7 ways to boost cyber resilience in the smart building industry

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Henning Sandfort, Chief Executive Officer, Building Products, Smart Infrastructure, Siemens AG & Alina Matyukhina, Cybersecurity Manager, Smart Infrastructure, Siemens AG


  • Smart buildings are an important tool in bringing down energy consumption.
  • The technology smart buildings use is vulnerable to cybercrime, so the sector needs to improve its cybersecurity.
  • This involves getting processes in place to ensure that cybersecurity is a priority throughout the lifecycle of all the products used in smart buildings.

In order to deal with problems such as increased population and climate change, we will need smart infrastructure that operates efficiently and saves energy. In the European Union, for example, 40% of energy consumption is attributable to existing buildings. Smart buildings offer one way to bring consumption levels down, but in order to do this the sector needs to improve its cybersecurity.

A smart building uses automated processes to control operations such as heating, ventilation, air conditioning, lighting and security. Many smart buildings rely on Internet of Things (IoT) technology, which means they have sensors to collect data and software to manage it in order to minimize energy use and environmental impact.The demand for this building type will increase significantly in the coming years. According to recent studies, the global smart building market is forecasted to grow to $127.09 billion by 2027, with a compound annual growth rate of 12.5%.

The sector must address the security challenges presented by smart buildings. Studies have shown that 57% of IoT devices are vulnerable to medium or high-severity attacks. Cyberattacks have already harmed several businesses, including critical infrastructure such as hospitals, data centers, and hotels.

To protect against cybercrime, smart building companies should follow the following 7 principles.

Infographic showing the 7 principles of cybersecurity
There are seven ways in which companies can make sure their products contribute to smart buildings’ cybersecurity Image: Siemens

1) Governance

Companies need adequate security know-how. They need to be clear about roles and responsibilities in this area, and to develop a clear set of security messages about how incidents should be dealt with. Each team should ensure that its product, solution, or service has adequate built-in cybersecurity. Companies need to support customers in maintaining cybersecurity over the entire lifecycle of the product or building.

2) Secure supply chain

Companies should require partners throughout the supply chain to meet reasonable levels of security before establishing business agreements. They should integrate their security requirements into their terms and conditions and assess suppliers to find potential protection leaks. They also need a process to identify and manage the security risks of all externally sourced components. This can be done using an automated tool to monitor and track vulnerabilities.

An infographic showing that 'cybersecurity is everyone's responsibility'
Cyber security can only be achieved if building operators, system integrators, planners and owners all play their part Image: Siemens

3) Cybersecurity in product development

Companies should include cybersecurity in the initial design of products. This process could start with defining a cybersecurity target for each product based on market needs. It is more cost-effective to address security early in the lifecycle of a product, than it is to fix problems later on.

Security experts should perform threat and risk assessments throughout the lifecycle of the product, in order to identify and mitigate potential risks. This should start early in the product development process and should be repeated for every significant update. Before releasing a new product, companies should ask independent third-party organizations to test it for potential vulnerabilities.

4) Internal and external cybersecurity awareness

People are at the heart of a successful and effective cybersecurity strategy. Investing in continuous training and awareness will help safeguard organizations against cyberattacks. Employees who are involved in security-related processes should be adequately trained, and there should be clear guidance about who to contact with internal questions or problems.

Companies in the smart building sector also need to share information and work together to keep each other updated of new threats as well as best practices.

5) Vulnerability and incident handling

Any suspected incident should be treated as real until proven to be a false alarm. Every company needs a guide setting out how security incidents should be resolved in a timely manner. They must ensure that they’ve done everything possible to mitigate the risk of a breach.

It is vital that companies are transparent about incidents, informing customers and other required stakeholders when they find vulnerabilities. In the event of a problem, corporate communications are as important as fixing the technical defect, because cyberattacks may damage a business’ reputation and erode the customer’s trust.

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

6) Risk-based asset management

The development environment of the product is one of the most critical assets of a company and needs to be protected. It is important to ensure that the product has not been altered or disclosed in any way during the development process. For example, a developer may unintentionally download a malicious program which could lead to an infection being distributed as part of a product. It is vital to perform the asset classification as well as protection and to repeat it on a regular basis. Critical assets should be identified and classified, and protection measures defined for each asset.

7) Compliance with cybersecurity standards

Owners need to comply with latest cybersecurity regulations and make cybersecurity a part of tender specifications. There are three key cybersecurity standards for the smart building industry: two international (IEC 62443, ISO 27001) and one EU-level (European NIS Directive). Building operators benefit from the precise definition of requirements, the implementation of standardized processes and from the availability of documentation related to each respective standard. Nevertheless, no supplier can create IT security alone: building operators, system integrators, planners and owners are a crucial part of it.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNOCHA/Adedeji Ademigbuji Children displaced by the recent violence in Jonglei State, South Sudan, sit outside a church, home to thousands of displaced people.

World News in Brief: Millions displaced in South Sudan, global meat supply quadruples, Middle East crisis deepens global hunger

This article is published in association with United Nations. Months of fighting and insecurity have forced hundreds of thousands of people to flee their homes in South Sudan’s eastern Jonglei State, triggering “one of the most severe conflict-related displacement emergencies in recent years”, the UN refugee agency (UNHCR) said on Friday.  Tweet URL Fighting between the […]
© WFP/Marco Frattini Aid is distributed to displaced families in northern Lebanon.

Lebanon crisis: Needs soar as UN launches new funding appeal

This article is published in association with United Nations. The UN in Lebanon appealed for an additional $331.5 million on Friday to help 1.4 million people in crisis as already massive needs continue to grow, three months since deadly violence erupted between Hezbollah fighters and Israeli forces. “Humanitarian needs are soaring with each day of the […]
© UNICEF/Amer Almohibany Destroyed buildings in Harasta, Ghouta. A suburb of Damascus, Ghouta was the site of a deadly chemical weapons attack in August 2013.

Undeclared chemical weapons found in Syria, including type used in notorious Ghouta massacre

This article is published in association with United Nations. Chemical weapons inspectors have uncovered a significant cache of previously undeclared chemical weapons in Syria – including rockets of the same type used in the notorious 2013 Ghouta attack – in what the UN’s top disarmament official called a “momentous discovery” for international security. Izumi Nakamitsu briefed […]
© UNICEF Vanessa Frazier, Special Representative on Children and Armed Conflict, during a visit to frontline areas in Ukraine.

Growing up with sirens: UN child rights envoy on the toll of the Ukraine-Russia war

This article is published in association with United Nations. Children in Ukraine have been profoundly impacted by years of war, sheltering in underground schools – or forced to study online – and living with the psychological strain of constant air raid sirens that could spell death for them and their families. But children on both sides […]
OCHA/Charlotte Cans The El Niño-induced drought in Ziway Dugda, Oromia region of Ethiopia, is affecting every family and they don't have enough food at home to feed themselves. (file photo).

El Niño confirmed, set to fuel more extreme weather, says WMO

This article is published in association with United Nations. The UN urged all countries on Tuesday to bolster early warning systems after confirming the onset of El Niño, warning that the Pacific Ocean-warming phenomenon will bring above-average temperatures “nearly everywhere” and fuel more extreme weather. According to the World Meteorological Organization (WMO), there is an 80 […]
© UNICEF The aftermath of a Russian strike on a residential area in Kyiv, Ukraine’s capital.

UN deplores another wave of Russian attacks across Ukraine

This article is published in association with United Nations. Overnight attacks in three key cities in Ukraine have left several civilians dead, scores more injured, and homes, hospitals and shops destroyed or damaged, the UN Humanitarian Coordinator in the country said on Tuesday.  Matthias Schmale condemned the large-scale Russian assault on the capital Kyiv, as well as Dnipro and Kharkiv, […]
© WHO/Joël Lumbala A shipment of essential medical supplies for the Ebola response arrives at Bunia airport in Ituri province, DR Congo.

DR Congo Ebola outbreak: Nurses discharged after full recovery

This article is published in association with United Nations. Four nurses who fell ill with Ebola in the eastern Democratic Republic of the Congo (DRC) have been discharged from hospital after recovering from the often-fatal illness that sparked an international health alert.  “More recoveries are expected, especially when people are diagnosed early and able to access care, and […]
This article is published in association with United Nations.

Under fire, Kharkiv is already building for a peaceful tomorrow

This article is published in association with United Nations. Every day in Kharkiv begins with uncertainty: air raid sirens interrupt sleep; missiles strike residential neighbourhoods, industrial sites, and roads. Anxious citizens rush into metro stations during bombardments and children study underground. Yet amid the destruction, Ukraine’s second-largest city is doing something that may seem almost impossible […]
© UNOCHA A heavily damaged apartment building in Sloviansk, eastern Ukraine.

UN warns Ukraine war risks spiralling ‘out of control’

This article is published in association with United Nations. The United Nations on Thursday warned of a dangerous escalation in the war in Ukraine after a wave of large-scale Russian strikes and threats of further attacks, with Secretary-General António Guterres saying “the death spiral must stop.” Addressing the Security Council in New York, Mr. Guterres said […]
© WHO A frontline health worker in PPE (personal protective equipment) takes part in the Ebola response in eastern Democratic Republic of the Congo.

Ebola outbreak in DR Congo collides with conflict and hunger, WHO warns

This article is published in association with United Nations. The UN World Health Organization (WHO) on Wednesday warned that eastern Democratic Republic of the Congo faces a “catastrophic collision of disease and conflict” as a fast-spreading Ebola outbreak outpaces containment efforts in a region already battered by armed violence, mass displacement and acute hunger. WHO Director-General […]
© WFP/Michael Castofas WFP staff and responders handle boxes of supplies at a logistics site in DR Congo during the Ebola outbreak.

International airlines urged to stick to safety measures in wake of Ebola outbreak

This article is published in association with United Nations. As a deadly Ebola strain continues to spread in the Democratic Republic of the Congo (DRC), with cases confirmed in neighbouring Uganda, the UN aviation agency is urging governments and flight operators to closely follow guidelines put in place following the COVID-19 pandemic. The outbreak of the […]
© WHO Supplies to bolster the response against the Ebola outbreak in Ituri province arrive in the town of Bunia.

Ebola epidemic spreading rapidly and outpacing containment efforts

This article is published in association with United Nations. There are more than 900 suspected cases of the Bundibugyo strain of Ebola in the Democratic Republic of the Congo, and 220 suspected deaths, the head of the World Health Organization (WHO), Tedros Ghebreyesus, said on Monday. The latest outbreak of the deadly disease, which WHO has declared […]
This article is published in association with United Nations.

WHO chief calls for urgent Ebola action and pandemic preparedness

This article is published in association with United Nations. The recent Ebola and hantavirus outbreaks demonstrate that the world is still vulnerable to rapidly spreading infectious diseases, Tedros Ghebreyesus, the head of the World Health Organization (WHO), warned on Saturday at the close of the 79th World Health Assembly in Geneva. His call came as Ugandan […]
This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com