The building is
the operation.
Security monitoring for building management, access control and the systems a property depends on to open in the morning. Passive, agentless, and watched by the same 24/7 SOC that runs our IT customers.
What is smart building security?
Smart building security is the monitoring and protection of the operational systems that run a property: building management and HVAC, access control and door systems, lifts, lighting, metering and the networks they sit on. It differs from IT security because those systems were procured as building services rather than as technology, are usually maintained under contract by third parties with their own remote access, and cannot be taken offline for patching without the building itself degrading.
Everyone maintains it.
Nobody owns it.
That sentence is the whole difference between building systems and every other estate, and it is why buildings are so consistently the weakest network on a site.
A plant has an OT manager. A corporate network has an IT director. A building has a landlord who owns the plant, a tenant who owns the fit-out, a managing agent who holds the contracts, and an M&E contractor who actually touches the equipment. Each of them is doing their job. None of them has been asked to secure it.
So the systems arrive commissioned, connected and working, with a remote-access account for the maintainer that was set up during handover and has never been reviewed since. The building operates perfectly. The security position is invisible, and stays invisible until somebody looks.
That is what this service does first. Not a threat briefing, and not a proposal to replace equipment that is doing its job — an honest picture of what is on the network, who can reach it, and which of those routes anybody still needs.
Four layers, four owners,
and one shared network.
Monitoring is designed around how a property is really run, rather than around an org chart that does not exist.
Building systems are not layered the way an industrial network is. There is no Purdue model here and usually no segmentation to respect — a lighting controller, a door system and a chiller frequently share a flat network because they were installed by different contractors in different years and each needed an address.
What there is instead is a map of who owns and who can reach each part, and that is the map worth having. It is also the one nobody has, because no single party has ever had reason to draw it.
Roof plant
Chillers, air handling units, lift motor rooms and comms.
- AHU
- Chillers
- Lift plant
Occupied floors
HVAC zones, lighting, occupancy sensing and tenant fit-out.
- VAV
- Lighting
- Occupancy
Ground and lobby
Access control, door systems, intercom, visitor management and CCTV.
- Access control
- Intercom
- CCTV
Basement plant
Boilers, pumps, generators, lift machinery and the fire panel.
- Boilers
- Pumps
- Fire panel
The shared network and remote access
The flat network they all sit on, plus vendor portals, maintenance VPNs and contractor laptops.
- BACnet/IP
- Vendor VPN
- Cloud portals
Everything the building
needs to open.
System types rather than product names, because what is installed varies by building and none of it changes how the monitoring works.
-
Building management
The BMS head-end and the controllers it talks to across heating, cooling and ventilation.
-
Access control
Door controllers, readers, intercoms and the visitor systems attached to them.
-
Lifts and transport
Lift controllers and the monitoring links maintainers use to reach them.
-
Lighting and occupancy
Addressable lighting, presence sensing and the controllers that schedule them.
-
Energy and metering
Sub-metering, power monitoring and the gateways that report consumption.
-
Fire and life safety
Networked panels and their monitoring links, watched but never interfered with.
Fire and life safety systems are monitored for network behaviour only. We observe the traffic and we alert on it; we do not integrate with, command or automate anything that a life safety certificate depends on, and no response playbook we write will touch one.
A service, not
another dashboard.
Facilities teams do not have an analyst to spare, so nothing here assumes you will staff a console.
24x7x365 monitoring
A manned SOC watching building systems around the clock, including the hours a property is empty — which is when unattended access is most useful to somebody and least likely to be noticed.
Passive and agentless
Nothing is installed on a controller and nothing is scanned. A building system that stops is a building that stops, and no security control we deploy has a route to causing that.
An inventory that is real
Continuous discovery of what is actually on the network, including the devices a contractor added during a refurbishment and told nobody about. Most estates find things here they had no record of.
Remote access mapped
Every route into the building systems from outside them: vendor portals, maintenance VPNs, cloud dashboards. Who holds each one, and whether it is still needed.
Multi-site, one view
A property portfolio is many buildings with inconsistent kit and inconsistent contractors. They are monitored as one estate rather than as a stack of separate engagements.
Reporting for the people who ask
Output written for a managing agent, an asset owner or a board, not a SIEM export that somebody has to translate before the meeting.
Nothing goes in
before the map is agreed.
The first deliverable is the picture nobody currently has, and it is useful whether or not you go further.
-
01
Discover what is there
Passive observation of the building network to identify the systems, the controllers and the communication patterns between them. No scanning, and nothing installed on anything that is running.
-
02
Map who can reach it
Every inbound route: maintenance VPNs, vendor cloud portals, contractor accounts and any remaining dial-in. Each one attributed to a party and a contract where one exists.
-
03
Agree what is monitored
What gets watched, what gets alerted on, who is called and at what hour. Fire and life safety systems are scoped as observe-only in writing at this point.
-
04
Run it
Continuous monitoring through the same 24/7 SOC as everything else, with a named escalation path that reaches the party who can actually act — which in a building is rarely the person who received the alert.
The obligation usually arrives
before the incident does.
Buildings tend to reach security through a contract or a framework rather than through a breach.
- NIS2 pulls building operators into scope where a property supports an essential service — healthcare estates, transport hubs, utilities sites and data centres in particular.
- Cyber Essentials Plus is increasingly a condition of public sector and large corporate tenancy, and building systems sit inside the assessed boundary whether or not anybody remembered them.
- Tenant due diligence is the most common trigger of all. A corporate occupier asks the managing agent what protects the building systems, and there is no answer on file.
- Insurance and asset valuation follow the same path: a question that used to be about sprinklers is now also about who can reach the plant remotely.
Seven kinds of building,
one shared problem.
The systems are broadly the same. What changes is who is in the building, what happens when it stops, and who is asking the questions.
-
Offices and multi-tenant
Managed workplaces and mixed-occupancy estates.
The most fragmented ownership of any property type: landlord plant, tenant fit-out and a different contractor on each. Tenant due diligence is usually what starts the conversation.
-
Retail and shopping centres
Malls, retail parks and anchor stores.
Public access, long trading hours and concession fit-outs that connect to the landlord network on terms nobody documented.
-
Healthcare estates
Hospitals, clinics and care facilities.
Building systems sit alongside clinical equipment, and a ventilation or access failure is a patient safety event rather than an inconvenience.
-
Education campuses
Universities, colleges and multi-building schools.
Sprawling estates with decades of accumulated controls, open networks by culture, and capital projects that add systems faster than anyone records them.
-
Data centres
Colocation and enterprise facilities.
Cooling and power are the service. A building systems failure is a customer-facing outage, and clients audit the building as closely as the racks.
-
Hotels and leisure
Hotels, venues, stadia and visitor attractions.
Guest-facing systems bridge building networks and public wifi, and seasonal or event staffing means access lists that grow far faster than they shrink.
-
Industrial and logistics
Warehouses, distribution centres and light industrial.
Building services and process automation share a network, so a BMS route can reach material handling. Highly automated sites feel a stoppage immediately.
-
Something else?
Most portfolios are a mix, and mixed is the harder case.
Tell us what the estate looks like and how it is contracted. If the systems are too old or too closed for us to monitor usefully, we would rather say so than sell you an assessment that concludes it.
Start a conversation
What we have written
about building systems.
How A Managed IoT SOC Works: Detection, Triage, And Response Explained
Learn how a managed IoT SOC provides 24/7 detection, specialist triage and operationally aware response for IoT environments.
Internet of ThingsPassive Vs. Active IoT Monitoring: Why Non-Intrusive Matters In Operational Environments
Learn why passive IoT monitoring provides non-intrusive security visibility for OT environments without disrupting critical operations.
Internet of ThingsWhat Is IoT Security Monitoring And Why Does 24/7 Coverage Matter?
Learn why IoT security monitoring and 24/7 visibility are essential for detecting threats and protecting connected devices.
Internet of ThingsBMS Vulnerabilities: How HVAC, Access Control, And Lighting Systems Get Hacked
Learn how attackers exploit BMS vulnerabilities in HVAC, access control, and lighting systems, and why these systems are targeted.
Internet of ThingsHow Smart Buildings Work: From HVAC To Access Control Systems
Learn how smart buildings work, from HVAC and access control to BMS architecture and why it matters for security.
Internet of ThingsLateral Movement In IoT Environments: How Attackers Pivot From IT To OT
How attackers use lateral movement to pivot from IT into IoT and OT environments, and why this threat is so difficult to detect.
Smart building security, answered.
What is smart building security?
Smart building security is the monitoring and protection of the operational systems that run a property: building management and HVAC, access control and door systems, lifts, lighting, metering and the networks they sit on. It differs from IT security because those systems were procured as building services rather than as technology, are maintained under contract by third parties with their own remote access, and cannot be taken offline for patching without the building degrading.
Why are building systems a security problem at all?
Because of who owns them, more than what they are. A landlord owns the plant, a tenant owns the fit-out, a managing agent holds the contracts and an M&E contractor touches the equipment. Each party is doing its job and none has been asked to secure it, so systems end up on a flat network with remote-access accounts created at handover and never reviewed. The result is usually the weakest network on a site and the least examined.
Will monitoring disrupt the building?
No. Monitoring is passive, non-intrusive and agentless: it observes a copy of network traffic without interacting with any controller. Nothing is installed, nothing is scanned, and no configuration is changed on equipment that is running. A building system that stops is a building that stops, so there is no mechanism by which the monitoring can cause it.
Do you touch fire or life safety systems?
We monitor them for network behaviour and we alert on what we see. We do not integrate with, command or automate anything a life safety certificate depends on, and no response playbook we write will touch one. That limit is agreed in writing during scoping rather than assumed.
Our systems are maintained by contractors with remote access. Is that a problem?
It is normal, and it is usually the single most valuable thing an assessment produces: a complete list of who can reach the building from outside it, which contract each route belongs to, and which are still needed. Most estates find at least one account belonging to a supplier they no longer use.
Which protocols and systems do you support?
Detection is tuned to industrial and building protocols including BACnet and Modbus, rather than generic IT signatures applied to building traffic. On the systems themselves we work in types rather than product names: building management, access control, lifts, lighting, metering and life safety. Tell us what is installed during scoping and we will say plainly whether we can monitor it well.
We have a portfolio rather than one building. How does that work?
It is monitored as one estate. A portfolio typically means inconsistent equipment, inconsistent contractors and inconsistent documentation building to building, so the discovery phase does more work up front and the reporting is structured by property afterwards. The alternative, a separate engagement per site, produces exactly the fragmentation that caused the problem.
Does this help with NIS2 or Cyber Essentials Plus?
Yes. NIS2 pulls building operators into scope where a property supports an essential service, and Cyber Essentials Plus increasingly forms part of public sector and corporate tenancy conditions, with building systems inside the assessed boundary. Reporting is built to produce the evidence an assessor asks for rather than a data export somebody has to interpret.
Who gets called when something happens?
Whoever can actually act, which in a building is rarely the person who first receives an alert. The escalation path is agreed during scoping and names the party responsible for each system, including the contractor holding the maintenance contract where that is the right call at three in the morning.
Start with who can
reach the building.
The first deliverable is the picture nobody currently has: what is on the network, which contractor or vendor can reach it from outside, and which of those routes anybody still needs. It is useful whether or not you go further.