New Research Reveals Intelligent Building Security Risks Vulnerabilities and Mitigation Strategies

Groundbreaking report includes guidance to aid decision makers and help protect buildings against an array of threats and risks

The ASIS Foundation, in partnership with BOMA International (BOMA) and the Security Industry Association (SIA), today released groundbreaking first-of-its-kind guidance for practitioners in the security and building management fields. Intelligent Building Management Systems: Guidance for Protecting Organizations provides a framework to help decision-makers assign a risk-based criticality or impact to their building and asks relevant security questions to develop appropriate mitigation strategies. It also serves to establish a common language between the many intelligent building stakeholders.

The guidance is based on original research, Building Automation & Control Systems: An Investigation into Vulnerabilities, Current Practice and Security Management Best Practice, by David J. Brooks, Michael Coole, and Paul Haskell-Dowland of Edith Cowan University in Perth, Australia. The research provides an exhaustive overview of identified intelligent building critical vulnerabilities and mitigation strategies.

“The ASIS Foundation is delighted to work with our partners BOMA and SIA to support such critical research in a rapidly developing but insufficiently understood field,” says Sandra Cowie, CPP, director, Global Security and Business Continuity, Principal, and 2018 ASIS Foundation President. “Building automation invokes cutting-edge issues and technology such as the Internet of Things and advanced video analytics, as well as traditional concerns such as physical access control and proper procedures. The integrated whole undoubtedly poses challenges that are still emerging. This research is indispensable to helping our members get a handle on both the challenges and the opportunities of this fast-growing market.”

According to the report, the intelligent building market is growing 31% per year and is expected to exceed $59B by 2023. These systems are increasingly embedded into the contemporary built environment due to the demand for reduced operating costs, government regulation, and greater monitoring, control and operability. However, this growth comes with a substantial set of security vulnerabilities that many security and facility professionals have not accounted for. Importantly, the research finds a significant disconnect between security and facility professionals’ perceived understanding of intelligent building threats and risks versus actual dangers. In addition, the report revealed that a lack of common terminology and practices can result in misunderstandings and siloed views of associated security risks. The report findings emphasize the need to:

  • Take a multidisciplinary proactive management approach to intelligent building vulnerability mitigation, and
  • Fuse multidisciplinary participants into an intelligent building security team.

Additional findings include the recognition of intelligent building integrators and cybersecurity experts as partners who can help organizations better understand threats and risks, and more effectively achieve intelligent building security.

“The research developed by the ASIS Foundation provides insights that should be leveraged by our members and the industry to better understand and identify vulnerabilities within Intelligent Building Systems. An essential outcome from this project is the recommended guidance and checklist that will help security practitioners and security technology solutions providers work together to implement strategies to mitigate against potential risks,” says Don Erickson, chief executive officer, SIA.

For more information or to download infographics and the free report, visit www.asisfoundation.org.

Featured

  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.