BAS SECURITY
Building Automation Cybersecurity: Risks and Standards
Why building automation systems are targets, what CISA says about exposed BACnet, how BACnet Secure Connect works, how ISA/IEC 62443 and NIST SP 800-82 apply to buildings, and which training and certificates exist.

Building automation system (BAS) cybersecurity means protecting the controllers, networks and front ends that run HVAC, lighting, access control, lifts and metering, chiefly by keeping them off the public internet, separating them from IT networks, controlling contractor remote access and moving to authenticated, encrypted protocols such as BACnet Secure Connect. The frameworks to build on are ISA/IEC 62443, which ISA says applies to building automation, NIST SP 800-82 for operational technology, and CISA's guidance on reducing internet exposure.
Checked on 11 October 2026 against the sources listed under this post.
A building management system (BMS) is operational technology (OT). NIST's SP 800-82 Rev. 3, the US government guide to OT security, lists "building automation systems" alongside industrial control systems and physical access control systems as examples of OT. That matters, because it means the security lessons from factories and utilities apply to offices, hospitals, campuses and data centres too. NIST has also published an initial public draft of Revision 4, with comments due by 30 November 2026.
Why are building automation systems a target?
Building systems sit in an awkward place: they are critical to occupants, maintained by outside firms, connected for convenience and kept for decades.
- Long lives and old protocols. Controllers often stay in service for many years, and many still speak BACnet/IP, BACnet MS/TP, Modbus or LonWorks without encryption or device authentication.
- Contractor access. Mechanical, controls and fire contractors need remote access. Shared logins, always-on remote desktop tools and cellular modems are common.
- Flat networks. A BMS often shares switches or VLANs with the corporate network, so a compromise on one side can reach the other.
- Physical consequences. An attacker who can change set points or schedules can overheat a server room, unlock doors or disrupt a hospital ward.
The best-known example shows the contractor risk rather than the BMS itself. In 2014 Brian Krebs reported, from sources close to the investigation, that the attackers who breached US retailer Target first entered its network on 15 November 2013 "using network credentials stolen from" its HVAC contractor, Fazio Mechanical Services (Krebs on Security). The lesson for building engineers is that vendor access is part of the attack surface.
What does CISA say about exposed BACnet?
CISA's Internet Exposure Reduction Guidance warns that "threat actors can use internet-based search and discovery platforms" to find systems with default credentials and outdated software. Its list of services that deserve investigation includes port 47808, labelled "BACnet: Building automation and control networks", next to Modbus, DNP3 and OPC UA.
CISA is careful on two points. First, "an open port does not necessarily indicate a vulnerability or compromise", but every exposed OT service should be checked and justified. Second, "internet exposure reduction does not mean disabling necessary remote access"; the goal is to remove access that is not needed and secure what is. The guidance also tells owners to find out whether integrators, vendors or other third parties have remote access, including VPN credentials and cellular modems. CISA cites July 2026 activity against internet-exposed systems at more than 100 water and wastewater sector entities, commonly through PLCs connected directly to cellular modems, the same pattern found in many buildings.

How does BACnet Secure Connect improve security?
BACnet International describes BACnet/SC as "a secure, encrypted communication datalink layer", defined in Addendum 135-2016bj, that "uses WebSockets and TLS to implement peer authentication, message encryption, and reliable connection-oriented communication". It explains the key difference from BACnet/IP and MS/TP: BACnet/SC encrypts traffic so that no device on the network can read secure messages without the right keys.
When the addendum went to public review, ASHRAE's eSociety reported that all BACnet/SC connections are mutually authenticated, that it "eliminates broadcasts, supports DNS", uses TLS 1.3 and PKI certificates, and that it "should eliminate risky behavior such as placing unprotected devices directly on the internet" (ASHRAE, July 2019).

In this two-minute video, Siemens Knowledge Hub explains how BACnet/SC closes the security gap left by older BACnet networks. It is one of the lessons in our free Cybersecurity for Building Automation: BMS and BACnet course, which goes on to segmentation, secure remote access and zero trust.
Two cautions. BACnet International says BACnet/SC "does not replace existing BACnet options but complements them", so most sites will run mixed networks behind routers for years. And BACnet/SC adds a certificate system that someone must own: issuing, renewing and revoking device certificates is a new maintenance task that should be in the commissioning and handover documents.
How do ISA/IEC 62443 and NIST apply to a building?
ISA states on its 62443 page that the series sets cybersecurity benchmarks "in all industry sectors that use IACS, including building automation", and that in 2021 IEC recognised it as a horizontal standard. ISA calls shared responsibility a founding principle: the standards set requirements for asset owners, product suppliers, integrators and service suppliers. In a building, that means the owner, the BMS manufacturer, the controls contractor and the maintenance firm each have defined duties.
| 62443 idea | What it means in a building | Who owns it |
|---|---|---|
| Zones | Group systems by function and consequence: HVAC, access control, lifts, metering, fire interfaces | Owner, with the consultant |
| Conduits | Every connection between zones, to IT and to the outside, with its controls | Owner and integrator |
| Security levels | The target strength of protection for each zone, based on risk | Owner |
| System requirements (62443-3-3) | The security functions the BMS as delivered must provide | Integrator |
| Component requirements | Secure controllers, supervisors and software | Product supplier |
| Service provider requirements | How the maintenance firm handles access, patches and changes | Service supplier |
NIST SP 800-82 complements this with US-government guidance on OT architecture, risk management and controls, and is free to download. Many owners use 62443 for the contract language with suppliers and integrators, and NIST or their own corporate security policy for the governance.

