Facility Parking Guide Practical Parking Solutions for Facility Managers

Cybersecurity for Parking Access Control Systems After the 2026 ParkEngage Ransomware Attack

A ransomware claim against a parking software vendor is a facility-manager problem, not an IT one. What to demand in the contract and segment on the network.

Cybersecurity for Parking Access Control Systems After the 2026 ParkEngage Ransomware Attack

On May 1, 2026, the ransomware group FulcrumSec claimed ParkEngage as a victim on its leak site, threatening to publish data if negotiations did not begin. ParkEngage is a cloud parking platform used by airports, hospitals, universities, and commercial facilities for reservations, payments, and customer engagement — which describes a large share of the facilities reading this.

The instructive part for a facility manager is not the malware. It is that almost none of the exposure sits in equipment you own. Modern parking access and revenue control systems are cloud-connected software platforms holding customer and employee data, with vendor staff holding remote access into your network. Your leverage over that risk is exercised in two places only: the contract, and the network segment the equipment sits on. Both are decisions you make, and both are cheapest to make at renewal.

What your parking system actually holds

Facility managers routinely underestimate the data inventory, so list it explicitly before assessing risk:

  • Payment card data, or tokens plus the processing relationship, depending on architecture
  • Permit-holder PII — names, addresses, phone numbers, employer, sometimes employee ID
  • License plate reads with timestamps, which is movement and location history for identifiable individuals
  • Access credentials that in many buildings are the same badge or app that opens interior doors
  • Employee and tenant rosters, including shift patterns visible in access logs

That is a privacy-regulated dataset, not a facilities dataset. LPR history in particular is the category most likely to draw state privacy-statute attention and the one most facilities have never set a retention limit on.

The liability precedent is already established. The 2021 ParkMobile breach — a cashless parking vendor, not an equipment failure — ended in a $32 million settlement fund for affected users. When a parking vendor loses data, the tail is class-action litigation and notification cost, not a weekend of downtime.

The contract is where you have leverage

Every item below is normal in enterprise software agreements and routinely absent from parking-equipment and PARCS contracts. Put them in the RFP and the renewal, in writing:

  • SOC 2 Type II report, current, provided annually. Not a security whitepaper, not a trust-center webpage.
  • Penetration test cadence with a summary letter. Annual, third-party, with remediation status for findings.
  • PCI DSS attestation and a written scope statement naming which party is responsible for which control. If P2PE-validated hardware is in play, get the validation reference, since it materially changes your own scope.
  • MFA on all administrative access, including the vendor’s own staff. Ask specifically how vendor technicians authenticate.
  • A defined remote-support model. An always-on vendor tunnel into your PARCS network is the single most common weak point. What you want is brokered, time-boxed, logged access initiated by your request — not a standing connection nobody has audited since installation.
  • A patch and vulnerability SLA with named timeframes by severity, and confirmation that patching the operating systems under the application is somebody’s contractual duty.
  • Breach notification within a stated number of hours, not “promptly” or “without undue delay.” Your own notification obligations run on clocks you cannot control if the vendor’s clock is undefined.
  • Subprocessor disclosure, including where data is hosted and which analytics or support vendors touch it.
  • Data retention and deletion terms, with an explicit LPR retention window and a deletion certificate on termination.
  • Cyber liability insurance limits, evidenced, and an indemnity that survives termination.
  • A right to audit, or at minimum a right to receive the audit artifacts above.
  • Degraded-mode capability described in writing — what the equipment does when the cloud is unreachable.

The negotiating window is the renewal or the RFP. Mid-term, a vendor has no reason to agree to any of it; at renewal, most will concede the documentation items without a price change. Our vendor evaluation framework covers how to weight these against price and functionality in a scored comparison.

What you control on site: segmentation and credential hygiene

CISA’s guidance for building and operational technology is consistent on the fundamentals, and none of it is exotic. Segment enterprise and production networks according to trust boundaries and platform type — IT, IoT, OT, mobile, guest — and permit only the communications each segment actually requires. Isolate building automation from the corporate IT network and enforce least-privilege access. Apply the most stringent controls to the highest-criticality assets.

Translated to a parking facility:

  1. Get an asset inventory. CISA’s asset-inventory guidance for OT owners exists because nobody can defend what they have not enumerated. Every gate controller, pay station, LPR camera, intercom, EV charger, and the PC in the office running the management client.
  2. Put parking equipment on its own VLAN, not the tenant, guest, or corporate network. Cameras and pay stations sharing a flat network with office workstations is the configuration that turns one phishing click into a facility outage.
  3. Kill shared and default credentials. Named accounts, unique passwords, MFA where the platform supports it. Shared logins mean you cannot tell a technician’s session from an intruder’s.
  4. Time-box vendor remote access and log it. Review the log quarterly and ask who each session was.
  5. Keep firmware current, and read the advisories. Building systems get CISA ICS advisories regularly — the Johnson Controls Metasys advisory published this August is a recent example — and parking equipment runs on the same class of embedded platforms.

Your IT group can do most of this. What they need from you is the asset list and the vendor contact, which is why the inventory comes first.

Plan the degraded day

The question to answer before an incident: what happens operationally when the PARCS is encrypted or the cloud platform is unreachable for 72 hours?

Write the answer down. Do gates go free-flow, and what does that cost per day in lost revenue? Do you switch to manual tickets or validation slips, and does anyone still know how? How do monthly permit holders enter — is there an offline credential cache, or does the reader fail closed and strand your tenants? How do you reconcile the revenue gap afterward, and what evidence will your insurer want?

That per-day revenue loss figure is also your budget justification. A facility losing five figures a day to free-flow has an easy business case for a segmentation project and a tabletop exercise; a facility that has never calculated it has no case at all.

For FY2027, the fundable items are modest: a network segmentation project scoped with IT, credential cleanup, a half-day tabletop with your operator and vendor, and a contract review timed to renewal. The last one is free and has the highest return. The ParkEngage listing is a reminder that the vendor’s security posture becomes your incident, and the only time you get to influence it is before you sign.

Facility Parking Guide

An independent resource for facility managers navigating parking operations, maintenance, budgeting, and vendor selection. We provide practical, unbiased guides to help you manage parking assets effectively.