The Building Is Now Part of the Attack Surface
Introduction to a CISO Series on Facility Management, Building Technology and the ISMS
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
For many years, the relationship between information security and facility management appeared relatively simple.
Facility management protected the building. IT protected the systems inside it. Corporate security controlled physical access. Health and safety dealt with people, evacuation and statutory operating obligations. The CISO focused on information, networks, applications and cyber threats.
That division of responsibilities was never entirely accurate. Today, it is no longer sustainable.
Modern buildings are interconnected technical environments. Access-control systems communicate with identity platforms. Heating, ventilation and cooling systems are remotely managed. Cameras, alarms, lifts, energy meters, occupancy sensors and visitor-management platforms process data and exchange commands. Building-management systems connect technical equipment, maintenance providers, cloud services and internal networks.
The building is no longer merely the physical location in which information is processed.
The building itself has become an information-processing system.
That change introduces a new category of organisational risk. It creates dependencies that are neither purely physical nor purely digital. A cyber incident can now affect doors, cooling, energy, surveillance, workspace availability and emergency operations. A physical compromise can provide access to networks, devices, cables, technical rooms and sensitive information. A maintenance provider may have more persistent and privileged access to a critical site than many internal administrators.
Yet in many organisations, facility management still remains largely outside the Information Security Management System.
This series examines why that separation has become dangerous, why integration is difficult and what CISOs, facility leaders, IT managers and executive boards need to change.
A Blind Spot Created by Organisational History
Most security gaps in buildings are not created by deliberate negligence.
They are created by history.
Building systems were traditionally procured as specialised technical installations. Their purpose was functional: open and close doors, regulate temperature, detect smoke, control ventilation, operate lifts or record energy consumption.
Security requirements focused mainly on:
- operational reliability,
- fire protection,
- occupational safety,
- statutory inspections,
- maintenance,
- physical protection,
- availability,
- warranty obligations.
Cybersecurity was rarely a central design requirement.
This was understandable when individual systems were isolated, locally operated and dependent on proprietary hardware. It became less defensible as those systems acquired network interfaces, web consoles, cloud connections, mobile applications and remote maintenance capabilities.
The organisational model, however, often remained unchanged.
Facility management continued to own the system. IT sometimes provided the network. A service provider operated the application. A manufacturer retained remote access. Corporate security used the data. Procurement held the contract. The CISO was informed only when an audit identified a problem or a serious incident had already occurred.
No single function had a complete view.
That is the central governance problem.
The building may be technically connected, but its accountability remains organisationally fragmented.
The False Boundary Between IT and Building Technology
A common response from facility organisations is that building technology is not IT.
Technically, that may sometimes be correct. From a risk perspective, it is irrelevant.
A building-management controller does not have to resemble a conventional server to become part of the attack surface. An electronic locking platform does not have to be operated by the IT department to affect identity, access and physical security. A cloud-based visitor-management system does not stop processing personal data because it was purchased through a real-estate project.
The relevant questions are not:
- Is this system owned by IT?
- Does it run a standard operating system?
- Is it called an application?
- Does the facility team consider it an IT asset?
The relevant questions are:
- Does it process information?
- Can it be accessed remotely?
- Does it control a physical or operational function?
- Can its compromise affect confidentiality, integrity or availability?
- Does it create a dependency for a critical business process?
- Can it be used to reach other systems?
- Does it process personal, operational or security-sensitive data?
Once these questions are asked, the boundary becomes much less convincing.
Information security is not defined by departmental ownership. It is defined by risk.
Buildings Have Become Cyber-Physical Systems
The term cyber-physical system is sometimes dismissed as abstract language. In reality, it describes the operational condition of modern buildings very accurately.
A cyber-physical system combines digital control with physical effect.
A command entered into an application may unlock a door. A software configuration may change air pressure in a secure room. A compromised account may disable cameras. A remote connection may alter a controller. A cloud outage may prevent visitor registration. A ransomware incident may make an office building inaccessible even though the building itself remains structurally intact.
