← Back to InsightsOperational Control

Your Connected Building Just Became an AI Attack Surface. You Still Carry the Risk.

Building management systems, access control, tenant apps, and vendor portals are now connected operating surfaces, and AI expands every one of them. When a vendor platform fails, the owner carries the operational, legal, and reputation risk.

September 25, 2026 · By Drew Hall

Your Connected Building Just Became an AI Attack Surface. You Still Carry the Risk.

A building used to be a physical thing you secured with locks, cameras, and a night guard. Then it became a connected thing. Building management systems talk to energy platforms. Access control talks to tenant apps. Vendor portals reach into HVAC, metering, and elevators. Now AI workflows are being layered on top of all of it, reading operating data, triggering actions, and connecting systems that were never designed to talk to each other. Each of those connections is useful. Each one is also a door.

Here is the part that matters to an asset manager. When one of those doors gets opened by someone you did not invite, the vendor who built the platform does not sit across the table from your lender at the next refinancing. You do. The operational disruption, the privacy exposure, the reputation event, the diligence finding, all of it lands on the owner. The technology is distributed. The risk is not.

The building is now a connected operating surface, not a set of tools

Savills put the mechanism plainly in its analysis of being hacked through your building systems: modern buildings rely on a web of connected technologies, and every connected system adds an attack surface, a potential entry point that could be exploited to steal data, expose tenants, or disrupt operations. That framing is correct, and it is worth sitting with, because most owners still think about these systems the way they were sold: as separate tools, each solving a separate problem, each managed by a separate vendor.

That mental model is the problem. When systems are procured one at a time, they get connected one at a time, usually by the vendor, usually under whatever access terms the vendor prefers, and usually with no shared standard for who can reach what. The result is not a set of isolated tools. It is one large, loosely governed operating surface with dozens of entry points, and no single party holding the map.

AI accelerates this in two directions. It creates more connections, because AI workflows are only useful when they can read across systems and act on them. And it lowers the cost of attacking those connections, because the same tooling that helps a defender automate also helps an attacker automate. Travelers reported that cyber threats are now the top business concern as AI heightens the risk, and that concern is not abstract for real estate. It shows up as building systems that can be reached, data that can be exfiltrated, and operations that can be halted.

AI does not just expand the surface. It expands the blast radius.

The security question used to be: can someone get in? The better question now is: once they are in, how far does it spread? Realcomm framed an entire session around this exact idea, containing the blast radius of AI, because AI is introducing new risks faster than most organizations can update their policies, controls, and governance. That gap between capability and governance is where owners get hurt.

Here is the mechanism in plain operating terms. If your access control platform, your energy platform, and your tenant app all share credentials, sit on the same flat network, or route through a single vendor portal with broad permissions, then a compromise in the weakest of them can reach the strongest. An attacker who gets into a poorly secured tenant maintenance app should never be able to reach the building management system that controls life-safety equipment. If they can, that is not a software flaw. That is an architecture and governance failure, and it is one the owner is responsible for even when a vendor built every piece of it.

Blast radius is a design outcome. A building where systems are segmented, where identity is governed centrally, and where each vendor can reach only what its function requires is a building where one compromise stays contained. A building where everything can reach everything is a building where one weak vendor becomes a whole-portfolio problem. Same technology. Very different exposure. The difference is who architected the connections and under what rules.

Vendor access is the quiet variable in every breach

Every connected building has a list of parties who can reach into it: the BMS vendor, the access control provider, the energy platform, the app developer, the analytics tool, and increasingly the AI service reading the data. Each of those relationships carries a set of credentials, a level of access, and a data-handling practice that the owner rarely controls and often cannot even see. That is the exposure that does not show up on the P&L until something goes wrong.

The insurance market is already pricing this in. Underwriters are leaning harder on external data and AI, and they are being pushed to explain how they use that data without creating fairness or privacy problems. When carriers get more disciplined about data and predictability, they get more disciplined about what they will cover and at what price. A building that cannot show who has access to its systems, what those parties can reach, and how incidents are logged is a building that is harder to underwrite. That is a direct line from governance quality to insurance cost, and insurance cost is an operating expense that moves NOI.

