The Orphan in OT Security: Why Building Systems Are Everyone’s Blind Spot

I was in a discussion recently with an OT colleague who has spent his entire career in industrial environments, primarily in the energy sector, with very little exposure to manufacturing.

At one point, he asked me a simple question: “What exactly is OT in buildings?”

That question led to a realization we don’t talk about enough:

Building OT is the orphan of cybersecurity.

“That’s Not OT — That’s Facilities”

Every time I hear that sentence during an assessment, I already know what I’m about to find.

  • A flat network running BACnet next to a corporate VLAN
  • Unknown vendor remote access paths
  • Controllers installed in 2008 still running critical environments
  • And a security program that has invested millions in industrial OT… while building systems are effectively unmanaged

This isn’t a technical gap. It’s an ownership gap.

And it’s one of the most consistent and overlooked risks in modern organizations.

Two Faces of OT—Only One Gets Defended

We talk about OT as if it’s one domain. It’s not.

1. Industrial OT (Well Understood, Well Defended)

  • Power generation, oil & gas, water, manufacturing
  • Defined standards (IEC 62443, NIST 800-82, NERC CIP)
  • Dedicated OT security programs and leadership
  • Mature tooling and detection capabilities

2. Building OT (Widely Deployed, Poorly Governed)

  • HVAC, lighting, elevators, fire systems, access control
  • Building Management Systems (BMS)
  • Energy management and environmental controls
  • Critical infrastructure for hospitals, data centers, and pharma

This second category?

It rarely sits in a CISO’s risk register. Instead, it lives across:

  • Facilities
  • Real estate
  • Third-party contractors
  • Or legacy vendor agreements no one has reviewed in years

That fragmentation is exactly why it becomes invisible.

What People Miss About Building OT

Calling it “facilities” dramatically understates the risk.

In Healthcare

Building OT controls:

  • Operating room pressure environments
  • Isolation room airflow
  • Pharmacy compounding conditions

Failure here isn’t discomfort; it’s clinical risk.

In Pharmaceuticals

It governs:

  • Cleanroom pressure differentials
  • Temperature and humidity for product stability
  • Environmental compliance controls

A failure isn’t just a bad batch, it’s regulatory exposure.

In Data Centers

It controls:

  • Cooling systems for IT load
  • Power redundancy switching
  • Fire suppression systems

The same organization that enforces Zero Trust in IT often tolerates flat, unmanaged networks one floor below.

Why This Gap Exists

This isn’t negligence, it’s structural.

Traditional security models were built for IT, and even in OT, they were shaped around industrial systems.

But as outlined in your broader OT security work:

  • OT prioritizes availability and safety over confidentiality
  • Systems live for decades, not years
  • Downtime is not acceptable
  • Technology is often proprietary and fragile

Now apply that to building systems with no centralized ownership.

You get:

  • No asset visibility
  • No patch strategy
  • No monitoring
  • No incident response alignment

In short: unmanaged cyber-physical risk.

The Convergence Problem No One Owns

We often talk about IT/OT convergence.

But building OT sits in a third space:

  • Connected to IT networks
  • Influencing OT-like physical processes
  • Owned by neither

It’s not fully IT. It’s not treated like industrial OT.

So it becomes… everyone’s problem and no one’s responsibility.

The Real Risk: It’s Not Just Systems—It’s Entry Points

Building OT is not just operationally critical.

It’s also one of the easiest entry points into the enterprise:

  • Vendor remote access with weak controls
  • Internet-exposed BMS interfaces
  • Flat networks with no segmentation
  • Legacy protocols with no authentication

We’ve seen this pattern before.

Attackers don’t go through the front door. They go through the side entrance; no one is watching.

What Needs to Change

If you’re an OT CISO or security leader, this is where the shift starts.

1. Expand the Definition of OT

If it controls a physical process, it’s OT. That includes buildings.

2. Bring Building OT Into Governance

  • Add it to your asset inventory
  • Include it in risk assessments
  • Align it with your OT security program

3. Fix Ownership

This is the hardest part.

Security doesn’t need to “own” the building OT. But it must govern the risk.

That means aligning:

  • IT
  • Security
  • Vendors

4. Apply OT-Appropriate Controls (Not IT Copy/Paste)

Avoid the common mistake of forcing IT controls into OT environments.

Instead:

  • Segment networks
  • Control and monitor remote access
  • Implement passive visibility
  • Use compensating controls for legacy systems

Because what works in IT can break OT if applied blindly.

Closing Thought

Building OT isn’t a niche problem.

It exists in:

  • Every hospital
  • Every data center
  • Every corporate campus
  • Every smart building

And in most organizations, it’s still unaccounted for.

The industry has matured in securing industrial OT. But until we address building OT, we’re only protecting half the system.

Call to Action

Take a look at your current OT program.

Does it include building systems, or are they still treated as “facilities”?

Because the attackers already know the answer.

Previous
Previous

Two Years On: What My 2024 OT Predictions Got Right, Got Wrong, and Missed Entirely

Next
Next

When Pride Turns Into Exposure: How Social Media Posts Put ICS Environments at Risk