It’s no surprise. Modern buildings are getting smarter, more connected and more dependent on cloud platforms. Facility managers find themselves responsible for a new layer of risk that sits far beyond plant rooms and physical assets. Building management systems, HVAC controls, access control, CCTV, IoT sensors and energy platforms now operate across IP networks and remote connections, placing operational technology squarely in the cyber crosshairs. For FM leaders, cybersecurity has shifted from a background IT concern to a frontline operational liability, with direct implications for safety, comfort, compliance and continuity.
According to Check Point Software cybersecurity lead technologist Raymond Schippers, the real change lies less in the move to IP, which has existed for years, and more in the rapid cloud enablement of building systems. Remote access, cloud-based access control and internet reliant safety platforms have become standard, increasing both exposure and dependency. “There’s now a lot of reliance on internet connectivity for critical safety systems that hasn’t been there before,” Schippers says. “That’s why it’s critical that facility management and IT security collaborate closely to ensure reliability and resilience.”
When cyber risk is framed purely as data theft, the stakes can feel abstract. In buildings, the consequences are immediate and physical. A compromised HVAC system can push temperatures outside safe limits. An access control failure can leave a facility unable to confirm who is inside or whether they should be there. CCTV manipulation can erase visibility at the exact moment it is needed most. “It’s not about stolen data,” Schippers says. “It’s about the building ceasing to work.”
When digital threats become physical events
Cyber incidents in building environments rarely announce themselves with flashing alerts, more often appearing as operational issues, unexplained alarms or systems behaving unpredictably. ANZ at Honeywell cybersecurity business consultant Mark de Brito says these disruptions are usually felt first in day-to-day performance. “Something as simple as an unauthorised setpoint change can alter temperature, humidity or airflow in ways that degrade comfort,” he explains. In hospitals, data centres or aged care facilities, those shifts can escalate rapidly into safety, compliance or accreditation risks.
Loss of trust in data is another hidden impact. If sensors or point data are manipulated, operators lose visibility and confidence. Fault detection tools misfire. Optimisation routines become unreliable. Manual overrides creep in as teams attempt to regain control. While manual operation can keep a building running in the short term, it increases labour demands and raises the likelihood of human error.
“Access control failures carry their own risks,” de Brito says.”Systems may fail while they’re open or fail while closed, each creating serious consequences depending on the environment.”
In secure facilities such as correctional centres or airports, automated access remains central to maintaining safety and efficiency. “Removing that automation, even temporarily, changes how people move, how incidents are managed and how risk is controlled,” adds de Brito.
Behind many of these scenarios sits the convergence of IT and operational technology. De Brito points to the danger of poorly segmented networks where a compromised building device becomes a pathway into corporate systems. Legacy protocols such as BACnet (Building Automation and Control Networks) or Modbus, designed without modern authentication or encryption, remain common. “When long equipment life cycles collide with modern connectivity expectations, systemic risk spreads across an entire portfolio,” he says.
The hidden exposure of remote access and third parties
Few areas generate as much quiet risk as third-party access, with contractors, service providers and remote maintenance teams now requiring routine connectivity into live building systems. Yet trust often replaces verification, with shared accounts persisting across sites. VPN access lacks granular controls or session monitoring, while devices used by external technicians may sit outside any patching or security oversight.
From Honeywell’s perspective, de Brito says the assumption that a trusted vendor equates to a secure arrangement remains a persistent blind spot. “Once projects end or personnel change, access is often left in place indefinitely,” he notes.
Over time, identity sprawl becomes more than just a technical issue. It expands into a governance failure.
Schippers echoes that concern, stressing that visibility is the starting point. “You can’t protect what you can’t see,” he says. “Many organisations struggle to answer basic questions about which systems are internet facing, who can access them remotely and what would happen operationally if they went offline. Without that understanding, meaningful risk decisions remain impossible.”
Adding to this perspective, Anomali VP of Professional Services and Training Fernando Maymi, highlights that inadequate coordination between facility managers and security operations is among the greatest risks. “Facility managers know their building systems, but this knowledge is only partially shared with SecOps or risk teams,” he explains. “Their priorities often misalign: FMs focus on availability, SecOps on confidentiality. This misalignment leaves gaps adversaries can exploit, sometimes using AI to uncover hidden dependencies that cause operational failures.”
Maymi also stresses the underappreciated threat from third-party access. “Even with mature controls, maintenance teams often have direct, unfettered, unmonitored access to ICS [industrial control systems] components,” he says. “They could unknowingly introduce vulnerabilities or alter settings that create risk. Organisations rarely track this, yet it is a critical threat vector.”
One size never fits every facility
Cybersecurity strategies for buildings must reflect the environments they protect, ensuring core principles remain consistent, while adjusting individual execution strategies. For example, hospitals require tight controls around critical spaces where environmental tolerances directly affect patient outcomes, while aged care facilities often operate with smaller teams and limited on-site IT support, placing a premium on security that remains effective without complexity.
“Airports represent a different scale entirely,” de Brito notes, “with dense vendor ecosystems, regulatory obligations and continuous public access.” He says identity federation, zoning and constant monitoring become essential. “University campuses and mixed use developments introduce high user turnover, diverse building types and shifting tenancy patterns, each expanding the attack surface in unique ways,” he adds.
Maymi echoes the importance of tailoring strategies to facility type, adding that integrating facilities staff into existing IT security frameworks is vital. “GRC [governance, risk (management) and compliance] and SecOps teams often have effective IT security practices,” he says. “The missing piece is including facility management in the conversation, ensuring common threats are understood and mitigated collaboratively.”
Within the Australian context, established frameworks provide a useful baseline, with guidance such as the Essential Eight and relevant ISO standards helping organisations structure controls, governance and maturity models. Yet without operational translation these frameworks fall short, as cyber risk in buildings demands discussion in terms of habitability, safety and uptime rather than abstract compliance.
Schippers advises leaders to frame conversations around resilience. “Without resilience in those systems, your building becomes unmanageable,” he says. “Knowing who is in the building, where they are and whether they should be there sits at the heart of health and safety obligations.”
Planning now for an intelligent future
Looking ahead, as the convergence of HVAC, process control and industrial IoT continues to accelerate, it brings both opportunity and risk, with artificial intelligence and machine learning already analysing operational telemetry to detect anomalies that escape human notice.
Over time, these tools will move from reactive alerting to predictive insight, identifying weak signals before incidents unfold. Maymi says AI, predictive analytics and digital twins only deliver meaningful risk reduction if teams work collaboratively across GRC, SecOps and facilities. “When teams operate in silos, technology alone cannot protect. Unified workflows allow AI and digital twins to anticipate and mitigate attacks rather than simply react,” he explains.
Extending this capability further, digital twins allow operators to simulate building behaviour, configurations and cyber events so changes can be tested in a risk-free environment, enabling firmware updates, access policy shifts and incident scenarios to be modelled without exposing live systems, which delivers greater confidence with fewer unintended consequences.
For facility managers, the message is clear. Cybersecurity now lives alongside fire safety, mechanical reliability and compliance. It belongs in the plant room as much as the server room. The buildings of today already operate as digital ecosystems. Protecting them demands visibility, collaboration and a clear understanding that when cyber incidents strike, the impact is felt in the real world, not just on a screen.