Premier Provider of Building Automation & Energy Management Systems Integration in California

OT Cybersecurity: The Silent Threat to Your Building

OT Cybersecurity: The Silent Threat to Your Building

If your BAS network is reachable from the internet, it’s a cybersecurity target. And if you can VPN into it from home, it’s reachable. Building controls have been on attackers’ radar for over a decade.

For example, the 2013 Target breach traced back through an HVAC vendor’s network credentials. CISA has issued many advisories on BAS controller vulnerabilities. So this isn’t theoretical.

Why attackers care about BAS

It usually isn’t about the building data itself. Instead, it’s about lateral movement. A compromised BACnet network often connects to the corporate network. From there, attackers pivot to higher-value systems.

Even an isolated BAS attack hurts. For example, attackers can force shutdowns in a data center. They can compromise hospital pressurization, manipulate lab controls, and also deploy ransomware that locks operations out of their own building.

The right reference framework

The reference framework is NIST SP 800-82, “Guide to Operational Technology (OT) Security.” Most recently revised in 2023, is broadly written for industrial control systems. However, its principles map cleanly to building automation.

Six core moves

1. Segment the network

Separate the BAS network from corporate IT. Firewall everything between them. Limit traffic to specific documented data flows. Use VLANs at minimum. Use dedicated physical infrastructure where criticality warrants it.

2. Secure remote access

The era of “VPN into the JACE with the same password since 2014” is over. Deploy multi-factor authentication on every remote-access path. Also, use jump hosts for vendor access. Log every session. Then rotate credentials on a defined cadence.

3. Patch and harden

Niagara stations, BACnet routers, JACEs, and supervisory PCs all need a patch cadence. Follow Tridium’s published hardening guidance. Disable services you don’t use. Then change default credentials on every device.

4. Encrypt where you can

Use BACnet/SC for new and upgrade-capable installations, TLS on the supervisor web interface, SSH instead of Telnet, SFTP instead of FTP. Encrypt backup files at rest.

5. Monitor

You can’t respond to what you don’t see. At minimum, log authentication events, configuration changes, and unusual control activity. Forward logs to a SIEM if you have one.

6. Plan for failure

Every critical BAS needs documented manual-override procedures. You also need a known-good backup stored offline. And you need a tested restoration runbook.

Where this all converges

Federal facilities now anchor this whole posture to the DoD CMMC program. Healthcare is converging with HIPAA security expectations. In addition, cyber insurance underwriters are asking pointed questions about OT segmentation.

How Signet handles it

We treat OT cybersecurity as a design discipline. It’s not a post-install add-on. Our network architectures include segmentation, deployments follow Tridium’s published hardening guidance, service contracts include defined patch cadences.

We carry $2M in cyber insurance. Also, we’re pursuing CMMC Level 1 certification to maintain DoD contracting eligibility.

Talk to Signet Controls. Planning a BAS install, retrofit, integration, or service contract in California? We work across Los Angeles, Orange County, the Inland Empire, the Central Coast, and Kern County. Reach our team at info@signetcontrols.com or call (877) 874-4638.

References

[1] NIST SP 800-82 Rev. 3 — Guide to OT Security — https://csrc.nist.gov/pubs/sp/800/82/r3/final

[2] CISA — Cybersecurity Advisories — https://www.cisa.gov/news-events/cybersecurity-advisories