A property management company or an HOA runs on more connected equipment than most of its managers could list. Smart locks on unit doors and amenity spaces, cameras at entrances and pools, gate controllers, video intercoms, package lockers, thermostats and HVAC controls, irrigation timers, leak sensors. Each one was installed to solve a problem, usually by a different vendor, at a different time, on whatever internet connection the property had.
Across a portfolio of properties, that adds up to hundreds of devices connected to the internet, many still running default passwords and factory firmware, with no inventory anywhere of what exists, where it is, or who can reach it.
The Numbers Behind the Exposure
The Verizon 2025 Data Breach Investigations Report found that 20% of breaches began with the exploitation of a vulnerable device or system, a 34% increase over the prior year, making unpatched equipment one of the fastest-growing entry points attackers use. Censys, a firm that scans the public internet for exposed systems, identified more than 145,000 industrial control and building automation systems reachable online across 175 countries in 2024, and its 2025 research counted over 43,000 exposed instances of Tridium Niagara alone, a framework widely used to run building automation, access control, and HVAC systems, a figure that grew 9% in just the first half of the year. Many of these devices still accept the default credentials printed in the installation manual; Censys documented building and fuel-site controllers that ship with logins like "Admin/Admin" and remain discoverable through a simple search.
Building equipment is a particularly soft version of the problem. A camera or gate controller gets installed by a low-voltage contractor, connected to the property's router, and forgotten. The manufacturer may publish firmware updates for a few years, but nobody at the property applies them, and the vendor who installed the device has no contract to maintain it. The device keeps working, which is the only measure anyone checks.
What a Compromised Device Actually Exposes
A compromised smart lock or gate controller is a physical security failure: someone who shouldn't have access does. A compromised camera system means a stranger watching the entrances, the pool, the package room, and the parking garage, and incidents of hijacked residential cameras have made news repeatedly. For an association or management company, that's a resident-safety problem and a liability problem at the same time, and the board or firm that installed the equipment owns the question of why it wasn't secured.
Building devices are usually connected to the same network as everything else at the property, and in many portfolios those property networks connect back to the management company, to payment systems, resident records, and accounting. An attacker who compromises a forgotten camera has a foothold on the network behind it. From there, the target stops being the camera and becomes the management company's data: applications with Social Security numbers, bank details for dues and rent payments, owner records. The device was never the prize. It was the unlocked side door.
When a gate controller or access system fails or is knocked offline by an attack, residents can't get in, vendors can't get in, and the phones at the management office don't stop until it's fixed. Nobody budgeted for that day because nobody knew the device was a risk.
What Actually Contains the Problem
A management company needs a list of every connected device across every property: what it is, where it is, what firmware it runs, who installed it, and what it can reach. Most firms that go through this discover equipment they didn't know was online, installed by a vendor two contracts ago and still running the credentials it shipped with.
Default passwords get replaced with strong, unique credentials, and administrative access to devices gets restricted and documented. Firmware gets updated where the manufacturer still supports the device, and equipment past support gets flagged for replacement before it fails or is compromised. Device networks get segmented so a camera or gate controller can't reach the systems holding resident and financial data. Remote access for vendors gets locked down and logged rather than left open because it was convenient during installation.
Where a Managed IT Partner Helps
For a management company or association board, the obstacle is scale. The devices are scattered across dozens of properties, installed by vendors who are long gone, and there's no one on staff whose job is to track them.
A managed service provider can take that on as an ongoing, proactive service. The provider can build and maintain the device inventory across the portfolio, replace default credentials and apply firmware updates on a schedule, design the segmentation that separates building equipment from office and financial systems, and monitor for the unusual traffic that signals a compromised device. When a new property joins the portfolio or a vendor installs new equipment, the provider can fold it into the inventory instead of letting it disappear into the background.
For a board, there's a fiduciary angle as well: association funds paid for that equipment, and the association carries the liability if it's misused. Being able to show that the devices are inventoried, secured, and maintained is part of managing the community's risk.
If you can't list the connected devices across your properties, or you don't know whether a compromised camera could reach your resident records, a Network Discovery might be in order. We'll inventory what's connected at each property, show you what it can reach, and identify the exposure before someone else finds it.
Ready to take the next step? Contact the Connecting Point team today to discuss your organization's needs.
Fill out our Network Discovery Form to get started!
970.356.7224 | www.CPcolorado.com | sales@CPcolorado.com
Connecting Point is a trusted IT solutions provider based in Greeley, Colorado, helping businesses across Northern Colorado and beyond navigate technology decisions with confidence.


