A hacked door lock and a hacked database once belonged to two different worlds. In a modern office, school or hospital, they’re often the same incident. Physical and cybersecurity have merged because the systems behind a building’s locks, lifts and cameras now run on the same networks as its email and payroll data.

That merger creates a problem most organisations haven’t caught up with. Facilities teams manage the badge readers and CCTV. IT teams manage the network and the servers. When a smart thermostat or a biometric scanner sits on both sides of that line, no one owns the risk it creates. Attackers know this, and they’ve used it before: in one of the most studied breaches in retail history, criminals reached a major retailer’s payment systems through the login details of its heating and cooling contractor.

This guide sets out why smart buildings raise the stakes for physical and cybersecurity together, what the UK’s Product Security and Telecommunications Infrastructure (PSTI) Act and the EU’s NIS2 Directive mean for organisations in the UK and Ireland, and the four practical pillars of a unified defence strategy for connected sites.

The Convergence Reality: Why Smart Environments Are Inherently Vulnerable

For decades, physical security and cybersecurity ran on separate tracks. A guard checked badges at the door. An IT administrator checked passwords on the network. The two teams rarely spoke, because their equipment didn’t share a wire. The UK’s National Cyber Security Centre now groups this kind of site under the term “Connected Places“, its framework for smart, sensor-driven environments where physical infrastructure and digital networks share the same risk.

Smart buildings removed that separation. Door controllers, lighting systems, lifts, fire panels and HVAC units are now IP-connected devices, often installed by contractors who set a default password once and never returned. Each one is a small computer with access to the same network as finance systems or student records, which means a weakness in a door lock can become a route into a payroll database, and a phishing email can end with someone unlocking a server room from the other side of the world.

The 2013 breach at US retailer Target is still the clearest case study of what this convergence risk looks like in practice. Attackers stole network credentials from Fazio Mechanical, a Pennsylvania HVAC contractor with remote access to Target’s systems for billing and project work. Because that vendor connection wasn’t kept separate from the retailer’s payment network, the attackers moved from a refrigeration contract to point-of-sale terminals across nearly 1,800 stores, taking around 40 million card records and contact details for a further 70 million customers.

Target’s own reported costs ran past $200 million once settlements, legal fees and lost sales were counted. The vulnerability wasn’t the HVAC system itself. It was the assumption that a physical services vendor didn’t need the same scrutiny as a core IT supplier.

Regulatory Drivers in the UK and Ireland: PSTI and NIS2

Two pieces of legislation now shape how organisations in the UK and Ireland are expected to handle physical and cybersecurity for connected equipment, and neither one is optional guidance. One is already enforced. The other is still working its way through Parliament, but its obligations are already reaching organisations through contracts and board-level guidance.

The UK’s Product Security and Telecommunications Infrastructure Act

The PSTI Act 2022, along with its accompanying Regulations, came into force on 29 April 2024 and applies to manufacturers, importers and distributors of consumer connectable products sold in the UK, including smart locks, cameras, sensors and building controllers. Three requirements sit at its core: devices can’t ship with a default or easily guessed password, manufacturers must publish a way for security researchers to report vulnerabilities, and they must tell buyers how long a product will keep receiving security updates. These three requirements echo the international ETSI EN 303 645 standard for consumer IoT security.

Enforcement sits with the Office for Product Safety and Standards, which can issue recall notices, halt notices and fines of up to 4% of a company’s global turnover or £10 million, whichever is greater. For any organisation buying smart building equipment, PSTI compliance is a straightforward, checkable requirement to put in a procurement contract: ask the supplier for its security update commitment before signing, not after the device is on the network.

NIS2 and Where Ireland Stands

The EU’s NIS2 Directive extends cybersecurity risk management duties to a far wider range of sectors than its predecessor, including operators of essential services in energy, healthcare, transport and digital infrastructure, many of which run smart building systems as part of their core operations.

Member states were required to transpose NIS2 into national law by 17 October 2024. Ireland has not yet done so. The intended vehicle, the National Cyber Security Bill, remains before the Oireachtas, and on 8 July 2026 the European Commission referred Ireland, alongside France and Spain, to the Court of Justice of the EU over the delay, with a request for financial penalties to apply until transposition is complete.

