Report an Incident Become a Partner Careers Contact
Book a Demo
BMS · Access · HVAC · Lifts

The building is
the operation.

Security monitoring for building management, access control and the systems a property depends on to open in the morning. Passive, agentless, and watched by the same 24/7 SOC that runs our IT customers.

Building systemsMonitored
BMSHeating & ventilationlandlord
ACSAccess controlmanaging agent
LIFTLifts & transportunder contract
METEREnergy meteringtenant billed
REMOTEVendor VPNsusually nobody

What is smart building security?

Smart building security is the monitoring and protection of the operational systems that run a property: building management and HVAC, access control and door systems, lifts, lighting, metering and the networks they sit on. It differs from IT security because those systems were procured as building services rather than as technology, are usually maintained under contract by third parties with their own remote access, and cannot be taken offline for patching without the building itself degrading.

Where we start

Everyone maintains it.
Nobody owns it.

That sentence is the whole difference between building systems and every other estate, and it is why buildings are so consistently the weakest network on a site.

A plant has an OT manager. A corporate network has an IT director. A building has a landlord who owns the plant, a tenant who owns the fit-out, a managing agent who holds the contracts, and an M&E contractor who actually touches the equipment. Each of them is doing their job. None of them has been asked to secure it.

So the systems arrive commissioned, connected and working, with a remote-access account for the maintainer that was set up during handover and has never been reviewed since. The building operates perfectly. The security position is invisible, and stays invisible until somebody looks.

That is what this service does first. Not a threat briefing, and not a proposal to replace equipment that is doing its job — an honest picture of what is on the network, who can reach it, and which of those routes anybody still needs.

How a building is actually wired

Four layers, four owners,
and one shared network.

Monitoring is designed around how a property is really run, rather than around an org chart that does not exist.

Building systems are not layered the way an industrial network is. There is no Purdue model here and usually no segmentation to respect — a lighting controller, a door system and a chiller frequently share a flat network because they were installed by different contractors in different years and each needed an address.

What there is instead is a map of who owns and who can reach each part, and that is the map worth having. It is also the one nobody has, because no single party has ever had reason to draw it.

Building systems Observation only
Building Shared
ROOF

Roof plant

Chillers, air handling units, lift motor rooms and comms.

  • AHU
  • Chillers
  • Lift plant
Landlord, via M&E contract
FLOORS

Occupied floors

HVAC zones, lighting, occupancy sensing and tenant fit-out.

  • VAV
  • Lighting
  • Occupancy
Tenant, via fit-out
GROUND

Ground and lobby

Access control, door systems, intercom, visitor management and CCTV.

  • Access control
  • Intercom
  • CCTV
Managing agent
BASEMENT

Basement plant

Boilers, pumps, generators, lift machinery and the fire panel.

  • Boilers
  • Pumps
  • Fire panel
M&E contractor
NET

The shared network and remote access

The flat network they all sit on, plus vendor portals, maintenance VPNs and contractor laptops.

  • BACnet/IP
  • Vendor VPN
  • Cloud portals
Usually nobody
A commercial property read top to bottom, with the owner of each layer.
What we monitor

Everything the building
needs to open.

System types rather than product names, because what is installed varies by building and none of it changes how the monitoring works.

  • Building management

    The BMS head-end and the controllers it talks to across heating, cooling and ventilation.

  • Access control

    Door controllers, readers, intercoms and the visitor systems attached to them.

  • Lifts and transport

    Lift controllers and the monitoring links maintainers use to reach them.

  • Lighting and occupancy

    Addressable lighting, presence sensing and the controllers that schedule them.

  • Energy and metering

    Sub-metering, power monitoring and the gateways that report consumption.

  • Fire and life safety

    Networked panels and their monitoring links, watched but never interfered with.

One deliberate limit

Fire and life safety systems are monitored for network behaviour only. We observe the traffic and we alert on it; we do not integrate with, command or automate anything that a life safety certificate depends on, and no response playbook we write will touch one.

What you get

A service, not
another dashboard.

Facilities teams do not have an analyst to spare, so nothing here assumes you will staff a console.

1

24x7x365 monitoring

A manned SOC watching building systems around the clock, including the hours a property is empty — which is when unattended access is most useful to somebody and least likely to be noticed.

2

Passive and agentless

Nothing is installed on a controller and nothing is scanned. A building system that stops is a building that stops, and no security control we deploy has a route to causing that.

3

An inventory that is real

Continuous discovery of what is actually on the network, including the devices a contractor added during a refurbishment and told nobody about. Most estates find things here they had no record of.

4

Remote access mapped

Every route into the building systems from outside them: vendor portals, maintenance VPNs, cloud dashboards. Who holds each one, and whether it is still needed.

5

Multi-site, one view

A property portfolio is many buildings with inconsistent kit and inconsistent contractors. They are monitored as one estate rather than as a stack of separate engagements.

6

Reporting for the people who ask

Output written for a managing agent, an asset owner or a board, not a SIEM export that somebody has to translate before the meeting.

How it works

Nothing goes in
before the map is agreed.

The first deliverable is the picture nobody currently has, and it is useful whether or not you go further.

  1. 01

    Discover what is there

    Passive observation of the building network to identify the systems, the controllers and the communication patterns between them. No scanning, and nothing installed on anything that is running.

  2. 02

    Map who can reach it

    Every inbound route: maintenance VPNs, vendor cloud portals, contractor accounts and any remaining dial-in. Each one attributed to a party and a contract where one exists.

  3. 03

    Agree what is monitored

    What gets watched, what gets alerted on, who is called and at what hour. Fire and life safety systems are scoped as observe-only in writing at this point.

