The Leading News & Information Service For The Facilities, Workplace & Built Environment Community

Five Ways Facilities Managers Can Tackle Hidden Cyber Risks In Building Systems

Five Ways Facilities Managers Can Tackle Hidden Cyber Risks In Building Systems
24 July 2026 | Updated 23 July 2026
 

Facilities managers are being warned about the hidden cyber security risks inside their building systems because of new technologies which are moving at a rapid pace.

According to the latest UK Government Cyber Security Breaches Survey, 43% of businesses reported a cyber security breach within the last 12 months, while the number of businesses which have adopted advanced controls like two-factor authentication (47%) and user monitoring (30%) remains low.



Facilities managers have been quick to embrace new technology and benefit from its enhancements, including Building Management Systems, access control and CCTV, which are becoming interconnected by digital platforms.

Here are five tips from David Robinson, Head of Cybersecurity at Restore Information Management, on how facilities managers can take control of their building technology to reduce cyber security risks.


1. Know what systems you have and how they are connected

It is crucial facilities managers know what building systems they have and how each one is connected. A simple way of doing this is by keeping a protected inventory of each system that is either networked or remotely accessible, including who supplies the system and how the access is provided.

This is the first step to improving your baseline security and protecting your business from advanced cyber criminals, who, once they have access to a system, can go anywhere in that network.

Do not leave this inventory to your IT team. When building systems fail, everyone notices it immediately – and staff will turn to the facilities management team first for help.


2. Eliminate shared logins and default passwords

On the surface, shared logins and default passwords are easy to remember and convenient. In reality, they’re one of the most common weaknesses in an organisation’s cyber security.

Facilities managers should ensure they have a password policy in place. This could include changing passwords every three months, reducing the number of employees who know the passwords, or changing passwords and logins every time an individual leaves the workplace.

It’s important to be proactive about password policies and not just rely on making changes when someone forgets their login.


3. Tighten controls

Facilities managers need to do their due diligence when it comes to remote access and control. The best way to do this is by taking ownership of who has access to what and for how long.

Carry out a monthly in-house audit of contractors who have had access to a building, whether they were admitted into the building by an employee or whether they had access themselves, whether their work is complete or not. If it is complete, access should be changed so they no longer have any company knowledge.

It’s a good idea to do a similar audit with employees and regularly check whether anyone has left the business, what they had access to, and to update these access routes to prevent external exposure.


4. Separate systems

It’s important building network systems are separated from corporate IT networks. In the event of a security breach, separated systems mean the breach will be isolated to that one network rather than the entire organisation.

Facilities managers should liaise with their IT team to push for that separation if it doesn’t already exist. Managers have the chance to be proactive and push for change in legacy systems, and this is an important one they should make.


5. Make cyber security your responsibility

Facilities managers need to have a proactive approach to cyber security and should engage with the IT team and across their entire organisation. Hold awareness training for all employees and teach them about the real-world consequences of a building system cyber-attack  such as doors failing, areas being unlocked, heating and cooling systems being disabled and CCTV feeds becoming unavailable.

Make sure everyone knows they have a part to play when it comes to cyber security and protecting the business.


David Robinson, Head of Cybersecurity at Restore Information Management, said: “Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease.

Robinson added: “As today’s digital building systems become more connected and cloud-based, facilities managers are chasing systems that are evolving quicker than they can protect them. Without the right controls, attackers could cause disruption in building systems and the organisation’s wider network.”


Picture: An image of a person using a control panel in an office.

Article written by David Robinson | Published 24 July 2026

Share



Related Articles

The Hidden Cyber Risks In Your Supply Chain

Facilities Management businesses invest heavily in keeping buildings running smoothly, yet one of the biggest cyber risks often sits outside their control, their...

 Read Full Article
Three Controls That Stop Account Takeover Before It Starts

Francis West, CEO of Security Everywhere, warns that ‘Account Takeover’ is one of the most common ways cyber-attacks begin. It rarely starts with anything...

 Read Full Article
Outdated Technology is Costing the Public Sector £45 Billion a Year

One in four digital systems used by central government are outdated, costing the public sector £45 billion in productivity savings. This figure equates to paying...

 Read Full Article
Security Everywhere – Cyber Security Essentials Q&A Part Three

In Part 3 of our cyber security Q&A, Sheldon Reynolds talks us through the danger of reusing passwords and what happens on the dark web.  According to data...

 Read Full Article
The Rise of Impersonation Attacks – How Businesses Can Safeguard Their Emails

The cyber threat landscape is evolving at an alarming rate, and there's a new player in town that's causing mayhem in inboxes: impersonation attacks. In this...

 Read Full Article
Security Everywhere – Cyber Security Essentials Q&A Part Two

In Part 2 of our Q&A with cyber security expert Francis West, we discuss simple actions we can all take to be more cyber safe, what to do if you receive a suspicious...

 Read Full Article
Security Everywhere – Cyber Security Essentials Q&A Part One

Learn more about the realities of cyber crime in this Q&A with cyber security expert Francis West. From Whatsapp fraud to investment scams, cyber crime has...

 Read Full Article
UK Data Centres Designated as Critical Infrastructure

UK data centres are now classed as critical national infrastructure, the same status associated with energy supply, water supply, transportation, health and...

 Read Full Article
Worldwide IT Outage – What We Know So Far

A major IT outage caused major disruptions at airports, GP surgeries, and retail stores. Computer systems across the world crashed, experiencing the “Blue...

 Read Full Article
Reported Ransomware Incidents in UK Doubled in 2023

A Freedom of Information request has revealed that there was a resurgence in ransomware-related incidents following a quieter 2022.   In the first six months...

 Read Full Article