Your Building Systems Just Became a Cybersecurity Liability
Connected building systems can no longer be managed as one-off vendor installs. When energy, controls, and AI all run through the same network, the owner needs a governance standard, or the vendors write it for you.
A commercial building used to be a collection of separate machines. The chiller ran the chiller. The access-control system ran the doors. The lighting panel ran the lights. None of them talked to each other, and that isolation, accidental as it was, kept risk contained.
That building no longer exists. Today every one of those systems is connected. They share networks, exchange data, feed dashboards, and increasingly hand their data to AI models that make operating decisions. The signals converging across the industry this quarter all point to a single conclusion: building intelligence has quietly become an operational technology (OT) governance problem. Most owners have no standard for governing it.
The moment building systems became connected, they stopped being a facilities question and became a security, data, and asset-value question. Without an owner-controlled standard for identity, access, patching, segmentation, and data flow, you do not have a smart building. You have an attack surface that grows every time a new vendor installs a connection.
The signals are all pointing the same direction
Start with the regulators. The White House is standing up a formal AI and cybersecurity coordination group to bring AI developers and essential-services providers together to share threat information. When the federal government decides that AI and cybersecurity belong in the same room for critical services, commercial buildings (with connected HVAC, elevators, access control, and metering) sit closer to that category than most owners acknowledge.
Next, the patch treadmill. In a single update cycle, Microsoft patched more than 570 flaws, a reminder that the software running inside your building, and the workstations integrators use to reach it, is under constant repair. Every unpatched building controller, every forgotten vendor laptop with a VPN into the BAS, is a door someone else can open.
Then look at where the industry puts executive attention. The Realcomm CIO and Property Technology Forum now puts artificial intelligence, cybersecurity, smart buildings, operational technology, and data strategy in the same invitation-only conversation. Senior CRE technology leaders have recognized that these are one topic, not five separate tracks.
The protocol layer is adapting too. Propmodo reported on how Z-Wave is expanding to meet the demands of modern buildings, which means the connected-device count inside your properties is rising. More devices, more firmware, more identities to manage. And the money follows: Memoori's research found that smart-building startup funding jumped 80% in the first half of 2026, with $5.6 billion flowing into companies serving commercial buildings. Every one of those funded companies wants to install something on your network. Each install is another vendor holding a key.
Energy optimization is the tell
Energy is one of the largest controllable costs in a commercial building, and the industry's answer is no longer "tune the equipment." Realcomm's session on optimizing building energy use through data, controls, and integrated workflow frames it precisely: energy savings now depend on data, controls, and integrated IT/OT workflows operating together.
To capture the energy savings that reach NOI, the OT layer (physical controls) has to connect to the IT layer (data and analytics). The savings live in the integration. But the integration is exactly where the governance gap opens. When the energy platform, the metering vendor, the BAS integrator, and the AI analytics provider all need access to the same operational data, someone has to govern who gets what, under what identity, with what audit trail. If the answer is "each vendor set up their own connection," the result is counterparty risk stacked on counterparty risk, invisible on the P&L until diligence finds it.
IT is not OT, and treating them the same is the mistake
IT is email, accounting, leasing software: systems where a failure means downtime and a data breach means embarrassment and liability. OT is the physical world: the chiller, the fire panel, the elevators, the access doors. When OT fails or gets compromised, the failure is physical. It is a brand-reputation event. It is an insurance-claim exposure. It is tenants in the dark.
Most building systems were designed by OT engineers who never expected them to touch the internet, then connected by IT teams who never had to keep a chiller running. Neither discipline owns the seam between them. That seam, identity, access, segmentation, patching, data flow across the IT/OT boundary, is precisely where building intelligence lives now, and precisely where nobody is accountable.
If you don't own your data & digital infrastructure, your vendors do. When vendors own the seam between IT and OT, they own the two things that determine a building's risk profile and its intelligence. That is not a facilities problem. That is an asset problem.
The owner-controlled standard
The answer is not another point solution. Buying a security tool for one system while eleven other systems run vendor-default configurations does not produce governance. The answer is an owner-controlled operating standard that integrators plug into, rather than one each of them invents independently.
The PPP 5C™ plan maps onto the OT governance problem directly.
Clarify. A Peak Property Performance® Review establishes the current state: what systems are connected, who has access, what data flows where, and where the ungoverned seams are. You cannot govern what you have not mapped.
Connect. Build the owned network layer through SIC® (Security, Infrastructure, Connectivity) so connectivity is owner-controlled and repeatable property to property, with ElasticISP® keeping the building independent of any single carrier.
Collect. Aggregate operational data from building systems (treated as BoT®, Building of Things®, rather than an unmanaged sprawl of devices) into an owner-controlled data store with a consistent model.
Coordinate. Govern identity, access, privacy, data lineage, and rules of use across every vendor and system. This is the segmentation and access discipline the convergence demands, delivered as one standard instead of a dozen.
Control. With the foundation governed, decision engines and workflows (including the energy optimization the industry is pursuing) act under owner permissions through Property Brain™, and scale across the portfolio through Portfolio Brain™.
What this protects, in owner terms
Govern the IT/OT seam and three things happen that an asset manager cares about. Operating risk drops because access is controlled and audited rather than scattered across vendor accounts. The diligence position strengthens because you can show a buyer or lender exactly how the building's systems are governed. Energy and operating savings become capturable and defensible because the integrated workflow runs on data you own and control.
Leave the seam ungoverned and the opposite compounds. Every new vendor install adds another silo with its own identity management. Every unpatched controller adds exposure the building engineer may not see until a penetration test or incident surfaces it. Every vendor-owned connection is a finding waiting for the next refinance or sale, the kind of gap that diligence teams flag as unquantified risk, which translates into price adjustments or unfavorable deal terms.
The industry has communicated, five different ways this quarter, that building intelligence and OT security are now the same conversation. The owner who establishes the standard first, and makes vendors plug into that governance rather than the reverse, builds the position that compounds across assets and across transactions.
Start with a PPP Review of one property. Map what is connected, expose the ungoverned seams, and establish the standard you will scale portfolio-wide. Prove it on one asset before replicating it.
Own your data & digital infrastructure. Operate with strategic foresight. Build for the long game.
Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).
Your Next Step
Complimentary CRE Data & Digital Review Session
One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.