  4. 04

    Run it

    Continuous monitoring through the same 24/7 SOC as everything else, with a named escalation path that reaches the party who can actually act — which in a building is rarely the person who received the alert.

Where it lands

The obligation usually arrives
before the incident does.

Buildings tend to reach security through a contract or a framework rather than through a breach.

  • NIS2 pulls building operators into scope where a property supports an essential service — healthcare estates, transport hubs, utilities sites and data centres in particular.
  • Cyber Essentials Plus is increasingly a condition of public sector and large corporate tenancy, and building systems sit inside the assessed boundary whether or not anybody remembered them.
  • Tenant due diligence is the most common trigger of all. A corporate occupier asks the managing agent what protects the building systems, and there is no answer on file.
  • Insurance and asset valuation follow the same path: a question that used to be about sprinklers is now also about who can reach the plant remotely.
Where it runs

Seven kinds of building,
one shared problem.

The systems are broadly the same. What changes is who is in the building, what happens when it stops, and who is asking the questions.

  • Offices and multi-tenant

    Managed workplaces and mixed-occupancy estates.

    The most fragmented ownership of any property type: landlord plant, tenant fit-out and a different contractor on each. Tenant due diligence is usually what starts the conversation.

  • Retail and shopping centres

    Malls, retail parks and anchor stores.

    Public access, long trading hours and concession fit-outs that connect to the landlord network on terms nobody documented.

  • Healthcare estates

    Hospitals, clinics and care facilities.

    Building systems sit alongside clinical equipment, and a ventilation or access failure is a patient safety event rather than an inconvenience.

  • Education campuses

    Universities, colleges and multi-building schools.

    Sprawling estates with decades of accumulated controls, open networks by culture, and capital projects that add systems faster than anyone records them.

  • Data centres

    Colocation and enterprise facilities.

    Cooling and power are the service. A building systems failure is a customer-facing outage, and clients audit the building as closely as the racks.

  • Hotels and leisure

    Hotels, venues, stadia and visitor attractions.

    Guest-facing systems bridge building networks and public wifi, and seasonal or event staffing means access lists that grow far faster than they shrink.

  • Industrial and logistics

    Warehouses, distribution centres and light industrial.

    Building services and process automation share a network, so a BMS route can reach material handling. Highly automated sites feel a stoppage immediately.

  • Something else?

    Most portfolios are a mix, and mixed is the harder case.

    Tell us what the estate looks like and how it is contracted. If the systems are too old or too closed for us to monitor usefully, we would rather say so than sell you an assessment that concludes it.

    Start a conversation
Questions

Smart building security, answered.

What is smart building security?

Smart building security is the monitoring and protection of the operational systems that run a property: building management and HVAC, access control and door systems, lifts, lighting, metering and the networks they sit on. It differs from IT security because those systems were procured as building services rather than as technology, are maintained under contract by third parties with their own remote access, and cannot be taken offline for patching without the building degrading.

Why are building systems a security problem at all?

Because of who owns them, more than what they are. A landlord owns the plant, a tenant owns the fit-out, a managing agent holds the contracts and an M&E contractor touches the equipment. Each party is doing its job and none has been asked to secure it, so systems end up on a flat network with remote-access accounts created at handover and never reviewed. The result is usually the weakest network on a site and the least examined.

Will monitoring disrupt the building?

No. Monitoring is passive, non-intrusive and agentless: it observes a copy of network traffic without interacting with any controller. Nothing is installed, nothing is scanned, and no configuration is changed on equipment that is running. A building system that stops is a building that stops, so there is no mechanism by which the monitoring can cause it.

Do you touch fire or life safety systems?

We monitor them for network behaviour and we alert on what we see. We do not integrate with, command or automate anything a life safety certificate depends on, and no response playbook we write will touch one. That limit is agreed in writing during scoping rather than assumed.

Our systems are maintained by contractors with remote access. Is that a problem?

It is normal, and it is usually the single most valuable thing an assessment produces: a complete list of who can reach the building from outside it, which contract each route belongs to, and which are still needed. Most estates find at least one account belonging to a supplier they no longer use.

Which protocols and systems do you support?

Detection is tuned to industrial and building protocols including BACnet and Modbus, rather than generic IT signatures applied to building traffic. On the systems themselves we work in types rather than product names: building management, access control, lifts, lighting, metering and life safety. Tell us what is installed during scoping and we will say plainly whether we can monitor it well.

We have a portfolio rather than one building. How does that work?

It is monitored as one estate. A portfolio typically means inconsistent equipment, inconsistent contractors and inconsistent documentation building to building, so the discovery phase does more work up front and the reporting is structured by property afterwards. The alternative, a separate engagement per site, produces exactly the fragmentation that caused the problem.

Does this help with NIS2 or Cyber Essentials Plus?

Yes. NIS2 pulls building operators into scope where a property supports an essential service, and Cyber Essentials Plus increasingly forms part of public sector and corporate tenancy conditions, with building systems inside the assessed boundary. Reporting is built to produce the evidence an assessor asks for rather than a data export somebody has to interpret.

Who gets called when something happens?

Whoever can actually act, which in a building is rarely the person who first receives an alert. The escalation path is agreed during scoping and names the party responsible for each system, including the contractor holding the maintenance contract where that is the right call at three in the morning.

Where to start

Start with who can
reach the building.

The first deliverable is the picture nobody currently has: what is on the network, which contractor or vendor can reach it from outside, and which of those routes anybody still needs. It is useful whether or not you go further.

A Wizard Cyber security analyst