The BMS industry is undergoing a significant transformation as remote connectivity becomes the norm. Traditionally designed for isolated, on-premises control, many legacy BMS platforms lack the security architecture needed to withstand modern cyber threats once connected to the internet.

With building managers looking to improve operational efficiency and enable centralised control, BMS devices are often connected to corporate networks or directly to the internet, sometimes with minimal oversight.

This shift has revealed glaring vulnerabilities: unencrypted communications, hardcoded credentials, outdated firmware, and insecure protocols like BACnet and Modbus being exposed to public internet traffic.

Unlike IT systems, many BMS platforms were not built with cybersecurity as a core principle. As a result, they can become easy entry points for attackers, potentially compromising entire building infrastructures or even broader corporate networks. This issue is compounded by a general lack of visibility and patch management within operational technology environments.

The rise in ransomware, supply chain attacks, and targeted exploits against infrastructure has highlighted the urgent need for BMS vendors and facility managers to rethink security.

This means improving cybersecurity hygiene by:

  • segmenting networks
  • implementing strong authentication
  • and ensuring regular updates and monitoring.

In short, as remote access becomes essential, the BMS industry must pivot quickly toward secure-by-design architectures or risk becoming a persistent vulnerability in the digital enterprise.

Assessing the problem

Andrew Kelly, a Security consultant at the defence company Qinetiq, performed a study of smart buildings, ranging in size from small businesses with just a handful of employees to those with thousands of staff. In an interview with the BBC he said:

“It was the building management systems that jumped out as the most vulnerable…In all cases, pretty much without fail, these systems had been procured without thought to how to make them secure. I was absolutely shocked…We saw systems installed with default passwords where it would be a trivial exercise for someone remotely to gain access.”

And he found many building management systems were plugged into the corporate network without real consideration about who was able to access them.

“Just as a plumber wouldn’t worry about home security, so those installing building management systems may not think about security.”

His words were a scathing review of our industry. This interview was from 2016, but while customer compliance needs have led to increased adoption of VPN technology and strong authentication, there are still plenty of risks for building managers to contend with.

Manufacturers have done what they can to make systems harder to crack, however if those systems aren’t installed and implemented correctly security can’t be guaranteed.

It doesn’t matter how impressive a door is if nobody bothers to lock it.

BMS cybersecurity mistakes to avoid

It was just the HVAC guy
In November 2013 HVAC contractor Fazio Mechanical Services were working with US retailer Target when one of their employees fell for a phishing email, allowing hackers to steal a password.

This password gave the hackers access to Target’s POS systems, where they introduced malware that recorded credit card transaction information and transmitted the data to foreign actors.

It was projected that Target could face losses of up to $420 million due to the breach, making it a very costly mistake.

The incident demonstrated the importance of network segmentation: BMS controllers should not be on the same network as POS systems.

When Google was the Search Result
Also in 2013, cybersecurity researchers were able to gain access to the BMS systems at Googles’ Wharf 7 building in Sydney.

The researchers used Shodan, a specialised search engine that allows users to find devices connected to the internet like webcams, routers, servers and industrial systems.

By scanning the internet for devices with open ports and services the researchers were able to reveal critical systems that were never meant to be publicly accessible, putting one of the biggest companies in the world at risk. Weak credentials like default passwords let them push through an open door and gain full control over the building.

The incident demonstrated the importance of protecting remote building access with VPN technology or similar, ensuring that BMS systems are not exposed to public internet traffic.

Swimming in Defaults
In an incident which has since become one of cybersecurity’s most infamous cautionary tales since it occurred in 2017, a Las Vegas casino suffered a major data breach as a result of attackers using a wireless thermostat in a fish tank to access customer and employee data.

While no formal information has been published about the breach, the most likely cause seems to be that the thermostat, which was connected to the casino network, was not correctly configured, leaving it with default credentials that made it an easy entry point for the attackers, something that could easily have been avoided by paying closer attention.

Look at me, I am the admin now

In 2021 an engineering firm in Germany that specialised in building automations discovered that thousands of devices on a client’s estate were both inaccessible and no longer functional after the BMS network was insecurely exposed to the internet.

The hackers were able to use unique aspects of the control system against itself, unloading the devices and setting the bus coupling unit key, effectively wiping the devices and making them impossible to recover without the password.

Connect securely, or not at all

While cybersecurity horror stories might make you hesitant to get connected, without   visibility over your BMS system you’re missing out on data and capabilities that could save you money and time, while making your building more efficient.

By connecting to your BMS we can:

  • help you save energy
  • manage your controls more efficiently
  • offer tailored remote maintenance that cuts costs and downtime

So finding a way to connect securely is a key priority.

Whether it’s with a 4G router or through your internal network, our site connections use VPN technology to ensure site systems aren’t exposed to public internet traffic, and multi-factor authentication with an audit trail , giving you access and visibility without sacrificing on security. Our cloud-hosted BMS head-ends are deployed and hardened according to the latest manufacturer  guidelines, and regularly updated for the latest security fixes.

With the right connection and security procedures in place you can make your building smarter safely, and our IT Team and engineers offer expert help to choose and set up the connection that works for you.

By using a fully encrypted VPN tunnel to acquire BMS data, requiring multi-factor authentication for the select individuals who have permission to access the system, and ensuring that all connections to sensors or systems are secure, you can get the benefits of connectivity while protecting your system and your building.

In order to manage our customers’ connectivity more effectively we recently partnered with global leader Vodafone to deliver site connections.  This allows us to offer the security of a private SIM network with easier installation, end-to-end support through the connection life cycle and faster issue resolution, for a convenient, resilient and secure connection solution.

Ready to get connected safely?

If you’re interested in seeing how secure BMS connectivity could work for your building get in touch with us at sales@learnd.co.uk or request a quote.

company