Building Resilience: Integrating Risk Management in Smart Building Installations

As connected building technologies introduce new vulnerabilities, contractors need to adopt rigorous cybersecurity standards, oversight, and comprehensive policies.

Key Highlights

  • Connected building systems introduce cybersecurity vulnerabilities that require proper configuration, regular updates, and staff training to mitigate risks

  • Routine operational activities, such as change orders and labor transfers, can mask fraud; a culture of professional skepticism helps uncover these issues

  • Organizations that combine operational excellence with strong governance and risk management will be better positioned to navigate the complexities of modern, connected MEP environments.

During a routine internal audit, everything appeared to be in order.

Project managers were updating Work-in-Progress (WIP) schedules on time. Job cost reports reconciled to the general ledger. Change orders appeared properly documented. Timecards were approved, vendor invoices matched purchase orders, and service agreements were being billed according to contract terms.

On the surface, the control environment reflected discipline and compliance, exactly what the auditors expected to see. And yet, something did not sit right.

Consider a Realistic Scenario

A MEP contractor installs a high-end smart HVAC system in a commercial office building. The installation includes connected thermostats, wireless sensors, mobile-device access, remote diagnostics, and cloud-based monitoring capabilities. Months later, a cybersecurity incident occurs. A connected HVAC controller had been compromised through an unpatched vulnerability. It wasn’t just a device anymore—it was a doorway for the cyber attackers.

The building owner immediately begins asking questions:

  • Was the device securely configured during installation?
  • Were default passwords changed?
  • Were software updates installed?
  • Was the owner educated about maintaining the security of their network?
  • Did the contractor clearly communicate where its responsibilities ended and the owners’ responsibilities began?
  • Does the maintenance agreement include cybersecurity support, or only mechanical service?

The real question wasn’t just what went wrong—but who was responsible?

The after-action report revealed:

First line risk: Technicians lacked cybersecurity training and bypassed basic safeguards for speed and convenience.

Second line risk: Policies existed but were not operationalized; no enforcement, no monitoring, no accountability.

Third line gap: Process audits were reactive, not proactive; risks were identified only after exposure.

The Modern Risk Landscape is More Complex

These questions are becoming increasingly important because the answer is often unclear. General and Sub-contractors are entering an environment where the lines between contractor, technology provider, integrator, and managed service provider can become blurred.

While a contractor may not own the network, they are activating the smart HVAC system too. They may face claims of responsibility if connected devices were configured improperly, if vendor due diligence was inadequate, or if security expectations were not clearly documented during installation. The risk extends beyond operational disruption and can quickly become a legal, contractual, reputational, and customer-service issue.

Management is not alone and should be seeking help from their internal audit and risk management teams with identifying, mapping, assessing, evaluating and measuring these new risks. They should be asking:

  • Are cybersecurity responsibilities clearly defined in contracts?
  • Have we established standards for configuring connected devices?
  • Do our technicians receive cybersecurity awareness training?
  • Are third-party technology vendors appropriately vetted?
  • Do owners understand their responsibilities for ongoing network security?
  • Does our insurance program adequately address cyber-related exposures associated with connected building technologies?

The companies that address these questions proactively will be better positioned to address these risks with sound policies, training and customer solutions.

Connected Buildings, Smart Devices, and an Emerging Risk Blind Spot

We know connected homes and smart buildings are standard expectations rather than optional features. Today's MEP environments such as HVAC equipment, smart thermostats, building automation systems, indoor air-quality monitors, energy-management platforms, leak detection sensors, water management systems, and remote monitoring solutions increasingly rely on Internet of Things (IoT) connectivity.

In both residential and commercial environments, contractors are no longer simply installing mechanical equipment. They are deploying technologies that connect to home networks, corporate networks, cloud platforms, mobile applications, and third-party monitoring services. They are expanding the footprint of risk for themselves and their customers.

Professional Skepticism: The Most Underrated Control

Within a MEP contracting organization, professional skepticism often begins with simple questions from our example above:

  • What is the risk to a MEP contractor when installing and activating a smart device?
  • Why are connected building technologies being installed without documented cybersecurity requirements?
  • Now that activation is part of a financial control environment, what steps are we taking to ensure data integrity?
  • When are service technicians no longer coming on-site to inspect and repair devices, how are we ensuring the repair was done and we can bill for it?
  • How are software service technicians tracking their time for complete billing?

Taking a step back, MEP contractors should be asking:

  • Why is one project consistently outperforming similar jobs despite comparable challenges?
  • Why are labor transfers occurring at month end?
  • Why does a project manager rarely forecast losses while peers regularly do?
  • Why are change-order volumes increasing while margins remain unchanged?

These are not merely operational questions. They are risk-management questions. And in many cases, they are fraud-risk questions.

When Fraud Risk Enters the Conversation

For MEP contractors, fraud rarely begins with a dramatic theft or a fictitious multimillion-dollar transaction. More often, it emerges through routine operational activities that receive little scrutiny, such as:

  • Labor hours transferred between projects to improve reported job profitability
  • Unsupported or duplicate change-order charges
  • Material purchases billed to one project and consumed on another
  • Manipulated percentage-of-completion estimates
  • Unauthorized vendor master-file changes
  • Service work performed but billed outside company systems

Individually, these activities may seem insignificant. Collectively, they can distort job profitability, conceal project losses, and create material financial reporting and compliance risks. Many of the industry's highest fraud-risk areas stem from change-order management, subcontractor relationships, labor charging, project cost reporting, vendor relationships, and cost-reimbursable contracts.

Let’s reflect on the scenario above with the compromised smart HVAC device. Connected building fraud risks are commonly masked as normal operations. Where a hacker accessing vulnerable MEP devices like a HVAC system, may alter their behavior and reporting, and exploit trust between three parties that could raise questions about revenue integrity, and/or warranty claims. In operational reports and reviews, this might look like:

  • Small recurring billing inaccuracies within maintenance agreements
  • Higher-than-expected warranty claims tied to connected systems
  • Increased service dispatches with no mechanical faults found
  • Owner complaints about unexplained energy costs

Seeing and Asking About What Others Don’t

Returning to the opening story, the organization did not fail because it lacked controls, talented employees, or experienced project managers. It failed because nobody stopped to ask a simple but powerful question:

"Does this actually make sense?"

For MEP contractors, that question can apply to virtually every aspect of the business (job cost adjustments, labor allocations, change orders, vendor relationships, IoT technologies such as Smart HVAC and automation systems).

The organizations that will thrive in the years ahead will not simply be those that install the most sophisticated mechanical systems. They will be the ones that combine operational excellence with strong governance, effective fraud-risk management, cybersecurity awareness, and a culture that empowers employees to challenge assumptions when something does not look right or is considered perfectly normal.

Sign up for our eNewsletters
Get the latest news and updates

Voice Your Opinion!

To join the conversation, and become an exclusive member of Contractor Magazine, create an account today!