When it comes to connected buildings, cybersecurity cannot be something that is bolted on after the technology has been selected.

Lighting, heating, ventilation, access control, lifts, CCTV, energy meters and other building systems are increasingly connected to networks and to each other. That connectivity can deliver significant benefits — from improved energy efficiency and better data to smarter building management — but it also creates new security and operational risks.

And increasingly, those risks need to be considered before a purchasing decision is made.

That’s why the IoT Security Foundation has published its new ‘Building technology procurement guide: Procuring building technology securely‘ – a practical resource designed to help organisations make more informed and secure technology purchasing decisions.

Now, on Thursday 24th September 2026, members of the IoTSF Smart Built Environment working group will take part in a special webinar exploring the new guide and what it means for organisations procuring connected building technology.

Why does procurement matter?

A building technology decision isn’t necessarily a short-term decision.

The systems selected today can remain in buildings for many years, meaning that decisions made during procurement can have a long-term impact on cybersecurity, resilience, operational efficiency, compliance and cost.

Yet cybersecurity requirements can sometimes enter the conversation too late — after a technology has already been specified, suppliers have been shortlisted or a purchasing decision has effectively been made.

The new IoTSF guide takes a different approach.

It encourages organisations to make security part of the procurement process from the outset, bringing together the right people and establishing appropriate security requirements before suppliers are selected.

What will the webinar cover?

The webinar will provide an opportunity to explore the thinking behind the new guide and, importantly, how organisations can put its recommendations into practice.

Among the areas we’ll explore are:

Bringing the right people into the room

One of the guide’s key recommendations is the creation of a Procurement Project Steering Group (PPSG) for individual building technology procurements.

The idea is straightforward: Procurement decisions shouldn’t be made in isolation.

The PPSG brings together relevant expertise from areas including procurement, cybersecurity, IT and networking, facilities and property, sustainability, physical security, legal and compliance, finance and risk.

The webinar will explore why this cross-functional approach matters – and how organisations can make it work in practice.

Six principles for secure procurement

The guide sets out six core principles:

– Plan early, plan together
– Buy secure by design
– Demand evidence, not promises
– Protect the whole lifecycle
– Treat data integrity as critical
– Keep stakeholders informed

We’ll look at what these principles mean in the context of real-world building technology procurement.

Asking suppliers the right questions

It’s one thing to say that security is important. It’s another to establish whether a supplier can actually demonstrate that its technology is appropriately secure.

The guide provides practical questions that procurement teams can use when engaging with suppliers, including areas such as vulnerability disclosure, security assurance, software updates, remote access and Software Bills of Materials (SBoMs).

The webinar will look at how these considerations can become part of the procurement process rather than an afterthought.

Taking a lifecycle approach

Buying the technology is only one stage of its life.

The guide covers the wider procurement lifecycle — from pre-planning and sourcing through installation, operation and maintenance, right through to eventual decommissioning.

That means considering what happens after the purchase order has been signed, including how security requirements will be maintained throughout the technology’s operational life.

Matching security requirements to risk

Not every connected building system presents the same level of risk.

The guide uses the IoTSF Assurance Framework to help organisations establish proportionate security requirements and identify an appropriate Assurance Class for the technology being procured.

That provides a structured way to think about security requirements for everything from lower-impact sensors to systems such as HVAC, lifts, lighting control, access control and CCTV.

And what about AI?

AI is increasingly finding its way into building technology — from predictive maintenance and energy optimisation to occupancy analytics, CCTV and access control.

The guide therefore also addresses AI procurement, with questions covering areas including AI risk classification, training data, human oversight, explainability, model updates, data flows and AI incident response.

As AI becomes an increasingly important part of the smart built environment, these considerations are likely to become an increasingly important part of procurement too.

Who should attend?

This webinar isn’t just for cybersecurity specialists.

It will be particularly relevant to anyone involved in buying, specifying, approving, deploying or managing connected building technology, including:

– Procurement professionals
– Facilities and property managers
– Building owners and operators
– IT and cybersecurity teams
– Physical security professionals
– Sustainability teams
– Risk, legal and compliance professionals
– Technology and systems integrators
– Architects, consultants and specifiers
– Suppliers of connected building technology

If you have a role in deciding what technology goes into a building – or the requirements that technology has to meet — this webinar is for you.

A practical guide for a practical problem

The new Building Technology Procurement Guide is designed to make secure procurement more achievable, not more complicated.

It provides practical principles, questions and tools that organisations can use to bring security into purchasing decisions at the point where it can have the greatest impact.

The webinar on Thursday is an opportunity to hear directly from the people involved in developing the guide, understand the thinking behind it and explore how its recommendations can be applied to real-world procurement.

Join us on Thursday 24th September for this special IoTSF Smart Built Environment webinar. Click HERE to register.

Don’t just buy connected building technology. Make sure you’re buying it securely.