Case Study: Cyber Resilience in Facilities Services

How a Facilities Management Company Secured Operations, Reduced Risk Exposure, and Cut Cyber Insurance Premiums by 52%

Industry Example: Facilities Services & Management
Company Size: ~650 employees across multiple regional offices
Annual Revenue: US $210 million
Estimated Cyber Insurance Premium (Before): US $480,000/year
Estimated Cyber Insurance Premium (After): US $230,400/year
Savings: ~52% reduction through continuous monitoring and validated security controls

The Challenge

A leading facilities services provider—managing building operations, maintenance, security, and environmental services for commercial and public clients—was increasingly reliant on digital systems for work orders, access control, and vendor coordination.

The company faced growing cybersecurity challenges:

  • Operational disruption risk: Connected building management systems, IoT sensors, and client portals were potential targets for ransomware or system compromise.

  • Sensitive client data exposure: Personal data from tenants, vendors, and employees was stored across multiple systems.

  • Limited IT visibility: Regional offices and field staff accessed critical systems remotely, often with inconsistent security controls.

  • Rising insurance premiums: Insurers required documented evidence of security maturity and control validation for coverage.

Without a structured cyber assurance approach, the firm risked data breaches, service downtime, regulatory penalties, and elevated insurance costs.

The Solution

The facilities services company implemented a cyber assurance and control validation platform following the Antigen Security methodology, tailored to multi-site operations.

Key measures included:

  • Continuous Control Validation: Automated verification of endpoint protection, MFA, patching, and access controls across offices, field devices, and building systems.

  • Secure Remote Operations: Monitoring of mobile devices and contractor access to ensure compliance with security policies.

  • IoT & Building Systems Oversight: Continuous scanning of connected building management systems and IoT devices for misconfigurations or vulnerabilities.

  • Third-Party Vendor Risk Monitoring: Real-time assessment of subcontractors and service partners with access to client systems.

  • Insurer-Ready Reporting: Consolidated cyber posture and risk scorecards aligned with ISO 27001, NIST CSF, and SOC 2 for insurer and client review.

The Outcome

Rapid Risk Reduction
Within 40 days, the system detected and helped remediate:

  • Misconfigured access controls on IoT-enabled building sensors

  • Outdated software on field laptops and maintenance tablets

  • Shared accounts with weak or reused passwords across regional offices

Quantifiable Results:

  • Cyber control compliance improved from 68% to 95% across all sites

  • Cyber insurance premiums reduced by 52%, with expanded coverage for ransomware and data breaches

  • $249,600 in annual premium savings

  • Improved confidence with clients and insurers

  • No cyber incidents affecting operational continuity in the following 12 months

Operational and Strategic Benefits:

  • Simplified compliance reporting for SOC 2 and ISO audits

  • Reduced manual IT oversight workload by 60%

  • Strengthened trust with clients, vendors, and regulatory bodies

  • Enhanced ability to scale digital services securely across new facilities

Why It Matters for the Facilities Services Industry

Facilities services companies manage distributed operations, IoT-enabled buildings, and sensitive client data, making them increasingly targeted for cyber attacks. Common risks include:

  • Ransomware and operational disruption

  • Compromise of building management systems

  • Insider threats and third-party vendor vulnerabilities

  • Rising insurer and client requirements for cyber maturity

By implementing continuous validation, monitoring, and insurer-ready reporting, facilities services providers can:

  • ✅ Reduce cyber insurance costs and improve coverage

  • ✅ Protect client and tenant data

  • ✅ Prevent operational disruption and downtime

  • ✅ Demonstrate maturity to insurers, clients, and regulators

  • ✅ Strengthen competitive positioning and client trust


Ready to Secure Your Facilities Operations?

If your facilities services organization wants to reduce cyber risk, protect client data, and achieve measurable insurance savings, contact us to explore how a cyber assurance program for multi-site operations can deliver proven operational and financial benefits.