A building network was never designed to be a battlefield. It was designed to move badge swipes, thermostat setpoints, elevator telemetry, camera feeds, and tenant traffic from one place to another. For years, the gap between when an attacker found a way in and when a defender noticed was measured in weeks. That gap was your margin for error. AI is closing it.

The security community is now openly asking whether anyone is prepared for what faster, machine-assisted attack cycles mean in practice. A recent radical Briefing on cybersecurity in the age of AI put the discomfort plainly: the tooling that helps defenders also helps attackers move faster, probe more targets, and adapt in real time. For an asset manager, this is not an abstract tech story. It is a question about how much time your properties have between a compromise and a loss, and who is accountable for that time.
The window is shrinking, and buildings sit in the blast radius
Here is what changed. Attack reconnaissance that used to require a skilled human now runs at machine speed. Probing a network, finding an exposed device, testing credentials, and pivoting toward something valuable can happen in a compressed cycle. The practical consequence is that the detection-to-response window, the time you have to notice and act, is getting shorter while the number of things worth attacking keeps growing.
Commercial buildings are unusually exposed to this. A modern property runs dozens of connected systems: HVAC controllers, access control, video surveillance, elevator monitoring, energy metering, leak detection, and whatever the last three tenants and four vendors installed. Recent industry reporting has documented how connected building systems have become a primary target for attackers, precisely because each of those systems was procured separately, connected separately, and is often maintained by a vendor with its own remote-access credentials into your building. Most owners cannot produce a current, accurate list of every device on their network and who can reach it. That is not a hypothetical weakness. It is the exact map an automated attacker builds for you.
The reason this matters at the asset level is that operational technology and IT increasingly share the same physical and logical pathways. When they are not segmented, a compromise in a low-value system (a networked thermostat, a camera) becomes a doorway to a high-value one (the building automation controller, the tenant-facing network, the property management system). The attacker does not care which door they use. They care that the doors connect.
Regulators and insurers are already treating this as structural
This is no longer a fringe concern debated inside security conferences. The framing is moving toward critical-infrastructure logic. The Boston Business Journal recently argued that digital infrastructure needs the same safeguards as power grids, reflecting a broader shift: the systems that run daily life are being held to a higher standard of resilience because their failure has real-world consequences. Buildings, which house tenants, capital, and increasingly automated operations, sit squarely inside that logic.
Two forces make this a board-level and capital-level issue rather than an IT line item.
The first is insurance. Cyber coverage now comes with underwriting questions that look a lot like an operational review. Insurers want to know whether you segment your networks, control vendor access, retain logs, and can demonstrate governance. Weak answers mean higher premiums, tighter sublimits, or exclusions. In a market where property insurance is already under pressure, a preventable cyber exposure is a preventable cost that shows up directly against net operating income.
The second is diligence. When a property trades or refinances, operational risk gets examined. An acquirer or lender who finds ungoverned networks, unknown devices, and vendor-controlled data & digital infrastructure has found a reason to move on price or terms. This is the quiet mechanism most owners miss. Vendor-controlled data is the silent NOI tax that does not show up on your P&L until diligence finds it. By then, the price has already moved.
Why another dashboard does not fix a speed problem
The instinct, when the risk narrative gets loud, is to buy a tool. A monitoring dashboard. A threat feed. A managed detection subscription bolted onto whatever exists. This is understandable and it is insufficient, and the reason is structural rather than a matter of product quality.
A dashboard shows you what is happening on top of your data & digital infrastructure. It does not change the architecture underneath it. If your networks are flat, your device inventory is unknown, your vendor credentials are unmanaged, and your identity and access rules live in five different vendor portals, then a faster alerting layer just tells you about a fire you have no clean way to contain. Visibility without the ability to act is theater. When attack cycles compress, the value of raw visibility drops, because the time between seeing and needing to respond is exactly the time you no longer have.
There is a second problem specific to how buildings buy technology. Every point solution you add to close a gap tends to add its own connectivity, its own credentials, and its own island of data. You are trying to reduce exposure and you are quietly increasing the number of doors. The tool that promised to make you safer becomes another thing an attacker can enumerate.
The resilience question is not "can I see the attack faster." It is "is my building built so that a compromise is contained, my data is mine, and my response does not depend on a vendor deciding to call me back." That is an architecture question, and architecture does not come in a subscription.
Resilience is a repeatable standard, not a heroic project
What actually raises the bar is boring in the best way: a consistent operating standard for secure, segmented, governed data & digital infrastructure that you apply the same way at every property. Not a bespoke security project at each address, defended by whichever engineer happened to build it, but a documented standard that any building in the portfolio can be brought up to.
This is where owner control stops being a philosophy and becomes a security control. If you don't own your data & digital infrastructure, your vendors do. When your vendors own it, your security posture is the sum of their individual choices, none of which were coordinated, and none of which you can fully audit. You cannot govern what you do not control, and you cannot respond quickly to what you cannot govern.
The standard has recognizable pieces. Every device is known and lives on a network that is segmented, so a breach in one system cannot walk into another. Vendor access is provisioned, monitored, and revocable by the owner rather than baked in permanently. Identity, access, and rules of use are governed centrally rather than scattered across portals. Logs and operating history are retained by the owner, so you can reconstruct what happened and prove your posture to an insurer or a lender. This is the design intent behind a single, secure, segmented foundation, the Building of Things® approach, where every device and system runs on infrastructure the owner controls rather than a patchwork the owner merely rents.
How the 5C™ plan turns this into an operating discipline
At OpticWise this is the work, and it maps directly onto the Peak Property Performance® operating model. The PPP 5C™ plan, Clarify, Connect, Collect, Coordinate, Control, is not a security marketing wrapper. It is the sequence that turns a fragmented, exposed building into a governed one, and then repeats it across the portfolio.
Clarify starts with a review, not a purchase. You map what is actually on the network, who can reach it, where the data lives, and what is exposed. Most owners have never had this map, which is precisely why automated attackers find it so easy to build one first.
Connect and Collect establish secure, owner-controlled connectivity and a consistent data model, so segmentation and inventory are designed in rather than improvised. This is the managed data & digital infrastructure layer, and it is the same standard property to property, which is what makes it repeatable rather than heroic.
Coordinate and Control are the governance layer, Property Brain™ scaling to Portfolio Brain™. This is where identity, access, credentials, retention, and rules of use are governed under owner permissions, and where any monitoring engine or decision tool you choose operates on top of a foundation you actually control. The dashboard, if you want one, plugs in here, on your terms, reading your governed data, instead of becoming another silo.
The strategic payoff is portfolio-wide. Once the standard exists in one building, it becomes the standard for the next one. Resilience stops being a per-property scramble and becomes a documented capability you can show an underwriter, a lender, or a buyer. That is what moves the needle: not a faster alert, but a defensible posture that compounds across every asset you hold.
The bar just went up. Meet it with architecture.
AI did not invent the risk in your buildings. It removed the slack that let owners ignore it. The properties that come through the next few years without a preventable incident, a premium spike, or a diligence surprise will be the ones whose owners treated data & digital infrastructure as an asset to be owned and governed, not a cost to be outsourced and forgotten.
Start with a review. Map your exposure, name your leakage, and see how far your buildings are from a standard you could apply everywhere. Then build the standard once and scale it.
Own your data & digital infrastructure. Build for the long game.

