
A locked front door matters.
But if someone gets through it, you probably don’t want every other door in the building standing wide open. That’s essentially the problem many building automation networks face today. Firewalls, VLANs, remote-access controls, and other perimeter defenses all serve an important purpose: they make it harder for unauthorized users to enter the network in the first place.
But cybersecurity can’t stop there. During a recent “Stuck on a Bucket” webinar, Veridify Security CTO Derek Atkins put the issue in practical terms: building owners and integrators also need to think about what an attacker can do after that perimeter has been crossed.
And in many operational technology (OT) environments, that’s where the larger problem begins.
Why “Inside the Network” Can Carry Too Much Trust
Many OT networks are relatively flat. Once a device or user has access to the network, other devices may implicitly trust traffic coming from inside it.
In other words, getting through the perimeter can open up much more than one system. An attacker who compromises credentials, exploits a connected system, or crosses over from an IT environment may be able to move from one device to another because those devices have no reason to question whether a command coming from inside the network is legitimate.
That movement is known as lateral movement, and preventing it is an important part of modern OT cybersecurity.
A Firewall Still Matters
This doesn’t mean the firewall failed at its job.
It means the firewall has a particular job.
Think of a firewall as the gate around a neighborhood. It helps determine who gets through the entrance, and a well-designed perimeter can stop a great deal of unwanted traffic. But once someone is past the gate, the perimeter alone can’t necessarily determine which house that person enters, which room they access, or what they do once they get there.
The same is true for anomaly detection and monitoring tools.
Those tools can provide valuable visibility when something unusual happens. They can alert operators to suspicious traffic, unexpected behavior, or potential compromise. But an alert and an intervention are two different things. By the time someone receives the notification, investigates what happened, and responds, the unauthorized command may already have reached its destination.
That’s why good cybersecurity increasingly relies on layers rather than one perfect defense.
What If the Network Didn’t Automatically Trust You?
Zero Trust turns the traditional assumption around.
Instead of saying, “You’re already on the network, so you must belong here,” a Zero Trust approach requires verification. In a building automation environment, that can mean authenticating the devices themselves and verifying that communication is authorized before a command is acted upon. The distinction matters. An attacker could technically gain access to the network and still be unable to issue a valid command to protected equipment.
Being inside is no longer enough.
This is the principle behind device- and packet-level protection technologies such as KMC Dome™. Rather than replacing perimeter security, this type of protection adds another layer inside it by giving protected devices cryptographic identities and authenticating their communications. If one part of the network is compromised, that compromise does not automatically have to become permission to move everywhere else.
Why This Matters in Buildings
Building automation systems control physical equipment and conditions inside a facility. HVAC operation, ventilation, access control, lighting, and other connected systems can all affect how a building functions day to day. That means an unauthorized command is not just information moving across a network. It can result in something changing in the physical building.
That changes the cybersecurity conversation. The question isn’t simply: Can someone get in?
It also becomes: If they do, how far can they go?
Assume One Layer May Eventually Fail
No cybersecurity measure eliminates every possible risk. That’s exactly why defense in depth matters.
A firewall can help protect the perimeter. Monitoring can help identify unusual behavior. Strong credentials and good access practices can reduce obvious vulnerabilities. Device-level protection can help prevent unauthorized traffic from being acted upon even when another defensive layer has been crossed.
None of those makes the others unnecessary; rather, they make one another stronger.
For building owners and system integrators, that may be the more useful way to think about OT cybersecurity: not as building an impenetrable wall around the network, but as making sure one breach doesn’t automatically become access to everything behind it.
Because planning for the attack is just as important as preventing the attack.