It’s a fair question.
You’ve segmented the network. You’ve installed a firewall. Maybe you’ve even worked with the IT department to separate the building automation system from the rest of the organization’s network.
So…is it secure?
The honest answer is that it depends.
One of the biggest misconceptions about cybersecurity is that it’s something you can buy, install, and check off a list. We naturally look for the one solution that solves the problem—a firewall, a secure gateway, a new appliance, or the latest software update. Those technologies all have an important role to play, but cybersecurity doesn’t really work that way.
Securing a building automation system is much more like constructing a building itself. You don’t rely on a single beam to hold up the structure. Every wall, column, and connection contributes to the building’s overall strength. Remove enough of those pieces, and even the strongest structure becomes vulnerable.
The same principle applies to a BACnet network.
BACnet Was Designed for a Different Time
One of BACnet’s greatest strengths has always been interoperability. It allows controllers, sensors, workstations, and equipment from different manufacturers to communicate with one another, giving building owners the flexibility to choose the solutions that best fit their needs instead of being locked into a single vendor.
That flexibility is one of the reasons BACnet became the industry’s most widely adopted building automation protocol. But it’s also important to remember when it was developed.
When BACnet was introduced, most building automation systems lived on isolated networks. The expectation wasn’t that controllers would routinely communicate across enterprise networks, connect to cloud services, or provide remote access from virtually anywhere. Features like encryption, authentication, and access control simply weren’t part of the original protocol because they weren’t solving the problems the industry faced at the time.
Today’s buildings operate in a very different environment. Building automation systems are more connected than ever, which means protecting them requires adding security around the protocol rather than expecting the protocol itself to do everything.
That doesn’t make BACnet outdated. It simply means we have to be thoughtful about how we deploy and support it.
Good Security Begins Long Before Commissioning
It’s easy to think of cybersecurity as something that gets added near the end of a project. Once the controllers are online, the graphics are working, and the owner is preparing for turnover, security can feel like one more item to complete before the checklist is finished.
In reality, many of the most important cybersecurity decisions happen much earlier.
How will the network be organized? Where should traffic be separated? Who will have remote access after the project is complete? How will new devices be added? Who is responsible for maintaining network documentation once the system changes hands?
None of those decisions involve installing security software, yet they shape the security of the system for years to come.
That’s why experienced system integrators often think of network hardening as part of good system design rather than a separate cybersecurity exercise. Segmenting networks with VLANs helps contain problems before they spread. Firewalls and access control lists limit unnecessary communication between systems. Changing default passwords, disabling unused services, and documenting remote access reduce opportunities for unauthorized access while making the system easier to support over time. Individually, each measure provides only part of the solution. Together, they create layers of protection that strengthen the entire BAS.
The Strongest Networks Are Usually the Best Understood
Spend enough time with experienced system integrators, and you’ll notice they rarely start a troubleshooting conversation by talking about cybersecurity products.
Instead, they start by asking questions.
-
- “Has anything changed recently?”
-
- “Who added that controller?”
-
- “Is there an updated network diagram?”
-
- “When was the last backup?”
Those questions aren’t accidental. They reflect something that’s easy to overlook: a network can’t be effectively protected if no one fully understands what’s connected to it.
Good documentation isn’t busywork. It’s operational awareness. Current network diagrams, device inventories, configuration records, and clearly documented remote access methods allow technicians to understand how the system is supposed to behave. That makes it much easier to recognize when something isn’t behaving normally—and much easier to recover when problems occur.
Security Doesn’t End at Commissioning
It’s tempting to think of cybersecurity as another commissioning item. Once the network has been segmented, passwords have been changed, and the documentation has been handed over; it feels like the work should be finished.
In reality, that’s when the real work begins.
Buildings are constantly changing. Equipment reaches the end of its service life. Tenants remodel their spaces. New integrations are added. Service providers change, software evolves, and remote access needs to shift over time. A BAS that was carefully designed on day one can gradually become more difficult to manage if those changes aren’t tracked and reviewed along the way.
That’s why the healthiest cybersecurity programs look a lot like good facility management. They don’t wait for something to go wrong before paying attention. Instead, they routinely review who has access to the system, keep backups current, document significant changes, and watch for unusual behavior that deserves a closer look. Those aren’t extraordinary measures—they’re simply part of maintaining a system that’s expected to serve a building for decades rather than months.
The Goal Isn’t a Perfectly Secure Network
One of the challenges with cybersecurity is that there’s no finish line. There isn’t a point where you can confidently say a network is “done” or completely protected from every future threat. Buildings continue to evolve, and so do the risks surrounding them.
That’s why experienced system integrators rarely talk about creating a perfect network. Instead, they focus on building one that’s resilient. If something unexpected happens, can the problem be contained? Can the right people understand what they’re looking at? Can the system be restored without unnecessary confusion or downtime?
Those questions shift the conversation away from chasing the latest security technology and back toward something much more practical: building automation systems that are understandable, supportable, and recoverable throughout their entire lifecycle.
A Stronger BAS Is Built One Layer at a Time
People often ask what the single most important step is to secure a BACnet network. The honest answer is that there usually isn’t one.
Network segmentation matters. So do firewalls, access controls, strong credentials, current documentation, backup procedures, and clearly defined responsibilities. Each addresses a different piece of the overall picture, and together they create a system that’s far more resilient than any single technology could provide on its own.
In many ways, securing a BACnet network isn’t very different from designing the building it serves. Long-term performance depends on hundreds of good decisions made over time, not one dramatic solution. Cybersecurity works the same way. When those decisions are made intentionally—and maintained as the building changes—the result isn’t just a more secure network. It’s a building automation system that’s easier to operate, easier to support, and better prepared for whatever comes next.
Ready to strengthen your BAS security?
Hardening a BACnet network is more than adding security technology. It’s about designing, documenting, and maintaining systems that remain resilient throughout their entire lifecycle.
See the other white paper in this series, Hardening BACnet Networks: Practical Security Guidelines for OT Installers, for practical recommendations on network design, device hardening, documentation, and operational best practices.
If you’d like help evaluating your building automation cybersecurity posture, KMC Secure Connected Solutions provides practical assessments, guidance, and recommendations tailored to your building and operational needs. Whether you’re modernizing an existing BAS or designing a new deployment, our team can help you identify practical ways to strengthen your security strategy.
Learn more about KMC Secure Connected Solutions or contact KMC Controls to start the conversation.
