← Back to InsightsVendor Control & Governance

Open Building Systems Need an Owner-Enforced Operating Standard

Open protocols, integrator consolidation, and MFA scrutiny from cyber insurers all point to the same need. Owners need written rules for how building systems connect, how vendors get in, and how controls are verified before a property is accepted.

October 2, 2026 · By Drew Hall

Open Building Systems Need an Owner-Enforced Operating Standard

Most commercial properties have a written standard for how a roof is accepted, how an elevator is commissioned, and how a fire system is tested. Very few have a written standard for how building systems connect to the network, who holds the administrator credentials, or how a vendor's remote access is verified before the property goes live. That gap used to be an IT housekeeping issue. Several developments this year suggest it is becoming an asset-management issue, one that shows up in insurance renewals, refinancing diligence, and the cost of replacing a vendor.

Let's demystify this. I want to walk through four signals, explain what each one changes for an owner, and then describe a practical response: a repeatable property acceptance standard that the owner, not any single vendor, enforces.

One caveat up front. These signals are separate. None of them proves that a universal industry standard has emerged, and I am not claiming one has. What they share is a direction, and the analysis below is my read of where that direction leads.

Open systems move the integration decision to the owner

Lighting is a good place to start, because it is a system most asset managers think of as solved. In a Realcomm Live conversation on DALI and open standards, representatives from the DALI Alliance and Cooper Lighting Solutions described how addressable digital lighting changes the role of lighting in commercial buildings. Each fixture becomes an individually addressable device, and an open protocol means equipment from different manufacturers can, in principle, work together.

That is good news for owners, and it carries a responsibility. When a system is proprietary end to end, the manufacturer decides how it integrates, and the owner accepts the result. When a system is open, someone has to decide which devices are allowed on the network, how they are tested for interoperability, and where the data they produce goes. If the owner does not make those decisions, the installing contractor makes them by default, usually on a project timeline and a project budget.

The practical consequence is that openness only produces portability if the property has rules for using it. An open lighting protocol installed with contractor-held credentials and an undocumented network configuration can be just as difficult to replace as a closed one. The protocol is open; the property is not.

Integrator consolidation changes counterparty risk

The second signal comes from the integrator market. Memoori reports that Nordomatic, an independent European BMS integrator, passed $300M in revenue following a 2025 acquisition spree, as part of a longer M&A strategy. I am not commenting on that company's strategy or performance. The relevant point is structural: building-system integration is consolidating, and owners should expect the firm that commissioned their BMS to change hands at some point during a typical hold period.

For an asset manager, that is a counterparty question. When an integrator is acquired, its tooling, staff, remote-access methods, and support terms can change. If the only complete record of a property's controls programming, device inventory, and credentials lives with that integrator, the owner's operating continuity now depends on how the acquisition is integrated. That is a risk the owner did not underwrite and probably cannot see on the P&L.

A common pattern we see in PPP Reviews is that nobody on the ownership side can produce a current list of who has administrative access to which building systems. The answer usually lives in a vendor's records, and sometimes in several. Consolidation does not create that problem. It raises the cost of having it.

Remote access has become an insurance question

The third signal is from the insurance side. An Insurance Journal segment titled 'No MFA? A Cyber Attack Could Leave Your Business Uninsured' addresses the risk that a business without multifactor authentication may find itself without coverage after a cyberattack. This is general cyber reporting. It does not describe a specific building operational technology incident, and it does not establish that every carrier excludes claims on that basis. Owners should read their own policies and talk to their brokers.

What the reporting does establish is that access controls are being treated as a coverage matter, and that should change how an owner thinks about vendor remote access in buildings. HVAC, access control, lighting, metering, and elevator monitoring vendors frequently connect remotely to perform support. If those connections rely on shared passwords, or on credentials a vendor created and never documented, the owner may not be able to truthfully answer an insurance questionnaire about how remote access is authenticated across the portfolio.

The chain matters here. Undocumented vendor access leads to an inaccurate or incomplete answer on an application. An inaccurate answer creates coverage uncertainty after an incident. Coverage uncertainty is exactly the kind of surprise asset managers spend their careers avoiding, because it can turn an operating event into an unbudgeted capital event.

