The Security Standard Real Estate Should Be Borrowing From Federal Buildings
Building systems have become an attractive target for people who want to cause damage. The devices that control HVAC, lighting, elevators, and access control were once physically isolated and functionally obscure, which made them uninteresting to attackers and reasonably safe by default. That isolation is gone. Building automation systems now connect to enterprise networks, cloud platforms, and in many cases directly to the public internet, and the consequences of that connectivity are showing up in the data. Kaspersky research found that 38% of smart buildings experienced at least one cyberattack on their building automation systems in a recent twelve-month period. Claroty’s Team82 research unit analyzed nearly 500,000 building management system devices across more than 500 organizations and found that 75% of those organizations had BMS devices affected by known exploited vulnerabilities, meaning vulnerabilities that have already been used in documented attacks rather than theoretical weaknesses.
The physical consequences of these attacks are what distinguish building system breaches from conventional data breaches. In October 2021, an attack on building automation devices at an office building in Germany rendered roughly three-quarters of several hundred BAS devices nonoperational, disabling lighting, motion detectors, and window shutter controllers, and the building was operated on manual controls for weeks. Three major hospitals lost climate control for more than twelve hours in 2024 as a result of BAS ransomware. A cyberattack on Omni Hotels forced manual check-ins, disabled electronic room key systems, and took WiFi offline across properties, with attackers claiming to have stolen data on approximately 3.5 million guests. These are not information security incidents in the traditional sense. They are events where people could not get into their rooms, patients could not be kept at safe temperatures, and buildings could not perform their basic function.
That reality has pushed commercial real estate to take building system security considerably more seriously than it did even three years ago, though the industry’s default assumptions about what constitutes secure infrastructure have not always kept pace. “People stayed on prem to make it seem secure, but some of these servers are sitting under someone’s desk. That is not very secure at all,” said Etrit Demaj, Co-Founder of KODE Labs, which developed a building operating system for use in the federal government’s most sensitive physical environments. The on-premise assumption is one of the most persistent misconceptions in the space. Physical proximity to a server does not make it secure. What makes infrastructure secure is continuous patching, access controls, encryption, monitoring, incident response capability, and a team whose job is to maintain all of it. Those things are considerably harder to sustain on a server in a closet than on a properly managed cloud platform.
For real estate organizations trying to raise their standard, FedRAMP offers a useful framework even for those who will never pursue certification themselves. The Federal Risk and Authorization Management Program sorts cloud services into three tiers based on how much damage a breach would cause. The Low tier covers systems where a compromise would be an inconvenience rather than a crisis, things like public-facing information that was never sensitive to begin with. Moderate is where most federal cloud services land, covering the kind of data whose exposure would cause real operational and financial harm, and it requires a substantially more rigorous set of protections around who can access what, how information is encrypted, how changes to the system are tracked, and how quickly an organization can detect and respond to an incident. High is reserved for the most sensitive unclassified information the government handles, the systems supporting law enforcement, emergency services, financial operations, and health records, where a breach could threaten lives or cause severe organizational damage. Reaching that tier requires meeting several hundred distinct security requirements and having all of them verified by an independent assessor rather than self-attested.
The controls themselves are not exotic. They are the security practices that any serious organization should be following, applied comprehensively and verified independently. “Some of the most sophisticated real estate companies are already doing these steps, they just generally rely a lot more on vendors,” Demaj said. That reliance is not itself a problem. Most real estate organizations are not going to build internal security teams capable of maintaining FedRAMP High controls across their technology stack, and they should not try. What they can do is use certification as a screening mechanism when evaluating the vendors they depend on. A vendor that has completed FedRAMP authorization has submitted to independent third-party assessment, documented its security architecture in detail, and committed to continuous monitoring obligations that require ongoing investment rather than a one-time effort.
That ongoing dimension is what makes certification a more meaningful signal than a security questionnaire or a compliance attestation. FedRAMP authorization is not a static credential. Authorized providers must submit monthly continuous monitoring reports, undergo annual assessments, and maintain the control environment as the underlying systems evolve. Sustaining that requires an organizational commitment that goes well beyond a compliance checkbox. “You really have to have a team that is passionate about security,” Demaj said. That passion matters in an industry where the technology lifecycle and the building lifecycle are badly mismatched. “Sometimes tech can be put in when a building is being built and can be obsolete by the time a building is ready to lease.” A building system specified during design, installed during construction, and commissioned at delivery may be running on firmware that is three or four years old before the first tenant moves in, and the vulnerabilities discovered during that period do not wait for the certificate of occupancy.
The federal government’s approach to building security is instructive precisely because the stakes force a level of rigor that the commercial market has not yet been compelled to match. Federal agencies operate some of the largest and most complex building portfolios in the country, and they operate them under security requirements that assume adversaries are actively attempting to compromise their systems. Commercial real estate operates under no such assumption in most cases, which is why building automation controllers running manufacturer default passwords remain one of the most commonly exploited vulnerabilities in the sector.
What the federal approach demonstrates is that security rigor at this level is achievable, not aspirational. The controls exist, the assessment infrastructure exists, and vendors are willing to meet the standard when there is a reason to. As tenants become more sophisticated about what they are exposing themselves to when they occupy a connected building, and as insurers begin pricing that exposure into their underwriting, the ability to demonstrate verified security will become part of how buildings compete. The owners who can point to independently assessed infrastructure will be in a meaningfully different conversation than those who can only offer assurances.
The post The Security Standard Real Estate Should Be Borrowing From Federal Buildings appeared first on Propmodo.