This convergence changes the impact of a security incident.
Traditional information-security scenarios often focus on:
- data theft,
- account compromise,
- malware,
- service disruption,
- unauthorised system access.
In a connected building, the same attack may also result in:
- loss of physical access,
- closure of a site,
- disruption of critical rooms,
- loss of cooling or power,
- failure of surveillance,
- manipulation of occupancy information,
- exposure of movement and access data,
- unsafe or uncontrolled operating conditions.
Not every compromised sensor creates a safety crisis. Not every building-automation vulnerability becomes a route into the corporate network. Exaggeration would be unhelpful.
But the potential for digital events to create physical and operational consequences is now real enough that it must be governed systematically.
The Asset-Management Problem
One of the first difficulties for the CISO is that many organisations do not know which connected building systems they operate.
Facility records often contain valuable technical information:
- manufacturer,
- model,
- installation date,
- maintenance provider,
- inspection date,
- service contract,
- physical location.
What they frequently do not contain is the information required for cyber risk management:
- IP address,
- network zone,
- firmware version,
- operating system,
- cloud dependency,
- remote-access method,
- administrative accounts,
- authentication method,
- logging capability,
- encryption support,
- interfaces to other systems,
- support lifecycle,
- known end-of-life date.
The organisation therefore possesses an asset register, but not necessarily a security-relevant asset inventory.
This distinction matters.
A system can be known as a technical installation and still remain invisible to the ISMS.
That invisibility creates a predictable chain of consequences:
- no formal security classification,
- no documented owner,
- no cyber risk assessment,
- no vulnerability process,
- no monitored remote access,
- no defined incident route,
- no recovery objective,
- no management reporting.
The absence of integration does not mean the risk is absent. It means the risk is unmanaged.
The Remote Maintenance Reality
Remote maintenance is one of the most important themes in this field.
Facility systems often depend heavily on external providers. Specialist expertise may be available only from the manufacturer, system integrator or maintenance company. Permanent or recurring remote access is therefore common.
From an operational perspective, this is efficient.
From a security perspective, it can be problematic.
Typical weaknesses include:
- shared service accounts,
- permanent VPN access,
- vendor-controlled credentials,
- unmanaged maintenance laptops,
- undocumented mobile routers,
- missing multifactor authentication,
- no time-limited approval,
- no session recording,
- no regular access review,
- accounts that remain active after contract changes,
- weak separation between customer environments.
The facility manager may reasonably view the service provider as a trusted technical partner.
The ISMS must also view that provider as a privileged third party whose compromise could affect multiple critical systems or locations.
These are not contradictory perspectives. Both are necessary.
Why Facility Managers May Resist ISMS Integration
CISOs often underestimate how the integration message is received.
From the perspective of facility management, the ISMS may appear to bring:
- more documentation,
- more approval steps,
- more audits,
- more restrictions,
- more cost,
- more interference by IT,
- more personal accountability for historical weaknesses.
This can quickly be interpreted as an attempt to place facility management under the authority of the CISO.
That would be the wrong model.
The CISO should not become the operator of building systems. Information security should not take over statutory building responsibilities. IT should not dictate changes to safety-related equipment without understanding operational consequences.
Facility management must retain technical and operational ownership.
But ownership includes responsibility for cyber risk where systems process information, provide remote access, depend on digital platforms or influence critical business operations.
The ISMS provides the common governance framework. It does not replace professional facility expertise.
This distinction is essential for acceptance.
Different Risk Cultures
Facility managers and CISOs often evaluate risk differently.
Facility management is accustomed to tangible failure modes:
- mechanical breakdown,
- fire,
- water damage,
- power failure,
- failed inspections,
- unavailable spare parts,
- unsafe operating conditions.
Cyber risk may appear less concrete.
Why would an attacker target a ventilation system? Why should a 15-year-old controller be considered unsafe when it has operated reliably for years? Why should remote maintenance be restricted when the supplier has always been trusted?
