Years ago, attackers gained access to Target’s network through a small HVAC contractor that had legitimate credentials to connect to the retailer’s systems. Security tools detected suspicious activity early in the attack, but identifying the breach and responding to it proved to be two very different challenges. Without a well-defined response plan, valuable time was lost, allowing the attackers to continue their work. It’s an incident that’s often remembered because of its scale, but for Dave Bohlmann, it illustrates a much more practical lesson for building automation professionals. The question isn’t simply whether you’ll detect a cyber incident. It’s whether everyone knows what happens next. Throughout this CyberBYTES series, we’ve explored the building blocks of operational resilience—governance, risk awareness, asset visibility, secure remote access, and credential management. Each of those disciplines reduces risk and strengthens day-to-day operations. But none of them eliminates the possibility that something unexpected will happen. That’s why every organization also needs a plan for responding when prevention isn’t enough. Many organizations invest considerable effort into preventing cyber incidents, and rightly so. Strong passwords, secure remote access, asset inventories, and good security practices all reduce the likelihood of an attack succeeding. What they don’t do is answer the questions that arise after an incident has already begun. Experienced system integrators understand that no technology environment is immune from the unexpected. Hardware eventually fails, people make mistakes, vendors encounter unforeseen issues, and even well-managed organizations occasionally face situations they didn’t anticipate. Those realities aren’t unusual—they’re simply part of operating complex building systems over time. The organizations that respond most effectively aren’t necessarily the ones with the newest technology. They’re the ones that have already decided how they’ll respond when something unexpected happens. An incident response plan isn’t written for the day everything goes right. It’s written for the day everyone is under pressure. One of the strengths of Dave’s approach is that he doesn’t treat incident response planning as a technical exercise. Instead, he encourages organizations to answer a series of practical questions before they’re ever needed. Who is on the response team? Who has the authority to make decisions? Who communicates with employees, leadership, legal counsel, insurance providers, or the public? Who decides when an incident should be escalated? Which building systems are most critical to restore first? Those aren’t questions anyone wants to debate while an incident is unfolding. The value of an incident response plan is that it removes uncertainty when people are already dealing with enough of it. And just as importantly, Dave reminds us that incident response planning follows—not replaces—the work discussed in previous CyberBYTES episodes. Organizations first need to understand their assets and assess their risks before they can build an effective response strategy. Writing a response plan is an important first step. Practicing it is what makes it useful. Dave recommends conducting tabletop exercises—structured discussions that walk teams through realistic cybersecurity scenarios before an actual incident occurs. These exercises don’t interrupt building operations, but they do reveal whether people understand their responsibilities and whether the plan works the way everyone expects. Organizations are often surprised by what they discover. A phone number is outdated. Two people assume they’re responsible for the same task. A critical vendor isn’t included in the notification process. Recovery priorities aren’t as clear as everyone believed. Finding those gaps during a tabletop exercise is exactly the point. Each exercise strengthens the plan, clarifies responsibilities, and gives teams greater confidence that they’ll know what to do when an unexpected situation arises. Incident response planning isn’t only valuable for building owners. System integrators should have a response plan for their own organizations as well. They also have an opportunity to help customers begin thinking through the practical questions that often go unasked until after an incident has already started. As trusted advisors, integrators routinely help customers understand how systems communicate, how buildings operate, and how technology supports business continuity. Discussing incident response is simply another extension of that relationship. Questions such as Who should we call first?, What systems are most critical?, and How would we coordinate our response? encourage customers to think beyond prevention and begin preparing for continuity. Those conversations create value regardless of whether a cyber incident ever occurs. If a cyber incident affected your BAS this afternoon, could your team confidently answer these questions? ☐ Who would lead the response? ☐ Does everyone understand their role? ☐ Have communication responsibilities been assigned? ☐ Have you practiced the plan through a tabletop exercise? ☐ Which systems would your organization restore first? If those questions require discussion rather than immediate answers, your incident response planning still has room to grow.
In this CyberBYTES episode, Dave Bohlmann explains why planning and practicing an incident response is just as important as preventing one. Learn how clear roles, practical planning, and tabletop exercises help organizations respond with greater confidence when unexpected events occur.
One idea has quietly connected every article in this CyberBYTES series. Operational resilience doesn’t happen by accident. It grows through preparation. Governance prepares organizations to make good decisions. Visibility helps teams understand their environments. Secure remote access and credential management reduce unnecessary risk. Backups help organizations recover. An incident response plan brings those efforts together by defining what happens when people must act under pressure. Preparation doesn’t guarantee that incidents won’t occur. It ensures they don’t have to become organizational chaos. KMC Secure Connected Solutions helps building owners and system integrators strengthen operational resilience through cybersecurity assessments, incident response planning, and practical guidance designed specifically for building automation systems. Whether you’re developing your first response plan or refining an existing one, preparing today helps your organization respond with greater confidence tomorrow. Learn more about KMC SCS™ Explore KMC Dome™ The Hidden Cyber Risks of Smart Buildings The Cybersecurity Gap in Legacy Building Systems What Is Zero Trust and Why Does Your Building Need It?
Detection Is Only the Beginning
Good Response Plans Answer Practical Questions
Plans Improve When They’re Practiced
System Integrators Can Lead the Conversation

CyberBYTES Quick Check
Watch the CyberBYTES Episode
Preparation Builds Confidence
Continue the Conversation
