Let's demystify what's actually happening in the smart building market this summer, because underneath the headlines about acquisitions and AI, there's one structural shift that matters to owners more than any single product announcement.
The market is moving from isolated systems to governed platforms. Incumbents are investing directly in startups instead of watching from a distance. Access control is consolidating around identity and authorization. Realcomm is putting IT/OT collaboration and data governance at the center of its programming. And the cost of getting cyber risk wrong just hit a record high.
Each of those is a separate story. Together, they say the same thing. The technical question for an owner is no longer does my building have connected systems? Nearly every building does. The question is whose standard do those systems run under?
Here's what most integrators won't tell you: without an owner-controlled standard for identity, access, segmentation, patching, integration, and data rights, every vendor you add becomes another control plane. And control planes you don't own are risk you can't see.
The consolidation isn't cosmetic, it's about who holds the keys
Start with access control, because it's the clearest signal. In the recent PropTech Connect briefing, SwiftConnect acquired HID SAFE, a physical identity and access management platform. That's not a feature purchase. That's a company buying the layer that decides who is allowed to do what inside a building.
Why does that matter? Because access control used to be a door reader and a badge. Now it's an identity and authorization system that touches your network, your tenant experience, and your data. When that system consolidates under one vendor, the vendor doesn't just control the doors. They control the policy that governs the doors.
Zoom out and the pattern repeats across the whole market. Memoori's research found that in the first half of 2026, 23% of strategic investments in smart building startups involved a major industry player: ABB, Allegion, Carrier, Honeywell, JLL, Johnson Controls, Schneider Electric, and Siemens among them. The incumbents aren't observing the startup landscape anymore. They're shaping it.
Read that as an owner, not a technologist. The vendors who already sit inside your building are consolidating the smaller vendors around them. The stack is getting more integrated, and more concentrated. Integration is good. Concentration under someone else's governance is a liability.
There's a second-order effect worth naming. When a vendor absorbs the identity layer, your switching cost quietly climbs. Ripping out a badge reader is easy. Ripping out the authorization policy that ten other systems now depend on is not. Concentration doesn't just add risk, it hardens lock-in, and lock-in is what shows up as reduced negotiating leverage at your next renewal.
IT and OT are converging, and the industry finally admits it
For years, building systems (HVAC, lighting, access, elevators, metering) lived on operational technology (OT) networks that IT teams barely touched. That separation is gone.
Realcomm is now organizing its programming around exactly this. Its upcoming Industry Excellence Showcase highlights how award-winning teams "strengthened IT and OT collaboration" and "advanced data governance." And in a Realcomm Live conversation on open platforms, industry leaders from Aamidor Consulting and Tridium spent their time on the evolution of smart buildings and the importance of governance and collaboration, not on any single product.
Here's why IT/OT convergence is a governance problem, not just a networking one. IT security has decades of maturity: patching cycles, identity management, zero-trust segmentation, audit trails. OT systems were designed to run for twenty years and never be touched. When you connect an OT device to an IT network (and every smart building does) you inherit the worst of both worlds unless someone governs the seam.
Consider what that seam actually looks like in a real building. A rooftop unit installed in 2011 speaks a protocol nobody on your team can patch. A metering gateway added in 2019 sits on the same flat network as tenant Wi-Fi. An access controller updated last month has admin credentials shared across three of your properties. None of these is a scandal on its own. Together they are exactly the attack surface an adversary maps first, because they know the owner has never inventoried it.
That someone should be you. When it's a vendor instead, the seam becomes a black box. You can't see what's patched, what's segmented, or who has access. And you're accountable for all of it.
The stakes just got measurably higher
Governance debates used to feel abstract. They don't anymore, because the cost of getting it wrong is now a number.
The Insurance Journal reported that the average cost of a data breach reached a record $5 million, with artificial intelligence having "radically shifted" the cyber risk landscape. That's not a smart building statistic specifically, but every connected building system is now part of that attack surface.
And the threat is getting more autonomous. SecurityWeek covered the White House's Gold Eagle initiative, a federal clearinghouse using frontier AI to rank and coordinate vulnerability remediation across critical infrastructure before attackers reach them. When the federal government builds AI to out-run AI-driven attackers, that tells you where the risk curve is heading.
For an asset manager, this maps directly to two line items you already track. Property insurance is repricing hard, and cyber exposure is now a diligence question. A breach that traces back to an ungoverned building system isn't a ticket, it's a brand-reputation event and an insurance-claim exposure that surfaces at the worst possible moment.
