The Orphan in OT Security: Why Building Systems Are Everyone’s Blind Spot
I was in a discussion recently with an OT colleague who has spent his entire career in industrial environments, primarily in the energy sector, with very little exposure to manufacturing.
At one point, he asked me a simple question: “What exactly is OT in buildings?”
That question led to a realization we don’t talk about enough:
Building OT is the orphan of cybersecurity.
“That’s Not OT — That’s Facilities”
Every time I hear that sentence during an assessment, I already know what I’m about to find.
- A flat network running BACnet next to a corporate VLAN
- Unknown vendor remote access paths
- Controllers installed in 2008 still running critical environments
- And a security program that has invested millions in industrial OT… while building systems are effectively unmanaged
This isn’t a technical gap. It’s an ownership gap.
And it’s one of the most consistent and overlooked risks in modern organizations.
Two Faces of OT—Only One Gets Defended
We talk about OT as if it’s one domain. It’s not.
1. Industrial OT (Well Understood, Well Defended)
- Power generation, oil & gas, water, manufacturing
- Defined standards (IEC 62443, NIST 800-82, NERC CIP)
- Dedicated OT security programs and leadership
- Mature tooling and detection capabilities
2. Building OT (Widely Deployed, Poorly Governed)
- HVAC, lighting, elevators, fire systems, access control
- Building Management Systems (BMS)
- Energy management and environmental controls
- Critical infrastructure for hospitals, data centers, and pharma
This second category?
It rarely sits in a CISO’s risk register. Instead, it lives across:
- Facilities
- Real estate
- Third-party contractors
- Or legacy vendor agreements no one has reviewed in years
That fragmentation is exactly why it becomes invisible.
What People Miss About Building OT
Calling it “facilities” dramatically understates the risk.
In Healthcare
Building OT controls:
- Operating room pressure environments
- Isolation room airflow
- Pharmacy compounding conditions
Failure here isn’t discomfort; it’s clinical risk.
In Pharmaceuticals
It governs:
- Cleanroom pressure differentials
- Temperature and humidity for product stability
- Environmental compliance controls
A failure isn’t just a bad batch, it’s regulatory exposure.
In Data Centers
It controls:
- Cooling systems for IT load
- Power redundancy switching
- Fire suppression systems
The same organization that enforces Zero Trust in IT often tolerates flat, unmanaged networks one floor below.
Why This Gap Exists
This isn’t negligence, it’s structural.
Traditional security models were built for IT, and even in OT, they were shaped around industrial systems.
But as outlined in your broader OT security work:
- OT prioritizes availability and safety over confidentiality
- Systems live for decades, not years
- Downtime is not acceptable
- Technology is often proprietary and fragile
Now apply that to building systems with no centralized ownership.
You get:
- No asset visibility
- No patch strategy
- No monitoring
- No incident response alignment
In short: unmanaged cyber-physical risk.
The Convergence Problem No One Owns
We often talk about IT/OT convergence.
But building OT sits in a third space:
- Connected to IT networks
- Influencing OT-like physical processes
- Owned by neither
It’s not fully IT. It’s not treated like industrial OT.
So it becomes… everyone’s problem and no one’s responsibility.
The Real Risk: It’s Not Just Systems—It’s Entry Points
Building OT is not just operationally critical.
It’s also one of the easiest entry points into the enterprise:
- Vendor remote access with weak controls
- Internet-exposed BMS interfaces
- Flat networks with no segmentation
- Legacy protocols with no authentication
We’ve seen this pattern before.
Attackers don’t go through the front door. They go through the side entrance; no one is watching.
What Needs to Change
If you’re an OT CISO or security leader, this is where the shift starts.
1. Expand the Definition of OT
If it controls a physical process, it’s OT. That includes buildings.
2. Bring Building OT Into Governance
- Add it to your asset inventory
- Include it in risk assessments
- Align it with your OT security program
3. Fix Ownership
This is the hardest part.
Security doesn’t need to “own” the building OT. But it must govern the risk.
That means aligning:
- IT
- Security
- Vendors
4. Apply OT-Appropriate Controls (Not IT Copy/Paste)
Avoid the common mistake of forcing IT controls into OT environments.
Instead:
- Segment networks
- Control and monitor remote access
- Implement passive visibility
- Use compensating controls for legacy systems
Because what works in IT can break OT if applied blindly.
Closing Thought
Building OT isn’t a niche problem.
It exists in:
- Every hospital
- Every data center
- Every corporate campus
- Every smart building
And in most organizations, it’s still unaccounted for.
The industry has matured in securing industrial OT. But until we address building OT, we’re only protecting half the system.
Call to Action
Take a look at your current OT program.
Does it include building systems, or are they still treated as “facilities”?
Because the attackers already know the answer.