Blog - Latest News

Smart buildings created an attack surface. Zero Trust owns it.

Smart buildings keep celebrating comfort and energy savings. Almost nobody owns the building automation security problem that arrives with them — the attack surface we just created.

Every controller, meter gateway, and BMS link is a door. When that door sits on the same path as identity and finance systems, “building kit” is operational technology in all but name. It falls into the same threat model as any other asset that can talk to corporate IT. NIST’s Zero Trust Architecture (SP 800-207) puts the point bluntly: focus on resources, not on network location, and authorize before a session starts. That framing is as useful for HVAC and access control as it is for SaaS.

I work security architecture across Victoria and remote clients. The pattern is consistent: facilities buys smart, IT inherits the blast radius, and nobody refreshes the system boundary. This piece expands a LinkedIn note from September 2026 — what the standards and surveys actually say about Zero Trust smart buildings, and what I keep pushing teams toward on OT/IT segmentation.

What the literature says about building automation security

Building automation is not a sealed island. Controllers talk to gateways. Gateways talk to cloud dashboards. Vendors dial in for support. Occupancy sensors feed analytics. Access control syncs with HR directories. Billing and energy platforms sit one hop from the LAN that hosts identity providers.

That picture is documented, not anecdotal. NIST SP 800-82 Revision 3 treats building automation systems as part of the OT estate and stresses safety and reliability constraints that pure IT risk models often miss. A 2021 Computers & Security survey by Graveto, Cruz, and Simões notes that BACS security has historically been addressed in a less structured way than industrial control systems, even as IP and IoT interconnection widen the attack surface around protocols such as BACnet and KNX. Li et al.’s critical review (arXiv 2210.11726) maps vulnerabilities across management, automation, and field levels, covering BACnet, KNX, LonWorks, and Modbus, and ties them to connectivity with intranet and internet paths. Morales-González and colleagues (2024) survey protocol-level attacks and observe that secure extensions such as BACnet/SC still leave meaningful gaps.

Connectivity is useful. It is also how HVAC, door controllers, and metering become lateral-movement paths. An unpatched gateway with a default credential is not a “building problem.” It is a foothold. Once you are on the OT side of a flat network, pivoting toward corporate IT is a networking exercise, not magic.

Teams often assume the vendor owns that. Vendors own their product. You own the environment it lands in — authentication, internet reachability, and what it can touch when something goes wrong.

Four practices that shrink Zero Trust smart buildings risk

None of this requires a new buzzword. It requires ownership and a living boundary.

1. Inventory every device — you cannot protect what you cannot see

Start with a living inventory: controllers, gateways, meters, badge readers, cameras on building VLANs, vendor jump boxes, cellular modems, and the odd Raspberry Pi left behind after a pilot. Capture firmware versions, management URLs, and who holds the credentials.

Passive discovery plus a walk of the plant room beats a spreadsheet finished last year. Map each asset to a function and an owner. If nobody owns it, it is already an exception — and exceptions are where breaches hide. Inventory is the precondition for OT/IT segmentation, patching, and Zero Trust access. Without it, every other control is theatre.

2. Segment building OT from corporate IT

Flat networks are the silent failure mode. Put building systems in dedicated segments with explicit allow-lists — not the same VLAN as printers and guest Wi‑Fi. North–south traffic to identity, monitoring, or cloud brokers should be intentional. East–west between BMS and finance should be rare or nonexistent.

Practical moves: separate VLANs or VRFs for OT, deny-by-default firewall rules, jump hosts for break-glass admin, and monitoring that alerts on unexpected protocols. If a temperature controller can open a session to your IdP or a finance database, your diagram is lying. Segmentation buys time. When a vendor appliance is compromised, you want the blast radius to stop at the building domain — not walk into Entra ID, AWS, or the ERP.

3. Treat vendor remote access as Zero Trust — not a permanent VPN hole

Permanent site-to-site VPNs and always-on vendor accounts are still common. They are also how “support access” becomes a standing tunnel into your estate. Prefer just-in-time access: time-boxed grants, MFA, least privilege to the specific gateway or console, session recording where it fits, and automatic revoke when the ticket closes.

Recent work on Zero Trust for critical OT systems (HICSS 2025) emphasises remote access and BYOD scenarios while acknowledging legacy limits — exactly the tension building operators face. Ask vendors to land in a broker you control, not directly on the OT LAN. You approve the session. You see the audit trail. You end it when the work is done.

4. Change defaults and own patch and credential governance in-house

“The vendor will do it” is not a control. Change default passwords before commissioning. Rotate shared service accounts. Track CVEs on the gateways you actually run. Decide who applies firmware and how you verify it.

Build a simple governance loop: asset owner, patch window, credential vault, and an exception register with expiry dates. If a controller cannot be patched, compensate with stricter segmentation and monitoring — and schedule replacement. Leaving known-bad firmware on a network path to identity is a choice, even when it feels inherited.

How Zero Trust Architecture maps to buildings

SP 800-207’s core tenets travel well outside the cloud:

  • Verify explicitly — every remote session, every admin console, every API to the BMS cloud.
  • Use least privilege — vendor roles scoped to the asset and the ticket, not domain admin forever.
  • Assume breach — segment so a compromised meter gateway cannot reach your IdP or billing stack.

If you already run Zero Trust for workforce access — Cloudflare Access, conditional access, workload identity — extend that policy language to building OT: who, what, from where, for how long. The HVAC network does not get a free pass because it “isn’t IT.” Cloud identity is often the crown jewel next door. Building systems that share a path to that identity plane belong in the same threat model as any other privileged service.

FAQ: Zero Trust and smart buildings

Does Zero Trust replace network segmentation for building OT?

No. SP 800-207 still assumes you protect resources with continuous verification; OT/IT segmentation is how you limit blast radius when a field device or gateway fails that verification. Treat them as complementary.

Is BACnet/SC enough to call a building “secure”?

It helps on the wire for BACnet paths, but Morales-González et al. and the broader survey literature show protocol upgrades alone do not close gaps at management, automation, and field layers — inventory, access brokerage, and patch governance still matter.

Where should facilities and IT start if the estate is already messy?

Inventory the devices that can reach corporate identity or the internet first. Segment those paths. Put vendor remote access behind time-boxed Zero Trust controls. Patch and credential work follows once you can see the estate.

Own the boundary

Smart buildings will keep shipping comfort and efficiency. The work is making sure HVAC, access control, and billing systems do not become lateral-movement paths because nobody refreshed the system boundary when the sensors arrived.

If you want a second opinion on architecture for Zero Trust smart buildings — inventory, OT/IT segmentation, vendor access, or a scoped review of a retrofit — I am available for that kind of conversation.

Services ·
Request a service ·
zameni.us

Expanded from a LinkedIn note (September 2026).

References

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *