Cyberattacks on smart buildings: How to protect your infrastructure.

Buildings often last 50 years or more, whilst their infrastructure has a lifespan of ten to 20 years. Technology becomes obsolete much more quickly: software within one to three years, and security patches are often overdue after just one to three months. This huge discrepancy in lifecycles makes smart systems vulnerable to cyber attacks. Analyses by Maik Paprott, Head of the UMB Cyber Defence Centre, demonstrate that an unpatched firewall granted attackers access to 150 web services within minutes.

  #Cyber Defense  
23.06.2026
Martin Gartmann, CEO, UMB
Martin Gartmann
+41 58 510 12 15
martin.gartmann@umb.ch

In Switzerland, connected systems such as photovoltaic installations and building management systems are booming. Smart buildings promise efficiency and sustainability, but without robust IT security, they become gateways for dangerous cyberattacks. Many technologies from past decades are vulnerable. Pragmatic measures and strategies – from assessments to penetration tests – can close security gaps and build resilience.

Theory vs. Reality: The Discrepancy in Lifecycles

In theory, cybersecurity seems innovative and all-encompassing. In building services engineering, the reality is quite different. According to an analysis by BKW, a leading Swiss infrastructure and energy company, around 90 per cent of Swiss buildings are considered vulnerable to cyberattacks. They are often 50 years old or older; their infrastructure lasts ten to 20 years – yet technology becomes obsolete after just three to five years, software after one to three years, and IT security within as little as one to three months. A timeline illustrates the change: in 1961, building plans were drawn by hand; in 1970, with mechanical assistance; and in 1984, the first PCs were introduced. In the 1990s, mobile phones were introduced and used in the planning process; in 2006, smartphones; and today, smartwatches that control networked systems. Rapid progress renders every innovation obsolete as soon as it is installed – gaps arise between planning and operation. In the worst-case scenario, we are trying to secure technology that dates back to the era of typewriters. 

There are many challenges: a lack of awareness regarding sensors and cameras with default passwords, information overload caused by building automation, a lack of visibility into connections, and inadequate technologies such as network segmentation or monitoring. There is no shortage of direct threats either: malware, web-based attacks, phishing, ransomware, internal threats – ranging from reconnaissance to actions on objectives.

In Switzerland, the Federal Office for Cyber Security (BACS) reported around 63,000 incidents in 2024, a 26 per cent increase compared to 2023, with threatening calls and phishing dominating. There were also almost 36,000 cyber incidents in the first half of 2025. Companies therefore feel insecure, and with good reason: in the 2025 SME Cyber Study, only 52 per cent of SMEs say they feel protected – down from 57 per cent the previous year. 

 

From malfunctions to life-threatening situations

Neglected security leads to disruptions such as malfunctions in heating, ventilation, lighting or security systems. Sensitive data – from access logs to personnel records – is at risk. More seriously, human lives are at stake, for example if cooling systems in hospitals fail or access controls at airports can be tampered with. In the energy sector in particular, which is closely linked to building services, cyber-sabotage poses a threat of blackouts. The ‘Cyber Europe’ exercise in June 2024, involving around 5,000 participants from over 30 countries, simulated an attack on the Swiss energy sector and highlighted vulnerabilities in networked systems. Specific examples: 23 web-based control systems for heating and air conditioning were directly accessible from the internet due to weak firewalls. A similar situation was found with Solar-Log systems: 31 photovoltaic installations tested in Switzerland had open ports that allowed password resets and granted access to automation networks. The aforementioned test by the head of the UMB Cyber Defence Centre – initial access via an unpatched firewall, followed by lateral movement via scanning – compromised the affected system within minutes and potentially exposed 150 web services. Such vulnerabilities turn smart buildings into smart attack vectors. 

 

AI seeks unauthorised access

In Switzerland, with its high car ownership rate – over 75 per cent of households own a car – smart garages or charging stations can become points of entry. Current trends are exacerbating this risk: According to the Microsoft Digital Defense Report, identity-based attacks rose by 32 per cent in the first half of 2025, 97 per cent of which were password sprays, i.e. the mass trialling of common passwords. In the electrical sector, attackers are increasingly using AI-powered phishing emails or deepfakes to deceive maintenance staff. An example from 2024: Ransomware struck a Geneva-based energy supplier, which was paralysed via unsecured building management systems (BMS) – cost: CHF 4.5 million per incident (according to a 2025 Deloitte study). Since April 2025, 164 attacks on critical infrastructure have been reported, leading to system failures or extortion. Energy suppliers were also affected. The EU’s revised NIS-2 obliges operators of critical facilities to carry out risk analyses. In Switzerland, a new cross-sector reporting obligation for cyber attacks on critical infrastructure (CSV) will also come into force, introducing a 24-hour reporting obligation for incidents from April 2025. The EU NIS 2 Directive extends this to supply chains and also affects Swiss companies with EU links by requiring resilience in 18 sectors, including building services engineering.

 

Six steps to resilience

Practical solutions are based on standards such as ISO 27001. These six steps are scalable and prioritise knowledge transfer, supplemented by BACS recommendations such as network segmentation, multi-factor authentication (MFA), updates and incident response plans:

  • Inventory and visibility: Create an inventory of your networked systems, for example using attack surface management platforms or DigitalRisk monitoring services.
  • Network segmentation and separation of IT/OT: Isolate building services using VLANs, firewalls and OT monitoring.
  • Access management: Least privilege principle, MFA, secure VPNs and logging.
  • Regular updates and patch management: Patch control devices and gateways; hold manufacturers accountable.
  • Awareness and responsibilities: Define roles; training reduces human error by up to 70 per cent.
  • Red teaming/penetration testing: Simulate attacks to detect vulnerabilities at an early stage.

Also recommended: Advanced Managed Detection and Response (MDR), logging with external storage, and Network Detection and Response (NDR) for real-time analysis, as well as strict access rights management with regular reviews.
These measures pay for themselves quickly: avoiding downtime saves millions. The Swiss Federal Office of Energy (SFOE) has been promoting building certifications with cybersecurity standards since 2023. In addition, KBOB published the recommendation ‘ICT Security in Building Automation’ in July 2025.

Resilience through culture and pragmatism

Innovative smart buildings without security pose a major risk – they become entry points for cyber attacks. Cybersecurity must be considered from the outset – from the specifications right through to handover. At a BKW building congress in September 2025, ‘Cybersecurity in building services’ was therefore a topic of discussion. Participants concluded that pragmatic solutions, clear responsibilities and an embedded security culture are necessary – ranging from reactive ‘firefighting’ to proactive prevention and forensic analysis. However, technology alone is not enough; resilience safeguards sustainability and operational safety. There is a particular need for action in the electrical sector, where smart grids and e-mobility converge.

An assessment reveals gaps. As part of the BKW Group, which covers energy, networks and services, UMB AG possesses comprehensive security expertise – ranging from CISO Advisory and Cyber Defence Services to Zero-Trust networks.

Switzerland in the cyber crosshairs

  • In 2024, around 63,000 cyber incidents were reported, an increase of 26 per cent (source: BACS Annual Report 2024). Particularly common: threatening phone calls and phishing.
  • A cyber incident costs Swiss companies an average of CHF 4.5 million (source: Deloitte study 2025).
  • The cybersecurity market in Switzerland is set to grow to CHF 1.15 billion by 2030 (source: Statista Market Forecast).
  • Effective measures drastically reduce the time spent on reactive measures – from 10,000 to 1,000 hours per year for prevention.