have Become Distributed Operational Technology

Modern buildings no longer resemble traditional facilities.

Instead, they have evolved into complex operational environments combining multiple technology domains.

A typical enterprise campus may include:

  • Building Management Systems (BMS)
  • HVAC controllers
  • Access control platforms
  • Video surveillance
  • Smart lighting
  • Energy optimization systems
  • Battery storage
  • Solar generation
  • Electric vehicle charging
  • Digital signage
  • Occupancy sensors
  • Environmental monitoring
  • IoT gateways
  • Cloud management platforms
  • AI-based optimization services

Each subsystem was usually introduced independently.

Each often has its own vendor.

Each follows its own lifecycle.

Each brings another trust relationship into the enterprise.

The result is not a single system.

It is an ecosystem.


Why Attackers Are Becoming Interested

Historically, compromising building systems required specialized knowledge of proprietary industrial protocols.

That barrier is disappearing.

Large language models can now assist attackers by analyzing documentation, interpreting unfamiliar protocols, generating scripts, identifying vulnerable configurations and accelerating reconnaissance.

AI is reducing the expertise required to attack cyber-physical infrastructure in much the same way it has already transformed attacks against traditional IT.

The economics have changed.

Attacks that previously demanded weeks of specialist work may soon require only hours.


The Invisible Infrastructure Problem

Most CISOs know exactly how many servers they operate.

Far fewer can answer questions such as:

  • Which buildings have remote maintenance connections?
  • Which HVAC vendors maintain persistent VPN access?
  • Which elevators receive cloud-based updates?
  • Which security cameras communicate with external services?
  • Which energy management platforms exchange data with cloud providers?
  • Which building systems share enterprise identities?

These unknowns create an invisible attack surface.

An attacker only needs one overlooked connection.


From Smart Buildings to Cyber-Physical Systems

The real issue is not automation.

It is dependency.

Business continuity increasingly depends on systems that blur the boundaries between physical operations and digital infrastructure.

Consider just a few examples.

A compromised HVAC controller may overheat server rooms.

An access control failure may prevent emergency responders from entering a facility.

Manipulated energy management systems may disrupt business operations without touching a single corporate server.

False sensor readings may influence AI-driven optimization engines to make harmful operational decisions.

The objective is no longer simply stealing data.

It is controlling physical outcomes.


AI Changes the Threat Model

Artificial intelligence is becoming part of building operations themselves.

Modern platforms increasingly optimize:

  • energy consumption
  • climate control
  • maintenance schedules
  • occupancy planning
  • predictive servicing
  • security operations

This creates an entirely new class of attacks.

Instead of exploiting software alone, attackers may manipulate the data on which intelligent building systems rely.

Sensor spoofing.

Data poisoning.

Digital twin manipulation.

Autonomous decision interference.

These attacks target trust rather than code.


Supply Chains Become Physical

Every connected building depends on external organizations.

HVAC providers.

Elevator manufacturers.

Energy companies.

Maintenance contractors.

Security integrators.

Remote support providers.

Cloud platform operators.

Every additional supplier introduces another trusted connection into the organization.

For many enterprises, third-party access to building systems now exceeds internal administrative access.

Managing supplier risk therefore becomes inseparable from securing the buildings themselves.


The Rise of Cyber-Physical Risk

Traditional cybersecurity frameworks focused on protecting information.

Modern enterprises must also protect operational continuity.

Buildings increasingly represent the convergence point between:

  • Information Technology (IT)
  • Operational Technology (OT)
  • Internet of Things (IoT)
  • Artificial Intelligence (AI)
  • Physical Security
  • Facility Management
  • Enterprise Risk Management

These domains can no longer operate independently.

A cyber attack against a building may ultimately become:

  • a safety incident,
  • a business continuity crisis,
  • a regulatory issue,
  • a reputational event,
  • or a financial loss.

The CISO therefore becomes a strategic stakeholder in areas that historically belonged elsewhere.


Security Governance Must Expand

The challenge is not simply adding another technology stack to the security program.

It requires expanding governance itself.

Asset inventories must include building automation.

Risk assessments must consider physical consequences.

Supplier governance must cover remote maintenance.

Incident response must integrate facility management.

Business continuity planning must address cyber-physical failures.

Security monitoring must include operational technology.

Most importantly, executive leadership must recognize that buildings have become digital assets.

Ignoring them creates governance blind spots that no amount of endpoint protection can compensate for.


The Next Decade

Smart buildings are rapidly becoming intelligent buildings.

Intelligent buildings will soon become autonomous buildings.

As AI increasingly coordinates physical infrastructure, the distinction between cybersecurity and operational resilience will continue to disappear.

Organizations that continue treating building security as a purely technical facilities issue will find themselves unprepared for attacks that combine digital compromise with physical impact.

For CISOs, this is not another niche discipline.

It is the next expansion of enterprise cybersecurity.

The buildings we work in are becoming computers.

And computers eventually become targets.


Coming Next in This Series

Over the coming articles, we will explore:

  • Why traditional IT security often cannot see building automation.
  • The hidden risks of digital twins and Building Information Modeling (BIM).
  • AI-driven attacks against Building Management Systems.
  • The growing threat posed by remote maintenance providers.
  • Building ransomware and cyber-physical extortion.
  • Sensor manipulation and AI decision poisoning.
  • Supply-chain attacks targeting facility operations.
  • Zero Trust architectures for smart buildings.
  • Governance models that bring Facility Management and the CISO together.
  • Building cyber resilience for globally distributed enterprises.

Because the next major cyber incident may not begin in your data center.

It may begin in your building.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.