Connectivity is becoming something that gets rated

The fourth signal is from India. ET Telecom News reported that TRAI has launched a digital connectivity rating platform for properties, including commercial properties, with the stated aim of supporting informed real estate decisions. That initiative is specific to one country, and I would not extrapolate it into a prediction about U.S. regulation.

The interesting part for owners anywhere is the premise. A regulator decided that a property's connectivity is relevant enough to a real estate decision that it should be visible and comparable. Whether or not a formal rating ever applies to your assets, the same logic is already at work in tenant site selection and in buyer diligence. If a property's connectivity and building-system configuration cannot be documented, it cannot be compared, and anything that cannot be compared tends to get discounted.

Layered on top of all four signals is the growing discussion about AI agents that take actions inside operating systems. The accountability question there is simple to state: if software can change a setpoint or open a door, whose rules is it following, and who can prove it? I raise this as an industry concern, not a sourced finding. It is the same access-governance question, with less human review in the loop.

What a property acceptance standard contains

Put the signals together and a practical requirement emerges. Owners need documented rules for how systems connect, how vendors gain access, and how controls are verified, applied the same way at every property. I think of this as a property acceptance standard: the conditions a building system must meet before the owner accepts it as part of the asset.

A workable standard covers six areas:

  1. Interoperability tests. Before acceptance, the system is shown to work on the owner's network and to exchange data through documented, open interfaces where the system supports them.
  2. Owner-held credentials. Administrator credentials for every system are created for, and held by, the owner. Vendors receive individual, revocable accounts.
  3. Segmented connectivity. Each system runs in its own network segment, so a compromised lighting controller cannot reach access control or tenant networks.
  4. Authenticated remote access. Vendor remote access runs through an owner-controlled path with multifactor authentication and logging. No shared passwords and no unmanaged remote tools.
  5. Data export rights. Contracts and configurations confirm the owner can export operating data and history in a usable format, independent of the vendor's platform.
  6. Recovery procedures. Configurations are backed up, restoration is documented, and the property can recover without depending on a single vendor technician.

None of these items is exotic. Their value comes from being written down and applied consistently, so that the tenth property is accepted the same way as the first.

The cost of skipping this is concrete. In one PPP Review of a 400,000 SF office property, we found roughly $300K of redundant fiber backbone, parallel runs nobody could explain, each under a different vendor's control. That is what accumulates when each system is installed on its own terms with no owner standard governing how it connects.

If you don't own your data & digital infrastructure, your vendors do.

Where this fits in the PPP 5C™ plan

The acceptance standard maps directly to the Peak Property Performance® PPP 5C™ plan. Clarify is the PPP Review: it inventories systems, credentials, access paths, and data rights, and identifies where the property depends on vendor-held knowledge. Connect and Collect are the managed data & digital infrastructure work that puts systems on a segmented, owner-controlled foundation, which we call BoT® (Building of Things®), and normalizes their data into a consistent model. Coordinate and Control happen in Property Brain™, where identity, access, lineage, and rules of use are governed, so any vendor platform or decision engine, including AI tools, operates under owner permissions.

Once the standard is proven at one property, it becomes the template for the next, and Property Brain™ becomes Portfolio Brain™. That is where the economics change. A repeatable standard lowers the cost of onboarding each new system, shortens diligence because the documentation already exists, and gives the owner real negotiating position when a vendor's terms change. Any operating savings that result reach NOI and get capitalized at the cap rate; at a 6% cap, each recurring dollar of NOI supports roughly $16.67 of value.

Start with one property

The practical next step is small. Pick one property, ideally one with a refinancing, insurance renewal, or major system replacement on the horizon. Run a PPP Review to establish what the owner actually controls today. Write the acceptance standard against what you find, apply it to the next system that gets installed or renewed, and then make it a contract requirement for every vendor that touches the building.

You will learn more from that one property than from any policy memo, and you will have a documented answer the next time a carrier, lender, or buyer asks how your buildings are governed.

Own your data & digital infrastructure. Build for the long game.

Drew Hall

Drew Hall

Founder & Chief Architect, OpticWise • Co-Author, Peak Property Performance®

Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).

Your Next Step

Complimentary CRE Data & Digital Review Session

One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.