Your browser is out of date. The site may not function correctly. Please update your browser.
Published:
Read Time: 3 mins
Public sector organisations are being urged to strengthen the cyber security of their connected building systems, as experts warn weaknesses in digital infrastructure could disrupt critical public services.
According to the latest UK Government Cyber Security Breaches Survey, 43% of businesses reported a cyber security breach within the last 12 months, while the number of organisations adopting advanced security controls such as two-factor authentication (47%) and user monitoring (30%) remains relatively low.
As councils, NHS trusts, schools, universities and other public sector organisations continue to invest in smart buildings, technologies such as Building Management Systems (BMS), access control, CCTV, lifts and environmental controls are becoming increasingly connected. While these systems improve efficiency and support service delivery, they also introduce new cyber security risks if not properly managed.
David Robinson, Head of Cybersecurity at Restore Information Management, says connected building systems should be treated as critical infrastructure.
He said: "Many building systems still rely on default credentials straight out of the box. If these credentials aren't changed, cyber criminals can gain access to critical systems with relative ease.
"As today's building systems become more connected and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt essential building services, compromise physical security or use vulnerable systems as a route into wider organisational networks."
David Robinson has shared five practical steps public sector organisations can take to strengthen the cyber resilience of their connected buildings.
1. Know what systems you have and how they are connected
Public sector organisations should maintain an up-to-date inventory of every network-connected or remotely accessible building system, including Building Management Systems, CCTV, access control and environmental controls.
Understanding which systems are connected, who manages them and how suppliers access them is the foundation of good cyber security.
2. Eliminate default passwords and shared accounts
Default credentials and shared logins remain among the most common vulnerabilities in connected building systems.
Every user, whether an employee or contractor, should have a unique account, with passwords updated regularly and accounts removed promptly when they are no longer needed.
3. Tighten control of remote access
Many public sector organisations rely on external contractors to maintain building systems, making effective access management essential.
Remote access should be approved, regularly reviewed and removed when contracts end. Organisations should also carry out routine audits of employee and contractor accounts to reduce unnecessary exposure.
4. Separate building systems from corporate networks
Building systems should be segmented from wider corporate IT infrastructure wherever possible.
If one network is compromised, segmentation helps prevent attackers from moving across the organisation and disrupting additional services.
Facilities, estates and IT teams should work together to review existing infrastructure and strengthen resilience.
5. Make cyber security part of estates management
Cyber security is no longer solely an IT responsibility.
Estates, facilities and IT teams should work together to ensure connected building systems are secure by design, supported by regular awareness training and ongoing reviews of access, suppliers and new technologies.
Protecting connected buildings is an important part of maintaining resilient public services.
For more information, visit: https://www.restore.co.uk/informationmanagement/
Ends
For more information, please contact:
Fran Herring, Rose Lock or Alex Hankinson
Midnight Communications
T: 01273 666 200
Notes to editors
About Restore Information Management
Restore Information Management is the largest UK-owned provider of information management services, specialising in secure physical document storage, digital transformation and data management.
Its solutions help organisations protect, transform and access their information seamlessly and efficiently. With a strong focus on innovation and customer-centric delivery, Restore Information Management enables businesses to streamline operations and remain competitive in a fast-moving digital landscape.
Restore Information Management is trusted by more than 6,000 clients across the UK, including more than 80% of NHS trusts. It is also a recognised leader in ESG, achieving a CDP ‘A rating’ in 2026, placing it in the top 4% of businesses in the UK for carbon reduction.