Smart buildings, smart risks: what the NCSC’s cyber warning means for property owners.
Commercial and retail property owners face increasing cyber risks as more building systems connect to the internet. The National Cyber Security Centre (NCSC) has warned that operational technology, edge devices (IoT sensors, smart cameras, network hardware) and internet exposed systems are becoming attractive targets for cyber attackers. In this article, Geraint Williams, Chief Information Security Officer (CISO) at Modern Networks, outlines the key risks for property portfolios, and the precautions owners and operators can take to improve cyber resilience, reduce disruption and protect critical building services.
Buildings are becoming a cyber target
Most commercial buildings now depend on a range of connected technologies. Building Management Systems (BMS), HVAC controls, energy management platforms, CCTV networks, access control systems, lift monitoring, smart lighting and remote maintenance solutions all help improve efficiency and reduce costs.
Many of these systems are connected to the internet, either directly or through third party services. The NCSC warns that organisations should not assume operational technology environments are isolated. Exposure can come from legacy connections, unmanaged assets, supplier access arrangements or configuration errors.
A successful attack could lead to:
- Loss of heating, ventilation or air conditioning services
- Building access system failures
- Disruption to CCTV and security operations
- Energy management interruptions
- Reduced continuity of property management services
- Damage to tenant confidence and reputation
Some incidents have caused limited disruption so far, but the threat landscape is changing.
The hidden risk inside connected buildings
Many commercial property organisations invest heavily in protecting corporate IT systems while paying less attention to building technology.
A typical property portfolio may include:
- Connected BMS controllers
- Remote monitoring gateways
- Networked fire and life safety interfaces
- Security management platforms
- Building automation controllers
- Smart utility and meter infrastructure
The NCSC recommends gaining a clear understanding of your technology architecture and identifying any systems that can be accessed from the public internet.
Property owners and operators should be able to answer a few simple questions:
- Which building systems are internet accessible?
- Which contractors have remote access?
- Are legacy systems still connected?
- Are unsupported devices still operating?
- Is there visibility across the whole estate?
Without clear answers to the above questions, risks can remain hidden until an incident happens.
Edge devices need greater attention
The NCSC highlights edge devices as an increasingly important area of concern. These devices sit at the outer boundary of a local network and are often targeted by attackers.
In commercial property environments, edge devices commonly support:
- Remote facilities management
- Third party maintenance access
- Energy monitoring services
- Security integration platforms
- Smart building applications
Property owners should ensure these devices remain supported by vendors, receive security updates promptly and are replaced before reaching end of life. Direct internet exposure should be avoided wherever possible.
Strengthen access controls
Weak credential management remains one of the most common security issues in operational environments.
The NCSC recommends removing default passwords, eliminating shared accounts and introducing multi-factor authentication (MFA). Strong authentication controls should be applied across all critical building systems.
This includes:
- BMS administration platforms
- CCTV management systems
- Access control software
- Building automation dashboards
- Vendor support portals
Third party contractors and maintenance providers often need access to building systems. Every connection should be monitored, controlled and governed through clearly defined processes.
Why network segmentation matters
Building systems should not share the same network as corporate IT systems.
Separating operational technology from business systems helps reduce risk and limits opportunities for attackers to move between environments.
For property owners and operators, this means:
- Separating BMS networks from corporate IT
- Isolating security systems from business applications
- Restricting communication between network zones
- Applying least privilege access controls
Strong segmentation can significantly reduce the impact of a cyber incident.
Monitor for unusual activity
Building technology environments usually operate in predictable ways. That makes unusual activity easier to detect when monitoring is in place.
The NCSC recommends logging and monitoring connectivity to operational technology environments, with a focus on spotting unexpected communications and configuration changes.
Effective monitoring should include:
- Remote access session monitoring
- Detection of unauthorised configuration changes
- Reviews of outbound connections
- Administrator activity logging
- Baselines for normal operational behaviour
Early detection can help prevent small issues from becoming major operational disruptions.
Cyber resilience goes beyond prevention
Preventing attacks is important, but resilience also means being prepared when incidents happen.
The NCSC advises organisations to maintain tested backups, recovery procedures and incident response plans. For commercial and retail property owners, resilience planning should cover:
- Recovery of BMS configurations
- Restoration of access control databases
- CCTV recovery procedures
- Building automation controller backups
- Manual operating processes during outages
The goal is to maintain building operations and minimise disruption, even during a cyber incident.
A board level risk for property portfolios
The NCSC’s latest warning sends a clear message. As buildings become more connected, cyber resilience becomes a core operational concern rather than a purely technical one.
Cyber security now has a direct impact on building performance, service continuity, asset value and stakeholder confidence. Property owners who understand their internet exposed assets, secure edge devices, strengthen access controls, monitor operational environments and prepare for recovery will be better placed to manage the risks ahead.
Smart buildings bring clear benefits, but they also create new responsibilities. Treating cyber resilience with the same importance as physical security and health and safety is becoming essential for every commercial and retail property portfolio.
Act now
Review your building technology estate, identify any internet exposed systems and assess how operational technology is protected across your portfolio. The earlier weaknesses are found, the easier and less costly they are to address. A proactive approach today can help protect operations, tenants and long-term asset value tomorrow.
Modern Networks helps commercial property owners and managing agents reduce cyber risk and strengthen operational resilience. With decades of experience, we deliver the digital infrastructure, support and service management that today’s occupiers expect.
Get in touch now to discuss your building or portfolio’s needs.
About the author
Geraint Williams is Chief Information Security Officer at Modern Networks and a cybersecurity specialist with more than 20 years’ experience in information security, ethical hacking, and digital risk management. He leads the company’s security strategy, helping commercial property organisations navigate an increasingly complex threat landscape. Prior to joining Modern Networks, Geraint held senior positions at GRCI Group and IT Governance, where he played a key role in developing CREST-accredited penetration testing services and delivering cybersecurity compliance programmes. A published author, educator, and regular industry speaker, Geraint is recognised for combining deep technical expertise with practical insights into digital resilience and cyber risk.
Reference
NCSC: Disruptive cyber activity highlights risk from internet-exposed systems and edge devices.