Data & Technology

Cybersecurity

Building technology as an attack surface.

Data & Technology

What it studies

Cybersecurity of building systems studies building technology as an attack surface: BMS, access control, cameras and IoT sensors connected to a network and therefore vulnerable to the same threats as office IT, often with weaker protection because operational technology (OT) was historically kept separate from IT.

Why Facility Management needs it

FM typically manages the operational technology but not the IT security around it, creating an organisational gap exactly where OT and IT meet. An attack via the BMS can have physical consequences (climate, access) that IT security alone does not cover.

Questions it answers

  • Is the BMS network separated from the office network, or do they share the same infrastructure without segmentation?
  • Who is responsible for patching operational technology: FM, IT, or no one?

Evidence sources

  • IEC 62443 — cybersecurity for industrial automation and control systems (applicable to building OT); the NIS2 Directive (EU) for critical sectors.

Operating and management implications

  • OT security requires a different patch regime than IT: a BMS cannot simply be restarted during office hours.
  • NIS2 extends the scope of cybersecurity obligations to sectors where building management previously fell outside scrutiny; applicability must be determined per organisation and jurisdiction.

Related services

  • BMS & Building Automation; Security (physical and digital threat can converge)
To the Services Atlas

Related capabilities

  • OT/IT network segmentation and patch management

Related operating models

All operating models

Related standards

  • IEC 62443 series; NIS2 Directive (EU 2022/2555, jurisdiction-dependent implementation).

The standards section arrives in Part 7.

Common misuse

  • IT security policy applied one-to-one to OT systems without accounting for the different availability requirements of building technology.

Current research frontier

The overlap between physical security (see the Security knowledge domain) and cybersecurity of building systems is still rarely organised as one function; most organisations keep separate owners for each.

Further reading

  • IEC 62443-2-1:2010, security programme requirements.
  • NIS2 Directive, EU 2022/2555.