That gap doesn’t mean Irish organisations can wait. In July 2026, Ireland’s National Cyber Security Centre published governance guidance stating that cybersecurity risk management sits with the most senior level of management in NIS2-affected entities, regardless of where the domestic legislation stands. Supply chain contracts, cyber insurance policies and parent-company compliance programmes are already passing NIS2 obligations down to Irish sites in practice. Any organisation that manages smart building infrastructure connected to essential services should treat the directive as active now, not as a future date on a legislative calendar.

For a wider view of how these obligations sit alongside general cyber risk, see our guide on why cyber security matters for organisations of every size.

The Four Pillars of Cyber-Physical Defence

Turning regulation into daily practice comes down to four areas of control that apply whether the site is a school, a hospital or a corporate office. Each pillar addresses a different point where a physical device and a digital network meet, and none of them work well in isolation from the others. If any of the terms below are unfamiliar, our key cybersecurity definitions page is a useful reference to keep open alongside this section.

Pillar 1: Identity and Access Management at the Edge

Every door controller, camera and sensor needs its own verified identity on the network, not a shared login passed between contractors. Multi-factor authentication should apply to any remote access a vendor or engineer uses to reach building systems, and default credentials need changing before a device goes live, not after an incident. Access rights should also expire: a contractor who finished a lift maintenance job in March shouldn’t still hold network credentials in September.

Pillar 2: Network Segmentation and OT Isolation

The Target breach happened because a vendor’s network access wasn’t separated from payment systems. The fix is segmentation: building management systems, CCTV and access control should sit on their own network segment, walled off from finance, HR and customer data by firewalls that only allow the specific traffic each system needs. If a smart thermostat is compromised, segmentation is what stops that compromise reaching a server holding personal data.

Pillar 3: Continuous Monitoring and Unified Security Operations

A door forced open at 2am and a login attempt from an unusual location at 2am are the same event if they happen in the same building on the same night, but only if someone is watching both feeds together. Merging physical security alerts and network monitoring into a single operations view, rather than two separate dashboards read by two separate teams, is what turns a coincidence into a caught intrusion.

Pillar 4: Physical Hardening of Digital Assets

Cybersecurity depends on physical security as much as the reverse. Server rooms, network cabinets and building controllers need locked enclosures, tamper alerts and controlled access, because a network is only as secure as the box someone can plug a device into. A firewall configured correctly means little if the switch behind it sits in an unlocked cupboard.

Bridging the Cultural Divide: IT and Facilities Management

Physical and cybersecurity, Bridging the Cultural Divide

Technology alone won’t close the gap between physical and cybersecurity. The bigger obstacle is often two teams with different priorities and no shared language.

Facilities teams are trained to keep systems running without interruption because a fire door that fails to lock is a safety hazard. IT teams are trained to patch quickly because an unpatched server is a breach waiting to happen. Put those instincts in the same room without a shared process, and neither side trusts the other’s judgement about what counts as an acceptable risk.

Industry perspective: Security teams that have merged physical and cyber incident response consistently report the same lesson: the technology integration is the easy part. The harder work is agreeing, in writing, who signs off a change to a building control system, who gets the first alert when a device goes offline unexpectedly, and who has the authority to isolate a compromised system even if that means a door stays locked longer than a facilities manager would like.

Closing that gap takes structure rather than goodwill. A joint risk register that both teams update, shared incident response drills that run at least twice a year, and a single point of accountability, often a Chief Security Officer role that spans both domains, give the two disciplines a shared reference point instead of two competing ones.

Practical Framework: Implementing a Unified Security Strategy

Physical and cybersecurity, Practical Framework

Moving from separate physical and cybersecurity functions to a unified one works best as a staged project rather than a single policy announcement. Three phases cover the ground most organisations need to work through.

Phase 1: The Integrated Risk Assessment

Start with a full inventory of every connected device on site, from door controllers to smart lighting, and map which network segment each one sits on and who has access to it. This assessment should score both the cyber risk (can it be remotely compromised) and the physical consequence (what happens if it is), because a compromised smart lock and a compromised printer carry very different levels of danger, even if both run on the same network.

Phase 2: Technology Procurement and Interoperability

Once the risk picture is clear, procurement policy needs updating so that new building systems are bought with security requirements written into the contract, not added afterwards. That means asking suppliers directly whether their products meet PSTI requirements, how long they’ll receive security updates, and whether the system can integrate with existing monitoring tools rather than requiring a separate proprietary dashboard.

Phase 3: Response Orchestration

The final phase builds the playbook both teams follow when something goes wrong: who’s notified first, what gets isolated automatically, and how physical response (locking down a zone) and digital response (disconnecting a device) happen in a coordinated sequence rather than two separate, uncoordinated reactions. Running this playbook as a drill, not just a document, is what proves whether it actually works under pressure.

The ROI of Convergence: Beyond Risk Mitigation

Reducing risk isn’t the only return on this work. Combined security operations typically cost less to run than two separate teams with duplicate monitoring tools and overlapping vendor contracts, because alerts are triaged once instead of twice and licences aren’t paid for twice over. Insurers are also starting to ask directly about physical and cybersecurity integration when underwriting cover for organisations with smart building infrastructure, which means a documented unified strategy can affect premiums as well as protection.

Our cybersecurity facts and statistics page tracks the wider cost and frequency data behind this shift, for anyone building a business case. For a CFO or board weighing up the cost of this work, the business case rests on fewer incidents, lower operating overheads and better insurance terms, not just a harder target for attackers.

The Ten-Point Smart Building Security Audit

Use this list as a starting point for a facilities and IT walkthrough of any connected site.

  1. List every network-connected device on the premises, including door controllers, cameras, lighting and HVAC.
  2. Confirm no device is still running a factory default password.
  3. Check that building management systems sit on a separate network segment from finance and HR systems.
  4. Confirm multi-factor authentication is required for any remote vendor access.
  5. Review contractor access logs and remove permissions for anyone whose work has finished.
  6. Confirm each supplier’s security update commitment is on file and matches PSTI requirements.
  7. Test whether a physical security alert and a network alert from the same incident reach the same response team.
  8. Check that server rooms and network cabinets are locked and monitored for tampering.
  9. Run a joint IT and facilities incident response drill at least once a year.
  10. Confirm one named person holds accountability for both physical and cybersecurity outcomes.

Conclusion: Where Smart Building Security Is Heading

Physical and cybersecurity will keep converging as more building systems connect to the network, and the organisations that treat them as one discipline, with one risk register and one incident response plan, will be better placed than those still running two separate teams that only compare notes after something has gone wrong. PSTI and NIS2 are pushing that convergence into law, but the stronger reason to act is the same one the Target breach demonstrated over a decade ago: a network is only as secure as its least protected connected device, wherever that device happens to sit.

Frequently Asked Questions

What is the difference between physical security and cybersecurity in a smart building?

Physical security controls who can enter a space and touch equipment, such as locks, guards and cameras. Cybersecurity controls who can access the data and networks that the equipment runs on. In a smart building the two overlap because most physical security devices are now also network devices.

How does the UK PSTI Act affect existing smart building equipment?

The PSTI Act applies to products sold in the UK from 29 April 2024 onwards, so equipment already installed before that date isn’t retroactively covered. Any replacement or new devices bought after that date need to meet the Act’s password, vulnerability reporting and update transparency requirements, which is why procurement policy should be updated even for existing sites.

What are the main components of cyber-physical security?

Most frameworks group cyber-physical security into identity and access management, network segmentation, continuous monitoring, and physical hardening of network equipment. Each addresses a different point where a physical device and a digital network connect.

Can a cyber attack cause physical damage or disruption to a building?

Yes. Attackers who gain control of building management systems can manipulate HVAC, lighting or access control, and compromised systems have been used as a route into unrelated corporate networks, as in the well-documented 2013 Target breach, which began with a compromised HVAC contractor account.

Who should lead an integrated physical and cybersecurity team?

Larger organisations increasingly appoint a single Chief Security Officer role covering both physical and cyber risk, reporting to the board, so that neither discipline is treated as subordinate to the other. Smaller organisations can achieve the same effect with a joint committee that has clear, written decision-making authority.

Does NIS2 apply to private commercial buildings in Ireland?

NIS2 applies by sector and size threshold rather than by building type, so it reaches organisations in essential and important sectors, such as energy, healthcare, transport and digital infrastructure, that operate commercial premises, including their smart building systems. Ireland hasn’t yet transposed the directive into national law, but organisations already subject to contractual or parent-company NIS2 obligations should treat compliance as current rather than pending.