Get a quote

Blogs

Blogs

Cyber security for Facilities Managers: Five ways to reduce risk in building systems 

David Robinson

By David Robinson,

Head of Cyber Security, Restore PLC.

As building systems become more connected, facilities managers have a growing role to play in cyber security. To improve resilience:

  • Maintain an inventory of connected building systems. 
  • Eliminate default passwords and shared logins. 
  • Regularly review employee and contractor access. 
  • Separate building systems from corporate IT networks. 
  • Make cyber security awareness part of everyday facilities management. 


According to the latest UK Government Cyber Security Breaches Survey, 43% of businesses reported a cyber security breach in the last 12 months. Yet many organisations still lack important security controls, with only 47% implementing two-factor authentication and 30% using user monitoring.
 

As building management systems, CCTV, access control and other operational technologies become increasingly connected, facilities managers have an important role to play in identifying vulnerabilities and reducing cyber risk across the built environment.  


1. Know what you have

You cannot protect what you do not know exists. Start by maintaining an accurate inventory of all building systems that are networked or remotely accessible, including details of suppliers, support arrangements and access methods. Understanding how systems connect is the foundation of effective cyber security. [twinfm.com] 

 

2. Eliminate weak credentials

Default passwords and shared logins remain one of the most common security weaknesses. Every system should have unique, strong credentials, with clear processes for updating passwords and removing access when employees or contractors leave.  

 

3. Review access regularly

Access permissions can quickly become outdated. Facilities teams should work alongside IT to review who has access to building systems, whether that access is still required, and ensure permissions are removed when projects end or responsibilities change.  

 

4. Separate critical systems

Where possible, building systems should be kept separate from corporate IT networks. Network segregation helps contain incidents and reduces the risk of a compromise spreading across the wider organisation.  

 

5. Make cyber security a shared responsibility

Cyber security is not solely an IT issue. Facilities managers play a vital role in protecting operational technology and should promote awareness across their teams and supplier network. A cyber-attack on building systems can have real-world consequences, from failed access controls to disrupted heating, cooling or surveillance systems.

Protecting the buildings of tomorrow

Facilities managers are no longer just responsible for maintaining buildings. They are responsible for overseeing increasingly connected environments that support business operations every day. 

As digital building technologies continue to evolve, organisations that understand their systems, control access effectively and embed cyber security best practice will be better placed to minimise disruption, strengthen resilience and protect critical operations.

Need help strengthening your organisation’s cyber resilience? 

As building systems become increasingly connected, understanding and managing cyber risk is more important than ever. Restore Information Management helps organisations identify vulnerabilities, improve cyber resilience and protect critical information and operational systems from emerging threats. 

Speak to our cyber security specialists today to discuss your cyber security strategy and discover how we can help strengthen your security posture.

To find out more, or discuss your needs, why not get in touch?

Give our specialists a call on 01293780075

Contact us