Commercial real estate has quietly become an operational technology sector in its own right: modern buildings run networked HVAC control, access control and badge systems, elevator management, and increasingly, comprehensive building automation platforms that tie lighting, security cameras, and environmental controls into a single connected system — infrastructure that a decade ago would have been standalone, isolated equipment, and today frequently sits on the same IP network as the building's tenant-facing IT infrastructure.
Why building automation systems are an underappreciated attack surface
A building automation system's job is convenience and efficiency — centralized control over environmental and access systems across a large facility — which is precisely why it tends to be integrated as broadly as possible, often by a facilities team or a specialized building automation contractor operating with limited coordination with the organization's conventional IT security function. That organizational gap matters more than it might first appear: a building automation system with access to physical access control (door locks, badge readers) represents a security-relevant system by any reasonable definition, but it's frequently procured, deployed, and maintained entirely outside a security team's visibility, evaluated on operational and energy-efficiency criteria rather than security ones.
The physical-access dimension that distinguishes this sector
Unlike most enterprise IT security concerns, a compromise of building automation or access control systems can translate directly into physical building access — a manipulated badge system or door controller doesn't just create a data problem, it can grant an intruder physical entry to spaces the organization assumes are secured. That's a meaningfully different consequence profile than the confidentiality and availability concerns most security frameworks are built around, and it means building automation security deserves evaluation against a physical-security threat model, not merely a conventional IT one.
What to look for in a security approach for this sector
Explicit inclusion of building automation and access control systems within the organization's security scope, rather than treating them as facilities-managed infrastructure outside conventional IT security review. If your security team cannot answer basic questions about what's running your building's access control system, that's the gap to close first.
Network segmentation between building automation systems and general corporate IT networks, given how frequently these systems are integrated onto shared infrastructure for convenience without a corresponding security architecture review of what that integration actually exposes.
Software supply chain visibility for building automation platforms and their integrated subsystems, since these systems increasingly combine software from the primary building automation vendor with components from access control, camera, and environmental sensor manufacturers — each representing a separate dependency chain worth understanding.
Vendor and contractor access governance for the facilities teams and specialized contractors who typically maintain these systems, recognizing that building automation maintenance access is frequently broader and less monitored than equivalent access to core IT infrastructure would be permitted to be.
Why multi-tenant buildings raise the stakes further
A commercial building housing multiple independent tenant organizations adds a layer of complexity beyond a single-occupant facility: the building owner's automation system frequently has a level of access and visibility across the entire facility that no individual tenant can fully audit or control, meaning a tenant's own security posture is partly dependent on a building operator's practices they have limited ability to verify directly. That's a supply-chain-like trust relationship in its own right, and tenant organizations handling sensitive work — legal, financial, or government-adjacent functions in particular — increasingly ask building owners and property managers direct questions about automation system security as part of lease negotiations, a due-diligence pattern that's likely to become more standard as awareness of this risk category grows.
A closing note on retrofit projects
Older buildings retrofitted with modern automation systems frequently graft new networked controls onto legacy wiring and infrastructure never designed with security segmentation in mind, which is exactly where a careful architecture review before integration pays off most.
How Safeguard helps
Safeguard's continuous inventory and software supply chain visibility extend to building automation and access control platforms, bringing this frequently overlooked category of operational technology into the same documented, auditable picture organizations already expect for their conventional IT infrastructure — closing a visibility gap that exists mainly because of how these systems have historically been procured and managed, not because they matter less.