Our earlier guide to OT cybersecurity and IEC 62443 explains the series in more depth, and free IEC 62443 training lists the free courses that teach it. For a real-world reminder of what OT attacks look like, see our report on Iran-linked PLC attacks in 2026.
Build security into commissioning and handover
The cheapest time to secure a building is before it is handed over. Add security checks to the controls commissioning scripts: confirm that no BMS device answers from the internet, that default passwords have been changed, that each contractor has a named account, that the remote access path works only as designed, and that the network matches the zone and conduit drawings. Hand the owner an asset list, the network drawings, the account list and, on BACnet/SC sites, the certificate records, so the operations team can keep the system secure after the contractors leave.
What training and certificates exist for BAS cybersecurity?
There is no single licence for building automation security. The skills combine BMS engineering, networking and OT security, and the credentials come from different bodies.
| Credential or route | Issued by | What it shows |
|---|---|---|
| ISA/IEC 62443 Cybersecurity Fundamentals Specialist | ISA | Course and exam on the 62443 series; the first of four certificates |
| ISA/IEC 62443 Cybersecurity Expert | ISA | Awarded automatically after all four ISA 62443 certificates |
| BMS vendor training | Each manufacturer | Competence on that vendor's controllers and front end |
| Employer or client authorisation | The owner | Permission to work on a specific site's systems |
ISA's certificate programme says "each certificate requires successful completion of a course and exam", that Certificate 1 comes first and the rest can be taken in any order, and that the Expert certificate is awarded on completing all four. Training firms can teach the material; the certificate itself comes from ISA.
Free courses for building automation security
Start with Cybersecurity for Building Automation: BMS and BACnet, which contains the Siemens video above. If you need the BMS basics first, Building Management Systems (BMS): HVAC Control, BACnet and Building Automation covers controllers, points, protocols and commissioning. To go deeper on the standard, OT and ICS Cybersecurity with ISA/IEC 62443 walks through zones, conduits and security levels. Our guide on how to verify an engineering training certificate explains what employers check when you list any of these.
Every course is free in full. An optional EDWartens Certificate of Completion, from US$8.99, is not an ISA/IEC 62443 certificate, is not issued by ISA and is not accredited; anyone can verify it at edwartens.com/verification.
Take the free course
Questions
Why are building automation systems a cybersecurity risk?
They control physical services such as HVAC, lighting, access and lifts, they often run for many years on older protocols without encryption, and they are maintained remotely by outside contractors. An exposed controller or a stolen vendor login can give an attacker a path into the building or the corporate network.
Is BACnet secure?
Classic BACnet/IP and MS/TP carry messages without encryption. BACnet Secure Connect (BACnet/SC), defined in Addendum 135-2016bj, adds mutually authenticated, encrypted connections using TLS and secure WebSockets. It complements the older options, so most buildings will run a mix for years.
Does ISA/IEC 62443 apply to buildings?
Yes. ISA says the 62443 series sets cybersecurity benchmarks in all sectors that use industrial automation and control systems, naming building automation, and that IEC recognised it as a horizontal standard in 2021. Its zones, conduits, security levels and supplier requirements map directly onto a BMS.
What does CISA recommend for internet-exposed building systems?
CISA's Internet Exposure Reduction Guidance says to identify internet-accessible assets, remove exposure that is not needed and secure the remote access that is. It lists port 47808, BACnet, among the services to investigate, while noting an open port is not proof of compromise.
Which certifications exist for building automation cybersecurity?
There is no single building-specific licence. Widely recognised options include ISA's four ISA/IEC 62443 cybersecurity certificates, starting with the Cybersecurity Fundamentals Specialist, which each need a course and an exam. These come from ISA, not from training providers that teach the material.
Can a free course prepare me for BMS security work?
It can give you the background: how BMS networks and BACnet work, where they are weak and how 62443 is applied. It does not replace an ISA certificate, vendor training or experience on live systems, and a certificate of completion is evidence of study, not of competence.
Sources
- CISA: Internet Exposure Reduction Guidance (read 11 October 2026)
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security (September 2023), with planning note on Rev. 4 draft (21 September 2026)
- ISA: ISA/IEC 62443 Series of Standards (read 11 October 2026)
- ISA: ISA/IEC 62443 Cybersecurity Certificate Program (read 11 October 2026)
- BACnet International: BACnet Secure Connect (read 11 October 2026)
- ASHRAE eSociety: Protecting Building Automation Systems with BACnet Secure Connect (July 2019)
- Krebs on Security: Target Hackers Broke in Via HVAC Company (5 February 2014)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

Purdue Model for ICS Security: The Levels Explained

IEC 62443 Explained: Roles, Zones and Security Levels

Zeek for ICS: Logging Industrial Protocols With ICSNPP

Cyber Resilience Act Reporting Obligations: What Machine Builders and OEMs Must Do Now

Controls Engineer Certifications: CAP, CCST and More

Do Online Courses Count as CPD or PDH for Engineers?


