Cybersecurity resilience is a health and safety issue

By

Louise Shea

Share this:

As technology develops rapidly and new innovations emerge, our cities are becoming increasingly interconnected and digital – from transport infrastructure to building ecosystems. And the market for smart cities is surging globally, projected to grow to a $3.75tn market by 2030. Our increasingly digital-first approach means that buildings – offices, homes and public spaces like hospitals and schools – now rely on OT and IoT technologies as much as bricks and cement. Smart technology is deeply embedded into critical and non-critical systems: emergency lights, security cameras, fire alarms and even smart hospital beds. Despite this, we’re still navigating how to reinforce our systems and arm ourselves against digital security vulnerabilities.

Cybersecurity is often considered a bolt-on post construction or design, but the process and mindset need to change to mitigate both health and safety risks and financial losses. We’ve seen some progress at a local level, but nationally we need considered strategic frameworks to embed cyber resilient infrastructure into the heart of construction.

Protecting smart infrastructure

Integrating cyber informed engineering (CIE) into the protection of smart infrastructure transforms the approach to project design by embedding cybersecurity from the outset. This proactive strategy leverages CIE to conduct thorough cyber risk assessments, develop robust security architectures, and implement comprehensive compliance training. By prioritising cybersecurity in the initial engineering phase, CIE ensures a safer, more cohesive, and resilient infrastructure that effectively mitigates cyber threats across IT, IoT and OT.

The persistent and escalating threat of cyberattacks carries severe financial and legal repercussions, with the UK experiencing £30bn in cybercrime related losses in 2023, a figure projected to rise by approximately 15% annually. Embedding cybersecurity, guided by CIE during the planning phase of smart infrastructure, is far more cost effective than addressing it as an afterthought. Retrofits and add-on solutions can increase mechanical, engineering and plumbing (MEP) budgets by 10-15%, whereas proactive CIE integration streamlines security and optimises costs.

Moreover, vulnerabilities in cybersecurity systems pose significant health and safety risks in the built environment. In smart buildings, critical systems such as fire alarms and lighting are often interconnected with broader networks. A cyberattack disrupting these systems during an emergency could translate a digital threat into a physical danger, putting the safety of building occupants at risk. By leveraging CIE to prioritise robust cybersecurity from the design stage, these risks can be mitigated, ensuring safer and more resilient infrastructure.

The pillars of CIE

We can break down CIE and design into three core pillars – 1) Assessing cyber risks, 2) Designing with security in mind and 3) Ensuring regulatory compliance.

Cyber risk assessments can enable developers to identify and address potential threats early across a project. Assessing the risks in advance means that requisite security considerations can be integrated from the outset, improving ROI and pre-empting vulnerabilities in networks and data.

Designing security system architecture requires enhancing the overall safety of buildings whilst maintaining the aesthetic appeal and design integrity. Improving networks and data security does not have to result in impenetrable buildings that look like concrete blocks: physical and digital security no longer come at the expense of aesthetics.

London’s Telehouse TN2 building reflects this approach: a complex design, the TN2 building has a unique exterior, reflecting an electronic circuit board, while blending in seamlessly with the commercial surroundings of Canary Wharf. But it’s also resilient – its perimeters are protected by alarmed fences, gated entrances, a security management system with card access, and CCTV, all powered by its own on-campus 132kV grid substation. Integrating connective cybersecurity with physical security is the next critical planning step for secure buildings, and the design stage is where architects can and should contribute.

The third pillar, compliance, ensures alignment with regulations, although local and national directives often lack the rigour required for cybersecurity resilience.

Local authorities leading the way

Beyond this, government intervention, frameworks and support systems are critical to encourage cyber-secure features. Where we’re seeing a lack of urgency and pace on a national level, local governments and councils are stepping in, establishing cybersecurity as a fundamental pillar of future urban development. Some of the UK’s biggest cities are integrating cybersecurity considerations in early planning stages, across London’s boroughs and further north.

Both Manchester and Bristol have mandated cyber risk assessments for smart building projects, whilst the Greater Manchester Combined Authority published a Cyber Strategy for 2023-2028, which recognised the role of security in ‘Cyber Places.’ The framework outlined necessary requirements for critical systems (transport and health) throughout the design phase and recognised the potential threat of cyber attacks early on.

In 2023, the Greater London Authority (GLA) updated its Smart London Plan, encouraging specific boroughs to follow suit and increase support around smart infrastructure. The London Borough of Hackney in particular, integrated extra layers of security, in the wake of a 2020 ransomware attack, costing the council £12m. Now, Hackney encourages new developments to incorporate high standards to secure BMS and IoT from initial design phases.

As smart city and building growth accelerates, national frameworks stand to learn a lot from the standards local governments are setting.

The future of cyber resilience in the built environment

The rapid expansion of smart cities, places and buildings is intensifying, accompanied by a growing need for robust security measures. Local authorities are beginning to realise the value of proactively embedding cybersecurity within the built environment, rather than reacting to cyber incidents on a case-by-case basis: a reactive approach that falls dangerously short of addressing the scale of the challenge.

National frameworks must adopt similarly high standards and integrate cybersecurity resilience supporting local councils and the private sector. By establishing CIE into designs for cities, places and buildings beyond Critical National Infrastructure and acting pre-emptively, architects, developers, and city planners will be empowered with the opportunity to rethink and redesign how they plan, engineer and construct infrastructure for an increasingly digital world. This approach will enhance safety, reduce future costs, and build resilience ensuring a secure and sustainable future. What are we waiting for?

REGISTER TODAY

to get our daily newsletter, with all the latest news, views and analysis, delivered straight to your inbox – for FREE!

BE CONNECTED

We offer a wide variety of business-critical content and networking services to suit every budget