Show Notes
Preventive Maintenance Is a Cybersecurity Control
Modern commercial buildings run on connected systems. HVAC controllers, lighting, elevators, access control panels, fire alarms, sensors, and building-management platforms increasingly communicate across networks. That connectivity supports more efficient operations, but it also creates an expanding attack surface that building owners, facilities teams, and IT leaders cannot afford to ignore.
This episode of Built, Wired & Secured examines a simple but important principle: preventive maintenance is not only an operational practice. It is also a cybersecurity defense. When firmware is outdated, default credentials remain active, undocumented devices appear on the network, or updates are continually deferred, a routine maintenance backlog can become a security exposure.
The Threat Behind a Routine Maintenance Task
The conversation opens with a scenario involving a routine HVAC filter change. A technician finds an unapproved device behind an air-handling-unit panel, quietly connected to the building network and collecting data. The issue is not airflow or a failed mechanical component. It is an unknown, unmanaged network-connected device with no clear owner, installation record, or security review.
- Connected building devices can be installed outside the original design.
- Unapproved sensors, controllers, and other equipment may communicate externally without visibility from IT or facilities.
- Devices that are not maintained can become weak points because their firmware, credentials, and configurations are never reviewed.
- Unknown devices create blind spots, and blind spots create opportunities for attackers.
The central lesson is that a maintenance walkthrough can reveal security risks that conventional IT reviews may miss. Facilities personnel are often physically closest to the systems that create these risks, while IT teams are responsible for protecting the network those systems use. Both perspectives are necessary.
Deferred Firmware Updates Can Create Real Exposure
The episode describes a rooftop RTU controller running firmware that was already three years old. The maintenance team knew an update was needed, but postponed it to avoid disruption during a tenant event. Later, the controller began sending traffic to an unfamiliar IP address and was found to have been compromised for weeks.
Another example involved a building-management-system firmware update that was delayed because the team did not want to take the system down during business hours. A few weeks later, that system was used as a pivot point to access the tenant network. Neither situation was described as catastrophic, but both required avoidable remediation and demonstrated how an unpatched building system can affect far more than the equipment it controls.
- Postponing updates may feel safer in the short term because it avoids immediate downtime.
- Unpatched controllers can become entry points into larger building or tenant environments.
- Scheduled maintenance windows create a controlled opportunity to perform updates with less disruption.
- Configuration reviews and anomaly checks should be part of the same maintenance process.
Default Passwords and Missing Documentation Are Long-Term Liabilities
Many connected building systems are installed by contractors who later leave the project, company, or market. When no documentation or formal handoff exists, property teams may not know which credentials are active, whether default passwords were changed, or who retains remote access.
The episode highlights an access-control environment that had not been updated because of the cost of a software license and the concern about downtime. The building later discovered that an old contractor still had active credentials and could remotely open doors. The resulting liability, remediation, notifications, legal involvement, and system replacement cost substantially more than the proactive update would have cost.
Documentation is therefore not administrative overhead. It is part of the security posture of the building. Owners need accurate records of connected devices, responsible parties, firmware versions, credentials, configurations, and support relationships.
The Hidden Attack Surface in Smart Buildings
Building technology is no longer limited to a few isolated control panels. HVAC, lighting, elevators, access control, fire alarms, vending machines, and other systems may all be IP addressable. Every connected system can be a potential entry point when it is unknown, unpatched, poorly configured, or separated from IT oversight.
- Track every network-connected building system.
- Maintain firmware-version visibility.
- Identify systems that IT does not know are present.
- Review devices installed by vendors and contractors.
- Investigate unfamiliar traffic and unexpected external communications.
Security cannot protect assets that no one knows exist. A current inventory is the foundation for both preventive maintenance and cybersecurity.
Changing the Maintenance Mindset
Building owners may view maintenance as a cost center, particularly when an update or repair requires downtime, a license fee, or a vendor visit. The episode argues for a broader operational view. The question is not only what happens if the HVAC, doors, lighting, or controls fail. It is also what happens to tenant trust, business continuity, reputation, and liability when those systems become unreliable or insecure.
