Managing cyber risk in a ‘smart building’ environment

CyberArticleOctober 1, 2026

From environment to elevators, the management of modern buildings depends on operational technologies that can amplify an organization’s cyber risks.
Share this

For a growing number of organizations, the advent of “smart buildings,” structures employing advanced automation for the performance of key building operations, is revolutionizing facilities management. Building management systems (BMS), increasingly augmented by artificial intelligence, deliver efficiency and sustainability only imagined by owners and facilities managers of the past.

The smart building concept is more than just the implementation of new automation tools. It is the integration of those tools to deliver intelligence, efficiency and sustainability in the management of a facility’s physical environment. Intelligent control platforms are evolving beyond the management of HVAC systems and lighting controls, integrating energy management, environmental monitoring, access control and various automation services into a single, digital layer. With more organizations building advanced BMS platforms, the smart building automation market is projected to grow from $122.49 billion in 2026 to more than $191 billion by 2030.1

As BMS platforms enable coordinated, automated workflows, heightened cloud connectivity and enhanced vendor access, connected devices now permeate the facility’s operational systems. But expanding connectivity can expose BMS networks to some of the same attack surfaces threatening enterprise IT systems, raising concerns that smart buildings could become high-value targets for cybercriminals.

And because BMS technologies may lack the mature security controls designed to harden enterprise networks against incursions, unseen vulnerabilities could provide bad actors with unprotected points of entry.

From isolation to connection

As noted by the National Institute of Standards & Technology (NIST), operational technologies providing critical building services initially had little resemblance to traditional IT systems. Operational technologies were isolated from corporate networks, ran proprietary control protocols, and used specialized hardware and software. But as BMS platforms begin to converge with IT networks to enable connectivity and remote access, their isolation from the broader cyber threat environment is waning, creating a greater need to secure BMS systems against cyber incursions.2

By one estimate, roughly 44% of the more than 1.2 billion Internet of Things (IoT) devices deployed in commercial properties worldwide have weak or no security protections, presenting easy footholds for cyberattacks. Recent incidents affecting more than 11,000 smart commercial buildings in a 12-month period underscore how a single compromised IoT device or vendor connection can cascade into physical disruptions, safety risks, and enterprise-wide breaches.3

No matter how a network intrusion is initiated, whether through an inadequately defended operational application, malware in an email attachment, a backdoor IoT vulnerability, or an AI-enabled incursion, the financial and operational stakes of data breaches have never been greater. According to IBM’s Cost of a Data Breach Report 2026, analyzing data from March 2025 through February 2026, breach costs reached a record global average of $4.99 million per event, a 12% increase over prior year. The U.S. average was higher than any other country, more than doubling the global average at $11.5 million, which the report attributes to higher business costs and regulatory fines.4

For smart building owners and operators, cyberattacks can rapidly increase BMS-related breach costs due to cascading operational failures. A cyber event affecting a building’s operational network can shut down HVAC, disable facility access control, disrupt elevators, spike energy consumption, or render office space unusable, costing thousands per hour in downtime.

Asking the right questions about operational risks

As BMS operational technologies continue to expand across business sectors and occupancies it will be critical for risk professionals to respond to an evolving and increasingly complex cyber risk environment. Effectively addressing all cyber threats to enterprise IT networks must include awareness of the exposures posed by the connectivity of operational technologies, including complete inventories of all equipment and systems interfacing with the corporate network.

A 2025 report by the federal government’s Cybersecurity & Infrastructure Security Agency (CISA), Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators, can be of particular value in developing strategies to protect against cyber threats that may present through a building’s operational technologies and systems.5

The following are questions risk managers, IT security professionals, facilities managers and others responsible for the sustainability of today’s smart buildings may want to consider in developing an effective cyber resilience plan:

