The building your tenants work or live in is now a network. The HVAC that keeps their spaces cool, the access control system on their front door, the BMS dashboard your facilities team checks from their phone, all of it is connected. And most of it was designed before cybersecurity was part of the picture.

For decades, building systems and IT systems lived in separate worlds. HVAC ran on proprietary protocols. Access control systems were air-gapped. The most sophisticated attack a building management system faced was someone manually turning a thermostat. That separation is gone. The drive toward smart building efficiency — predictive maintenance, remote monitoring, energy optimization, and tenant experience platforms — has connected operational technology (OT) to enterprise IT networks, and in many cases, directly to the public internet.

The result is a threat surface that most CRE operators have not yet fully mapped, managed by vendors who were never hired to think about cybersecurity, running on protocols that were never designed to resist attack. And attackers have noticed.

The Central Risk
"Building systems that were once isolated — HVAC controllers, access control servers, elevator management systems — are now connected to enterprise IT networks, cloud platforms, and in some cases the public internet. This connectivity creates operational value, but it also exposes these systems to the full spectrum of cyber threats that previously only IT departments had to manage."

Section 1: Why Multifamily & Commercial Real Estate Is Now a Priority Target

Ransomware operators choose targets based on one calculation: the cost of downtime relative to the cost of recovery. By that logic, commercial real estate is close to an ideal target.

A building that loses HVAC control cannot maintain safe operating temperatures for tenants or server rooms. A building with locked access control cannot let tenants in. A property management firm that loses access to its systems cannot process lease payments, coordinate maintenance, or communicate with thousands of tenants. The operational disruption from a successful attack is immediate, visible, and expensive, which is exactly what makes the ransom demand credible.

Building automation systems are now the third most common ransomware target, behind traditional IT and healthcare (enhanced.io, April 2026). That ranking reflects an operational reality that attackers have identified before most CRE operators have: buildings are now attack surfaces, and they are significantly less defended than the IT networks attackers have spent years learning to penetrate.

The smart building market reached $126.6 billion in 2024 and continues to expand: 87% of industry leaders say they plan to continue investing in smart building technology (Help Net Security, 2025). More than 1.2 billion connected IoT devices are now installed in commercial properties worldwide, and approximately 44% lack strong security protections (CRE Insight Journal, February 2026). Each new device added to a building network in the name of operational efficiency is a potential entry point.

What makes CRE specifically attractive, rather than other OT-heavy sectors, is the combination of financial exposure, operational criticality, and historically low security investment:

  • Large, regular wire transfers (lease payments, acquisition financing, construction draws) create BEC fraud opportunity at scale
  • Tenant data: Social Security numbers, background checks, financial records, etc. create breach notification liability across multiple state laws
  • Operational dependence on building systems (HVAC, access, elevators, fire safety) creates leverage for ransomware operators
  • Multiple third-party vendors with remote access to building systems create a supply chain attack surface that is rarely monitored
  • Historically underfunded IT and security functions compared to sectors of equivalent financial scale

Section 2: The OT/IT Convergence Problem: Where Attacks Actually Enter

Understanding where building cybersecurity risk lives requires understanding how modern buildings are structured technically and where the design assumptions that governed decades of building technology no longer hold.

Building Management Systems: The Nerve Center

A Building Management System (BMS), also called a Building Automation System (BAS), is the central platform that controls and monitors a building's mechanical, electrical, and environmental systems. HVAC, lighting, elevators, fire suppression, energy monitoring, and increasingly access control all flow through the BMS. In a modern commercial building, the BMS is not a single device; it is a network of controllers, sensors, and gateways that communicate using protocols like BACnet, Modbus, and LonWorks.

Those protocols were designed for reliability in closed, isolated networks. They were not designed for internet connectivity, and they do not have native encryption or authentication. When a BMS is connected to enterprise IT networks for remote monitoring, energy reporting, or integration with cloud-based tenant platforms, those legacy protocols are exposed to an environment they were never built to operate in.

Claroty's Team82 unit analyzed nearly 500,000 BMS devices across more than 500 organizations and found that 75% have BMS affected by Known Exploited Vulnerabilities (KEVs), not theoretical vulnerabilities, but weaknesses already actively exploited in the wild and documented by CISA. Of those affected organizations, 51% have BMS with KEVs that are also linked to ransomware campaigns and are insecurely connected to the internet.

The Shodan Problem
Shodan, the search engine that indexes internet-connected devices, consistently finds thousands of building automation controllers using manufacturer default passwords. An attacker can identify a specific BMS model, search Shodan for internet-exposed instances of that model, log in with the default credentials, and be inside a building's control systems in minutes. This is not a sophisticated attack. It is a script and a search query.

From a Temperature Sensor to the Corporate Network

The network architecture of most residential and commercial buildings creates a direct path from building OT systems to corporate IT networks that security teams rarely model in their threat assessments. An unpatched IoT temperature sensor typically communicates with a floor-level controller, which connects to the BMS gateway, which connects to the enterprise network for remote access and reporting. From a compromised temperature sensor to a BMS controller is often a single network hop with no security controls, no segmentation, and no monitoring between them.

