
Operating reality
Somebody else installed it, and somebody else still connects to it.
In most industrial sectors the operator employs the engineers. In buildings, that is rarely the arrangement. The estate is run by a facilities team, and the systems within it were specified by a designer, installed by a contractor, commissioned by an integrator and are still remotely supported by that integrator under a maintenance agreement signed years ago. Ownership of the asset and control of the access are frequently in different hands.
The technical picture follows from that. BACnet, Modbus, LonWorks and KNX coexist because each subsystem was procured separately, and they often share one flat network because nothing in the original scope required otherwise. Cloud-connected analytics, energy dashboards and remote-support portals were added over time by whoever was engaged at the time, each with its own outbound connection, and no single review ever considered them together.
Shared occupancy adds a boundary problem that has no equivalent on a plant site. One network and one building management system may serve a landlord, several tenants and a managed service provider, so a question as simple as who declares an incident and who authorizes a response has a contractual answer before it has a technical one.
So the program starts with the register nobody owns — every system, every connection, every party with a route in, and the agreement that grants it. Segmentation and monitoring follow, and they are far easier to design once the access picture is honest.
In a building, the first security question is not what is connected. It is who holds the contract that connects to it.
Operational priorities
Four things facilities programs have to get right.
These are the priorities that decide whether an estate program holds together across buildings, contracts and tenants, ahead of any question about tooling.
01 · Access is a contract question first
Integrator, contractor and OEM connections exist because a commercial agreement created them. They are inventoried against those agreements, brokered through a managed route, and tightened at renewal or retender rather than by asking a supplier to volunteer a change.
02 · One network, many protocols
BACnet, Modbus, LonWorks and KNX rarely authenticate anything on their own, so the protection is architectural. Zoning is drawn by service criticality, with the systems that keep the building habitable separated from those that merely report on it.
03 · Life safety stays out of scope
Fire detection, suppression, emergency lighting and life-safety interlocks are reviewed by documentation and configuration only. They are never tested, exercised or used to demonstrate a finding, and their certification authority is never disturbed.
04 · A defined boundary per occupant
Where a landlord, tenants and a service provider share infrastructure, the program names who owns each system, who is notified, who decides, and who may act. Without that, an incident is spent establishing authority rather than restoring service.
In scope
Five environments we work in.
Collection is passive and review is configuration-based. Fire and life-safety systems are examined on paper only, and no work is performed in a clinical, live-tenant or operationally critical space without the building's own permit and change process.
BMS, BAS and HVAC
Head-end and supervisory servers, field controllers and unitary devices, chillers and chilled water plant, air handling and terminal units, and the graphics, scheduling and trending layers above them — commonly a mixture of BACnet, Modbus, LonWorks and KNX because each subsystem was procured separately.
These protocols authenticate little or nothing on their own, so protection is architectural rather than device-level. We work from the head-end configuration, controller lists, network drawings and passively collected traffic. Nothing is written to a controller, no setpoint is changed, and no override is used to demonstrate a finding in an occupied space.
Power, UPS and generation
Electrical distribution and power monitoring, UPS and battery systems, generator control and automatic transfer switching, and the interfaces that make a facility resilient on the drawing.
Fire detection, suppression, emergency lighting and life-safety interlocks are reviewed by documentation and configuration only. They are never tested, never exercised, and their certification authority is never disturbed. For the rest, the question worth answering is whether the resilience is only as independent as it appears: dual paths managed through one gateway, one credential or one supplier's remote connection are a single point that the topology diagram does not show.
Security and access systems
Access control head-ends and door controllers, video surveillance and its storage, intrusion detection, and visitor management, with the workstations and servers that support them.
These systems are often the best connected and least governed on an estate, because they were installed by a security contractor rather than by an IT or engineering function. Cameras and controllers reach the internet for support, credentials are shared across sites, and firmware sits where it was at handover. Review is by configuration and by contract, and findings are framed so they can be raised with the security integrator under the agreement that already exists.
Facilities network and cloud services
The building network and its VLANs, the boundary with corporate or tenant IT, and the cloud analytics, energy optimization platforms, metering services and support portals reached across it.
Each outbound service was added by whoever was engaged at the time, and no single review has looked at them together. We rebuild that picture from firewall rule sets and routing, establish which connections are genuinely outbound-only and which can accept a session in return, and give each a stated purpose and a named owner. Where a landlord, tenants and a service provider share infrastructure, the boundary is documented per occupant before anything is redesigned.
