4 min read

Security by Design for Buildings: Why Cybersecurity Must Start Before Construction

The most expensive cybersecurity weakness is often created before construction begins. Security by Design and Privacy by Design must become mandatory requirements in planning, procurement and commissioning—not expensive retrofits.
Security by Design for Buildings: Why Cybersecurity Must Start Before Construction
Photo by Claudio Schwarz / Unsplash

Part 8 of the series 

The Building Is Now Part of the Attack Surface


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


The most expensive cybersecurity decision is often the one made before the first cable is installed.

Not because it introduces risk.

Because nobody recognises it as a security decision.

When organisations plan a new building, renovate an existing facility or modernise building automation, discussions typically focus on:

  • architecture,
  • construction,
  • functionality,
  • sustainability,
  • energy efficiency,
  • workplace design,
  • operating costs,
  • regulatory compliance.

Cybersecurity often enters the conversation much later.

Usually after procurement.

Sometimes after commissioning.

Occasionally after the first security assessment.

By then, the most important decisions have already been made.

Security has become an expensive retrofit instead of a design principle.

Buildings Are Software Projects

Modern buildings are no longer collections of independent technical systems.

They are integrated digital platforms.

A contemporary office building may contain thousands of connected components:

  • building automation controllers,
  • HVAC systems,
  • access-control platforms,
  • surveillance systems,
  • lighting controls,
  • elevators,
  • environmental sensors,
  • occupancy analytics,
  • visitor management,
  • smart energy systems,
  • cloud-based maintenance platforms.

Every interface introduces software.

Every software component introduces identity.

Every identity introduces cyber risk.

Construction projects have therefore become software projects—whether organisations recognise it or not.

Security Cannot Be Installed Later

A familiar pattern appears repeatedly.

A new building is completed.

Operations begin.

Months later, the security team discovers:

  • unsupported authentication,
  • shared administrator accounts,
  • undocumented network connections,
  • supplier-owned cloud platforms,
  • missing logging,
  • insecure remote maintenance,
  • proprietary protocols,
  • weak encryption,
  • no integration with enterprise identity management.

The inevitable question follows.

“Can we fix it?”

Usually yes.

Efficiently?

Rarely.

Security added after commissioning costs significantly more than security designed from the beginning.

Procurement Defines Security

The first security architecture is often written—not by the CISO—but by procurement.

Tender documents determine:

  • authentication requirements,
  • encryption standards,
  • logging capabilities,
  • lifecycle support,
  • software update mechanisms,
  • supplier responsibilities,
  • interoperability,
  • remote-access models,
  • documentation quality,
  • ownership of operational data.

If these requirements are absent, suppliers deliver according to contract.

Not according to cybersecurity expectations.

The contract becomes the security architecture.

Security by Design Means Asking Better Questions

Many organisations still reduce Security by Design to technical controls.

Its real value lies in early governance.

Questions should include:

  • Who owns the system after commissioning?
  • How are identities managed?
  • Which enterprise services will integrate?
  • Who maintains software?
  • How long is security support guaranteed?
  • How are vulnerabilities reported?
  • Can the platform generate security logs?
  • Does it support modern authentication?
  • Can remote access be restricted?
  • How are suppliers authenticated?
  • Who owns encryption keys?
  • How will systems eventually be replaced?

Good architecture begins with good questions.

Data Privacy by Design Is Equally Important

Modern buildings process increasing volumes of personal information.

Examples include:

  • access events,
  • visitor identities,
  • occupancy analytics,
  • location information,
  • CCTV recordings,
  • parking usage,
  • environmental preferences,
  • workspace reservations.

These datasets reveal behavioural patterns.

Privacy therefore cannot be considered separately from cybersecurity.

Data minimisation.

Purpose limitation.

Access control.

Retention.

Transparency.

These principles belong inside building design—not merely inside compliance documentation.

Architects, Engineers and CISOs

One of the largest governance challenges is organisational timing.

Construction projects involve:

  • architects,
  • electrical engineers,
  • mechanical engineers,
  • automation specialists,
  • project managers,
  • procurement,
  • contractors,
  • facility management.

Cybersecurity often joins the project only after technical specifications are complete.

At that point, influence has largely disappeared.

Security by Design requires the CISO to become an early stakeholder—not a late reviewer.

The Cost of Vendor Lock-In

Building technology frequently depends on proprietary ecosystems.

Closed management platforms.

Vendor-specific protocols.

Exclusive maintenance contracts.

Restricted firmware.

Custom engineering tools.

Initially, these solutions appear efficient.

Years later they create dependency.

Security improvements become limited by vendor priorities.

Migration becomes expensive.

Lifecycle planning becomes uncertain.

Open architectures may require greater effort initially.

They often provide significantly greater resilience over the system lifecycle.

Security Architecture Extends Beyond Networks

Many organisations define security architecture primarily through network diagrams.

Buildings require broader thinking.

Architecture includes:

  • trust boundaries,
  • identity models,
  • supplier access,
  • operational processes,
  • lifecycle governance,
  • maintenance procedures,
  • resilience strategies,
  • incident response,
  • recovery planning.

Cybersecurity is not another technical subsystem.

It is a property of the overall design.

Designing for Failure

Resilient buildings assume failure.

Controllers will fail.

Networks will fail.

Cloud platforms will fail.

Suppliers will fail.

Authentication services will fail.

Security architecture should therefore answer:

  • How does the building continue operating?
  • Which manual procedures exist?
  • How are emergency overrides governed?
  • Which systems degrade safely?
  • Which functions remain available?
  • How is recovery prioritised?

Security by Design includes graceful degradation—not merely attack prevention.

The Lifecycle Perspective

Construction projects usually end with commissioning.

Cybersecurity begins there.

Connected buildings require governance throughout:

  • planning,
  • procurement,
  • implementation,
  • testing,
  • operation,
  • maintenance,
  • upgrades,
  • decommissioning.

Every lifecycle phase introduces different risks.

Ignoring later phases creates tomorrow’s legacy problems.

Executive Leadership Matters

Security by Design cannot be delegated entirely to technical teams.

Executive management determines whether cybersecurity becomes:

  • a procurement criterion,
  • an investment priority,
  • a governance requirement,
  • a board-level expectation.

If leadership rewards only delivery speed and construction cost, security inevitably becomes secondary.

If leadership defines resilience as a strategic objective, project decisions change accordingly.

What Mature Organisations Do Differently

Organisations with mature cyber-physical governance:

  • involve the CISO during project planning,
  • define mandatory cybersecurity requirements in procurement,
  • integrate Security by Design and Privacy by Design into construction governance,
  • require security architecture reviews before commissioning,
  • standardise identity and logging requirements,
  • avoid unnecessary vendor lock-in,
  • document lifecycle responsibilities,
  • test operational resilience before handover,
  • ensure facility management, IT and security jointly approve critical systems.

Most importantly, they recognise that the cheapest security control is the one implemented before construction begins.

Conclusion

Buildings have become long-lived digital platforms.

The design decisions made today will influence operational resilience for decades.

Cybersecurity therefore cannot remain an afterthought added shortly before handover.

It must become an architectural discipline.

Not because every building will become a target.

But because every connected building will eventually become part of the organisation’s digital ecosystem.

Security by Design is therefore not about adding more controls.

It is about ensuring that resilience is designed into the building long before anyone starts working inside it.

Because the easiest vulnerability to manage is the one that never enters the design.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.