Your browser is out of date. The site may not function correctly. Please update your browser.

Smart buildings becoming an overlooked cyber security blind spot, expert warns

Published:
Read Time: 3 mins

Connected building systems are creating an overlooked cyber security risk for organisations as attackers increasingly target operational technology alongside traditional IT infrastructure, according to cyber security experts.

The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the last 12 months. Yet many organisations continue to overlook the security of internet-connected building management systems, access control, CCTV and other operational technologies that increasingly underpin day-to-day operations.

David Robinson, Head of Cybersecurity at Restore Information Management, says many organisations are unknowingly leaving these systems exposed through weak cyber hygiene.

He said: "Many building systems still rely on default credentials straight out of the box. If these credentials aren't changed, cyber criminals can gain access to critical systems with relative ease.

"As today's digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network."

David Robinson has outlined five ways organisations can reduce cyber risk across connected building systems.

1.    Understand your attack surface

Organisations should maintain an up-to-date inventory of every network-connected or remotely accessible building system, including Building Management Systems (BMS), access control, CCTV and environmental controls.

Knowing what systems exist, who manages them and how they are accessed is the first step towards reducing the attack surface.

2.    Remove default credentials and shared accounts

Default passwords remain one of the simplest ways for attackers to compromise connected systems.

Organisations should replace manufacturer credentials immediately, eliminate shared logins and ensure every employee or contractor has a unique account that can be individually monitored and removed when no longer required.

3.    Control remote access

Third-party suppliers and maintenance contractors often require remote access to operational technology environments, but these connections can introduce unnecessary risk if they are not tightly managed.

Access should be formally approved, regularly reviewed and removed as soon as projects or contracts end. Dormant contractor accounts should never remain active.

4.    Segment operational technology from corporate IT

Building systems should be isolated from corporate networks wherever possible.

Network segmentation helps prevent attackers from moving laterally between operational technology and business systems, reducing the impact of a successful breach.

Security teams and facilities teams should work together to review legacy environments and identify opportunities to strengthen resilience.

5.    Treat building systems as a cyber security priority

Operational technology should form part of an organisation's wider cyber security strategy rather than sitting outside it.

Awareness training, regular security reviews and designing new building systems with security in mind can significantly reduce the likelihood of compromise.

Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset.

For more information, visit: https://www.restore.co.uk/informationmanagement/

Ends

Editors notes

For more information, please contact:

Fran Herring, Rose Lock or Alex Hankinson

Midnight Communications

restore@midnight.co.uk

T: 01273 666 200

Notes to editors

About Restore Information Management

Restore Information Management is the largest UK-owned provider of information management services, specialising in secure physical document storage, digital transformation and data management.

Its solutions help organisations protect, transform and access their information seamlessly and efficiently. With a strong focus on innovation and customer-centric delivery, Restore Information Management enables businesses to streamline operations and remain competitive in a fast-moving digital landscape.

Restore Information Management is trusted by more than 6,000 clients across the UK, including more than 80% of NHS trusts. It is also a recognised leader in ESG, achieving a CDP ‘A rating’ in 2026, placing it in the top 4% of businesses in the UK for carbon reduction.

https://www.restore.co.uk/informationmanagement/

Building access

Building access

More  Download

Credit: Huum

David Robinson

David Robinson

More  Download

Credit: Restore Information Management

Restore Information Management team

Restore Information Management team

More  Download

Credit: Restore Information Management

CCTV

CCTV

More  Download

Credit: Jan Van der Wolf

Cameras

Cameras

More  Download

Credit: Jakub Zerdzicki