What happens to your smart building ROI when there is no risk management? CRE portfolios are getting more connected, but governance isn’t keeping up. Cybersecurity gaps, unclear ownership, and missing operating models are quietly killing the returns that justified the investment in the first place.
In this podcast episode, we were joined by Cecilia A. Li, CIO at Urban Edge Properties, and co-host Rob Murchison, CEO at Intelligent Buildings to unpack why smart building ROI is a risk management problem, not a technology problem!
Urban Edge is a REIT managing 73+ properties and over 17.2 million square feet of retail real estate across the Washington D.C. to Boston corridor.
Smart Building ROI Is a Risk Management Problem
Unlike traditional IT, which gets upgraded regularly and lives entirely in the digital world, operational technology (OT) in buildings is cyber-physical. It interacts with the real world. HVAC systems last 15–20 years. Lighting controls, and meters, all operate on dramatically different upgrade cycles.
The result? A fragmented patchwork of technologies at different stages of their lifecycle, managed by different internal stakeholders and external vendors, with no unified oversight. That fragmentation creates cybersecurity exposure, unplanned downtime, inflated operating costs, and, critically, it blocks the path to data-driven risk management.
The Catalyst: When IT Meets OT
For Urban Edge, the wake-up call came at a RealComm conference, where the Real Estate Cyber Consortium highlighted a glaring gap: most organizations protect their corporate IT environments but leave building OT systems dangerously exposed.
The “aha moment” was recognizing that technology convergence had already blurred the line between these two worlds, but the organizational structures hadn’t caught up. Asset managers owned OT. IT owned corporate tech. Nobody owned the space in between.
What followed wasn’t a single conversation but a sustained effort to build trust between IT and asset management, walking properties together, understanding which systems mattered most, and mapping out tolerance for downtime. The team even brought in a white-hat hacker who demonstrated how he’d compromised an entire cruise ship, a floating mixed-use asset with retail, office, and residential, by exploiting its interconnected building systems. That demonstration made the need for risk management obvious.
What Changes With Governance in Place
Once Urban Edge established a stronger relationship between IT and asset management, several practical benefits followed. Vendor onboarding became faster because there was a standard architecture and clear policy. Emergency escalations dropped. Technology budgets became more predictable, something asset managers value above almost everything else.
The key principle: always start with the business problem, not the technology. What are you trying to solve? Only then do you evaluate solutions and, importantly, vet partners on their cybersecurity posture. Vendors that can’t meet baseline security requirements don’t make the cut, regardless of their feature set.
The Vendor Contract Opportunity
One practical lever that many owners overlook: contract renewal cycles. When vendor agreements come up for renewal, whether annual or multi-year, it’s a natural opportunity to insert governance language, set expectations around patching responsibilities and risk management, and create enforceability.
It’s about being fair to vendors, too. You can’t be frustrated with a vendor for not meeting a standard you never communicated. Governance gives everyone, owners, IT teams, asset managers, and vendors, a shared playbook.
The Integrator Blind Spot
A live audience question surfaces an often-overlooked link in the chain: the systems integrator. Integrators carry just as much cybersecurity responsibility as vendors and operators. The Urban Edge team has seen it firsthand: temporary passwords like “123” set during installation for convenience, then forgotten after the project wraps. That’s a front door left open.
The recommendation: hold integrators to the same governance standards as everyone else, and make accountability explicit in every contract.
Data as Gold
The episode closes with a provocative reframe. All the cybersecurity work, the governance, the policies, the architecture standards, is defensive. It’s risk management. But the real payoff comes once that foundation is in place: the ability to use building data to drive better operating decisions.
Without governance, no CIO is going to trust building data enough to act on it. With governance, the data becomes gold, powering efficiency gains, informed capital planning, and buildings that actually operate as designed.
Key Takeaways
Treat digital infrastructure like a utility. You don’t think about water, gas, or electricity until they fail. Building technology is the same, and it deserves the same governance, standards, risk management, and accountability.
Cybersecurity is an enterprise risk, not a department problem. A breach can cost north of $5 million. That’s not an IT issue or an asset management issue. It’s a risk management issue that demands cross-functional ownership.
Governance unlocks ROI. Without it, smart building pilots stall, innovations don’t scale, and the operating model never evolves. With it, you get faster vendor onboarding, fewer emergencies, predictable budgets, and, ultimately, data-driven decision-making.
Start with relationships, not technology. Success at Urban Edge began with walking properties alongside asset managers, understanding their pain points, and building mutual trust. The tech came later.
Use contract renewals as a governance lever. Every renewal cycle is a chance to align vendor expectations with your security architecture and accountability standards.


