Security keypad with illuminated buttons mounted on a wall for controlled access entry.

How to Keep Elevators, HVAC, and Access Controls Secure When Vendors Have Network Access

July 28, 2026

The technician who serviced your elevator control system six months ago may still have active credentials on your network — and neither of you knows it. Vendor network access security real estate operators tend to overlook isn't a theoretical problem. It's a gap that exists right now in most commercial properties, and it's entirely fixable.

Your Building Systems Are on Your Network — Whether You Planned It That Way or Not

Modern building systems — elevators, HVAC controllers, access card readers, and IP-based security cameras — are not isolated devices. They communicate over the same network infrastructure your business runs on, and most property managers approved that connectivity at installation and have not reviewed it since.

What Does "Connected" Actually Mean for a Building System?

A BACnet-enabled HVAC controller — a device that uses the BACnet protocol to send temperature and equipment data over an IP network — needs to reach the vendor's monitoring platform. An IP-based Otis elevator diagnostic system requires remote access for routine firmware updates and fault analysis. Both are legitimate requirements. Both create persistent network connections that persist long after the technician leaves the building.

Building automation system cybersecurity starts with knowing which systems are connected. For most New Jersey commercial properties, that list is longer than the property manager realizes.

Why Vendor Access to These Systems Is a Cybersecurity Blind Spot

The risk is not the vendor company itself — it's the uncontrolled, persistent, and undocumented access credentials that remain active after a job is complete. Three specific failure modes account for most of the exposure in commercial properties.

  • Shared or never-rotated credentials: A vendor creates one login for all their technicians. When a technician leaves that company, the credential stays active — and no one on either side thinks to revoke it.
  • Open VPN tunnels or remote desktop sessions: VPN tunnels — encrypted pathways into your network — and remote desktop sessions are often configured for a service call and left running indefinitely because disabling them requires deliberate action no one scheduled.
  • Unmanaged vendor laptops: A technician plugs a personal or company laptop into your building network to run diagnostics. That laptop is not subject to your endpoint security policies — no antivirus standard, no patch management requirement, no visibility into what else it may be running.

The 2013 Target breach is the best-documented public example of this failure pattern. Attackers used credentials stolen from Target's HVAC vendor to enter the network, then pivoted to payment systems. Third-party vendor IT risk real estate operators face follows the same structural logic.

The Hidden Risk of Flat Networks in Multi-Tenant and Multi-Site Properties

A flat network is one where every connected device — from the HVAC controller to the accounting workstation — can potentially communicate with every other device. For a commercial real estate portfolio, a flat network means a single vendor credential can reach far more than the system it was issued for.

Network segmentation: The practice of dividing a network into isolated zones — called VLANs — so that a device or credential in one zone cannot reach systems in another without explicit permission.

Why Multi-Site Portfolios Multiply the Risk

Consider a New Jersey operator managing five suburban office buildings on a shared network. A vendor servicing the access control system at one building holds credentials that, on a flat network, could reach accounting software or tenant data at every site. OT IT network segmentation — separating operational technology like building controls from information technology like financial systems — eliminates that lateral path.

Most small real estate firms have never had this conversation with their IT provider. Break-fix support does not surface it. It requires someone who is looking for the problem.

What a Proper Vendor Access Policy Actually Looks Like

A vendor access policy governs who can connect to your building systems, under what conditions, and for how long. Four specific controls make up a functional policy for a commercial real estate operation.

  1. Vendor access inventory: A written list of every third party holding credentials or remote access to any building system. This document does not exist at most properties — building it is the first step.
  2. Time-limited or just-in-time access: Rather than standing credentials, access is provisioned for a defined service window and expires automatically. This applies to elevator companies like Schindler or Kone and building automation vendors like Johnson Controls or Honeywell — all of whom have standard remote access requirements a good IT policy can accommodate without blocking legitimate service.
  3. Formal vendor offboarding checklist: A documented process that revokes credentials when a vendor contract ends or when a named technician leaves that company. Without a checklist, revocation depends on someone remembering to do it.
  4. Network activity logging: All vendor sessions are recorded and reviewable. Logging does not prevent an incident — it ensures one can be detected and investigated.

