Networked devices increase cyberattack risk for building systems

Issue 5 2022 Commercial (Industry)

Companies face an increasing but under-recognised threat from cyberattacks on building systems and facilities managers need to act now with IT professionals to address the issue, Verdantix is warning.

Verdantix is an independent research and advisory firm with expertise in digital strategies for environment, health & safety, ESG & sustainability, net zero & climate risk, operational excellence and smart buildings.

It highlights how a sharp rise in the number of connected devices across building systems mean that the operational technology (OT) used to run facilities creates a growing risk of cyberattack. Connected OT networks are converging with their IT counterparts, blurring traditional lines of responsibility for cybersecurity, just as ageing building systems require replacement, and the number of attacks rises.

Without sufficient security controls, Verdantix warns, these systems are introducing significant new risks and more entry points for cybercriminals to exploit. The past five years have seen a massive explosion of Internet of Things (IoT) sensors and smart devices deployed, with firms frequently selecting these smart devices based on cost and functionality, resulting in facilities having many devices with poor inbuilt cybersecurity controls.

It is estimated that cyberattacks aimed at IT systems cost businesses $945 billion in 2020 through damage to data and systems, lost productivity, and theft of money, intellectual property, and personal data, despite $145 billion in cybersecurity expenditure.

Verdantix’s Best Practices: Enhancing Your Smart Building Cyber Security Programme found firms are not aware of the full extent of their risk exposure from their OT, as they often do not keep registers of connected devices, or the level of cybersecurity protection provided.

Compiled after interviews with experts from the cybersecurity, IT and building technology sectors, the report shows how companies can adapt. Its publication comes as more connected devices via the Internet of Things (IoT) transform the landscape, but just 32% of firms evaluate IoT security risks as part of the onboarding process for third parties and just 54% run penetration tests on their IoT devices.

Rodolphe D’Arjuzon, global head of research at Verdantix says, “The first step for rebooting a smart building cybersecurity strategy is defining clear responsibilities and embedding cyber management into facilities operations across procurement, technology management and staff training.

“Facilities managers should not develop a siloed cyber programme on their own, but rather partner with their IT and security peers to integrate cybersecurity into different building management processes.”

Find out more at www.verdantix.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

New algorithm for OT cybersecurity risk management
Industrial (Industry) Information Security News & Events Commercial (Industry)
OTORIO’s new risk management model and attack graph analysis algorithm technology, calculates OT cybersecurity threats and provides risk mitigation actions, prioritised according to actual exposure and potential impact on operations.

Read more...
Smart buildings require smarter networks
Commercial (Industry) Infrastructure Facilities & Building Management IoT & Automation
The smart building is not a new concept, but it's more than just four walls built sustainably, but a network that interconnects people, processes, data, and things. Lots and lots of things.

Read more...
The next generation of Point of Sale
Commercial (Industry) Security Services & Risk Management Products & Solutions
New digital point-of-sale (POS) platforms are gaining traction, which means payment providers and investors should take note.

Read more...
Vehicle entrance control
ZKTeco Access Control & Identity Management Commercial (Industry)
Secure your premises and control who enters with access control systems from ZKTeco. The company offers various types of entrance control terminals for pedestrians and vehicles.

Read more...
New R2 billion Pick n Pay super distribution centre
Flow Systems Access Control & Identity Management Products & Solutions Commercial (Industry)
Flow Systems Manufacturers was selected to be part of the security infrastructure at the new Pick n Pay inland distribution centre, which covers an area of 36 ha.

Read more...
Post-pandemic access control features
Paxton Access Control & Identity Management Products & Solutions Commercial (Industry)
Access control features introduced at the height of the pandemic are still useful as effective, integrated entrance control mechanisms today.

Read more...
Integrated security management platforms with biometrics
ZKTeco Access Control & Identity Management Commercial (Industry)
Biometric solutions have become the focus in many discussions as businesses seek more sophisticated security solutions beyond the traditional identification badge and access control system.

Read more...
Complete solutions, delivering complete protection
Gallagher Access Control & Identity Management Integrated Solutions Commercial (Industry)
The recent release by Gallagher of Command Centre v8.80 and Command Centre Web enables all organisations to make security easier, faster and more efficient.

Read more...
Redefining access control in the commercial sector
Axis Communications SA Commercial (Industry) Access Control & Identity Management
Technology is key to keeping assets and personnel safe and secure, especially in the face of concern surrounding proposed new trespassing laws.

Read more...
SALTO launches integrated Technology Partner Programme
Salto Systems Africa News & Events Access Control & Identity Management Commercial (Industry)
SALTO Systems has announced it is offering other technology leaders the opportunity to partner with it for an integrated and improved customer offering.

Read more...