And it compounds. An underwriter who can't verify how your building systems are governed prices that uncertainty into your premium. A buyer's diligence team that finds ungoverned OT during a sale prices it into the offer. In both cases you pay for the governance gap twice, once in risk carried, and again in value discounted. Neither charge appears on your P&L until someone else has already done the math.
Here's the villain, stated plainly: vendor-controlled data & digital infrastructure is a silent NOI tax that doesn't show up on your P&L until diligence (or a breach) finds it. By then, the price has already moved.
The technical fix is a standard you own, not a product you buy
So what does "good" actually look like? It's not another platform. It's a standard (applied consistently across every property) that governs six things:
Identity. One authoritative source for who is who, across tenants, staff, and vendors. Not a separate identity silo per system.
Access. Authorization tied to that identity, with least-privilege as the default and revocation that actually works when a vendor contract ends.
Segmentation. OT and IT properly separated, so a compromised thermostat can't reach your building management system or your tenant data.
Patching. A known, documented state for every connected device, because you can't defend what you can't inventory.
Integration. Open, owner-governed connections between systems, so adding a vendor doesn't mean adding a control plane.
Data rights. Clear ownership of the operational data every system generates, with lineage, retention, and rules of use that you set.
The reason a standard beats a product is portability. A product governs one building until you replace it. A standard governs every building you apply it to, and it survives vendor changes, because the rules live with you rather than with whoever sold you the box. That's the difference between buying a capability and owning one.
If you don't own your data & digital infrastructure, your vendors do. And when identity, access, and data rights are held by vendors, your "smart building" is really their asset with your name on the deed.
How OpticWise builds the standard into the building
This is precisely the layer OpticWise operates. The PPP 5C™ plan (from Peak Property Performance®) turns OT governance from an afterthought into the operating standard.
Clarify. A PPP Audit™ reviews the current state of your data & digital infrastructure: what's connected, what's patched, who has access, and where data rights leak to vendors. In one PPP Review of a 400,000 SF office property, we found roughly $300K of redundant fiber infrastructure, parallel backbones nobody could explain, each under a different vendor's control. That's what ungoverned looks like when you finally shine a light on it.
Connect. We build the owned network layer through SIC® (Security, Infrastructure, Connectivity) with ElasticISP® making connectivity ISP-agnostic and owner-controlled. Segmentation and identity are designed in, not bolted on.
Collect. Operational data from every BoT® (Building of Things®), device flows into the owner's data lake under a consistent model, with lineage intact.
Coordinate. Identity, access, privacy, and rules of use are governed centrally. This is the seam between IT and OT, and you own it.
Control. Property Brain™ and Portfolio Brain™ deliver real-time intelligence on top of data you own, decision engines that operate under your permissions, not a vendor's.
The 5S® user experience (Seamless Mobility, Security, Stability, Speed, Service) is what tenants and staff feel while all of this runs quietly underneath.
The move to make now
The market is consolidating around governed platforms whether you participate or not. The only real choice is whose standard governs your buildings. If it's a vendor's, you're renting your own intelligence and inheriting risk you can't audit. If it's yours, every new system plugs into a standard you control, and your operational data compounds into capitalized value at every refi and exit.
Start with one property. Run a PPP Review. Get the honest inventory of who holds your identity, access, and data rights today. Then build the standard once and apply it portfolio-wide.
Find a better way. Own your data & digital infrastructure. Build for the long game.
References Cited
- Memoori Research: "8 Incumbents Betting Big on Smart Building Startups in 2026": https://memoori.com/8-incumbents-betting-big-smart-building-startups-2026/
- PropTech Connect: "SwiftConnect acquires HID SAFE": https://d37Hm404.eu1.hubspotlinks.com/Ctc/5G+113/d37Hm404/VWsgSQ8tkDn4Vf48Jw3yJkX5W8kTzPf5RTF_xN1-yX_H3pyd0W7lCdLW6lZ3pQW9f4NDG8W-q3bW6R6VDz8Jt9m6W8JBBv912mGJ-
- Realcomm: "Industry Excellence Showcase: Lessons from Digie Award Leaders": https://www.realcomm.com/webinars/1080/industry-excellence-showcase-lessons-from-digie-award-leaders
- Realcomm Live: "AI, Open Platforms and the Evolution of Smart Buildings": https://youtu.be/wYH15KIAn7A
- Insurance Journal: "Cost of a Data Breach Reaches Record $5 Million on Average": https://www.insurancejournal.com/news/national/2026/07/29/879536.htm
- SecurityWeek: "Is Patching Dead? Vulnerability Management in the Post-Mythos Era": https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/

