Hack Proof: Cybersecurity & Smart Buildings
It was January 2017 during a busy tourist season in Austria, and the Romantik Seehotel Jaegerwirt was filled with guests. Ready to ski and sightsee, some travelers had paid more than $500 a night for the alpine lodging. When multiple guests began complaining that their key cards could not unlock their rooms, hotel staff tried in vain to remedy the problem, but they were frozen out of their own computer system. Then the ransom email arrived.
Sent to the hotel's managing director, the note demanded about $1,800-worth of bitcoin if the hotel would like to regain access to their system. The note ended with a friendly, "Have a nice day," news sources reported at the time. If not paid soon, hackers indicated that the ransom amount would be doubled. With the full house of guests to consider, the hotel complied and paid the hackers.
The Austrian hotel incident is one of many that highlights new considerations property managers must take as buildings and their features get smarter and more connected. Anywhere there is automation, there is risk, and with the growing popularity of IoT (Internet of Things) in real estate and smart buildings, property managers need to be prepared for all of the threats that come with the convenience and simplicity.
POINTS OF ATTACK
David Peterson, the director of smart properties at the Maryland-based Blackpoint Cyber and a 25-year commercial real estate veteran, explains that adding automation like climate controls, security systems or timed lights comes with additional potential "attack surfaces."
"These devices typically rely on an IP-based communication system—much like on a PC—and these can be vulnerable to malicious hackers," Peterson says. "It could be a building automation system, an unsecured maintenance portal, a CCTV or a security system, or even an individual laptop, and if there's a weak point, attackers can get in."
Peterson says the most common method hackers use to quickly bring down a network is called "lateral spread," and it's one that you probably have already seen attempted. "It starts with a well-worded email to the right individual, coercing that person to inadvertently give up their credentials or click on a link; if this succeeds, the hacker is now in the network where they will perform reconnaissance to gain access to privileged accounts and high-value targets and eventually spread their malware," Peterson says.
Jim Young, co-founder and CEO of San Diego-based Realcomm Conference Group, says hackers are looking for easy points of access, and every new piece of equipment that comes into a building may be a risk, along with anything attached to a modem.
"There are modems on equipment in the closets of some buildings that nobody even knows about," he says, adding that these devices are fairly simple for a hacker to locate. He says websites like shodan.io, which calls itself "the world’s first search engine for Internet-connected devices," is an easy way for anyone to find the devices that are exposed and vulnerable.
Just like the potential points of attack, the motives of hackers vary wildly. "If it’s a nation-state, they could be looking for disruption or a financial goal," Young says. "It could be disgruntled employees or kids just playing around, saying, 'Let’s turn off the lights.' There are multiple goals, multiple types of people and multiple types of threats." Other possible aims are making the buildings inaccessible, stealing visitor or occupant data or even destroying equipment.
Highlighting the power a hacker can wield, Peterson asks, "If they get into a building with tenants and manipulate the HVAC system, lights or security, what can the staff do?"
Adds Young, "Imagine turning off the heat in Chicago in winter or the air conditioning in L.A. in the summer. Then there’s negative impact on the brand."
To regain control of the building, victims may need to pay a certain amount of money (ransom demands differ) to unlock the system and unencrypt the files. "It could be as easy as cleaning up a desktop or laptop with an anti-virus software, but it may also take a team of experts to unlock. The longer it takes, the more expensive it could be," Peterson says.
Depending on how severe the hack is, it could take days or weeks to gain control and a secure status again, Young says. Both Young and Peterson agree that it all depends on how prepared the building and its managers and owners are.
"You want to disincentivize these nefarious characters," says Peterson.
CYBERSAFE AND SOUND
In this ever-changing tech environment, Peterson encourages property managers to get educated and be prepared. "You have to ask yourself what you would do," he says. "You have to assume a cyberhack is on the horizon."
Questions for property managers to consider include: Does your insurance cover a hack? Who would pay for the damage? What about the damage to your reputation? Whether a smart system is in place or in the plans, these concerns must be addressed.
Rather than trying to navigate cybersecurity alone, Young suggests property managers have the guidance of their organization’s IT experts. "You need to have an IT liaison or partner inside the company to help," he says. Then, with the help of IT (and after making sure that the corporate office does not already have cybersecurity measures in place), property managers can reach out to a cybersecurity expert for a consult.
"There are a lot of impostors in IT, OT and IoT," Young says. "If they don’t have experience with all three, you are going to pay for their learning curve."
Because hackers are looking for easy targets, Peterson says having an expert perform a cyber assessment on your property can be very informative. Without giving any identifying information about his client, Peterson recounted his company’s recent security evaluation of a large North American shopping center. "They wanted us to assess their system, and it was wide open. It literally took our experts 15 minutes to figure it out," he says.
Blackpoint Cyber takes a three-tiered approach in protecting smart buildings through monitoring, detecting and responding to threats, he says. Monitoring involves 24/7 live monitoring of a building’s systems. If something out of the ordinary is detected, Blackpoint determines if it is a nonissue that should be ignored or if it requires action. "If an alert gets escalated to the next level, our team has the ability to make an immediate response, and we will alert your team according to our predetermined action plan that we set up in the onboarding process," Peterson says.
Being educated and safe doesn’t mean you and your building will be completely immune to hackers, "but it will be less likely to happen, and if you're better prepared, it's more likely the building will get back on track," Young says.
REPRINTED FROM THE JOURNAL OF PROPERTY MANAGEMENT, VOL. 84, NO. 4, WITH PERMISSION FROM THE INSTITUTE OF REAL ESTATE MANAGEMENT. FOR MORE INFORMATION ON IREM AND ITS PUBLICATIONS, VISIT WWW.IREM.ORG.
This Week’s Sponsor
Altus Group is a market leader providing software, data solutions and technology-enabled expert services enabling commercial real estate professionals to connect to the market. ARGUS® solutions are the industry standard for creating cash flows and valuations helping thousands of commercial real estate professionals gain transparency into their property assets, manage risk and optimize their portfolios.
For a list of suggested topics and to submit a proposal, visit: Speaking Opps.
Register early and save!
UPCOMING REALCOMM WEBINARS
COMMERCIAL REAL ESTATE & Technology – The Importance of Developing a STRATEGY - 9/19/2019
It wasn’t long ago that a Commercial Real Estate CIO was responsible only for functions such as networking, file and print servers, computer hardware, desktop applications and e-mail. Over the last 5+ years other responsibilities have entered the sphere of the CIO including marketing, operations (smart buildings), occupant experience and cybersecurity, to name a few. Additionally, emerging technologies such as AI, Machine Learning, Blockchain, AR/VR, autonomous, robotics and others are impacting their world as well as their clients. Never before has it been so important for a Real Estate CIO to develop a comprehensive digital strategy, encompassing all aspects of the organization. This webinar will focus on the importance of developing a comprehensive digital strategy.
Founder of Realcomm Conference Group, an education organization that produces Realcomm, IBcon and CoRE Tech, the world's leading conferences on technology, automated business solutions, intelligent buildings and energy efficiency for the commercial and corporate real estate industry. As CEO, Jim interacts with some of the largest companies globally pertaining to some of the most advanced and progressive next generation real estate projects under development.
Ilan Zachar is currently Chief Technology Officer at Carr Properties, a privately held REIT known for its portfolio of trophy-quality properties in the Washington D.C. In this role, Ilan leverages vision and foresight to cross-pollinate best practices, processes, systems and resources across corporate operations/affiliates. Under his leadership, this has resulted in improvements in bottom-line costs, top-line business growth/scalability, operational sustainability and high performance and overall, strengthening his company’s role as a market leader. For over 20 years, Ilan has been executive business leader and innovative technology strategist for multinational real-estate and property development companies worldwide.
Sineesh Keshav is the Chief Technology Officer at Prologis. In this role, he oversees all aspects of the technology strategy and is responsible for leading the company’s global data and digital transformation. Since joining Prologis in 2018, Sineesh and his team have been focused on a capability driven, customer-centric approach to innovation and digitalization.
With over 24 years of experience in real estate, Kevin's expertise encompasses enterprise IT design, integration and ecological adaptation, helping his clients deriving ongoing value by improving their manageability, effectiveness and ongoing efficiencies. Prior to joining RealFoundations, Kevin served as a CIO for a large-NY owner operator and as a SVP of IT for an Ohio based REIT overseeing the strategic planning, enterprise architecture and information architectures.
Mike Salazar has extensive experience in consulting and sales with Enterprise companies, regarding strategic cross function technology, mainly focused on IoT and AI platforms. Named Star on the Rise by Security Industry Association in 2016, he is currently the Practice Director for Smart Buildings at HID Global. Through innovative solutions he helps organizations unlock value and realize business intelligence. Honored to call many of the most notable companies of our time happy customers.
Dharmendra is the Industry Principal at Yardi Systems. Dhar’s well-rounded and practical background in the industry includes experience as a software vendor, consultant and customer. Prior to Yardi Systems, he was the Vice President of Revenue Management and Analytics for Denver-based Apartment Investment and Management Co. (AIMCO), one of the largest multifamily REITs in the U.S., where he led the development and implementation of revenue management and business intelligence systems.
Malcolm Hobbs is VP of Marketing and Market Development at Join. Malcolm has extensive startup and enterprise marketing and business development experience in markets including SaaS, Industrial IoT, Analytics and Sustainability. At Join, he is helping to redefine how owners secure their buildings from digital threats and deliver advanced digital workplace services in today's tech-forward buildings.