ChannelLife UK - Industry insider news for technology resellers
United Kingdom
Connected building systems pose growing cyber risk

Connected building systems pose growing cyber risk

Mon, 3rd Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.

The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.

Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.

David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.

"Many building systems still rely on default credentials straight out of the box. If these credentials aren't changed, cyber criminals can gain access to critical systems with relative ease. As today's digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network," Robinson said.

Attack surface

Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.

In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.

He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.

Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.

Remote access

Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.

Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.

The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.

Network separation

Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.

This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.

Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.

Strategic priority

Robinson's final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation's wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.

That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation's connected estate and can affect both physical security and business continuity if disrupted.

Restore Information Management is one of the UK's larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. "Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset," Robinson said.