Regulations, Risk, and Reality: What the Rules Really Mean for Controls

CyberBytes banner: Making Sense of Building Automation Cybersecurity on a blue gradient background, hosts Fred Gordy & Dave Bohlmann

If you’ve worked in building automation for any length of time, you’ve probably noticed that cybersecurity conversations are changing.

Not long ago, most discussions centered on protecting computers and networks. Today, they’re increasingly about protecting business operations.

When a cyber incident can shut down HVAC systems, disrupt building access, or make a facility temporarily unusable, the conversation naturally expands beyond IT. It becomes a question of operational resilience, business continuity, liability, and customer confidence.

That’s why understanding today’s cybersecurity landscape isn’t just helpful—it’s becoming an important part of serving customers well.


A New Kind of Risk

In 2019, attackers remotely took control of a commercial building’s HVAC and lighting systems until the building became unusable. A ransom demand followed. The incident was handled quietly through insurance, with no public disclosure or regulatory fines.

Dave Bohlmann refers to this type of attack as “siegeware.”

Unlike traditional ransomware, which encrypts files, siegeware targets the building itself. Occupants may not lose access to their data—but they can lose access to heating, cooling, lighting, ventilation, or other essential building functions.

The result isn’t simply a cybersecurity event. It’s an operational disruption.

As buildings become smarter and more connected, this type of operational risk deserves just as much attention as traditional cyber threats.


Regulations Are Only Part of the Story

One of the biggest misconceptions surrounding building automation cybersecurity is that organizations only need to worry when new regulations appear.

The reality is more nuanced.

While there are still no HVAC-specific cybersecurity laws, existing building codes, fire codes, OSHA requirements, contractual obligations, and civil liability can all become relevant when a cyber incident affects safety or building operations.

Just as importantly, customer expectations are changing.

Organizations increasingly expect vendors, contractors, and system integrators to understand cybersecurity risks, communicate clearly, and help identify practical ways to reduce them.

In many cases, cybersecurity has become less about regulatory compliance and more about responsible operations.


Insurance Is Asking Different Questions

Another significant change is happening in the insurance industry.

As cyber incidents affecting operational technology have become more common, insurers have begun looking beyond traditional IT environments.

Building owners may now be asked questions such as:

    • Is the building automation system remotely accessible?
    • Are OT and IT networks appropriately separated?
    • Who manages remote access credentials?
    • Are responsibilities for cybersecurity clearly defined?
    • Is there an incident response plan?

These aren’t simply insurance questions.

They’re practical questions that help organizations understand their own environments.

And they’re excellent conversation starters for system integrators working alongside customers.

 

Moving Beyond Compliance

It’s easy to think of cybersecurity as another compliance exercise.

But compliance establishes a minimum standard. Operational resilience aims for something greater.

Organizations that understand their systems, document responsibilities, coordinate vendors, and prepare for incidents are often better positioned to recover when unexpected events occur.

That’s one reason the CyberBYTES series focuses on preparation rather than fear. No organization can eliminate every risk.

Every organization can become better prepared.


What This Means for System Integrators

System integrators are uniquely positioned to help customers navigate this changing landscape. You don’t have to become an attorney or an insurance expert.

But you can help customers ask better questions.

You can encourage conversations about remote access, documentation, asset visibility, and operational planning before projects are complete instead of after an incident occurs.

Sometimes the greatest value isn’t installing another controller.

It’s helping customers understand risks they hadn’t considered yet—and giving them confidence that they’re taking practical steps to address them.

CyberBYTES Quick Check

Could your customer answer these questions today?

  • Who manages remote access?
  • What cyber risks could interrupt building operations?
  • Would insurance cover a siegeware event?
  • Who makes decisions during a cyber incident?

If those answers aren’t clear, you’ve identified an opportunity to strengthen operational resilience.


Watch the CyberBYTES Episode

In this CyberBYTES episode, Dave Bohlmann introduces the concept of siegeware and explains why regulations, insurance, and operational risk are reshaping cybersecurity conversations for building owners and system integrators.

▶ Watch the CyberBYTES Episode: Regulations, Risk, and Reality

Moving from Awareness to Action

Understanding today’s cybersecurity landscape isn’t about preparing for every worst-case scenario.

It’s about understanding how changing risks, customer expectations, and operational realities affect the buildings we design, maintain, and support.

KMC SCS™ (Secure Connected Solutions™) helps building owners and system integrators evaluate cybersecurity risks, improve operational resilience, and develop practical strategies that fit their environments—not generic checklists.

As cybersecurity continues evolving, organizations that prepare today will be better positioned to operate confidently tomorrow.

Related Resources

Learn more about KMC SCS™ https://www.kmccontrols.com/consulting/

Explore KMC DOME™ https://www.kmccontrols.com/product/kmc-dome-grouped/

Related Reading