This is the pivot path that makes smart building vulnerabilities so operationally dangerous. An attacker who gains a foothold through a building system is not necessarily contained to building systems. If the BMS is on the same network as the property management platform, the corporate email server, and the finance team's systems, the initial foothold can become a full network compromise.

Third-Party Vendor Access: The Overlooked Entry Point

Modern commercial buildings rely on multiple specialized vendors, such as HVAC contractors, elevator maintenance firms, access control providers, energy management consultants, and property technology platforms. Each vendor typically has remote access to the specific systems they maintain. That access is almost never governed with the same rigor as internal network access: credentials are often shared, sessions are rarely monitored, and access rights are infrequently reviewed when vendor contracts end.

Supply chain cyber risk is now one of the fastest-growing threats in smart real estate (COR Advisors, February 2026). When a single vendor's system is compromised, every building that vendor has remote access to becomes a potential target. For a national CRE portfolio with dozens of properties and hundreds of vendor relationships, the exposure is systemic.

OT + IT Attack Surface in CRE & MF Why This Matters Operationally
BMS / BAS with legacy protocols (BACnet, Modbus, LonWorks) No native encryption means traffic can be intercepted; commands can be injected if systems are reachable
Default credentials on IoT controllers and sensors Shodan exposes internet-connected instances; default credentials make access trivial, no credential cracking required
Flat network architecture connecting OT to IT A compromised building controller becomes a lateral movement entry point into the corporate network
Unmanaged third-party vendor remote access Each vendor is a potential entry point; compromised vendor = access to every building they service
Tenant portals and property management platforms Tenant PII, lease data, and banking information — breach triggers state notification laws and FTC Safeguards Rule obligations
IP cameras and physical security systems Often on the same network as BMS; known to carry vulnerabilities; can provide surveillance intelligence to attackers during reconnaissance

Section 3: Wire Fraud and Business Email Compromise: The Financial Attack Surface

The OT/IT attack surface in smart buildings is the emerging threat. Business email compromise targeting real estate transactions is the established one, and it is already costing the sector hundreds of millions of dollars annually.

The FBI's 2025 Internet Crime Report logged more than $20.8 billion in total cybercrime losses, with over $275 million of those specifically from real estate wire fraud. Real estate is the number one industry targeted by BEC wire fraud, according to Securafy's 2026 CRE security analysis, a distinction that reflects the sector's defining characteristic: large, regular wire transfers between multiple parties on a known, predictable schedule.

A commercial lease payment, an acquisition closing, a construction draw, a security deposit — these are the transactions that CRE operates on. They are also the transactions that BEC attackers target. The average real estate BEC incident results in losses of $150,000 to $200,000 (Stewart Title, April 2025). The American Land Title Association reports that nearly 30% of title companies experienced an attempted BEC attack in the last year.

How BEC Works in CRE Transactions

A BEC attack on a commercial real estate transaction typically follows a predictable sequence that exploits the complexity and volume of parties involved in a deal:

1
Reconnaissance. Attackers monitor email communications of a party to the transaction, the broker, the title company, the property manager, or the law firm. They identify the transaction timeline, the parties involved, the expected wire amount, and the payment schedule. This monitoring phase can last weeks.
2
Account compromise or spoofing. Either through phishing or domain spoofing, the attacker inserts themselves into the communication chain, appearing as a trusted party.
3
Updated wire instructions. At the critical moment (typically just before a scheduled wire transfer), the attacker sends updated wiring instructions directing payment to an account they control. The instructions come from what appears to be the title company, the attorney, or the seller.
4
Misdirected transfer. The recipient, under time pressure and believing the instructions are legitimate, completes the wire. Recovery once funds have moved through multiple accounts is rare; the FBI's financial fraud team recovers approximately 79 cents on the dollar on BEC cases reported within 72 hours, and far less after that.
The 2026 Wire Fraud Signal
Despite growing awareness, the attempt rate has not decreased. BEC targeting real estate has become industrialized: attackers have systematized the reconnaissance and impersonation workflow to the point where it operates at scale across thousands of simultaneous target transactions.
Is your portfolio on the verified list?

See which IT Managed Services firms are verified for CRE cybersecurity

TechRadiant's Best IT Managed Services report features verified firms with documented expertise in OT/IT security, building system monitoring, and wire fraud prevention — evaluated specifically for commercial real estate and multifamily portfolios.

Section 4: What the Most Secure CRE and Multifamily Portfolios Are Doing Differently

The CRE and MF firms making measurable progress on cybersecurity in 2026 share a common starting point: they have stopped treating cybersecurity as an IT function and started treating it as an asset management function. The risk calculus is identical to any other portfolio risk: probability of event multiplied by magnitude of consequence, and the consequence of a significant cyber event in commercial real estate now includes operational disruption, regulatory liability, reputational damage, tenant defection, and in some cases litigation from tenants or investors.

