Networked devices increase cyber risks for building systems

Issue 5 2022 News & Events

Companies face an increasing but under-recognised threat from cyberattacks on building systems, and facilities managers need to act now with IT professionals to address the issue, independent research and advisory firm Verdantix is warning.

It highlights how a sharp rise in the number of connected devices across building systems mean that the operational technology (OT) used to run facilities creates a growing risk of cyberattack. Connected OT networks are converging with their IT counterparts, blurring traditional lines of responsibility for cybersecurity, just as ageing building systems require replacement and the number of attacks rises.

Without sufficient security controls, Verdantix warns that these systems are introducing significant new risks and more entry points for cybercriminals to exploit. The past five years have seen a massive explosion of Internet of Things (IoT) sensors and smart devices deployed, with firms frequently selecting these smart devices based on cost and functionality, resulting in facilities having many devices with poor built-in cybersecurity controls.

Verdantix’s ‘Best Practices: Enhancing Your Smart Building Cyber Security Programme’ found that firms are not aware of the full extent of their risk exposure from their OT, as they often do not keep registers of connected devices, or the level of cybersecurity protection provided.

Compiled after interviews with experts from the cybersecurity, IT and building technology sectors, the report shows how companies can adapt. Its publication comes as more connected devices via the IoT transform the landscape, but just 32% of firms evaluate IoT security risks as part of the onboarding process for third parties, and just 54% run penetration tests on their IoT devices.

Rodolphe D’Arjuzon, global head of research at Verdantix, said: “The first step for rebooting a smart building cybersecurity strategy is defining clear responsibilities and embedding cyber management into facilities operations across procurement, technology management and staff training.

“Facilities managers should not develop a siloed cyber programme on their own, but rather partner with their IT and security peers to integrate cybersecurity into different building management processes.”


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Showtime for Securex
Technews Publishing News & Events
We have once again reached the time of year when the security industry focuses on Securex. This issue includes a short preview, with more coming online and via our special Securex Preview news briefs. ...

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Igniting standards, powering protection
Securex South Africa News & Events Fire & Safety
Fire safety is more than compliance, it is a critical commitment to protecting lives, assets, and infrastructure. At Firexpo 2025, taking place from 3 to 5 June at Gallagher Convention Centre, that commitment takes centre stage.

Read more...
Digitising security solutions with AI and smart integration
Regal Security Distributors SA Technews Publishing Integrated Solutions
The Regal Projects Team’s decades of experience and commitment to integration have brought the digital security guard to life as a trusted force for safer, smarter living.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
From the editor's desk: We’ve only just begun
Technews Publishing News & Events
The surveillance market has expanded far beyond the analogue days of just recording and/or monitoring screens. The capabilities of surveillance technology today extend to black screen monitoring with ...

Read more...
The future of the surveillance channel
Duxbury Networking Technews Publishing Elvey Security Technologies SMART Security Solutions Surveillance
The video surveillance market has evolved from camera-based specifications to integrated solutions that solve customers’ problems. Moreover, the growth of AI and cloud has changed the channel even more, with more to come.

Read more...