A facility manager receives a text message that appears to come from the IT team. The message says their employee password is about to expire. To avoid losing access, they must verify their account before the end of the day.

The request does not look suspicious. The wording is clear. The timing feels plausible. The link leads to a login page that looks familiar.

But the message is fake. The login page is designed to capture credentials.

CredGovernance-CO1

This is the kind of risk that is becoming harder to spot. AI makes phishing emails, smishing messages and impersonation faster and more persuasive. Scammers today are not always sending clumsy messages filled with spelling mistakes and other obvious signs. They create requests that appear routine, sound professional and are specific enough to seem credible.

In addition to tricking people into sharing passwords or other sensitive information, cyber criminals may also exploit weak passwords, shared accounts, old credentials and legacy permissions.

FMs have an important role to play in credential governance. They understand how buildings are used day to day and who needs access to certain sites. They know contractor activities, which areas require tighter control and where temporary access is common. That operational knowledge helps IT, security and integrators design access processes and guidelines that are both secure and practical.

As threats become more prevalent and convincing, password changes alone are not enough. FM, security and IT teams can work together to keep access intentional and secure.

Credential governance is part of an overall cybersecurity plan

Physical security systems often remain in place for many years. During that time, employees leave, contractors change, vendors come and go, devices are added, roles shift and operating procedures evolve.

Credential governance is the discipline of managing access privileges. It includes how credentials are created, assigned, reviewed, changed and removed over time. It also includes how organizations manage temporary access, device passwords and vendor access.

Managing credentials is an important part of an overall strong cybersecurity plan in physical security environments and is a shared responsibility.

CredGovernance-CO2FMs can implement a few best practices to ensure strong credential governance and cybersecurity measures are in practice at their organization.

1. Reduce shared access & improve accountability

CredGovernance-CFMJ ExtraShared credentials may seem convenient, especially when teams are managing contractors, cleaning crews, maintenance staff, delivery personnel or short-term project teams. But shared access creates an accountability gap.

The same issue applies to shared administrator accounts for video surveillance, access control or other physical security systems. If several people use the same login, it is harder to track access, investigate configuration changes, review activity or manage permissions when an employee leaves or changes positions.

FM teams can reduce this risk by assigning unique credentials wherever possible. Modern access control and identity management tools can support temporary credentials, scheduled permissions and automated expiration dates. Temporary access can be tied to a named person, an approved role and a defined time. Contractor and visitor credentials expire automatically when the work is complete, and access is limited to the areas and systems required for the task.

2. Use multifactor authentication & password managers

Strong authentication reduces the risk that a stolen, guessed or reused password can be used on its own.

There are three main ways to confirm someone is who they say they are:

CredGovernance-Infograhic

Multifactor authentication combines two or more of these factors. If someone loses their badge or a password is compromised, they are still protected by the second form of authentication.

Password managers can help reduce the risk of predictable passwords. People often choose passwords or PINs based on familiar patterns, such as names, dates or a root word followed by numbers and special characters. When asked to change a password, they may simply increase the number at the end. Random, unique passwords are stronger, but they are difficult for people to remember.

Password managers within security systems help solve that problem by generating and storing stronger credentials.

3. Manage device credentials

People are not the only source of credential risk. Devices must also be secured.

Video surveillance cameras, access control readers, alarm panels, intercoms and other connected devices can provide an entry point into broader networks if they are poorly managed. A camera is not a standalone piece of building equipment. It is also a network-connected endpoint.

Default credentials on devices introduce a risk. While newer regulations and security practices increasingly discourage or prevent the use of default passwords, many legacy systems may still rely on them.

Another common issue is using the same password across many devices. If one camera password is compromised and that same password is used across the system, the exposure can quickly expand.

Device credentials should be unique, strong and managed consistently. Some systems can automate password rotation on a schedule and generate long, random credentials that are not based on familiar human patterns. This reduces the burden on FM and security teams while improving protection.

CredGovernance-CO3These approaches allow organizations to manage device identity without leaving passwords unprotected and easily accessible.

4. Include access reviews in operating procedures

Credential governance works best when it is part of routine operations.

Over time, employees may change roles, move departments or take on new responsibilities. They have access to different buildings, rooms, systems or data. Some people gradually accumulate more access than they need to do their current job because their old access is never removed.

One of the most common ways to reduce risk is to limit access to the systems and spaces someone actually needs. This is often called the principle of least privilege.

FM can help by building access reviews into standard procedures. Access should be reviewed when employees are onboarded or change roles, when contractors start or finish work, and when employees leave the organization. Quarterly or annual reviews can also help identify access rights that are no longer valid.

Offboarding is especially important. If an employee leaves, their physical access can be removed at the same time as their corporate email and network access. One way to support this is through single sign-on or centralized identity management.

CredGovernance-CO4When digital identity and physical access systems are connected, disabling an employee’s digital account can also help remove access to the site itself. This reduces the risk that access remains active because different teams manage different systems.

Role-based access control also makes it easier to adjust permissions as needs change. Access is assigned based on roles or personas. For example, janitorial staff may need building access during early morning or overnight hours. A temporary contractor may need access to one mechanical room for a specific project window. When access is tied to roles, it becomes easier to review and manage.

FM, security & IT collaboration

Credential governance requires coordination between teams.

CredGovernance-CO5

To begin having collaborative discussions, a good place to start is a joint review of current access practices. FM, security, IT and the integrator can look at how credentials are issued, how temporary access is managed, how device passwords are managed, how access is removed and who owns each step. The goal is to identify potential cybersecurity gaps and where clearer processes or guidelines are needed.

Procurement is also an opportunity for collaboration. IT and cybersecurity teams are increasingly involved in purchasing physical security systems. FM can review and outline operational needs that might otherwise be missed, such as frequent contractor access, physical building requirements and common uses, or seasonal staff needs.

Credential governance protects more than passwords

Credential governance is one of the ways organizations maintain control over access, accountability and system reliability as physical security environments become more connected.

Strong credential practices help reduce the risk that a stolen password, shared account, forgotten vendor login or unmanaged device credential will create a larger problem. They also make it easier to understand who accessed a site, changed a setting or viewed information.

As physical security systems become increasingly connected, FMs help ensure access remains aligned with operational needs while supporting broader cybersecurity best practices.