Deferred maintenance can produce expensive operational failures, such as postponing a relatively small repair and later replacing a major chiller. The security consequences may be even more difficult to quantify because they can include exposure of tenant networks, remote access to physical spaces, notifications, legal costs, and reputational damage.
Practical Actions for Building Owners and Operators
- Treat every maintenance activity as an opportunity for a security review, not merely a mechanical inspection.
- Audit connected systems to identify hidden entry points and undocumented devices.
- Establish a process requiring new devices to be approved, documented, and maintained.
- Review firmware status, credentials, configurations, and unexpected system behavior during maintenance windows.
- Build regular collaboration between facilities and IT instead of allowing the teams to operate in silos.
- Present maintenance investments in terms of avoided operational, cybersecurity, tenant-trust, and liability costs.
The best operating day is the one nobody notices. That quiet outcome depends on intentional maintenance, clear ownership, documented systems, and coordination between the people who operate the building and the people who secure its technology.
Preventive Maintenance Is More Than an Operations Task
In a connected commercial building, preventive maintenance is often discussed in terms of uptime. Change filters. Inspect equipment. Repair worn components. Update systems before they fail. Those activities matter, but they now serve another purpose as well: they help protect the building from cybersecurity risk.
Today’s building environments include far more than traditional mechanical systems. HVAC controllers, lighting controls, access control panels, elevator systems, fire alarms, building-management platforms, sensors, and even vending machines may be connected to a network. That connectivity can improve visibility and operational efficiency, but it also means a building can have many more potential entry points than owners realize.
The question is no longer whether maintenance supports cybersecurity. The question is whether the maintenance program is actively identifying and reducing cyber risk, or allowing that risk to accumulate unnoticed.
Unknown Devices Create Security Blind Spots
Consider what can happen during a routine HVAC service visit. A technician opens an air-handling-unit panel and finds a small device connected to the building network. It was not part of the original design, no one can explain who installed it, and no one knows when it began communicating. The device may have been collecting or transmitting data for months.
That is not simply an equipment-management issue. It is an unmanaged asset on the network.
Connected devices often enter commercial properties through normal operational activity. A contractor installs a sensor. A vendor adds a controller. A system integrator makes a change to support a building project. Each change may appear minor in isolation. But when those changes occur without approval, documentation, inventory management, or coordination with IT, the building develops blind spots.
Attackers benefit from blind spots. A device that is unknown to IT is unlikely to be included in patching, monitoring, access reviews, or incident-response planning. A device that is unknown to facilities may remain physically installed and operational long after its purpose has been forgotten.
A strong maintenance program helps close this gap because maintenance personnel are regularly present where connected systems live. Their work can reveal devices, cabling, controllers, and changes that may not appear in a traditional IT asset list.
Deferred Firmware Updates Are Not Harmless Delays
It is easy to understand why teams postpone firmware updates. An update may require a maintenance window. It may affect tenant activity. It may create concern that a controller, building-management system, or access-control platform will experience disruption during business hours. Those are legitimate operational considerations.
But delay has a cost.
One example discussed in the episode involved a rooftop RTU controller running firmware that was three years old. The team knew the firmware was outdated but continued to postpone the update because of an upcoming tenant event. Later, the controller began sending traffic to an unfamiliar IP address and was found to have been compromised for weeks. The incident was described as a proof of concept rather than a catastrophic breach, but remediation still took months.
Another example involved a building-management-system update that was deferred to avoid downtime. A few weeks later, that system was used as a pivot point to access the tenant network. The event was embarrassing and avoidable, and it demonstrated a key reality: the security impact of a building-system weakness may extend beyond the building system itself.
An unpatched controller can be more than a backlog item. It can be a path into other connected environments. When owners and operators assess whether to delay an update, they should weigh not only the immediate operational disruption but also the risk of leaving a known weakness in place.
