The Hidden Door: Why Remote Maintenance Has Become the Most Dangerous Entry Point into Smart Buildings
Modern buildings rarely operate in isolation.
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Behind every intelligent office tower, production facility, logistics center or government campus stands an invisible ecosystem of external specialists. HVAC engineers monitor climate systems. Elevator manufacturers perform diagnostics. Fire protection companies update control panels. Energy providers manage smart meters. Building automation vendors troubleshoot controllers from hundreds of miles away.
None of this is unusual.
In fact, remote maintenance has become essential to modern facility operations.
It reduces travel.
Accelerates repairs.
Improves availability.
Lowers operational costs.
But every trusted remote connection introduces something else.
Another door.
For decades, cybersecurity concentrated on protecting employees, endpoints and corporate networks.
Today, many attackers no longer begin with employees.
They begin with trusted service providers.
For the modern CISO, remote maintenance has become one of the least visible—and potentially most dangerous—parts of the enterprise attack surface.
Every Smart Building Has Invisible Visitors
Walk through a modern office building and very little appears unusual.
Lights operate automatically.
Heating adjusts itself.
Elevators optimize traffic.
Security doors unlock for authorized employees.
Yet behind these everyday functions are dozens of organizations maintaining systems from outside the building.
Remote engineering access is now common across:
- Building Management Systems (BMS)
- HVAC controllers
- Energy management platforms
- Fire detection systems
- Elevators
- Access control
- CCTV platforms
- Smart lighting
- Solar installations
- Battery storage
- Electric vehicle charging infrastructure
Each connection exists for legitimate business reasons.
Each also extends the organization’s trust boundary.
Trust Has Become the Attack Surface
Cybersecurity traditionally assumes that authenticated users are legitimate users.
Remote maintenance challenges that assumption.
A vendor account may be:
- compromised
- stolen
- reused
- shared
- poorly protected
- insufficiently monitored
From the building’s perspective, however, it remains trusted.
Attackers increasingly understand this.
Rather than attacking the building directly, they compromise the trusted relationship surrounding it.
The building itself becomes the second victim.
The Legacy Problem
Many building automation environments were never designed for today’s threat landscape.
Remote access often evolved gradually over many years.
A VPN added for convenience.
A vendor portal introduced during an upgrade.
A cellular gateway installed for emergency support.
A temporary engineering account never removed.
Over time, exceptions accumulate.
The result is rarely a single security weakness.
It is a collection of historical decisions that quietly expanded the attack surface.
Many organizations no longer know exactly how many remote connections exist—or why they still exist.
Convenience Rarely Disappears
Operational technology values availability.
If remote maintenance prevents downtime, it quickly becomes indispensable.
Unfortunately, convenience tends to outlive necessity.
Permanent VPN tunnels remain active.
Shared administrator accounts continue to exist.
Default credentials survive hardware replacements.
Engineering workstations retain unrestricted access.
Temporary service accounts become permanent infrastructure.
None of these decisions appear catastrophic individually.
Together they create an environment where trusted access gradually becomes unmanaged access.
Third Parties Multiply Enterprise Risk
Every additional supplier expands the organization’s security perimeter.
Unlike traditional IT outsourcing, building automation often involves dozens of highly specialized vendors.
Different companies may maintain:
- HVAC systems
- elevators
- security systems
- electrical infrastructure
- lighting
- energy optimization
- industrial controls
- environmental monitoring
Each supplier maintains its own cybersecurity maturity.
Each operates under different security practices.
Each introduces another potential entry point into the enterprise.
Cybersecurity can no longer evaluate only internal controls.
It must evaluate the resilience of the entire operational ecosystem.
AI Is Changing Vendor Reconnaissance
Artificial intelligence accelerates attacks against trusted suppliers as much as it accelerates attacks against enterprises.
Public documentation.
Maintenance manuals.
Support portals.
Product catalogues.
Technical certifications.
Organizational structures.
All become easier to analyze.
Attackers can identify likely service providers, understand maintenance processes and prioritize organizations whose compromise provides the greatest operational reach.
Instead of attacking one building, they increasingly seek access to the companies maintaining hundreds of buildings.
One Vendor, Hundreds of Buildings
Perhaps the greatest strategic risk lies in concentration.
A single maintenance provider may support:
hundreds of offices,
multiple government agencies,
critical infrastructure,
healthcare facilities,
industrial plants,
and commercial properties.
Compromising one supplier potentially provides access to an enormous number of downstream environments.
This is the cyber-physical equivalent of software supply chain attacks.
Except the target is no longer software.
It is operational trust.
Zero Trust Must Reach Operational Technology
Many organizations have invested heavily in Zero Trust architectures for enterprise IT.
Identity verification.
Least privilege.
Continuous authentication.
Conditional access.
Session monitoring.
Remote maintenance often remains outside these controls.
Trusted vendors may still receive broad network access simply because “they have always had it.”
That assumption belongs to another era.
Zero Trust should increasingly extend into building operations.
Every remote session should answer familiar questions:
Who is connecting?
Why now?
From where?
To which system?
For how long?
Was the activity expected?
If these questions cannot be answered, trust is no longer being managed.
It is merely being assumed.
Governance Before Technology
Technology alone cannot solve the problem.
The larger challenge is governance.
Many organizations cannot produce a complete inventory of:
- remote maintenance providers
- engineering accounts
- permanent VPNs
- cloud management portals
- service gateways
- cellular connections
- privileged vendor identities
Without visibility, meaningful risk management becomes impossible.
The first security control is not stronger authentication.
It is knowing that the connection exists.
Questions Every CISO Should Ask
Remote maintenance deserves the same executive attention as cloud administration or privileged identity management.
Key governance questions include:
- Which suppliers have remote access to our buildings?
- Which systems are permanently reachable?
- Are engineering accounts individually assigned?
- Is multi-factor authentication enforced?
- Are sessions logged and monitored?
- Are privileged connections approved for each use?
- Can remote access be disabled immediately during an incident?
- Do contracts define cybersecurity obligations?
- Have suppliers been included in cyber resilience exercises?
The answers often reveal more risk than vulnerability scans ever will.
Looking Ahead
Smart buildings cannot function without trusted partners.
Remote maintenance is not the problem.
Unmanaged trust is.
The organizations that successfully secure cyber-physical infrastructure will not eliminate vendor access.
They will govern it with the same discipline applied to privileged access inside enterprise IT.
Because the next major intrusion into your building may never cross the front door.
It may arrive through the maintenance connection that everyone forgot existed.
Coming Next
Part 4 – Building Ransomware: When Attackers Stop Encrypting Servers and Start Disrupting Buildings
Why ransomware is evolving beyond IT systems to target HVAC, elevators, access control, energy management and other operational technologies—turning physical disruption into a powerful form of cyber extortion.
Publication Note & Disclaimer
This article provides security and governance analysis, not legal advice. Regulatory obligations must be assessed against the facts, jurisdictions, data types, and roles of the organizations involved.
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion