The building systems that used to be boring are now the ones keeping people up at night. For decades, the controllers that run HVAC, lighting, elevators, and access control were physically isolated and functionally obscure. That combination made them uninteresting to attackers and reasonably safe by default. Nobody thought of them as a security problem because nobody outside the mechanical room could reach them.

That isolation is gone. As Propmodo recently put it, building automation systems now connect to enterprise networks, cloud platforms, and in many cases directly to the public internet. Every one of those connections is a convenience for an operator and an opportunity for an attacker. The devices did not get more secure as they got more connected. They got more exposed.
For an asset manager, this is not an IT curiosity. It is a change in the risk profile of the physical asset itself. Let's demystify what actually changed, why it lands on your P&L, and what belongs in your operating standard across the portfolio.
What Actually Changed Inside the Building
A modern building runs on operational technology, or OT. This is the layer of controllers, sensors, and automation that keeps the physical plant running: building automation for HVAC, lighting control, elevator dispatch, access control readers, and surveillance cameras. Historically this layer lived on its own wiring, spoke its own protocols, and answered to a facilities vendor who visited on a schedule.
Three things collapsed that separation. First, owners and operators wanted remote visibility, so these systems got connected to the corporate network and the cloud. Second, vendors wanted remote support, so they got standing remote access to the equipment they installed. Third, the equipment itself got smarter, which means it now runs software that can be exploited like any other computer.
Here is the operational consequence that matters. A camera, a thermostat, and an elevator controller are now nodes on a network, and most of them were never designed with security as a priority. Many ship with default credentials, infrequent firmware updates, and no ability to enforce modern authentication. When they sit on the same flat network as tenant data or the property management system, a weak device becomes a doorway to everything else.
That is the mechanism. Connectivity turned obscure equipment into reachable equipment, and reachable equipment that cannot defend itself becomes the softest target in the building.
Why This Reaches the P&L, Not Just the IT Budget
Asset managers reasonably ask a version of the same question about any technology topic: what's it really worth, and where does it show up in the numbers? OT security shows up in three places.
The first is insurance. Cyber coverage is diverging sharply from other lines. Industry reporting describes cyber liability breaking away from the pack, with rising ransomware losses and severity even as pricing stays soft and capacity stays abundant. Carriers are responding by tightening the conditions of coverage, not just the price. Multi-factor authentication has become one of those conditions. As the insurance press has warned, a business without MFA can find that a cyber attack leaves it effectively uninsured, because the policy language treats missing controls as a failure to meet the terms. For an owner, a denied claim after an incident is a direct hit to capital that no cap rate math anticipated.
The second is operational continuity. An access control system that goes down is not a help desk ticket. It is a life-safety and brand-reputation event that can shut a building's front door and put security staff into manual mode. An HVAC system taken offline in July is a tenant retention problem and a lease-up risk. These events do not appear on the P&L as a line called cyber. They appear as OpEx variance, as retention exposure, and occasionally as an insurance-claim event.
The third is valuation and diligence. Vendor-controlled data is the silent NOI tax that does not show up on your P&L until diligence finds it. An acquirer's technical review that surfaces unpatched building controllers, unknown remote-access accounts, and no device inventory becomes a price-adjustment conversation. By then the number has already moved against you. Every dollar of exposure a buyer can attach to remediation is a dollar they subtract from your basis, capitalized at their cap rate.
The Playbook Already Exists
The encouraging part is that nobody has to invent the standard. The federal government has been securing connected building systems for years, and the practices are well documented. Propmodo's point is worth borrowing directly: commercial real estate should adopt the security standard that federal buildings already use for connected systems. The playbook is not exotic. It is a set of operating disciplines that most owners simply have not applied to the OT layer.
The core practices are these. Maintain a current inventory of every connected device in the building, because you cannot protect what you cannot see. Segment the network so building systems do not share a flat path with tenant or corporate data, which contains a compromised device instead of letting it roam. Require multi-factor authentication on every account that can touch a control system. Govern vendor access so that remote support is granted deliberately, logged, time-limited, and revoked when the engagement ends. Keep audit trails so you know who did what and when. Design the network for resilience so a single failure does not take the building offline.
None of this is a product you buy once and forget. It is governance you operate continuously. That distinction is the whole point, and it is where most owners get it wrong. Buying a security appliance and installing it on a building that still has a flat network, default passwords, and forgotten vendor accounts is spending money without reducing risk.
Why This Belongs in the Data & Digital Infrastructure Standard
Here is the trap. If OT security lives with the on-site facilities team as a one-off project, it gets done unevenly, documented poorly, and forgotten between vendor visits. Property managers run the building. They are not the right party to design network segmentation or govern vendor credentials, and asking them to be technologists is how good intentions turn into gaps. This skill set is different from traditional building operations, and treating it as a side task guarantees inconsistency across a portfolio.
The better way is to make OT governance part of the managed data & digital infrastructure standard, applied the same way at every address. This is what OpticWise means when it talks about owner-controlled data & digital infrastructure. The building's connectivity runs on a single, secure, segmented foundation, our BoT® (Building of Things®) approach, so every device runs on ground the owner controls rather than a patchwork of vendor networks nobody can fully account for.
If you don't own your data & digital infrastructure, your vendors do. In an OT context that phrase is literal. The remote-access account, the controller configuration, and the audit trail all sit inside a vendor's platform, on a vendor's terms, until you decide to own that layer yourself.
Mapping It to the PPP 5C™ Plan
The Peak Property Performance® framework, PPP 5C™, turns this from a concern into a repeatable operating standard. It runs in five steps.
Clarify. A PPP Audit™ maps every connected device, every remote-access account, and every vendor with a standing credential. You cannot govern what you have not inventoried, and most owners are surprised by what the review surfaces. It is the same pattern we saw in the duplicate fiber backbone case, where a review of a large office property found roughly $300,000 of redundant fiber under separate vendors' control that nobody could explain. Fragmentation hides until someone looks.
Connect. Establish secure, owner-controlled connectivity that is segmented by design, repeatable property to property, so building systems never share a flat network with data that matters.
Collect. Capture device and access data into a consistent model, including the audit trails that both insurers and acquirers now expect to see.
Coordinate. Govern identity, access, and rules of use through Property Brain™. Vendor access becomes deliberate, logged, time-limited, and revocable, rather than a standing key that outlives the contract.
Control. Operate the standard continuously and, once it is standardized, extend it across the portfolio through Portfolio Brain™. The security posture stops being a per-building improvisation and becomes a governed capability that compounds.
That progression is the difference between a building that passed a one-time security project and a portfolio that operates to a defensible standard every day.
What to Do Next
Start with one property. Run a review to inventory connected devices, remote-access accounts, and vendor credentials, and see what the flat-network and default-password reality actually looks like behind the equipment you already own. That single exercise usually reframes the conversation from "do we have a problem" to "how fast can we standardize the fix."
Then make OT governance part of the operating standard rather than a project. The owners who treat connected building systems as an operating discipline will pass diligence cleanly, keep their coverage intact, and avoid the operational surprises that quietly tax NOI. The ones who treat it as an IT side issue will keep discovering the problem at the worst possible moment, in a claim denial or a diligence memo.
Own your data & digital infrastructure. Build for the long game.