The CISO must translate cyber threats into operational consequences.
The message should not begin with a control reference or a policy requirement.
It should begin with a scenario:
- What happens if the access-control platform becomes unavailable on Monday morning?
- Who can still enter the building?
- Can permissions be managed manually?
- What happens if a former service provider retains administrative access?
- Can an unexplained configuration change be traced to a person?
- What happens if the server-room cooling system is manipulated?
- Can the building be operated safely without its cloud platform?
- Who informs the SOC when a facility technician identifies unusual system behaviour?
This is where the two risk cultures can meet.
Cybersecurity is not a replacement for operational safety. It is an additional cause of familiar operational consequences.
The Governance Gap
The greatest risk is not necessarily a missing firewall or an outdated controller.
The greatest risk is unclear accountability.
In a connected building, responsibility may be divided among:
- the property owner,
- the tenant,
- facility management,
- IT,
- corporate security,
- health and safety,
- procurement,
- the system integrator,
- the maintenance provider,
- the cloud operator,
- the local site manager.
Each party may be responsible for one part of the system, while no one is responsible for the full risk.
Who approves remote access?
Who owns the cyber risk?
Who ensures that a critical system remains supported?
Who decides whether an urgent security update can be installed?
Who can isolate a compromised controller?
Who informs employees when the access system fails?
Who reports the incident to management?
Who pays for the replacement of an insecure legacy system?
Unless these questions are answered before an incident, they will be answered under pressure during one.
That is not resilience. It is improvisation.
The ISMS Must Expand Without Becoming Bureaucratic
Integrating facility management into the ISMS does not mean applying every conventional IT control to every building device.
That approach would fail.
Building systems have different characteristics:
- long operating lives,
- proprietary technologies,
- limited update capabilities,
- manufacturer dependencies,
- safety implications,
- narrow maintenance windows,
- complex warranty conditions,
- low tolerance for untested changes.
A conventional patching target may be technically impossible. A standard endpoint agent may not be supported. Restarting a controller may disrupt building operations. An update may require certification or vendor approval.
The answer is not to exclude these systems from security governance.
The answer is to manage them according to their operational reality.
That may require:
- network segmentation,
- strong remote-access controls,
- compensating monitoring,
- application allow-listing,
- configuration backups,
- tested manual procedures,
- controlled maintenance windows,
- lifecycle replacement planning,
- formal risk acceptance.
A mature ISMS distinguishes between security objectives and standardised implementation methods.
The objective remains mandatory. The implementation must be proportionate and technically appropriate.
What This Series Will Examine
This series explores the integration of facility management, building technology and information security from the perspective of a CISO.
It will examine:
- why building systems remain invisible to many ISMS programmes,
- how asset inventories must change,
- why remote maintenance creates systemic third-party risk,
- where conventional patch-management models fail,
- how digital identity and physical access are converging,
- why facility incidents must be connected to cyber incident response,
- how security requirements should enter construction and procurement projects,
- which governance model can align facility management, IT, corporate security and the CISO.
The aim is not to turn every facility manager into a cybersecurity specialist.
The aim is to ensure that digital building risks are visible, owned, treated and reported with the same discipline applied to other critical enterprise risks.
The CISO’s New Responsibility
The CISO does not need to own the building.
But the CISO must ensure that the organisation understands the building as part of its security architecture.
That requires more than an audit checklist. It requires a new conversation with real-estate teams, facility managers, engineers, corporate security, procurement, IT, business continuity and executive management.
The conversation should begin with a simple observation:
We used to protect information inside buildings. We must now also protect buildings that process information.
Once this is understood, the strategic consequence becomes clear.
A modern building is not passive infrastructure.
It is a connected operational platform, a source of sensitive data, a dependency for business continuity and a potential route between the digital and physical worlds.
It is part of the attack surface.
And it must become part of the ISMS.
Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion