Building Network Segmentation for IoT: A Property Manager's Field Guide
How to separate HVAC controls, access, cameras, sensors and tenant traffic on one building network, and what to ask your vendors to document.
Walk into the telecom room of a typical mid-rise and you will find one set of switches carrying the building automation system, the door controllers, the camera recorder, the elevator monitoring modem, the sensors the last owner bought and, in the worst cases, the tenant Wi-Fi. Every one of those systems was installed by a different contractor who needed it to work that week. Segmentation is the discipline of putting each of them in its own lane, so a fault or a compromise in one cannot reach the rest.
Why flat building networks fail
A flat network means any device can talk to any other device. A compromised camera can scan the access-control controllers. A tenant laptop plugged into a spare port can see the building automation server. A broadcast storm from a faulty switch takes down everything at once. These are not exotic scenarios; they are the ordinary consequences of treating the building as one room.
The cost of a flat network rarely shows up until something goes wrong, and then it shows up in every system together. Segmentation replaces one large failure domain with several small ones, which is the same logic a fire separation applies to a floor plan.
Start with an inventory, not a diagram
You cannot segment what you have not counted. A building survey should list every switch, controller, gateway, recorder, access point and meter, with its location, its owner, its firmware version and the vendor who supports it. Most properties discover devices nobody remembers buying, including cellular modems, old wireless bridges and unmanaged switches hidden above ceilings.
Walk the risers, open every mechanical and electrical room and record what you find. Compare the physical list against what the network sees. The gap between the two is where your first risks live.
A practical VLAN plan for a mid-rise
A workable design uses a small number of segments with plain names. Typical segments are building automation, access control, video, sensors and IoT, tenant or resident services, guest and contractor access, management, and the property office. Each gets its own address range, its own firewall rules and its own monitoring.
The rules matter more than the labels. Building automation should talk to its controllers and a managed gateway, not to the property office. Cameras should send video to the recorder and nowhere else. Tenant traffic should reach the internet and nothing inside the building. Anything that does not need to cross a boundary should not be allowed to.
Vendor access without a permanent hole
Many building systems come with a vendor who needs remote access for support. The common shortcut is a port forward or a vendor-owned modem, which creates a permanent, unmonitored path into the building. A safer pattern is a managed remote-access gateway that issues time-limited sessions, logs what the vendor touched and closes the path afterwards.
Put this requirement in contracts. Ask each vendor how they connect, who at their firm has access, whether credentials are shared and how access is removed when an employee leaves their company.
The dull but essential parts: switches, power and labels
Segmentation depends on managed switches, not on consumer gear. Each port should be labelled, each switch should have a unique administrative credential and each configuration should be backed up. Battery backup for core switches keeps alarms and access control reporting through short power events.
A labelled patch panel and a printed one-page diagram in each telecom room turn a four-hour fault into a twenty-minute one. This is the cheapest improvement in the entire programme and the one most often skipped.
Monitoring and change control
Once segments exist, watch them. Alert on new devices appearing in a segment, on devices going offline, on traffic crossing boundaries it should not cross and on configuration changes. A change log that records who changed what and why gives you the history you need after an incident.
Agree who approves changes. In many buildings, a contractor adds a device and a port rule on the day, and nobody records it. A simple approval step, even a shared form, keeps the design from decaying.
Rolling segmentation out in an occupied building
Do it in stages. Begin by building the new segments and moving low-risk devices such as sensors. Next, move cameras and access control during planned windows with the vendor present. Leave building automation for a quiet period, with a rollback plan and the mechanical contractor on call. Tell tenants about any planned Wi-Fi interruption in advance.
Test after each stage and update the drawing before moving on. Expect surprises: devices hard-coded to an address, controllers that only speak to one server and a surprising number of forgotten bridges. Surprises are the point of the exercise.
Checklist
- Inventory every switch, controller, gateway and recorder in each telecom and mechanical room
- Name an owner and a vendor for each system
- Define segments for building automation, access, video, sensors, tenants, guests and office
- Replace vendor port forwards with a logged remote-access gateway
- Back up every switch configuration and store the copies offline
- Label ports and post a one-page diagram in each telecom room
- Alert on new devices and boundary-crossing traffic
- Review the design every six months and after every acquisition
Where this lands by property type
Facilities Teams
Facilities teams keep heat, air, water and lifts running. Increasingly those systems are networked, and the team needs IT that understands operational priorities. Typical exposure: mechanical systems on networks the facilities team cannot see.
Commercial Landlords
Commercial landlords compete on building quality: reliable connectivity, secure access and a smooth fit-out process. Technology gaps show up in vacancy and renewal rates. Typical exposure: tenants asking for connectivity options the building cannot provide.
Property Developers
Developers define the technology a building lives with for decades. Decisions made at design stage, on risers, cabling and carrier access, are expensive to change after turnover. Typical exposure: telecom rooms sized too small and placed without carrier input.
Services that address this topic
Guidance like this works best inside a coordinated programme, not as a one-off fix. These PropertyIT services cover the topic directly.
Smart Building Networks
A smart building network is the cabling, switching, VLAN design and firewalling that lets mechanical, security and tenant systems share one physical plant while staying logically separate.
S / SystemsStrata Council Technology
Strata Council Technology gives councils and strata managers a reliable system for records, notices, voting, financial reporting and secure document sharing, built around the obligations in the Strata Property Act.
S / OperateMulti-Site Network Management
Multi-Site Network Management applies a common design, configuration backup, monitoring and change process to the networks of every property in a portfolio, from head office to the smallest site office.
Next step: a building technology survey
PropertyIT is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery for property teams. If this article describes a situation in your buildings, book a free 30-minute consultation: call (604) 632-4959 or email info@SAZ.ca. We will give you a plain-language view of your options, and a fixed-price scope if you want one. No lock-in, no pressure and no obligation.
Frequently asked questions
Do we need segmentation in a small building?
Even a 30-suite building benefits from keeping tenant Wi-Fi, cameras and door controllers apart. The design can be simple, with three or four segments, and still removes the largest risks.
Will segmentation break my building automation system?
It can if done carelessly, which is why we inventory first, test with the vendor and keep a rollback. Properly planned, controllers continue to talk to their server as before.
How long does a segmentation project take?
A single building is typically a few weeks including survey, design and staged cut-over. Portfolio programmes run in waves, with the first building acting as the template.
Who should own the building network?
One named person or firm. Without an owner, every vendor adds devices on their own terms, and the design degrades. We often take this role for properties without in-house IT.