A hotel door lock is no longer just a physical maintenance job. Neither is an office tower’s lift system, its HVAC grid, or its central climate control.
As building management systems link hardware directly to the internet, developers, asset managers, and hotel operators face a global attack surface covering an estimated 1.2 billion connected IoT devices across commercial properties worldwide.
Crucially, 44% of these devices lack basic security protections, whilst 75% of active building management units operate with known, unpatched flaws. According to recent commercial property research, a single 12-month monitoring period saw cyber incidents disrupt operations in more than 3,200 office properties and affect over 11,000 smart commercial buildings globally.
Systemic Vulnerabilities in Real Estate Hardware
The vulnerability of modern commercial real estate stems from structural flaws in building management infrastructure:
- Known Exploited Flaws: Cyber-physical security firm Claroty analysed nearly 500,000 building management devices across more than 500 organisations globally, finding that 75% of organisations operate building management systems with active, known vulnerabilities cataloged in CISA’s Known Exploited Vulnerabilities database. Furthermore, 51% of these systems are insecurely connected to the public internet.
- High Targeted Rates: Global telemetry from Kaspersky’s Industrial Control Systems CERT reveals that building automation remains among the most heavily targeted operational technology sectors worldwide, with 23.5% of smart building control systems encountering blocked cyber threats within a 12-month monitoring period.
- Hospitality Penetration: In the hospitality sector, unpatched software is linked to roughly 33% of all cyber incidents, with legacy property management platforms and in-room IoT devices cited as the primary entry points.
Financial Exposure and Asset Paralysis
When operational technology breaks down, physical disruption translates directly into lost earnings, immediate cleanup expenses, and contractual liabilities.
In the U.S., a high-profile attack on MGM Resorts International saw cybercriminals use social engineering to reset employee login details, gaining administrator access to enterprise networks. Threat actors deployed ransomware that shut down digital room keys, lift systems, parking gates, and gaming floors across its Las Vegas properties. MGM elected to take its internal networks offline to contain the attack rather than pay a ransom. The decision resulted in an estimated $100 million negative impact on Adjusted Property EBITDAR alongside tens of millions in direct remediation costs.
Six months later, Omni Hotels & Resorts suffered a cyberattack that forced a nationwide shutdown of its reservation systems, electronic door locks, and point-of-sale terminals. Threat actors exfiltrated personal details from more than 3.5 million guest records.
Beyond single-brand property outages, downtime creates immediate financial exposure through tenant contracts. When an office tower or hotel is forced to close for even 24 hours, lease reimbursement clauses and operational penalties hit property revenue directly.
How the Industry Has Responded
The scale of recent losses has forced a shift from passive containment to structural architectural changes across major real estate portfolios and equipment manufacturers:
- Zero Trust Adoption: Following its breach, MGM invested an estimated $40 million to $50 million to replace implicit network trust with a strict Zero Trust Architecture, ensuring that single-point credential compromises cannot escalate across corporate identity networks.
- Embedded Vendor Protections: Building automation supplier Johnson Controls embedded security directly into its OpenBlue platform through acquisitions (such as Tempered Networks for Airwall micro-segmentation) and threat-detection partnerships with Nozomi Networks and DigiCert.
- Government and Regulatory Directives: Joint guidance issued by CISA, the FBI, and the UK’s National Cyber Security Centre (NCSC-UK) mandates that building management systems adopt Zero Trust principles to prevent threat actors from using building hardware as lateral entry points into tenant networks.
What This Means for the Industry
The rapid expansion of connected real estate directly broadens operational risk. As the global smart building market accelerates past $170 billion, spending on dedicated cyber security is growing at 12.5% annually to reach $9.0 billion. For property owners, this commercial growth means cyber defense is no longer a technical detail—it is a basic condition of running modern buildings.
Operationally, the sector faces a clear visibility gap. Industry surveys show that 90% of property management teams cannot answer three basic questions: What connected assets exist in the building, how are they connected, and who has access to them?. At the same time, reliance on third-party system integrators using shared credentials across multiple properties creates unmonitored supply chain exposure.
Regulators worldwide are actively enforcing accountability across borders. Under Article 21 of Europe’s NIS2 Directive, global operators managing essential commercial assets or digital infrastructure within the EU face strict legal duties for supply chain risk. Concurrently, international property contracts increasingly mandate compliance with IEC 62443, the global benchmark for operational technology security.
Smart building security has evolved into a core operational duty alongside structural engineering and fire safety. As connected property deployments expand, forward-thinking operators are replacing implicit network trust with strict Zero Trust frameworks – directing capital towards cyber-physical defence to safeguard asset valuations and ensure long-term resilience.