  • Connected building systems - Have we identified the building systems connected to internal networks, the internet or third-party platforms?
  • Asset inventory - Do we maintain an inventory of building management systems, sensors, controllers, access control systems, cameras, elevators, HVAC systems and other connected assets?
  • Criticality - Do we know which systems are most critical to building operations, tenant services, safety-related processes or business continuity?
  • Remote access - Who has remote access to building systems, and how is access approved, monitored and removed when no longer needed?
  • Third-party vendors - Do vendor agreements address cybersecurity expectations, incident notification, access management and responsibility for system updates?
  • Network segmentation - Are building systems separated from corporate IT networks where appropriate?
  • Authentication - Are strong passwords, multi-factor authentication and unique user accounts used for systems supporting remote or privileged access?
  • Patch and vulnerability management - Is there a process to review, prioritize and apply updates for connected building systems, including legacy equipment?
  • Monitoring - Are unusual activities, failed logins, unauthorized changes or system disruptions monitored and escalated?
  • Incident response - Do cyber incident response plans include building systems and facilities teams, not just corporate IT?
  • Business continuity – Do we have a clear view of how building system outages could affect operations, tenants, customers, suppliers or revenue-generating activities?
  • Recovery planning - Can critical systems be restored, operated manually or supported through alternative processes if digital controls are unavailable?
  • Configuration management - Are approved security configurations documented for connected building systems, and are changes reviewed, tested and tracked?
  • Vulnerability assessment and testing - Are building systems assessed for vulnerabilities using methods that account for operational, safety and availability constraints?
  • Privileged access management - Are administrative accounts limited to authorized users, monitored for misuse and reviewed regularly?
  • Backup and recovery validation - Are configurations, system data and recovery procedures backed up securely and tested to confirm critical building systems can be restored?
  • Asset lifecycle and end-of-life management - Is there a plan to identify, replace or isolate unsupported building technologies and securely decommission retired assets?
  • AI-enabled tools - Where AI-enabled maintenance, monitoring or analytics tools are used, do we understand what data they access and how decisions or alerts are reviewed?

Insights help build resilience

Whether the cyber risk in question is a frontal attack on a corporate data network or a backdoor incursion through connections with a building’s internal, operational technologies, a key step toward building cyber resilience is investing the time and resources to perform a thorough, comprehensive assessment of all an organization’s attack surfaces. Insights provided by CISA, NIST and other technical experts can be valuable in navigating the resilience journey.

Zurich’s own Cyber Risk Management professionals, part of our Zurich Resilience Solutions team, can provide a wide range of insights and ideas to help insureds fight back against cybercrime, building resilience to help head off cyber events, and recovering from any events that do occur. For more information, read our detailed whitepaper report: “Cyber Resilience: Preparing Risk Executives for Cyber Events.”

 

References

  1. “Intelligent Building Automation Technologies Market Driven by AI, Cloud, and IoT Advancements.”Markets and Markets. 12 April 2026.
  2. Guide to Operational Technology Security.National Institute of Standards & Technology (NIST). NIST Special Publication SP 80082r3. September 2023.
  3. “Cybersecurity Risks in Smart Buildings.”CRE Insight Journal. 16 February 2026.
  4. IBM Cost of a Data Breach Report 2026.IBM. 29 July 2026.
  5. Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators. Cybersecurity & Cybersecurity & Infrastructure Security Agency (CISA). August 2025.
This is a general description of risk engineering or risk management services provided by Zurich Resilience Solutions, which is part of the Commercial Insurance business of Zurich Insurance Group and does not represent or alter any insurance policy or service agreement. Such services are provided to qualified customers by affiliates of Zurich Insurance Company Ltd, including but not limited to Zurich American Insurance Company, 1299 Zurich Way, Schaumburg, IL 60196, USA, and The Zurich Services Corporation, 1299 Zurich Way, Schaumburg, IL 60196, USA. The opinions expressed herein are those of Zurich Resilience Solutions as of the date of the release and are subject to change without notice. This document has been produced solely for informational purposes. All information contained in this document has been compiled and obtained from sources believed to be reliable and credible but no representation or warranty, express or implied, is made by Zurich Insurance Company Ltd or any of its affiliated companies (Zurich Insurance Group) as to their accuracy or completeness. This document is not intended to be legal, underwriting, financial, investment or any other type of professional advice. Zurich Insurance Group disclaims any and all liability whatsoever resulting from the use of or reliance upon this document. Nothing express or implied in this document is intended to create legal relations between the reader and any member of Zurich Insurance Group. Certain statements in this document are forward-looking statements, including, but not limited to, statements that are predictions of or indicate future events, trends, plans, developments or objectives. Undue reliance should not be placed on such statements because, by their nature, they are subject to known and unknown risks and uncertainties and can be affected by numerous unforeseeable factors. The subject matter of this document is also not tied to any specific service offering or an insurance product nor will it ensure coverage under any insurance policy. No member of Zurich Insurance Group accepts any liability for any loss arising from the use or distribution of this document. This document does not constitute an offer or an invitation for the sale or purchase of securities in any jurisdiction.