Your browser is out of date. The site may not function correctly. Please update your browser.
Published:
Read Time: 3 mins
Organisations are being warned that weak cyber security in connected building systems could leave them exposed to physical security incidents, as smart buildings become increasingly reliant on digital technologies.
According to the latest UK Government Cyber Security Breaches Survey, 43% of businesses reported a cyber security breach within the last 12 months, while the number of businesses adopting advanced security controls such as two-factor authentication (47%) and user monitoring (30%) remains relatively low.
At the same time, building technologies such as access control, CCTV, Building Management Systems (BMS), lifts and environmental controls are becoming increasingly interconnected. While these systems improve operational efficiency, they can also create new opportunities for cyber criminals if security is not properly managed.
David Robinson, Head of Cybersecurity at Restore Information Management, says organisations often focus on protecting traditional IT systems while overlooking the technologies responsible for securing their buildings.
He said: "Many building systems still rely on default credentials straight out of the box. If these credentials aren't changed, cyber criminals can gain access to critical systems with relative ease.
"As today's building systems become more connected and cloud-based, security often fails to keep pace. Without the right controls, attackers could disable CCTV, interfere with access control systems, unlock doors or use vulnerable building systems as a route into the wider corporate network."
David Robinson has shared five ways organisations can strengthen the cyber security of connected building systems and reduce the risk of physical security incidents.
1. Know what systems you have and how they are connected
Security begins with visibility. Organisations should maintain an up-to-date inventory of every network-connected or remotely accessible building system, including access control, CCTV, Building Management Systems and other operational technologies.
This should include who manages each system, who has access and how remote connections are provided.
Understanding the environment is the first step to reducing opportunities for attackers.
2. Eliminate default passwords and shared accounts
Default credentials and shared logins remain among the most common weaknesses in connected security systems.
Manufacturer passwords should be replaced immediately, shared accounts removed, and every employee or contractor provided with an individual account that can be monitored and disabled when no longer required.
Strong access management makes it significantly harder for attackers to gain unauthorised access.
3. Tighten remote access controls
Remote maintenance is essential for many security and building systems, but unmanaged access creates unnecessary risk.
Organisations should regularly audit contractor and employee accounts, remove dormant users and ensure all remote access is approved, time-limited and reviewed throughout the lifecycle of a contract.
4. Separate security systems from corporate networks
Where possible, building systems should operate separately from wider corporate IT networks.
Network segmentation limits the impact of a successful cyber attack by preventing attackers from moving laterally into other business-critical systems.
Facilities, IT and security teams should work together to identify opportunities to improve resilience across legacy infrastructure.
5. Treat cyber security as part of physical security
Cyber security should be embedded into every security strategy rather than viewed as an IT issue alone.
Regular awareness training, closer collaboration between security and IT teams, and designing new systems with security in mind can reduce the likelihood of compromise.
As buildings become smarter, protecting physical assets increasingly depends on securing the digital systems that control them.
For more information, visit: https://www.restore.co.uk/informationmanagement/
Ends
For more information, please contact:
Fran Herring, Rose Lock or Alex Hankinson
Midnight Communications
T: 01273 666 200
Notes to editors
About Restore Information Management
Restore Information Management is the largest UK-owned provider of information management services, specialising in secure physical document storage, digital transformation and data management.
Its solutions help organisations protect, transform and access their information seamlessly and efficiently. With a strong focus on innovation and customer-centric delivery, Restore Information Management enables businesses to streamline operations and remain competitive in a fast-moving digital landscape.
Restore Information Management is trusted by more than 6,000 clients across the UK, including more than 80% of NHS trusts. It is also a recognised leader in ESG, achieving a CDP ‘A rating’ in 2026, placing it in the top 4% of businesses in the UK for carbon reduction.