How Does Your BAS Actually Know Which Devices to Trust? 

Banner for 'The Intelligent Building Playbook' with geometric line background and blue title typography, indicating a new white paper

Think about the last time someone showed up at your office to perform work on the building. 

They probably didn’t walk straight through the front door and head into a mechanical room. Someone verified who they were, confirmed why they were there, and determined what areas they were allowed to access before handing over a visitor badge. 

Most organizations take that process for granted because it makes sense. Before someone is allowed into the building, we establish two things. 

Who are you? 

And should you be here? 

Modern cybersecurity asks those same questions. 

As building automation systems become more connected, they aren’t just exchanging information with trusted controllers on isolated networks anymore. Devices communicate across enterprise networks, remote connections allow technicians to support systems from miles away, and new equipment is added throughout the life of the building. Every one of those interactions depends on trust. 

The challenge is that computers don’t recognize people the way we do. 

They need another way to answer those two simple questions. 

Trust Is More Than Encryption 

When cybersecurity comes up, encryption often gets most of the attention. We hear about encrypted traffic, secure tunnels, and protecting information as it moves across the network. 

Encryption is important. 

But encryption only protects the conversation once you’ve decided who gets to participate in it. 

Before two devices exchange information, each one needs confidence that the other is really who it claims to be. Once that identity has been established, the system still has to determine whether that device should be allowed to communicate in the first place. Only then does encryption protect what they’re saying to one another. 

That’s why cybersecurity professionals talk about three closely related ideas: authentication, authorization, and encryption. They’re often mentioned together, but they solve very different problems. 

Authentication answers the question, “Who are you?” 

Authorization asks, “Should you have access?” 

Encryption protects the conversation after those questions have already been answered. 

Miss any one of those steps, and the overall security of the system begins to weaken. 

There Isn’t Just One Way to Establish Trust 

If you’ve followed this series from the beginning, you’ve probably noticed a recurring theme. 

There are very few universal answers in building automation. 

The same is true here. 

Some organizations already have mature IT departments with established certificate management processes and predominantly IP-based building systems. In those environments, BACnet/SC may fit naturally because it extends familiar IT security concepts into the BAS. 

Other organizations face a different reality. Their buildings may include decades of investment in legacy controllers, MS/TP networks, or third-party equipment that still performs reliably but wasn’t designed to support modern certificate-based architectures. Rather than replacing working infrastructure, they may look for approaches like KMC Dome that establish trust in different ways while accommodating both new and existing devices. 

The important point isn’t deciding which technology is universally superior. 

It’s understanding what kind of environment you’re trying to protect and choosing an approach that fits the way your building actually operates. 

The Hard Part Isn’t Technology 

One of the more interesting observations from cybersecurity professionals is that establishing trust is often the easy part. 

Maintaining it is where organizations struggle. 

Buildings don’t stand still. Equipment gets replaced, contractors change, ownership shifts, and new devices are added over time. Every one of those changes affects the network’s understanding of what’s trusted and what isn’t. 

That’s why mature cybersecurity programs spend just as much time thinking about governance as they do technology. 

Who approves new devices before they’re added to the BAS? 

Who owns the credentials that establish trust? 

How are devices removed when they’re retired? 

Who reviews alerts when something unexpected appears on the network? 

Those questions don’t have glamorous answers, but they determine whether even the strongest authentication technology remains effective five or ten years after it’s deployed. 

Trust Is Something You Maintain 

Perhaps that’s the biggest lesson from this entire series. 

Cybersecurity isn’t about finding the newest technology or adopting the latest standard. 

It’s about building systems that people can understand, support, and confidently operate over time. 

That starts with good cyber hygiene. It continues through thoughtful network design, strong collaboration between IT and facilities, and choosing security technologies that match the operational realities of the building. 

And it doesn’t end once those technologies are installed. 

Just as trust between people is built over time and maintained through consistent actions, trust within a building automation system requires ongoing attention. Devices are added. Credentials change. Buildings evolve. A cybersecurity strategy has to evolve with them. 

The organizations that recognize this aren’t simply building more secure BAS networks. 

They’re building more resilient ones. 

Ready to strengthen your BAS security? 

Authentication, authorization, and encryption each play an important role in protecting today’s connected building automation systems—but choosing the right approach depends on your building, your existing infrastructure, and your long-term operational goals. 

Download the full white paper, Deep Dive: How BACnet/SC and Veridify DOME Handle Authentication, Authorization, and Encryption, to explore the technologies behind modern BAS authentication and learn how different approaches establish trust across connected building systems. 

If you’d like help evaluating your building automation cybersecurity posture, KMC Secure Connected Solutions provides practical assessments, guidance, and recommendations tailored to your building and operational needs. Whether you’re evaluating authentication strategies, planning future upgrades, or looking to strengthen an existing BAS, our team can help you identify practical next steps. 

Learn more about KMC Secure Connected Solutions or contact KMC Controls to start the conversation.