Categories: Blog

Building Automation Cybersecurity: Facility Guide

Building Automation Cybersecurity: A Practical Facility Guide

Building automation cybersecurity starts with knowing what is connected, who can reach it and how the building will operate if digital access is disrupted. For most facility teams, the highest-value first steps are an accurate asset inventory, elimination of unnecessary internet exposure, controlled remote access, separation of operational technology from business networks, reliable backups and a practiced response plan.

A building automation system, or BAS, can control HVAC, lighting and other physical processes. That makes it operational technology, not merely another office application. Cybersecurity changes must therefore account for occupant comfort, equipment protection, uptime and safety. NIST recommends a risk-based approach tailored to each system’s business and operational requirements.

Why does building automation cybersecurity require joint ownership?

BAS environments cross traditional boundaries. Facility staff understand sequences, alarms and operating consequences. IT and security teams understand identity, networks, logging and incident response. Integrators and manufacturers understand product-specific configurations and support limits. A workable program assigns all three groups clear responsibilities.

Begin by naming an accountable owner for the BAS, a technical security contact and an operations decision-maker. Document who can approve remote access, create accounts, apply updates, change control logic, restore backups and communicate during an incident. If these responsibilities exist only in a vendor relationship or in one employee’s memory, the building has a continuity gap.

The Tustin Group’s energy management and building automation services page describes the types of controls and integrations that may exist in a modern facility. The exact system architecture and cybersecurity scope must be confirmed before any change.

What belongs in a BAS asset and access inventory?

Inventory more than the front-end workstation. Include servers, supervisory controllers, field controllers, gateways, routers, switches, wireless devices, sensors with network functions, operator stations, cloud services, mobile applications and vendor support tools. Record manufacturer, model, firmware or software version, physical location, network address, supported protocols, business function and system owner where available.

Then map access paths. Ask:

  • Can any device or login page be reached directly from the public internet?
  • Which users, vendors and service accounts can connect remotely?
  • Are accounts unique to individuals or shared?
  • Which BAS components communicate with the corporate network or cloud?
  • What third parties can change software, schedules, setpoints or sequences?
  • When were dormant accounts and obsolete connections last removed?

Do not scan, patch or isolate live controllers without an operational review. Some legacy devices are sensitive to network traffic or cannot support modern security controls. Use passive discovery or approved maintenance procedures when appropriate.

How should remote access be secured?

Remote access is useful for troubleshooting and after-hours support, but it should be intentional and limited. CISA’s current OT guidance recommends removing operational assets from the public internet, using secure remote-access methods, applying strong authentication and least privilege, and disabling dormant accounts.

A practical design generally routes approved users through a managed access point rather than exposing a controller or BAS web page directly. Require a unique identity for each person, phishing-resistant multifactor authentication where the platform supports it, time-bounded vendor access and logs that show who connected and what they did. Review emergency or break-glass accounts separately and protect their credentials.

Remote access arrangements must be compatible with the installed products and the organization’s security architecture. A VPN alone is not a complete control; endpoint security, account management, patching, monitoring and authorization still matter.

What does useful network segmentation look like?

Segmentation limits the paths between business IT, guest networks, building systems and external services. It can reduce the chance that an incident in one environment spreads directly into another. The design should be based on required data flows, not an assumption that every device needs broad connectivity.

Zone or path Facility question Desired evidence
BAS devices Which devices actually need to communicate? Approved device and protocol list
Operator access Who needs control versus read-only visibility? Role-based account matrix
IT integration What data crosses between OT and enterprise systems? Current data-flow diagram
Vendor access When and how can a third party connect? Approved, logged access workflow
Cloud services What happens if the internet or provider is unavailable? Documented local fallback

Firewall rules and network changes should be planned with IT, facilities, integrators and equipment stakeholders. Test them during a controlled window and preserve a rollback path.

How should patching and backups be handled?

