A facility management system, a CAD or BIM model and a building management system operating largely independently: for a long time, this was the digital infrastructure of many buildings. Data was transferred manually, interfaces remained manageable and many applications ran on the organisation's own network. This world is changing. Today, companies connect CAFM systems with IoT platforms, Common Data Environments, digital twins, ERP software and mobile applications. Sensors continuously provide data on energy consumption or equipment condition. Cloud platforms make information available from anywhere. External service providers access the same systems. In future, AI applications are expected to control even more processes automatically.
This brings benefits. Data no longer needs to be maintained multiple times, faults can be detected faster, processes automated and buildings controlled more precisely. Yet every new connection also increases the number of potential points of attack. For Matthias Mosig, Head of Digital Transition at TÜV SÜD Advimo, and Dr Stefan Veit, Head of Electrical and Building Services Engineering at TÜV SÜD Industrie Service, cybersecurity is therefore an essential part of digitalising facility management. As systems become more interconnected, their protection must develop at the same pace.
Applications become a digital ecosystem
As long as CAFM, CAD/BIM and building management systems, including the equipment they control, operate largely independently, the number of interfaces remains limited. While this reduces the potential for automation, it also keeps the attack surface smaller. Risks then arise primarily in the local network, through physical access or outdated software when companies fail to install updates regularly. Increasing connectivity changes this. Applications move to the cloud, IoT platforms supply real-time data, systems exchange information automatically and external FM service providers access data and applications.
:quality(80))
This creates additional routes through which attackers can enter the digital infrastructure. Application programming interfaces play a key role here. They enable automated data exchange between different applications. This very connection makes digital processes efficient, but can also become an entry point if companies do not adequately protect their interfaces. The more closely systems work together, the more important encryption, secure access, clearly defined permissions and continuous monitoring become. Security events must be logged so that unauthorised access, administrative actions and disruptions remain traceable in an audit-proof manner.
AI adds another layer of complexity
AI-powered applications further expand the digital landscape. Digital systems can already analyse ESG data, predict maintenance needs or support dynamic simulations, for example. In future, AI agents could connect multiple systems and manage some processes independently.
This increases more than the degree of automation. Companies also become more dependent on accurate data and reliable systems. Manipulated data can lead to incorrect decisions, for example. When AI systems initiate actions themselves, operators must therefore keep the entire chain in view: from data sources, interfaces and cloud platforms to the application itself. Critical AI use cases should include plausibility checks or manual controls, particularly for hallucinations, risks of bias, model changes or results that cannot be explained.
Benefits and risks therefore grow together. The more digitally interconnected a building is, the more processes can be automated. At the same time, a vulnerability can affect several connected systems.
When an IT problem becomes a building risk
Cybersecurity in facility management therefore affects more than data and computers. Building automation and safety systems directly influence a building's operation. Attackers could attempt to disable equipment, change parameters or deliberately trigger false alarms. Unauthorised access to security systems is possible both digitally and directly on site.
The consequences can go far beyond a conventional IT outage. When technical equipment stops working or is controlled incorrectly, operational disruption and financial losses can result. In the worst case, failures in safety-related systems may also affect people or public safety.
Cyber risks must therefore be considered from several perspectives. Alongside IT, these include operations and utilities, technical safety, the environment and financial consequences. This also changes responsibilities. In a digitalised building, cybersecurity cannot be delegated solely to the IT department. Critical AI use cases should include plausibility checks or manual controls, particularly for hallucinations, risks of bias, model changes or results that cannot be explained.
:quality(80))
Security starts before software procurement
Many companies only examine a system's security in depth when it is being introduced or is already running. By then, however, fundamental decisions about software, architecture and interfaces have long been made. TÜV SÜD therefore recommends involving IT, data protection and information security from the outset of digitalisation projects. Those involved must understand which existing systems will be connected, which interfaces are needed and which legacy applications will remain part of the architecture. The supplier's organisation, responsibilities, operating model, data processing regions and subcontractors should also be transparently described during procurement.
Operators should also take a closer look when selecting software. Where is the data stored? How does the provider protect its data centre? How is information encrypted? Which certifications are available? Through which interfaces does the system communicate with IoT platforms, ERP or other applications? A requirements specification must therefore cover more than functionality. For externally hosted components, operators should also contractually require penetration tests on request and the provision of results, including an action plan.
Not everyone needs access to everything
Access rights are a central issue. Digital building systems have long been accessed by more than a company's own employees. Operators, FM service providers, maintenance companies and other external partners also use them. As this group grows, companies need to define more precisely who may view, change or share which information. TÜV SÜD recommends individual roles and permissions instead of shared group accounts. Identity and access management systems can centrally control logins. Mobile devices require additional safeguards, such as two-factor authentication and the ability to block lost devices.
Such rules may initially seem unremarkable. In an incident, however, they determine whether a compromised user account provides access to a single application or to large parts of the digital building ecosystem.
:quality(80))
The work does not end at commissioning
Even a system that is well protected when introduced does not automatically remain secure. Software changes, new vulnerabilities emerge and attackers develop their methods. Operators must therefore regularly install security updates and patches and repeatedly review their systems. This includes structured vulnerability and patch management, as well as backups whose recoverability is regularly tested.
According to the TÜV SÜD experts, this involves recurring penetration tests, cybersecurity audits and risk assessments. Regular training should help employees understand how to use digital systems securely and respond to unusual activity. Maintenance contracts should also define how providers supply security updates. Cybersecurity thus becomes an ongoing operational task. A one-off assessment before commissioning is not enough.
More digitalisation requires a stronger security architecture
An isolated CAFM system needs different safeguards from a cloud platform connecting BIM, IoT, building management systems, external service providers and AI applications. Every additional interface therefore changes the security requirements. This is not an argument against greater connectivity. Many efficiency gains in facility management only arise when systems exchange data and automate processes. Yet the very connections that create these benefits also enlarge the attack surface.
When selecting new applications, asking 'What can the system do?' is therefore no longer enough. Operators should also know which other applications it communicates with, who can access it, which data is exchanged and what the consequences of a successful attack would be.
Cybersecurity becomes part of facility management
Digital building operation is also shifting the boundaries of traditional facility management. Those operating technical equipment are responsible for more than maintenance, availability or energy consumption. Operators increasingly need to understand how digital systems interact and which risks arise from their connectivity.
The gefma white paper 'Cybersecurity in Facility Management', published in October 2025 and co-authored by Matthias Mosig, also addresses this development. Alongside technical safeguards, it examines legal foundations, potential entry points and the roles and processes companies need for secure operation. The more digitally facility management works, the harder it becomes to separate building services from IT security. Cybersecurity thus becomes an operational responsibility spanning design, procurement, implementation and day-to-day operation. In terms of data protection, the GDPR, commissioned data processing, technical and organisational measures and the handling of personal data in AI components must be transparently addressed.

:quality(80))
:quality(80))
:quality(80))
:quality(80))
:quality(80))