How CNS Data Approaches This Problem for New Jersey Real Estate Firms

CNS Data's process starts on-site, at each building — not with a remote scan or a questionnaire. Every vendor who has deployed technology in the building is identified, every device on the network is catalogued, and access is formally scoped and documented before any other security work begins.

What the On-Site Review Actually Looks Like

A CNS Data technician walks the building, pulls up the network switch, and identifies every device currently connected — including building automation controllers, camera systems, and remote access endpoints that most property managers have never seen on a list. That device inventory is then cross-referenced against vendor relationships to produce a vendor access map the property manager likely does not have in writing.

This is the starting point for IT support for real estate companies in New Jersey — not an upsell. The standard break-fix model treats building system vendors as trusted by default and never formally reviews what they can reach. CNS Data's on-site OT review is what distinguishes managed IT services real estate operators actually need from generic remote support.

The Cost of Getting This Wrong: Financial Fraud and Infrastructure Disruption

Vendor access vulnerabilities connect directly to two categories of loss: financial fraud and physical infrastructure disruption. Both are concrete, not theoretical, for a commercial real estate operation.

How the Compromise Chain Works

  • Access control system compromise: A hijacked credential for an access control system — the network-connected door lock and reader platform — can unlock server rooms or tenant spaces without a physical key.
  • HVAC controller hijacking: A manipulated HVAC controller in a server room or data-center-adjacent space can cause sustained heat damage to equipment before staff notice anything wrong.
  • Network pivot to financial systems: An attacker who enters through a building system on a flat network can move laterally to property management financials and redirect wire transfers — a documented fraud pattern targeting real estate firms.

Steps You Can Take Before You Call an IT Provider

Three discovery steps will clarify your current exposure and make any conversation with a managed IT provider faster and more productive. None of them require technical knowledge to initiate.

  1. Request a written vendor access statement: Contact each building system vendor and ask them to provide, in writing, every remote access method and credential they currently hold for your properties. Their response — or inability to answer — is itself useful information.
  2. Check for an IoT or guest VLAN: A VLAN is a virtual network segment on your existing router or firewall. Ask your current IT contact whether your equipment supports a separate VLAN for building systems. Many small firms already own hardware that supports this but have never configured it.
  3. Review your vendor contracts for a revocation clause: Pull the service agreements for your elevator, HVAC, and access control vendors and confirm that each one includes a requirement to revoke credentials upon contract termination. If the clause is absent, flag it for your next contract renewal.

Frequently Asked Questions

Can a hacker really get into my business network through an elevator or HVAC system?

Yes. The 2013 Target breach began with credentials stolen from an HVAC vendor. Elevator HVAC access control network security matters because these systems sit on the same network as business applications. On a flat network, an attacker who reaches a building controller can move laterally to financial systems, file servers, or tenant data.

How do I know which vendors currently have remote access to my building systems?

Most property managers don't have a complete list. Start by contacting each building system vendor directly and requesting a written statement of every access method and credential they hold. A managed IT provider can supplement this by scanning your network and identifying active remote connections you may not know exist.

What is network segmentation and does my commercial property actually need it?

Network segmentation divides a single network into isolated zones using VLANs so that a credential in one zone cannot reach systems in another. Any commercial property where building automation controllers share a network with accounting software or tenant data needs segmentation — which describes most multi-tenant and multi-site properties in New Jersey.

How do I revoke vendor access without interrupting elevator or HVAC maintenance contracts?

Revoking standing credentials does not end a vendor's ability to service your systems — it replaces always-on access with time-limited or just-in-time access provisioned for specific service windows. Vendors like Schindler, Kone, Johnson Controls, and Honeywell all operate under these constraints at larger properties. A managed IT provider can configure this without disrupting active maintenance agreements.

Not Sure Who Has Access to Your Building Systems Right Now? Let's Find Out.

In a free consultation, CNS Data will walk through your current vendor access setup, identify the gaps most real estate operators don't know they have, and outline exactly what a secure, manageable framework would look like for your properties.

Schedule Your Free Consultation