Your building’s controls used to live on their own little island. Now they share a network with your staff, your cloud tools, and your vendors, and they don’t always get the same patching attention as everything else on it.
Why Building Controls Are Part of Your Cyber Risk Now
A modern building automation system is not a closed box. Controllers talk over IP, operators log in from workstations and phones, and integrations pull data into dashboards and analytics. That connectivity is what makes the system useful. It is also what puts it in scope for security.
NIST says as much. Its Guide to Operational Technology (OT) Security, SP 800-82 Rev. 3, finalized in September 2023, names building automation systems alongside industrial control systems and physical access control systems as OT it covers. If someone gets into your BAS, they can change setpoints, schedules, and alarms. That is a facility problem as much as an IT one.
Start With Passwords
Passwords are the cheapest fix on this list and the easiest one to put off. Here’s what to look for:
- Default logins that were never changed after commissioning.
- One shared account that the whole team, and every contractor, uses.
- Old access for people who left the company or finished the job years ago.
For what a good policy looks like, NIST’s password guidance (SP 800-63B Rev. 4) is a useful reference. It calls for at least 15 characters when a password is the only login factor. It says not to impose composition rules like mixing character types. And it says not to force periodic changes unless there is evidence a password has been compromised. In plain terms, long and unique beats complicated and rotated every 90 days.
Firmware: Why Updates Are Not Optional Anymore
Manufacturers are tightening security inside their own controllers. One example from our field work: newer firmware on some controller families now requires a password change before the controller will communicate over BACnet. That is good for security. It also means a routine update on a controller nobody has touched in years can leave it offline until credentials are set.
So treat an update as a planned job, not a quick click. Know what firmware each controller runs, read the release notes, schedule the work around building operations, and have someone on site who knows the platform. We handle controller firmware updates and password policy setup as part of our controls and integration work, across the platforms we support.
Look at the Protocol and the Pathways
Plain BACnet/IP was built to get equipment talking, and it is generally not encrypted on its own. BACnet Secure Connect is the newer secure variant, and BACnet International has run a program since January 2020 to help manufacturers build it into their products. If you are planning a retrofit or a new build, ask whether the equipment supports it. Choosing open standards makes that question easier to answer, which we covered in our post on open vs proprietary BAS.
Then look at the pathways in. Segment the BAS network from your corporate network. Find every remote access route, including vendor VPNs, remote desktop tools, and cellular modems. Close the ones nobody can explain.
A Six Point Checklist for Facility and IT Teams
- Inventory everything. List every controller, workstation, and server, with firmware versions.
- Remove default and shared accounts. One login per person.
- Set a password policy. Long and unique, with changes triggered by risk, not a calendar.
- Plan firmware updates. Release notes first, a rollback plan, and a technician who knows the platform.
- Map remote access. Know every path in and close the unused ones.
- Assign ownership. Decide who in facilities and who in IT is responsible for each item above.
How HBT Approaches It
We are a technology agnostic integrator, so we look at a mixed vendor building as one system, not three separate problems. Facilities knows the equipment. IT knows the network. Most gaps sit between the two, and part of our job is getting both sides to agree on who owns what. If you are not sure where your system stands today, a complimentary facility audit is a good place to start.
FAQ
Can a building automation system be hacked?
Any system connected to a network can be a target. NIST covers building automation systems under its operational technology security guidance. Unique credentials, current firmware, and a segmented network all reduce the risk.
How often should BAS firmware be updated?
There is no single schedule. Follow the manufacturer’s release notes, test the update, and plan it around building operations. Some firmware now adds required security steps, so do not update a controller without a plan.
Should we force BAS password changes every 90 days?
NIST’s guidance says not to require periodic changes unless a password may be compromised. Use long, unique passwords and change them when someone leaves or a credential is exposed.
Who owns BAS cybersecurity, facilities or IT?
Both. Facilities understands the equipment and what it controls. IT understands the network and access policy. Write down who owns each task so nothing falls between them.
Want a Second Set of Eyes on Your Controls?
Get a Complimentary Facility Audit
About the author
Bryan Lampley is Director of Critical Technologies at Hoffman Building Technologies. He works on controls and systems integration for data centers, pharma, and other critical facilities.
About Us
Hoffman Building Technologies has been a building automation specialist since 1985. We are 100% employee-owned and serve government and other facilities across the United States and into Europe. We integrate the platforms a facility already has rather than locking it into one brand.
Home | Government | Services | Contact Us | News & Blogs