Integrator and contractor access
Every remote path held by BMS integrators, maintenance contractors, security installers and OEMs, the credentials behind them, the agreements that authorize them, and what happens to each when a contract ends.
This is usually where the engagement starts, because it is the register nobody owns. Each path is inventoried against the commercial agreement that created it, then brokered through a managed route with credentials you issue and entitlements that expire. The controls that hold in this sector are contractual as much as technical, so requirements are written as specification language for the next maintenance retender rather than as a request for a supplier to give something up mid-term.
Related solutions
Where facilities engagements usually start.
Each stands alone. Most estates begin with one building that is representative of the portfolio, and reuse the specification and contract language it produces everywhere else.
Questions from this sector
What estates and facilities teams ask us first.
The integrator owns the BMS, not us. What can we actually change?
More than it feels like, though the lever is commercial rather than technical. You own the building, the network it sits on and the agreement that grants the access. The first deliverable is a register of every system, every connection and the contract behind it, which in most estates has never existed in one place.
From there, some things can be done unilaterally — network segmentation, the boundary to corporate or tenant IT, monitoring, and how integrator access is routed. The rest becomes specification language for the next maintenance retender or renewal, which is where terms like credential ownership, session brokering and revocation on demobilization are genuinely won.
We are the landlord. Tenants and a managed service provider share the same systems. Whose incident is it?
Contractually yours to establish before it happens, which is why we treat it as a design output rather than a footnote. The program names, per system, who owns it, who is notified, who decides, and who may act, and it does so in language that can be attached to a lease or a service agreement.
Without that, an incident is spent establishing authority instead of restoring service, and the argument happens while cooling or access is degraded. It is a short document and it is worth writing early.
Our facility is concurrently maintainable. If a controller fails, we fail over.
Resilience designed for component failure is not the same as resilience against a common cause, and that distinction is the whole of the answer. Redundant plant frequently shares one supervisory head-end, one engineering credential, one integrator connection or one management VLAN.
A failure takes one path. A compromised shared layer can affect both at once, and it can do so while the graphics still show a healthy system. We establish from configuration whether the independence is real, and where it is not, the remedy is usually modest — separating the management layer rather than rebuilding the plant.
Nothing can happen in a clinical area, a live tenant space or a data hall.
Agreed, and the assessment does not require it. Collection is passive and analysis is built from head-end configuration, controller lists, network drawings, firewall rule sets and the maintenance contracts, none of which needs entry to a sensitive space or any change to a running system.
Where physical work is eventually needed, it goes through your permit, access and change process on your timescale, with the same notice and escorting rules any other contractor would follow. We do not ask for an exception on the basis that the work is security work.
IT says building systems are not on the corporate network, so they are out of scope.
That is often how these systems end up unowned — outside the IT perimeter, outside the engineering standard, and connected to more than either party realizes. The separation is also rarely as clean as described: an energy dashboard, a metering feed, a shared authentication service or an integrator's portal usually crosses it somewhere.
The useful outcome is not moving building systems under IT. It is naming an owner for them, agreeing what IT provides, such as identity, monitoring and network engineering, and what the estates and engineering team retains, including the authority to decide when a change may land in an occupied building.
Next step
Start with one building and the access register.
A single representative site establishes effort, disruption and value before anything is committed across the portfolio, and produces the specification and contract language every subsequent building and retender can reuse.
- No active scanning — passive collection and configuration review only
- Fire and life safety excluded from testing — reviewed on paper, never exercised
- Occupied spaces respected — your permit, access and change process governs the work
- Integrator agreements reviewed, not bypassed — findings written so they can be contracted
- Vendor-independent — no reseller relationship with any BMS or security platform
Questions from this sector
What operators in this industry ask first.
Is building automation part of OT cybersecurity?
Yes. Building management, power distribution and UPS, cooling, fire and life safety, access control and lift systems are control systems with physical consequence. In a data centre, hospital or airport their failure stops the operation as surely as a process failure stops a plant, and they are frequently less governed than the IT estate beside them.
What is different about securing critical facilities?
Ownership. A facility's control systems are often installed by contractors, maintained by service providers, connected by a landlord or a building operator, and owned — on paper — by a facilities function that does not see itself as running industrial technology. The first piece of work is usually establishing what exists and who is accountable for it.
Which facilities does InnovAKT work with?
Data centres, hospitals and healthcare campuses, airports and transport facilities, and large commercial and institutional estates — environments where power, cooling, access and life safety have to keep working and where a building's control network has quietly become critical infrastructure.