Default Credentials Turn Convenience Into Liability
Default passwords remain a practical problem in connected building environments. Contractors may install systems using simple credentials, then leave without a complete handoff. Over time, the original contractor may be gone, the password documentation may be missing, and no one may know who still has access.
This becomes especially serious when the system controls access to physical spaces. In the episode, an access-control system had not been updated because the organization did not want to pay for a software license or experience downtime. It was later discovered that an old contractor still had active credentials and could open doors remotely.
The resulting response involved more than an update. It included a major liability issue, remediation work, notifications, legal involvement, and replacement of the system. The final cost was described as far greater than the proactive work would have been.
The lesson is straightforward: credentials are part of maintenance. Reviewing access, changing default passwords, removing former contractor access, and maintaining system documentation should be routine elements of managing connected building technology.
Maintenance Windows Should Include Security Reviews
Preventive maintenance is often framed as a way to prevent equipment breakdowns. In a smart building, it should also be framed as a recurring security-control window.
During scheduled maintenance, teams have an opportunity to do more than inspect filters, components, and performance. They can verify that the system is running expected firmware, review its configuration, check whether its communications are normal, identify unknown devices, and confirm that access remains appropriate.
This does not mean facilities personnel must become cybersecurity specialists. It means the maintenance process should include clear escalation and collaboration paths. If a technician encounters an unfamiliar device, an undocumented controller, a suspicious network connection, or a system with outdated credentials, there should be a documented process for involving IT and determining the next step.
The objective is not to turn every maintenance task into a disruptive project. The objective is to ensure maintenance does not ignore risks that are visible only when someone is physically working on the equipment.
Facilities and IT Need a Shared Process
One of the most important recommendations from the discussion is collaboration. Facilities and IT teams cannot operate as separate silos when building systems are network-connected.
Facilities teams understand the equipment, operating requirements, maintenance timing, vendor relationships, and tenant-impact considerations. IT teams understand the network, security controls, asset visibility, access management, and risk associated with connected devices. Neither group has the complete picture alone.
A workable process should ensure that every new network-connected device is approved, documented, and maintained. That includes identifying the device, recording its purpose, noting its location and vendor relationship, tracking its firmware and support status, and ensuring IT knows it exists on the network.
It should also establish a practical communication path for changes. A maintenance team should not add a sensor or controller to the network without IT awareness. Likewise, IT should not make security decisions that affect critical building operations without involving facilities.
Maintenance Protects Tenant Trust and Business Continuity
When a building system fails, tenants notice. They experience uncomfortable spaces, flickering lights, doors that do not work, and interruptions to normal business activity. When a connected system is compromised, the impact can include those same operational disruptions along with cybersecurity, liability, and reputational consequences.
Owners should therefore consider preventive maintenance as an investment in more than equipment life. It protects tenant confidence and helps support continuity of operations. It reduces the chance that a small known issue grows into a major mechanical expense, and it reduces the chance that an unmanaged or unpatched system becomes a security problem.
The most visible costs of deferred maintenance may be the equipment repair or replacement. The less visible costs can be greater: exposed networks, unauthorized physical access, remediation, notifications, legal concerns, lost confidence, and uncomfortable questions from current or prospective tenants.
A Practical Starting Point
Building owners and operators can begin by treating maintenance as a security control. Audit all connected building systems and identify what is actually on the network. Review firmware versions, document devices and vendors, assess credentials, and establish a process for managing new systems before they are connected.
Then create regular coordination between facilities and IT. The goal is not unnecessary complexity. It is shared visibility and a reliable routine for catching risks before they become operational failures or security incidents.
Preventive maintenance is about staying ahead of the problem rather than reacting after it has become expensive, disruptive, or public. For commercial properties, that approach helps create the best possible operating day: one in which systems work as intended, tenants remain confident, and no one has to notice the technology at all.
Listen to this episode of Built, Wired & Secured for a focused discussion on how maintenance routines can help protect connected building environments.