Vendor Remote Access to Building Systems: Closing the Door Contractors Left Open
Why HVAC, elevator, access and camera vendors need remote access, how that access gets abused, and a safe pattern for granting it.
Building systems are maintained by specialists who rarely visit. The HVAC integrator logs in from another city to adjust a schedule. The access-control company pushes a firmware update overnight. The camera vendor checks a recorder. All of that remote access is useful, and all of it is risk. Over years, buildings accumulate permanent paths for contractors, many of them undocumented, shared across employees and never closed. This article describes the problem and a safe pattern that keeps vendors productive.
The ways vendors connect
Some vendors install a cellular modem that gives them a private path into the controller network. Some request a port forward on the building firewall. Others use remote-desktop software on an old PC left in the mechanical room, or a cloud service that phones home from the equipment.
Each method bypasses whatever security the rest of the network has. A shared password written on the controller cabinet or kept in the vendor's team chat is the usual finishing touch.
What can go wrong
An attacker who steals a vendor employee's credentials gains entry to every building that vendor serves. A forgotten modem on an old firmware can be reached from the internet. A contractor who has left the vendor's company may still know a shared password.
The consequences range from nuisance to serious: heating schedules changed, doors unlocked, cameras disabled, or ransomware moving from a building controller into the office network.
Take inventory of remote paths
Walk every mechanical room, riser and server cabinet and list every device that can be reached from outside the building. Review firewall rules for forwarded ports. Ask each vendor, in writing, how they connect, which accounts they use, who has access and how access is revoked.
Compare their answers with what you find. Differences between the two are a finding in themselves.
A safer pattern: gateway, accounts and approval
Route vendor access through a single managed remote-access gateway. Each vendor employee receives a named account with multi-factor authentication, and sessions are limited to the systems that vendor supports. Access is requested and approved for a specific window, then expires.
The gateway records who connected, when and to what. If something changes unexpectedly, you can see who was logged in. This replaces a handful of permanent holes with one controlled door.
Put it in the contract
Vendor agreements should require named accounts, multi-factor authentication, prompt notice when an employee with access leaves, compliance with your remote-access procedure and notification of any security incident affecting your systems. Ask about the vendor's own security practices, including patching and staff screening.
When contracts renew, use the opportunity to add these clauses. Vendors that resist are telling you something.
Network separation as the safety net
Even with a good gateway, building systems should live on segments of their own, with firewall rules that allow only the required traffic. A compromised HVAC controller should not be able to reach the property office or the tenant network.
Segmentation limits the damage if something goes wrong and gives you a place to monitor unusual behaviour.
Review and renew
Quarterly, review the list of active vendor accounts, remove those no longer needed and check the logs for unexpected sessions. After a vendor change, rotate any shared credentials immediately.
Keep the register of vendors, accounts and approvals with the rest of your technology documentation. It will be valuable during an insurance renewal, an audit or an incident.
Mistakes we see repeatedly
Three patterns recur. Buildings accept a vendor's cellular modem without asking what it can reach. Shared logins survive staff changes at the vendor because nobody knows to ask. And contracts are renewed without a security clause because the conversation is about price. A short questionnaire at each renewal, covering connection method, named accounts, multi-factor authentication and leaver notification, closes most of the gap and tells you quickly which vendors take the issue seriously.
Checklist
- List every remote path into building systems, including modems and port forwards
- Ask each vendor in writing how they connect and who has access
- Replace permanent paths with a managed, logged gateway
- Use named accounts with multi-factor authentication for every vendor employee
- Grant access by approved time window
- Add remote-access clauses to vendor contracts at renewal
- Place building systems on separate network segments
- Review vendor accounts and logs every quarter
Where this lands by property type
Property Management Companies
A management company sells reliability to owners. Its own systems, from the ledger to the after-hours phone line, are the product, and every outage is seen by clients who pay for calm. Typical exposure: head office and site offices on different standards.
REITs & Asset Managers
REITs and asset managers answer to unit holders, lenders and auditors. Technology risk across the portfolio sits inside that accountability, even when each building is run by someone else. Typical exposure: property managers using different systems with different controls.
Commercial Landlords
Commercial landlords compete on building quality: reliable connectivity, secure access and a smooth fit-out process. Technology gaps show up in vacancy and renewal rates. Typical exposure: tenants asking for connectivity options the building cannot provide.
Services that address this topic
Guidance like this works best inside a coordinated programme, not as a one-off fix. These PropertyIT services cover the topic directly.
Smart Building Networks
A smart building network is the cabling, switching, VLAN design and firewalling that lets mechanical, security and tenant systems share one physical plant while staying logically separate.
S / SystemsMaintenance & Work-Order Systems
Maintenance & Work-Order Systems covers the selection, configuration and integration of tools that receive requests, dispatch technicians and vendors, track assets and feed costs into accounting.
S / SecurePortfolio Cybersecurity
Portfolio Cybersecurity applies a consistent security baseline across head office, site offices, building systems and third-party vendors, with attention to the fraud patterns that target property and finance teams.
Next step: a building technology survey
PropertyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery for property teams. If this article describes a situation in your buildings, book a free 30-minute consultation: call (604) 632-4959 or email [email protected]. We will give you a plain-language view of your options, and a fixed-price scope if you want one. No lock-in, no pressure and no obligation.
Frequently asked questions
Do all vendors need remote access?
No. Some only need it for emergencies. Grant it by request, for a defined window, rather than leaving it open.
What if a vendor refuses to use our gateway?
Escalate. Ask for the technical reason, offer alternatives and consider whether the vendor is the right fit if they will not meet reasonable security conditions.
How do we find hidden modems?
A physical walk-through combined with a network scan and a review of firewall rules usually reveals them.
Can PropertyIT manage vendor access for us?
Yes. We provide remote-access gateways, approval workflows and logs as part of Smart Building Networks and Portfolio Cybersecurity.