Skip to content

Magazine for digital value creation in the construction and real estate industry

When the digital twin becomes a target

BIM, Common Data Environments, IoT and connected building systems make construction projects more transparent and efficient. Every new connection also expands the digital attack surface. Using BIM and digital twins throughout a building's life cycle therefore means planning their protection from the outset. Cybersecurity is not a feature to add later: it is a prerequisite for reliable digital construction processes.

29/09/2026 · 5 min

Modern construction technologies: a drone, robotic arm, laser scanner, building site, and digital data overlays.KI-generiert
BIM and digital twins support construction projects, but can also provide entry points for cyberattacks.
Share this article

Digitalisation in construction has long meant more than converting paper plans into digital files. BIM is changing collaboration across design, procurement, construction and operation. Information is shared, data is exchanged across company boundaries, and more and more technical systems are being connected.

This creates considerable value, but greater reliance on digital information also brings new responsibilities. The more we rely on digital models and data to make decisions, the more important their availability, confidentiality, and reliability become. Manipulated information or an unavailable system can have a much greater impact in a networked construction process than a lost file on a single computer. Cybersecurity must therefore not remain solely the task of IT. It affects design, construction and operation, spanning the building's entire digital life cycle.

The attack surface doesn't end with the BIM model

It's not just the BIM file that needs protection. Digital building models contain information about structures, rooms, technical systems or access points. Project teams exchange documents via Common Data Environments. Software and networks connect numerous companies. Later, building automation, sensors, IoT applications, and other smart building systems are added. At the same time, the number of connected devices on site is growing.

Chart titled 'Challenges in the Construction and Real Estate Industry' showing a grid of issues categorized into general, global, and security-related themes.Dormakaba
Digital construction processes connect more data, systems and participants, expanding the attack surface as they do so.

There is also an organisational dimension: project teams change, employees move on, and external partners temporarily gain access to systems. This also changes access rights and responsibilities during a project.

Construction projects inherently divide work among many participants. Clients, planners, construction companies, subcontractors, manufacturers, and operators work together over extended periods and access shared information. Each additional project partner can create another handover point for data and access rights. At the same time, companies are constantly introducing new digital tools. However, awareness of the associated security risks does not necessarily develop at the same pace.

This becomes particularly clear with critical infrastructure. Digital models can contain information about security-sensitive areas of a building, technical systems, or access control solutions. Such information is valuable for planning and operation. However, it can also be of interest for sabotage or espionage. Protecting the digital building therefore becomes part of protecting its physical infrastructure.  Digital building data therefore also becomes a matter of operational risk management and regulatory compliance.

BIM can support resilience

This does not mean that we should work less digitally. On the contrary. BIM can, for example, provide detailed information about building structure, materials, and technical systems, thereby supporting risk assessments. Security and resilience measures can be considered earlier in the planning process. Perimeter protection and access control solutions can also become part of digital planning. The transition to a digital twin increases these benefits further. Current operational information can be linked to the building model and used, for example, for operation, maintenance, or crisis management.

However, the more important this information becomes to real-world decisions, the more important its integrity is. A digital twin only helps us if we can trust its data. We must therefore prevent information from being changed unnoticed or viewed by people who do not need access to it.

Diagram listing BIM applications (risk, resilience, security, crisis management) with an isometric city illustration showing diverse buildings.Dormakaba
As a digital twin brings together more information, access controls and data integrity become increasingly important.

Who needs what data?

BIM thrives on collaboration. Nevertheless, collaboration does not mean that all project participants should have access to all information. A specialist designer has different information needs from a construction contractor. A maintenance service provider needs information about the systems for which they are responsible. This does not automatically mean that they need full access to security-critical areas of a building model.

We must therefore think more carefully about what information we generate and how we classify it. Which data is sensitive? Who needs it for their task? Who is allowed to change it? How long should it remain available? And how do we handle access rights when people leave a project? These questions need to be addressed at the start of a BIM project and provide the foundation for its technical security planning.

In my view, every digital construction project should include an early risk assessment. This initially involves simple questions: What data is generated? Where is it located? Which systems access it? Which companies are involved? Who receives which access rights? What would happen if information were lost, made public, or manipulated?

The answers will vary greatly depending on the project. A residential building requires a different security strategy than an airport, a military facility, or an energy facility. Security requirements should therefore be based on the sensitivity of the respective project and its data.

For operators of critical infrastructure, this issue has become significantly more relevant from a regulatory perspective. The German NIS-2 Implementation Act came into force in December 2025 and tightens the requirements for the cybersecurity of affected entities. The German Critical Infrastructure Umbrella Act (KRITIS-Dachgesetz) came into force in March 2026 and transposes the European CER Directive on the resilience of critical entities into German law.

Security is not an afterthought

But we don't have to start from scratch. While standards do not automatically create security, they can help to organise responsibilities, information flows, and processes clearly and transparently. However, they only deliver value when applied in practice. This is particularly important in complex projects. When numerous participants work with different applications, we need common rules for data exchange, access, and responsibilities.

Increasing digitalisation does not automatically make buildings insecure. However, it changes the risks. Information that was previously distributed across file folders, individual plans, and separate systems can now be centrally available, interconnected, and partly directly linked to day-to-day building operations. This increases both their usefulness and their importance to a building's safe operation. Cybersecurity must therefore be considered over the same life cycle as the digital information itself: from design and construction through to operation.

No single company will find all the answers alone. Technologies continue to evolve, regulatory requirements change, and new digital applications create new risks. For those working in construction and real estate, this means keeping up with the issue.

My appeal is therefore to make cybersecurity and the protection of digital building data a subject of discussion in your company. Exchange ideas with planners, operators, manufacturers, and IT specialists. Use associations, professional organisations and standardisation bodies as sources of information, and contribute your own experience to their work.

This exchange helps us to share experiences, jointly develop standards, and identify new risks earlier. The digitalisation of the construction industry will continue. We must keep pace with it when it comes to security.

More on this topic

Infrastructure

From megaproject to standard: how Poland is advancing BIM

Between Warsaw and Łódź, Port Polska is developing a new international airport linked to a high-speed rail and road network. The project is among the most ambitious infrastructure programs in Europe and is digitally organized from the start. BIM, shared data environments, and open standards are intended to bring together hundreds of project participants. In 2026, the country is the official partner country of BIM World MUNICH.

29.09.2026

Infrastructure

Hamburg Central Station: coordinating complex construction projects with a digital twin

Hamburg Central Station faces a complex programme of parallel construction projects. A digital twin supports efficient coordination across projects: 4D simulations identify conflicts over space and time while the station remains operational and help resolve them. The semantic data model and its integration with existing IT systems also connect construction planning with day-to-day building operations.

29.09.2026