Create a repeatable process to monitor manufacturer notices and CISA advisories, evaluate exposure, test compatibility and schedule approved updates. “Patch everything immediately” may be unsafe for an operational system, while indefinite deferral leaves risk unmanaged. Record the decision, compensating controls and next review date when an update cannot be installed.

Back up server configurations, controller databases, graphics, sequences, schedules, license information and other files needed to rebuild the environment. Keep protected copies separate from the production system, and test restoration instead of assuming a successful backup job equals recoverability. Coordinate backup procedures with the BAS manufacturer or integrator.

What should a BAS cybersecurity service plan cover?

A service plan should identify the supported system boundary and divide responsibilities among the owner, IT team, integrator and manufacturers. Useful deliverables can include inventory updates, account reviews, backup verification, configuration baselines, alarm review, version tracking and an escalation process for security advisories. Explore The Tustin Group’s energy service agreement information as a starting point, then confirm whether the needed cybersecurity activities are included in the proposed scope.

Procurement is another control point. Ask vendors about supported product life, vulnerability notification, secure defaults, logging, account roles, encryption, backup portability and how remote support works. Avoid requirements that sound strong but cannot be operated by the facility team.

How can facilities prepare for a BAS cyber incident?

Add BAS contacts, diagrams and operating dependencies to the organization’s incident response and continuity plans. Define what conditions require isolating a connection, who can authorize control changes and how IT will preserve evidence. Practice a scenario in which the front end, remote connection or enterprise network is unavailable.

CISA emphasizes the ability to operate OT systems manually where feasible. For a building, that may mean documented local control procedures, known safe states, current contact lists and trained personnel. Manual operation varies by system and can introduce hazards, so procedures should be developed and tested by qualified stakeholders.

Organizations with multiple Mid-Atlantic facilities should verify service availability and system support at each address. Review the areas The Tustin Group serves, and use the contact page to discuss a site-specific automation need.

What do facility managers ask most often?

Is a BAS the same as an IT system?

No. A BAS uses digital technology, but it directly monitors or controls physical processes. Security decisions must account for operational reliability and safety.

Should a building automation system be connected to the internet?

Only when there is a justified need and an approved secure architecture. Direct public exposure should be removed; remote access should be controlled, authenticated and monitored.

Can legacy controllers be secured?

Often, risk can be reduced through segmentation, access control, monitoring and procedural safeguards even when a device lacks modern features. Product-specific review is essential.

Who should lead BAS cybersecurity?

Facilities, IT/security and the integrator should share defined responsibilities. One accountable owner should coordinate decisions and maintain the operating record.

Which sources informed this guide?

Sources reviewed August 12, 2026: NIST, SP 800-82 Rev. 3, Guide to Operational Technology Security; CISA, Primary Mitigations to Reduce Cyber Threats to OT; U.S. Department of Energy, EMIS Cybersecurity Best Practices. Apply guidance through a facility-specific risk and operational review.

The Tustin Group

Recent Posts

Healthcare Water Management Program: Legionella Risk Control

A practical framework for healthcare facility teams developing a water management program to reduce Legionella…

3 minutes ago

Commercial Building Retro-Commissioning: A Practical Guide

Commercial building retro-commissioning uses records, trend data, functional testing, corrective action, and verification to improve…

36 minutes ago

Fire Pump Testing Requirements: A Documentation Guide

A practical guide for facility managers who need to understand fire pump testing requirements, review…

55 minutes ago

Fire Alarm Inspection: A Facility Manager Guide

A practical commercial fire alarm inspection guide covering pre-test coordination, records, device access, integrated functions,…

1 hour ago

Boiler Water Treatment: Facility Manager Guide

A practical boiler water treatment guide for controlling scale, corrosion and carryover through testing, blowdown,…

1 hour ago

Cooling Tower Water Treatment: Practical Guide

Learn how a cooling tower water treatment program coordinates chemistry, blowdown, cleaning, monitoring and documentation…

2 hours ago