BMS Security in Plain English
What a building management system runs, what it speaks on the wire, where buildings get exposed, and what an assessment involves. Written for the people who run buildings, with the standards named at the end for the people who audit them.
The BMS runs the plant. Chillers, air handlers, pumps, lighting and the schedule, from one head-end.
It speaks BACnet/IP. A protocol written for a trusted network. Anything on the segment can read it, and can write to it.
Half of all buildings have theirs on the internet. By accident, through a modem, a portal, or a port someone opened for a contractor.
An assessment is passive. A walk, photographs and captures. Fire and lifts are observed and left as found.
What the BMS runs
A building management system is the head-end and the controllers that run the mechanical plant: the chillers and cooling towers, the air handlers and the VAV boxes on each floor, the pumps, the lighting, and the schedule that decides when the building is occupied. In most Australian commercial buildings it is a Siemens, Honeywell, Schneider, Johnson Controls, Delta, Distech or Innotech platform, installed by a mechanical services contractor and maintained under a service agreement.
Over the years it has also become the place other systems report to. The fire panel tells it what to do in fire mode. The access control system shares a switch with it. The energy analytics provider reads from it over the internet. The integrator dials into it to fix things. Each of those arrived on its own contract, and each one is a path.
What it speaks
Controllers and head-ends talk BACnet, and on modern sites BACnet/IP over ordinary Ethernet. The protocol dates from a time when the building network was its own island, so it carries no password of its own: a device that can reach the segment can read every value and write every setpoint. That is by design, and it is the single fact that makes segmentation the first control on every list.
BACnet Secure Connect, published in 2019, carries the same messages inside TLS: a known device sends, a known device reads, and a listener on the segment sees an encrypted stream. The major platforms support it on their current hardware. Adoption in Australian buildings is early and usually arrives with a head-end upgrade, so for most sites the practical answer today is a network of its own for the BMS, with a gate between it and anything a person can reach.
Where buildings get exposed
Six systems account for most of what an assessment finds, and a facilities manager can point to every one of them from the footpath.
The BMS controller in the roof plant room, on a segment it shares with the tenants. The access control panel in the comms room, holding every credential and door schedule, often the oldest device on the network. The fire indicator panel at the main entry, whose signalling unit reports to the monitoring provider over 4G and IP under AS 1670.3 and whose interface to the BMS drives the air handling in fire mode. The lift controller in the motor room, with an IP link or a modem for the lift company's remote monitoring. The unmanaged device, a camera or a foyer screen added by a contractor with a factory password and a cloud account nobody owns. And vendor remote access, the portals and VPNs whose accounts outlive the contracts that created them.
On the internet, by accident
In 2013 two researchers found the building management system of Google's Wharf 7 office in Sydney on a public search engine for connected devices, reached it through an unpatched Tridium Niagara instance, and pulled the configuration file with its passwords. Google disconnected it the same week. Twelve years later the pattern holds: a 2025 study of nearly 500,000 building devices across 500 organisations found half of the building management systems insecurely connected to the internet, and three quarters of the organisations running BMS devices with known, exploited weaknesses.
What an assessment involves
A call, thirty minutes. You describe the building and who maintains what. A fixed price follows in writing within two business days.
The site walk, one to two days. A walk of the plant rooms, the comms rooms and the risers, with photographs. Network captures are passive: a mirror port on the switch and a laptop that listens. Everything keeps running. The fire panel and the lifts are observed and left exactly as found, and that rule is written into the scope letter before anyone is on site.
The analysis, one to two weeks. Every controller, panel and device on an inventory, built the way the joint ASD and CISA guidance of August 2025 specifies it: protocol, role, address, firmware, who owns it. The network drawn as it really is, then grouped into zones and conduits under AS IEC 62443. Each way in from outside tested from outside.
The report and the briefing, half a day. A one-page summary the owner reads and a findings register your contractors work from. Every finding carries its evidence, the capture or the configuration or the screenshot that shows it, and its fix, with the contractor who owns that fix named. One briefing for you, one for your contractors if you want it.
The cloud edge
The remote paths into a building are the half of its security that lives outside it: the integrator's VPN, the lift company's modem, the security installer's portal, the analytics vendor's API, and the previous integrator's account that was never closed. The work is a roster of every path with who uses it and when, then one gate for the ones that stay: a jump host with a second factor and a log, so a vendor session is a recorded session and an ended contract is a closed account. Azure first, because that is what Canberra runs, then the rest.
What to ask your integrator
Five questions, and the answers tell you most of what an assessment would. Which switch is the BMS on, and who else is on it? How do you reach it from your office? Which of your staff have an account, and when did the last person leave? When was the head-end last patched? Does the fire panel talk to the BMS over the network, and who tested that path last?
The standards your auditor recognises
ASD's Principles of operational technology cyber security (October 2024), co-sealed by CISA, NSA and partners, set the six principles every assessment here follows, beginning with safety. The joint asset inventory guidance (August 2025) sets the inventory method. AS IEC 62443, adopted by Standards Australia in July 2025 with building automation named in the announcement, gives the zones, conduits and security levels. AS 1670.3 governs the fire panel's monitoring link and ISO 8102-20 the cyber requirements for new lifts. The Essential Eight is an IT model, and ASD says so for OT; the report explains where it stops at the plant room door.
Figures: Claroty Team82, June 2025, reported by SecurityBrief Australia; Infosecurity Magazine on the Wharf 7 case, 2013; cyber.gov.au for the ASD publications; Standards Australia, 10 July 2025.
Send the building's address and the BMS brand. A fixed price follows within two business days.
Get a fixed quote