The property industry risks “sleepwalking” into cyberattacks if it doesn’t take immediate action to strengthen security protocols, the RICS has warned.
A survey of facilities managers, service providers and FM consultancies undertaken by RICS found 27% of respondents said their building had been the victim of a cyber attack in the last 12 months. This represents a significant increase on the previous year, when 16% of respondents had experienced such an attack.
In addition, 73% of more than 8,000 business leaders believe a cybersecurity incident will disrupt their business in the next 12 to 24 months.
In a new practice information paper, RICS has set out a series of critical action points for owners, users and managers of buildings, as well as government and industry bodies, to mitigate risk and safeguard against the threat of rapidly evolving technologies.
The paper identifies operational technology such as building management systems, CCTV networks, Internet of Things (IoT) devices and access control systems as risk areas.
It also notes concerns that some buildings use outdated operating systems (OS). A building opened as recently as 2013 could conceivably use Windows 7; an OS that hasn’t received security updates from Microsoft in more than five years.
The paper sets out three five-point action plans for owners, managers and occupiers of buildings, professional industry bodies and governments to follow to mitigate risks and safeguard their properties against attacks.
Paul Bagust, head of property practice at RICS, said: “Buildings are no longer just bricks and mortar, they have evolved into smart, interconnected digital environments embracing increasingly sophisticated and ever-evolving technologies to enhance occupier experience. This has led to increasing data being collected and used to inform decision making; at the property manager, building user, occupier and owner levels. However, while these technologies bring many benefits, from efficiency gains and reduced negative impacts on the planet, they also create multiple risks and vulnerabilities which can be exploited by those looking to cause disruption.
“It is inconceivable to imagine a world where technology will not continue to pose a growing risk to a building’s operation, and it is equally impossible to consider that the management of digital risks will not be needed as an imperative measure to safeguard the future of a building and prevent systems from being compromised. I implore building professionals to read the paper and act now. Failure to identify these growing digital challenges and incorporate security countermeasures risks businesses sleepwalking into cyberattacks.”