This is the point where the philosophy becomes practical. If you don't own your data & digital infrastructure, your vendors do. And if your vendors control the connections, the credentials, and the data, then they also control your exposure. You inherit their weakest security practice as your own risk profile, without ever having agreed to it.

From attack surface to operating standard

The defensive move is not to buy another security tool and bolt it onto the pile. Another tool is another vendor, another set of credentials, another connection to govern. The move is to establish an operating standard that governs how every system connects, who can reach what, and how AI is allowed to act. That standard is the moat, because it is the one thing a fragmented, vendor-by-vendor approach cannot produce.

This is where the two-layer model does real work. Layer 1 is managed data & digital infrastructure that the owner controls: a single, secure, segmented foundation where building systems connect under one governed standard rather than a tangle of vendor-defined links. Our platform for that foundation is SIC® (Security, Infrastructure, Connectivity), and the connected-device standard that rides on it is BoT® (Building of Things®). The security value is structural. Segmentation is built in, not retrofitted. Identity is governed centrally, not scattered across a dozen vendor logins. Vendor access is scoped to function, so the BMS vendor cannot reach the tenant data and the app developer cannot reach life-safety systems.

Layer 2 is the owner-controlled intelligence layer, Property Brain™, which acts as a governed data plane and trust plane. This is what lets AI operate safely. AI workflows act under owner permissions, with lineage, retention, and rules of use defined by the owner rather than assumed by whatever service is reading the data. That governance is what turns AI from an uncontrolled new attack surface into a controlled operating capability. Standardize it across the portfolio and Property Brain™ becomes Portfolio Brain™, so your security posture is consistent from building to building instead of reinvented, and re-exposed, at every address.

Where an asset manager starts

Our Peak Property Performance® framework and its PPP 5C™ plan give this a sequence, and the first three steps are almost entirely a security exercise even though they are not labeled that way.

Clarify. Start with a PPP Audit™. Map every connected system, every vendor with access, and every path between systems. Most owners cannot produce this map today, which is precisely why they cannot answer a lender's or an insurer's security questions. Clarify also identifies what data is trustworthy and portable, which matters because data you cannot access is data you cannot govern.

Connect. Establish secure, owner-controlled connectivity that is segmented by design and repeatable property to property. This is the step that shrinks the blast radius, because it replaces vendor-defined connections with an owner-defined standard.

Collect. Capture and normalize operating data into a consistent model the owner controls, so the AI layer reads from a governed source rather than reaching directly into building systems.

Coordinate and Control are Layer 2. Coordinate governs identity, access, privacy, lineage, retention, and rules of use. Control lets decision engines and AI workflows act, but only under owner permissions. That is the difference between AI that helps you operate and AI that becomes the next entry point in the Savills list.

The economic case is direct. Contained breaches, governed vendor access, and auditable systems reduce the probability and severity of the events that damage NOI: operational downtime, privacy claims, insurance repricing, and diligence findings that move the sale price. Every operating dollar you protect capitalizes at your cap rate, which is why a security standard is not an IT expense. It is a value-protection strategy that shows up at every refinancing and every exit.

The rate environment makes this urgent rather than optional. As debt costs stay elevated and rate moves keep pressuring CRE debt, lenders and buyers are scrutinizing operations harder than they have in a decade. A building that can demonstrate governed, segmented, auditable systems is a building that survives that scrutiny with its terms and its price intact. A building that cannot is a building where a diligence team finds the risk before you priced it in.

The connected building is not going back in the box, and neither is AI. The only real choice is whether the connections that run your assets are governed by you or by the collection of vendors who happen to have keys. Own the standard, and the attack surface becomes a controlled operating surface. Leave it to the vendors, and you are managing an investment you cannot fully see and a risk you did not agree to carry.

Own your data & digital infrastructure. Build for the long game.

Drew Hall

Drew Hall

Founder & Chief Architect, OpticWise • Co-Author, Peak Property Performance®

Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).

Your Next Step

Complimentary CRE Data & Digital Review Session

One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.