The specific practices that distinguish the more secure CRE organizations from the more exposed ones:

1. OT/IT Network Segmentation

Separating building automation networks from corporate IT networks eliminates the lateral movement path that makes building system compromises so dangerous. A BMS that can communicate with HVAC controllers but cannot reach the corporate email server or the property management platform cannot be used as a pivot point into the broader network. Segmentation requires investment in firewall architecture and typically a network redesign project, but it is the single most effective structural defense against the OT-to-IT compromise pathway.

2. Asset Inventory Before Security Controls

You cannot secure what you have not identified. The most common finding in CRE cybersecurity assessments is that organizations do not have a complete inventory of their connected building systems; they know their HVAC vendor and their access control platform, but they do not know every device model, every firmware version, every network connection, or every third-party remote access credential that exists across their portfolio. A complete OT asset inventory, covering every BMS controller, HVAC gateway, IoT sensor, and vendor access path, is the prerequisite for meaningful security improvement.

3. Third-Party Vendor Access Governance

Vendor access to building systems should be governed with the same rigor as employee access to internal systems: just-in-time access provisioning, session monitoring, credential rotation on contract termination, and regular access reviews. Most CRE portfolios have dozens of vendors with standing remote access credentials that were provisioned when a contract was signed and never reviewed since. Closing this gap requires a vendor access governance program and typically tooling that enables session-level monitoring.

4. Wire Transfer Verification Protocols

BEC targeting wire transfers can be interrupted at the process level regardless of how sophisticated the spoofing attempt is. The protection: verbal confirmation of wire instructions via a phone number independently obtained (not from the same email thread) before any transfer above a defined threshold. This single procedural control prevents the vast majority of successful BEC wire fraud attempts. Leading CRE firms supplement this with email authentication standards (DMARC, DKIM, SPF) on all company domains, making domain spoofing significantly harder for attackers to execute convincingly.

5. 24/7 Monitoring That Covers Both IT and OT

Most CRE organizations that have security monitoring have IT security monitoring: coverage of corporate endpoints, email, and cloud applications. Few have monitoring that extends to building automation systems, IoT devices, and the OT network. The gap means that an attacker who enters through a building system can operate for weeks or months before detection, because the alerts that would surface the intrusion are not being generated. Extending monitoring to OT environments requires either specialized tooling or a managed security provider with genuine OT expertise, a capability that most general-purpose MSSPs do not have.

The Specialist Argument
General cybersecurity firms understand enterprise network threats. They do not necessarily understand BACnet, BMS controller firmware, the physical-cyber relationship in building access systems, or the specific regulatory exposure created by tenant PII in a CRE context. The most security-mature CRE portfolios are increasingly working with vertical specialists — firms that understand both the OT side of building systems and the IT side of property management platforms, rather than generalized security firms who apply a standard framework to an environment they do not fully understand.

Section 5: What a CRE Cybersecurity Audit Should Cover

A cybersecurity audit for a commercial real estate portfolio differs structurally from a standard enterprise security assessment because it must account for both the IT environment and the OT environment, as well as the relationships between them. The following framework covers the minimum scope of a credible CRE security assessment:

OT Environment Assessment

  • Complete inventory of all BMS, BAS, HVAC, access control, elevator, and life safety system devices across the portfolio including make, model, firmware version, and network connectivity
  • Network segmentation analysis: mapping the actual network architecture to identify where OT systems share network infrastructure with IT systems
  • Credential audit: identifying all default credentials, shared credentials, and accounts associated with former vendors or employees
  • Internet exposure scan: identifying BMS and IoT devices exposed to the public internet, including via remote access tools
  • Protocol analysis: identifying which BACnet, Modbus, or other legacy protocol traffic is traversing network boundaries it should not

IT Environment Assessment

  • Email authentication review (DMARC, DKIM, SPF configuration for all company domains)
  • MFA enforcement audit: which systems and accounts are protected by multi-factor authentication, with particular focus on finance, executive, and property management platform access
  • Endpoint detection coverage: confirming monitoring extends to all devices that connect to company networks
  • Property management platform access review: Yardi, AppFolio, MRI, and similar platforms often hold tenant PII and financial data; access governance should be audited
  • Vendor access review: inventory and assessment of all third-party remote access relationships

Process and Governance Assessment

  • Wire transfer verification protocol: does one exist, is it documented, is it consistently followed?
  • Incident response plan: does a plan exist that covers both IT incidents and building system incidents, with named roles and defined escalation paths?
  • Tenant data inventory: full inventory of what PII is collected, where it is stored, and which state breach notification laws apply
  • Cyber insurance review: coverage adequacy, whether policy requirements (MFA, backup verification, security awareness training) are actually being met
  • Security awareness training: frequency, content relevance to CRE-specific threats (wire fraud, BEC, smart building risks), and measurable completion rates