When the Office Computer Becomes the Open Door


For Louisiana life safety and property protection companies, cybersecurity is no longer simply an IT issue. Office computers may provide access to email, accounting and payroll software, customer databases, telephone systems, testing platforms, remote-support applications, alarm programming software, manufacturer portals and monitoring-center accounts. That connectivity makes an alarm company more efficient, but it can also make one compromised computer a doorway into many other systems.


Today's cybercriminals are not always interested in immediately shutting down a network and demanding a ransom. An attacker may quietly gain access, steal passwords, monitor email conversations, examine invoices, identify customers and vendors, and determine what other systems can be reached. The FBI has warned that compromised business email accounts can give criminals access to legitimate conversations, passwords and financial information, making it easier to impersonate employees and trusted business partners.


For an alarm company, the concern goes well beyond the information stored on one computer. Consider an office workstation with active or saved connections to email, accounting software, a VoIP telephone system, an online testing platform, a monitoring center's dealer portal and manufacturers' cloud platforms. If an attacker controls that workstation or steals the employee's credentials, those trusted connections could provide opportunities to attack additional systems. This process, known as lateral movement, allows criminals to expand their access after the initial compromise.


The life safety and security industry presents a particularly attractive target because companies may possess customer names and addresses, emergency contacts, account information, equipment records, service histories, programming credentials and remote-access capabilities. Dealers may also have authorized connections to video surveillance, access control, intrusion, fire alarm and monitoring systems. The alarm company itself may therefore become the pathway to another target.


Email is especially important because it is often at the center of a company's digital identity. Password resets are delivered through email, invoices and contracts are exchanged there, and years of customer and vendor communications may be available. Once criminals control an email account, they can study how the company operates and impersonate a legitimate employee. They may discover which monitoring center the company uses, which employees have administrative authority and which manufacturers and service providers the company works with.


Saved passwords and remote connections create additional risks. Browsers may save credentials, applications may remain signed in and employees may reuse passwords across multiple services. The FBI's investigation of the xDedic criminal marketplace found that more than 800,000 compromised computer credentials had been listed for sale, with stolen access used for crimes including ransomware and business email compromise. For an alarm dealer, credentials providing remote access to a business or customer system should be treated with the same care as physical keys to a protected facility.


The security and building systems industry has already experienced significant cyber incidents. In 2023, Johnson Controls, a major provider of building controls, fire and security technologies, disclosed that an unauthorized third party gained access to portions of its internal IT infrastructure, stole data and deployed ransomware. The incident disrupted access to business applications, and the company later reported approximately $27 million in impact to quarterly net income from lost and deferred revenue and incident-related expenses. Johnson Controls reported that it had not observed evidence that its digital products and solutions were affected, but the incident demonstrates how disruptive an attack on a company operating in an interconnected technology environment can become.


Protecting against these attacks requires layers of security rather than a single product. Multifactor authentication should be required wherever possible, particularly for email, remote access, financial systems, monitoring-center portals and administrator accounts. Employees should have individual accounts, passwords should not be reused between systems and access should be limited to what each employee actually needs. Companies should also reconsider storing sensitive passwords in browsers, spreadsheets or other unsecured locations and instead use appropriately managed credential-management solutions.


Networks should be segmented so that compromising an ordinary office computer does not automatically provide unrestricted access to every other system. Remote access should be tightly controlled, unused services disabled and computers, servers, firewalls and applications kept current with security updates. Modern endpoint protection can also help detect suspicious activity and attempts by an attacker to move between computers.


Companies should maintain secure offline or immutable backups and regularly verify that those backups can actually be restored. Employees should receive ongoing training to recognize phishing emails, fraudulent password-reset requests, suspicious QR codes, unexpected multifactor authentication prompts and requests to install remote-support software. Changes involving banking or payment information should always be independently verified using contact information already known to be legitimate.


Alarm companies should also periodically review everyone who has access to their monitoring center, programming platforms, video and access-control systems, manufacturer portals and other connected services. Former employees' accounts should be disabled immediately, unnecessary access should be removed and companies should know which employees and devices have administrative privileges.


Finally, every company should have an incident-response plan before an attack happens. Management and employees should know who to contact, including their IT or cybersecurity provider, monitoring center, bank, insurance carrier, attorney and appropriate law enforcement agencies. They should also know how to quickly isolate a compromised computer or account to help prevent an attacker from reaching additional systems.


Alarm professionals have always understood the importance of protecting communication paths, restricting access to critical equipment and controlling who has the keys. The same principles now apply to the company's digital environment. An ordinary office computer may contain access to email, financial information, monitoring accounts, programming platforms and customer systems. Cybersecurity is therefore becoming an important part of protecting the customers and systems entrusted to Louisiana life safety and property protection companies.


The greatest cybersecurity risk may not be the information stored on one compromised computer. It may be everything that computer is trusted to access.

Legal and Regulatory Disclaimer

Information provided by LLSSA is for educational and informational purposes only and should not be considered legal advice or the official position of any regulatory agency or organization. Users should independently verify all information with the appropriate authorities and consult qualified legal counsel or other professionals regarding their specific circumstances.