When Facility Management Meets Cybersecurity
Part 3 of the series
The Building Is Now Part of the Attack Surface
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Most organisations believe their biggest security challenge is technology.
It rarely is.
The more difficult challenge begins when two professional worlds collide.
Facility management speaks about buildings.
Cybersecurity speaks about information.
Facility managers discuss operating obligations, maintenance windows, HVAC systems, fire protection, contractors and building availability.
CISOs discuss assets, identities, attack paths, vulnerabilities, threat actors and risk treatment.
Both are responsible for resilience.
Yet they often describe completely different realities.
The result is not conflict because either side is wrong.
The result is organisational blindness.
Two Worlds Built for Different Missions
Facility management was never designed to defend against cyber attacks.
Its mission is to ensure that buildings remain safe, compliant and operational.
Success is measured through:
- operational availability,
- maintenance quality,
- statutory compliance,
- energy efficiency,
- construction budgets,
- workplace availability,
- occupant safety.
Information security measures success differently.
The CISO is expected to demonstrate:
- confidentiality,
- integrity,
- availability,
- cyber resilience,
- regulatory compliance,
- risk reduction,
- governance effectiveness,
- incident readiness.
Neither perspective is superior.
Both are incomplete on their own.
A modern building requires both.
Speaking Different Languages
Many integration projects fail before any technical work begins.
They fail because people believe they are discussing the same subject when they are not.
Consider a simple example.
A facility engineer says:
“The system is fully operational.”
The CISO immediately asks:
“Does it support multi-factor authentication?”
The engineer answers:
“That has nothing to do with whether the ventilation works.”
Both statements are correct.
Neither answers the other’s question.
The same misunderstanding appears repeatedly.
Facility management thinks in:
- equipment,
- installations,
- maintenance,
- inspections,
- contractors,
- availability,
- operating permits,
- life-cycle management.
Cybersecurity thinks in:
- assets,
- identities,
- attack surfaces,
- privilege,
- vulnerabilities,
- monitoring,
- incident response,
- risk ownership.
Without a common vocabulary, collaboration becomes translation instead of governance.
The Ownership Illusion
One of the most dangerous assumptions inside large organisations is:
“If everyone owns part of the system, somebody must own the risk.”
Reality is usually different.
Consider a connected access-control platform.
The building belongs to Real Estate.
Facility management operates the infrastructure.
Corporate Security defines access policies.
IT manages the network.
Identity Management synchronises accounts.
Procurement negotiated the contract.
The vendor hosts the cloud platform.
Legal reviewed the agreement.
The CISO performs periodic assessments.
Now ask a simple question:
Who owns the cyber risk?
Silence is surprisingly common.
Ownership of technology is not the same as ownership of security.
Responsibility Without Authority
Facility managers frequently carry statutory responsibilities.
They are accountable for operating buildings safely.
They cannot simply disconnect systems because a vulnerability was published.
They cannot postpone fire inspections because the SOC requires maintenance.
They cannot install firmware whenever a new security advisory appears.
Cybersecurity often underestimates these operational constraints.
At the same time, facility management sometimes underestimates cyber risk because attacks appear abstract until physical consequences become visible.
The challenge is not deciding who is right.
The challenge is balancing operational continuity with cyber resilience.
The CISO Does Not Own the Building
This point cannot be emphasised enough.
The purpose of integrating facility management into the ISMS is not to transfer responsibility to the CISO.
The CISO should never become responsible for operating lifts, HVAC systems or access-control hardware.
Facility management remains the operational owner.
Information security provides governance.
That distinction matters.
When CISOs attempt to become technical decision-makers for building systems, resistance grows immediately.
When CISOs provide a common framework for identifying, evaluating and reporting cyber risk, collaboration becomes possible.
An ISMS is a governance model.
It is not an operational takeover.
Why Resistance Is Natural
Many CISOs interpret resistance as a lack of security awareness.
Usually it is something else.
Facility management often hears:
- more documentation,
- more approval processes,
- more audits,
- more meetings,
- more controls,
- more delays,
- more costs.
What they rarely hear is how the ISMS will actually help them.
From their perspective, cybersecurity introduces additional work without solving their operational problems.
Acceptance cannot be demanded.
It has to be earned.
Different Risk Cultures
Imagine two incidents.
The first is a failed cooling unit.
The second is a compromised cooling controller.
Facility management immediately understands the first.
Cybersecurity immediately understands the second.
Operationally, however, both may produce exactly the same consequence:
The data centre overheats.
This illustrates an important lesson.
Cybersecurity rarely creates new operational outcomes.
It creates new causes.
Once facility teams recognise that cyber attacks simply represent another source of operational failure, the discussion changes dramatically.
Governance Begins With Clarity
The most important governance question is surprisingly simple.
Who decides?
Not who operates.
Not who maintains.
Not who purchased the system.
Who decides when security and operations conflict?
Examples include:
- shutting down remote access,
- approving vendor connections,
- accepting residual risk,
- delaying firmware updates,
- replacing unsupported controllers,
- introducing cloud services,
- granting emergency maintenance access.
If governance cannot answer these questions before an incident, the organisation will answer them during one.
That is exactly when poor decisions become expensive.
The Missing Executive Conversation
Many executive boards receive separate reports.
IT reports technology.
Facility management reports buildings.
Corporate Security reports physical incidents.
The CISO reports cyber risk.
Rarely are these perspectives combined.
As a result, boards believe they understand enterprise resilience while significant dependencies remain invisible.
A server room is not simply an IT asset.
It depends on:
- power,
- cooling,
- access control,
- fire protection,
- monitoring,
- maintenance providers,
- facility staff,
- external contractors.
Treating these as independent management topics creates fragmented risk oversight.
Building Trust Before Building Controls
Successful CISOs rarely begin integration with security policies.
They begin with relationships.
Facility managers possess decades of operational expertise.
Ignoring that expertise guarantees resistance.
Instead, security leaders should ask questions.
How is remote maintenance performed?
Which systems worry you most?
Which equipment cannot easily be replaced?
Where are the biggest operational dependencies?
What would stop the building from functioning tomorrow?
Those answers often reveal security priorities more effectively than any vulnerability scan.
The Shared Objective
Cybersecurity and facility management do not have competing goals.
Both want:
- reliable operations,
- predictable risk,
- resilient infrastructure,
- trusted suppliers,
- rapid recovery,
- safe working environments,
- informed executive decisions.
The ISMS simply provides the governance structure that allows those objectives to be managed consistently across organisational boundaries.
Breaking the Organisational Silos
True resilience begins when organisations stop asking:
“Is this an IT problem?”
Instead they ask:
“Does this create enterprise risk?”
That single shift changes ownership discussions completely.
Buildings are no longer isolated technical environments.
They are connected operational platforms supporting every critical business function.
Consequently, facility management is no longer just an operational stakeholder.
It is a strategic security partner.
Conclusion
Technology does not create organisational silos.
People do.
Most cyber incidents involving buildings do not begin with sophisticated attackers.
They begin with unclear ownership.
Conflicting terminology.
Fragmented responsibilities.
Separate reporting lines.
Disconnected governance.
An effective ISMS cannot eliminate organisational complexity.
But it can make accountability visible.
Because resilience does not emerge when everyone protects their own domain.
It emerges when everyone understands that they are protecting the same organisation.
Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion