In 2017, attackers hacked into a North American casino. But they did not target its servers directly. Instead, they gained access through an internet-connected fish tank.
The tank had sensors that remotely monitored and controlled water temperature and feeding. Because the device sat on the casino’s network without being properly secured or isolated, it became a back door into wider systems and the data held there.
The weakness was not the casino’s core security defences, but an unsecured device nobody was watching. It’s just one example of how the increasing digitalisation of building operations around the world risks making businesses more vulnerable to cyber attacks.
Building operations across the world increasingly run on networked systems. Access control, energy management, lifts and maintenance systems are all digitally connected, and any one of them can become a route in.
Businesses are facing increasing cyber risk
Cyber risk has moved from the margins of corporate concerns to the top of the agenda. In the Bank of England’s Systemic Risk Survey, some 77% of respondents now name cyber attacks among the most challenging risks to manage as a firm, up from less than 10% in 2014. The rise has tracked geopolitical risk over the past decade.
Risk of cyber attack has risen alongside geopolitical risk
Bank of England Systemic Risk Survey, Most Challenging Risks to Manage as a Firm (UK)

Source: Savills Research using Bank of England
And the costs can be severe. The financial impact of a cyber attack can now extend well beyond remediation costs and business interruption. Regulatory penalties add another layer of exposure. For example, in the UK, serious personal data failures can attract fines of up to £17.5 million, or 4% of global turnover. In the EU, essential entities such as healthcare and transport organisations can face fines of up to €10 million – or 2% of global annual turnover – for failing to meet cybersecurity and resilience obligations. Regulators in the US have also imposed multi-million-dollar fines following cyber incidents.
As buildings become more connected, they now form part of the ‘digital attack surface’ – any part of an organisation’s networks, hardware or software that a hacker could exploit. More than one in four (27%) respondents to the 2025 RICS Facilities Management survey said their building had been the victim of a cyber attack in the previous 12 months, up from 16% a year earlier.
“Smart buildings radically expand the cyber risk surface because anything connected to a building’s systems can affect the confidentiality, integrity and availability of the asset,” says Tim Spencer, Head of Property Management Technology and Data EMEA, Savills. “This includes BMS (building management system) and plant-room data to access control, HVAC, apps or even ‘unknown’ IP-connected devices, such as smart fridges or speakers.”
AI is giving attackers new ways to exploit this widening exposure, amplifying the vulnerabilities already created by connected property systems. AI accelerates code development and scaling operations, while making attacks harder to detect – though it can also be a tool for improving cyber defences.
Claude Mythos – a frontier model with cyber capabilities so powerful that its creator Anthropic has restricted access to vetted defensive partners – underlines how quickly capabilities are developing. It’s no surprise that the Allianz Risk Barometer survey now ranks AI as the second most important business risk after cyber incidents.
AI has risen rapidly as a business risk, now second to cyber incidents
The most important business risks in 2026 (global)

Source: Savills Research using Allianz Commercial
Managing cyber threats in property
PropTech and smart-building systems bring clear operational benefits, from energy management and predictive maintenance to tenant experience. But each connected device, platform and third-party interface also creates another potential point of vulnerability. Four priorities stand out when managing cyber risk: understanding what is connected, clarifying who is accountable, strengthening access controls, and building resilience into operations and contracts.
“The first step is understanding the unknown: what sits within the portfolio, what’s in the technology stack and where unseen vulnerabilities may exist,” says Ivo Krastins, Digital Advisory and Design Lead, Savills Property Management. “Anything unmanaged can become a cyber threat. Just as important is staff training. People need an understanding of the systems they use, because they remain a critical line of defence.” As in the fish tank incident, connected buildings can become a back door to wider business systems. This risks compromising data, exposing businesses to ransomware or locking them out of systems altogether when attackers shut down lifts, HVAC or lighting controls.
“Accountability for building technology is often spread across owners, managing agents, facilities teams, integrators and specialist vendors, so no single party has full visibility of the estate,” says Russell Perkin, Service Delivery Manager, Savills. “Add to that legacy systems never designed with modern security controls, but now connected to wider networks, and you have equipment that sits outside the patching, monitoring and decommissioning cycles.”
The next step is strengthening access controls: multifactor authentication, clear rules on who can access which systems and with what rights, and prompt removal of those rights when roles change, or contracts end. Building systems should also be segregated from corporate IT networks, so that a breach on one side cannot cascade unchecked into the other.
Vendor verification matters, too. Building owners and occupiers need assurance that third parties are patching software, encrypting sensitive data and applying the same standards across their own supply chains, with service-level agreements setting out exactly what access is granted and to whom.
Where controls fail, cyber insurance can limit the financial impact of an incident, but it will not cover every loss – regulatory fines and gross negligence among them – and is no substitute for robust protections.
Responsibility extends beyond the organisation itself. “Cybersecurity cannot stop at the building boundary,” says Andrew Williams, Head of Security and Resilience, Savills. “Owners need to understand who in the supply chain has access, what information they hold and whether service-level agreements give third parties routes into critical building systems or sensitive data.”
A new test for building resilience
Cyber resilience is now a key building asset management issue. It is increasingly shaping acquisition, fit-out and operation, alongside broader governance, resilience and ESG-related risk management.
In practice, this means maintaining a documented inventory of a building’s controllers, sensors, software and cloud services; monitoring that generates building-system alerts when necessary; and tested backup and recovery procedures so essential services can be restored quickly.
“Cybersecurity is no longer just an IT issue: it is becoming a real estate criterion. The exponential rise in cyberattacks is creating a new expectation among occupiers, one that will fundamentally reshape the design, operation, and management of office buildings, says Péroline Prevost-Manseau, Head of Agency and Workthere, Savills France. “ Buildings will need to demonstrate their ability to secure connected devices, networks, and data, just as they are currently expected to guarantee energy efficiency and occupant comfort.”
Increasingly, building owners are writing cyber security requirements into design specifications and supplier contracts at the outset, rather than retrofitting them once a problem emerges. It only takes one weak link for a breach to occur – and it might be sitting in a fish tank.