Networked devices increase cyber risks for building systems

Issue 5 2022 News & Events

Companies face an increasing but under-recognised threat from cyberattacks on building systems, and facilities managers need to act now with IT professionals to address the issue, independent research and advisory firm Verdantix is warning.

It highlights how a sharp rise in the number of connected devices across building systems mean that the operational technology (OT) used to run facilities creates a growing risk of cyberattack. Connected OT networks are converging with their IT counterparts, blurring traditional lines of responsibility for cybersecurity, just as ageing building systems require replacement and the number of attacks rises.

Without sufficient security controls, Verdantix warns that these systems are introducing significant new risks and more entry points for cybercriminals to exploit. The past five years have seen a massive explosion of Internet of Things (IoT) sensors and smart devices deployed, with firms frequently selecting these smart devices based on cost and functionality, resulting in facilities having many devices with poor built-in cybersecurity controls.

Verdantix’s ‘Best Practices: Enhancing Your Smart Building Cyber Security Programme’ found that firms are not aware of the full extent of their risk exposure from their OT, as they often do not keep registers of connected devices, or the level of cybersecurity protection provided.

Compiled after interviews with experts from the cybersecurity, IT and building technology sectors, the report shows how companies can adapt. Its publication comes as more connected devices via the IoT transform the landscape, but just 32% of firms evaluate IoT security risks as part of the onboarding process for third parties, and just 54% run penetration tests on their IoT devices.

Rodolphe D’Arjuzon, global head of research at Verdantix, said: “The first step for rebooting a smart building cybersecurity strategy is defining clear responsibilities and embedding cyber management into facilities operations across procurement, technology management and staff training.

“Facilities managers should not develop a siloed cyber programme on their own, but rather partner with their IT and security peers to integrate cybersecurity into different building management processes.”


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Pentagon appointed as Milestone distributor
Elvey Security Technologies News & Events Surveillance
Milestone Systems appointed Pentagon Distribution (an Elvey Group company within the Hudaco Group of Companies) as a distributor. XProtect’s open architecture means no lock-in and the ability to customise the connected video solution that will accomplish the job.

Read more...
Re-introduction of the booking system
PSiRA (Private Security Ind. Regulatory Authority) News & Events
[Sponsored] PSiRA is reintroducing the booking system for branch visits. Effective Monday, 4 December 2023, clients will be required to book a slot to visit any PSiRA branch.

Read more...
From the editor's desk: A sad but exciting goodbye
Technews Publishing News & Events
Welcome to the final monthly issue of SMART Security Solutions. This is the last issue of the year and the last monthly issue we will print. The SMART Security Solutions team wishes all our readers and advertisers a relaxing festive season and a peaceful and prosperous 2024.

Read more...
Regal celebrates successful golf day
Regal Distributors SA News & Events
Regal Distributors held its first official Regal Golf Day on 18 October at the Glendower Golf Course in Johannesburg. SMART Security Solutions was there on a hot summer’s day to meet many players and sponsors around the course.

Read more...
Gallagher Security releases Command Centre v9
Gallagher News & Events Access Control & Identity Management Integrated Solutions
Richer features, greater integrations, with the release of Gallagher Security’s Command Centre v9 security site management software designed to integrate seamlessly with various systems and hardware.

Read more...
Regal launches direct-to-branch WhatsApp communication
Regal Distributors SA News & Events
With a quick scan of a QR code and a few taps on your phone, installers, integrators, technicians or even end-users can chat directly with the team at their preferred Regal branch via WhatsApp

Read more...
FM Expo highlights industry trends and challenges
Securex South Africa News & Events Facilities & Building Management
Keeping tabs on what is happening within the building/facilities management arena can be frustrating, however, a quick way to find out what current trends, challenges, and solutions are available can be found at the Facilities Management Expo.

Read more...
All aspects of data protection
Technews Publishing Editor's Choice Information Security Infrastructure AI & Data Analytics
SMART Security Solutions spoke to Kate Mollett, Senior Director, Commvault Africa, about the company and its evolution from a backup specialist to a full data protection specialist, as well as the latest announcements from the company.

Read more...
South Africa shows a 1200% increase in deepfake fraud
News & Events Risk Management & Resilience
Sumsub released its third annual Identity Fraud Report of the year, analysing identity fraud across industries and regions based on millions of verification checks across 28 industries and over 2 million fraud cases.

Read more...
Projections for 2024’s Advanced Threats Landscape
News & Events Information Security
Kaspersky Global Research and Analysis Team (GReAT) experts offer insights and projections for 2024 in the Kaspersky Security Bulletin, with a focus on the evolution of Advanced Persistent Threats (APT).

Read more...