5 min read

The Invisible Infrastructure: What the ISMS Does Not See

The largest attack surface is often the one that never appears in the asset inventory. Legacy controllers, hidden interfaces, cloud services and remote maintenance create invisible cyber risk that many ISMS programmes still fail to govern.
The Invisible Infrastructure: What the ISMS Does Not See
Foto by E. Mehler 2026

Part 2 of the series 

The Building Is Now Part of the Attack Surface


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


Every successful attack begins with visibility.

Not visibility for the defender.

Visibility for the attacker.

Before exploiting vulnerabilities, compromising identities or deploying malware, attackers answer a much simpler question:

What exists that nobody is watching?

In modern enterprises, the answer is surprisingly often found outside the traditional IT inventory.

It exists in building management systems, electronic access control, surveillance platforms, environmental sensors, energy-management systems, maintenance gateways, cloud services operated by third parties and legacy controllers that have quietly remained operational for fifteen or twenty years.

These systems rarely appear on executive dashboards.

Many never appear in the ISMS at all.

That makes them dangerous—not because they are inherently insecure, but because they frequently remain invisible.

The Difference Between an Asset Register and Security Visibility

Most organisations believe they know their infrastructure.

They possess property databases.

Maintenance records.

Building documentation.

Floor plans.

Service contracts.

Equipment registers.

Construction drawings.

None of these were created to answer security questions.

A maintenance register tells the facility team where a controller is installed.

It rarely answers questions such as:

  • Who administers it?
  • Which identities authenticate to it?
  • Is it connected to the corporate network?
  • Does it communicate with a cloud platform?
  • Does it support encryption?
  • Can it produce security logs?
  • Does the SOC even know it exists?
  • Who approved the remote access?

An ISMS requires security visibility.

Traditional facility documentation provides operational visibility.

Those are not the same.

Invisible Does Not Mean Small

Security programmes often concentrate on systems considered strategically important:

  • Active Directory
  • Microsoft 365
  • SAP
  • Cloud infrastructure
  • Endpoints
  • Firewalls
  • Identity providers

Meanwhile, hundreds of operational devices remain outside governance.

Examples include:

  • Building Management Systems (BMS)
  • HVAC controllers
  • Electronic locks
  • Lift controllers
  • Digital signage
  • Lighting controllers
  • Occupancy sensors
  • Smart energy meters
  • Environmental monitoring
  • Visitor-management kiosks
  • Parking systems
  • Camera management servers
  • Alarm gateways
  • Power-management systems

Individually they appear insignificant.

Collectively they form an extensive digital ecosystem.

Attackers do not care which department owns these systems.

They only care whether they create opportunity.

Legacy Does Not Mean Offline

Many executives assume that older building systems are isolated.

In reality, the opposite has often happened.

Systems installed fifteen years ago have gradually accumulated:

  • Ethernet connectivity
  • VPN access
  • Vendor maintenance tunnels
  • Mobile applications
  • Cloud dashboards
  • API integrations
  • Remote monitoring
  • Identity synchronisation
  • Data exports
  • Web interfaces

Each addition solved a business problem.

Very few organisations reassessed the overall security architecture after every incremental change.

The result is technical evolution without governance evolution.

The Forgotten Controllers

One of the least visible components inside modern buildings is the programmable controller.

Controllers regulate:

  • temperature,
  • ventilation,
  • pumps,
  • lighting,
  • pressure,
  • access mechanisms,
  • energy distribution,
  • environmental monitoring.

Many continue operating for decades.

Unlike laptops, they are rarely replaced every four or five years.

Their operational life often exceeds twenty years.

That longevity creates multiple security challenges.

Manufacturers may no longer publish firmware updates.

Operating systems may be unsupported.

Authentication mechanisms may never have been designed for today’s threat landscape.

Logging capabilities may be minimal.

Yet these devices continue controlling critical business functions every day.

The absence of incidents is often interpreted as evidence of security.

Usually it is only evidence that nobody has looked closely.

Undocumented Interfaces

The most dangerous interface is often the undocumented one.

During projects, integrations emerge naturally.

An energy platform sends consumption data into reporting software.

Access-control systems synchronise identities with HR.

Visitor systems communicate with email platforms.

Meeting-room systems integrate with collaboration suites.

Environmental sensors upload data to cloud analytics.

Facility dashboards consume information from multiple operational systems.

Each integration appears reasonable.

Years later, nobody possesses a complete picture.

Security architects frequently document enterprise applications in detail while operational integrations remain scattered across vendors, project documentation and local administrators.

The attack surface expands faster than organisational knowledge.

The Cloud Nobody Counts

Shadow IT is no longer limited to business departments.

Facility management increasingly consumes cloud services.

Examples include:

  • remote maintenance portals,
  • building analytics,
  • predictive maintenance,
  • occupancy optimisation,
  • energy dashboards,
  • visitor platforms,
  • contractor management,
  • smart-lock management,
  • CCTV cloud storage.

Many operate entirely outside enterprise cloud governance.

Identity management differs.

Logging differs.

Contract management differs.

Risk assessments differ.

Sometimes procurement itself differs.

Yet these services often process:

  • personal data,
  • building layouts,
  • access information,
  • occupancy patterns,
  • maintenance schedules,
  • operational telemetry.

Ignoring them because they are not operated by IT creates a dangerous illusion of control.

Hidden Remote Access

Remote maintenance remains one of the largest blind spots in facility security.

The challenge is rarely malicious intent.

The challenge is accumulated complexity.

One building may contain remote connections established by:

  • elevator manufacturers,
  • HVAC vendors,
  • fire-protection contractors,
  • energy suppliers,
  • access-control providers,
  • camera integrators,
  • electrical contractors,
  • automation specialists.

Each connection made sense when installed.

Years later nobody knows:

  • which accounts remain active,
  • who still authenticates,
  • whether multifactor authentication exists,
  • whether credentials are shared,
  • whether sessions are monitored,
  • whether connections remain permanently available,
  • whether suppliers subcontract access.

Security depends on assumptions rather than evidence.

The Inventory Gap

An effective ISMS cannot protect unknown assets.

Unfortunately, inventory projects often stop too early.

Knowing that a controller exists is only the beginning.

Security inventories require additional information:

  • owner,
  • business criticality,
  • physical location,
  • network location,
  • firmware,
  • operating system,
  • communication protocols,
  • authentication methods,
  • external dependencies,
  • cloud integrations,
  • remote-access paths,
  • logging capability,
  • backup status,
  • support lifecycle,
  • end-of-life planning.

Without these attributes, risk assessment becomes speculation.

Unknown Assets Cannot Produce Meaningful Risk

Boards frequently request enterprise risk dashboards.

These dashboards often contain:

  • phishing metrics,
  • endpoint compliance,
  • vulnerability trends,
  • patching performance,
  • cloud posture,
  • identity risk.

What they rarely contain is a simple statement:

We do not know how many connected building systems we actually operate.

Unknown assets create unknown risk.

Unknown risk cannot be governed.

Risk management begins with visibility—not with scoring.

Why CISOs Should Care

Some security leaders dismiss facility infrastructure because it appears operational rather than digital.

That distinction no longer exists.

An attacker may never intend to compromise building automation itself.

Instead, building infrastructure can provide:

  • reconnaissance,
  • persistence,
  • lateral movement,
  • privileged third-party access,
  • operational disruption,
  • intelligence collection,
  • identity compromise,
  • physical access.

The objective is not always the controller.

Sometimes the controller is simply the quietest route into something else.

Building Visibility Before Building Controls

Many organisations immediately ask which security controls should be implemented.

That is the wrong first question.

Security controls cannot compensate for invisible infrastructure.

The first objective is visibility.

Visibility requires collaboration between:

  • Facility Management
  • Information Security
  • Enterprise Architecture
  • IT Operations
  • Corporate Security
  • Procurement
  • Asset Management
  • Business Continuity
  • Risk Management

No single department owns the complete picture.

Only together can they build one.

What Mature Organisations Do Differently

Organisations with mature cyber-physical governance no longer separate facilities from information security.

They establish:

  • a common asset inventory,
  • unified ownership,
  • lifecycle governance,
  • supplier visibility,
  • remote-access governance,
  • security architecture reviews,
  • integrated risk assessments,
  • SOC awareness of operational technology,
  • executive reporting covering both digital and physical infrastructure.

Most importantly, they stop asking whether a system belongs to IT.

Instead, they ask whether the organisation depends on it.

That single question changes the entire conversation.

Conclusion

Attackers rarely discover infrastructure by accident.

Organisations often do.

Every undocumented interface, forgotten controller, unmanaged cloud service and invisible maintenance connection represents uncertainty.

Uncertainty is not a technical weakness.

It is a governance weakness.

An effective ISMS cannot protect what it cannot see.

Before organisations invest in more security technology, they should ensure they actually know where their digital infrastructure begins—and where it silently continues beyond the traditional boundaries of IT.

Because the largest attack surface is often the one that never appeared in the inventory.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.