Building management systems control the heating, ventilation, air conditioning, lighting, access control and power that keep a building running. They are operational technology, with the same fragility as industrial systems, yet they are often treated as facilities equipment rather than as a security concern.
That gap is a problem. Building systems are frequently internet-exposed, lightly secured and connected to the corporate network, which makes them both a target in their own right and a way into the wider organization. Reducing their exposure is a practical, high-value step.
01Key takeaways
- 01
Building management systems (BMS/BAS) are operational technology controlling HVAC, access, lighting and power.
- 02
They are often internet-exposed and lightly secured, making them soft targets.
- 03
A compromised building system can disrupt operations and serve as a foothold into the wider network.
- 04
Segmentation and exposure reduction are the most practical defenses for building systems.
- 05
Many building controllers are touched rarely, making them strong candidates for disconnect-by-default access.
02What BMS and building automation systems are
A building management system, sometimes called a building automation system, is the network of controllers and software that operates a building's physical services. It manages HVAC, lighting, access control, elevators, energy and sometimes safety systems.
Technically, these are control systems much like those in a plant: embedded controllers, specialized protocols and long lifecycles. They share the fragility of industrial OT, but they are often owned by facilities teams and fall outside the scope of both IT and OT security programs.
Building systems are OT in everything but the org chart, and that gap is where the risk lives.
03Why building systems are soft targets
Building systems combine real-world impact with weak defenses. They can affect comfort, access and safety, yet they are frequently deployed with little security attention.
- Default or weak credentials that are rarely changed.
- Controllers and interfaces reachable from the internet for remote management.
- Outdated firmware and protocols with little authentication.
- Ownership by facilities teams without security support.
- Connections to the corporate network that are poorly segmented.
04Internet-exposed controllers
A recurring problem is building controllers placed directly on the internet so they can be managed remotely. Search engines for internet-connected devices routinely reveal exposed building systems, complete with identifiable interfaces.
An internet-exposed controller with weak authentication is an easy target. It can be manipulated directly, used to disrupt building services, or used as an entry point from which to reach the rest of the network. Removing that exposure is the single most valuable change for many buildings.
05Convergence with IT
Modern buildings increasingly connect their systems to the corporate network and the cloud for analytics, remote management and integration. This brings the same IT/OT convergence risk seen in industry: the building system becomes reachable from the enterprise, and the enterprise becomes reachable from the building system.
A compromised building controller on a poorly segmented network is not just a facilities problem; it is a potential foothold into corporate systems, and vice versa. The boundary between building systems and the rest of the network deserves the same care as any OT boundary.
06Segmentation and exposure reduction
The practical defenses for building systems mirror those for OT generally: separate them from other networks, remove unnecessary internet exposure, and limit how and when they can be reached.
- Place building systems in their own segment, isolated from the corporate network and the internet.
- Remove direct internet exposure of controllers and interfaces.
- Replace default credentials and restrict who can reach the systems.
- Provide remote management through controlled, brokered access rather than open exposure.
07Disconnect-by-default for rarely-touched controllers
Many building controllers are configured once and then touched only occasionally for maintenance or seasonal changes. Their need for connectivity is intermittent, which makes them strong candidates for keeping offline by default.
An AIRGAPNET controlled connectivity pattern can keep a building controller's management path disconnected by default and open it only for an approved maintenance window. A rarely-touched controller that is unreachable most of the time presents almost no remote attack surface.
08Closing thought
Smart buildings have quietly become full of operational technology, and that technology has quietly become some of the most exposed on the network. Treating building systems as facilities equipment rather than OT leaves a real gap that attackers are happy to use.
Bring building systems into the security program, segment them, remove their internet exposure, and keep rarely-used controllers offline by default. The same reachability reduction that protects a plant protects the building around it.
FAQFrequently asked questions
What is a building management system?
A building management system (BMS), or building automation system, is the network of controllers and software that operates a building's physical services such as HVAC, lighting, access control, elevators and energy. Technically these are control systems much like industrial OT.
Why are building systems often insecure?
They frequently have default or weak credentials, internet-exposed controllers, outdated firmware and little authentication, and are owned by facilities teams outside IT and OT security programs, with poor segmentation from the corporate network.
Can a building system be used to attack the wider network?
Yes. A compromised building controller on a poorly segmented network can disrupt building services and serve as a foothold into corporate systems. Convergence makes the building system reachable from the enterprise and the enterprise reachable from it.
How do you secure smart building systems?
Place them in their own isolated segment, remove direct internet exposure, replace default credentials, restrict who can reach them, and provide remote management through controlled, brokered access rather than open exposure.
Should building controllers be always connected?
Many are touched only occasionally for maintenance or seasonal changes, so their management path can be kept disconnected by default and opened only for approved windows. A controller that is unreachable most of the time has almost no remote attack surface.
SRCSources of record
Buildings are OT too
Take rarely-used building controllers off the network by default.
Segment building systems, remove internet exposure, and keep intermittently-used controllers disconnected by default, opening them only for approved maintenance windows.