The building is operating normally — until it isn’t.
A technician is called in after a series of comfort complaints and unstable schedules begin affecting tenants across multiple floors. The system hasn’t completely failed, but nobody can explain why overrides keep reappearing or why certain equipment is running outside scheduled hours.
As the troubleshooting process unfolds, the problems compound.
The original integrator is no longer involved. Several people who previously had remote access have left their companies. Documentation is outdated. Some controller changes were never backed up. Nobody is entirely sure which devices are still communicating externally — or who still has credentials to the system.
Eventually, someone asks the uncomfortable question:
Who actually owns the operational lifecycle of this building automation system?
For many commercial facilities, that question has become increasingly difficult to answer.
Modern building automation systems now support far more than HVAC control. They influence tenant comfort, energy performance, remote operations, compliance initiatives, sustainability goals, and portfolio-wide operational visibility. At the same time, systems are becoming more connected through cloud integrations, remote service access, analytics platforms, and enterprise network integration.
But while building technology has evolved quickly, operational governance around these systems often has not.
As Fred Gordy noted during a recent Stuck on a Bucket discussion hosted by KMC Controls (video below), “Cybersecurity in OT environments isn’t a one-time event or one single owner responsibility. It’s an operational lifecycle.”
That lifecycle is becoming harder to manage as buildings grow more connected, staffing pressures increase, and facilities teams are expected to operate larger portfolios with fewer internal resources.
The Problem Is Bigger Than Cybersecurity
Many conversations around building automation cybersecurity and OT cybersecurity still focus primarily on external threats or compliance frameworks. Those concerns matter, but they often obscure a more immediate operational reality inside commercial buildings.
The larger issue is operational discipline.
If no one knows what devices exist, how systems are connected, who has remote access, whether backups are current, or how systems would be recovered after failure, then the building is already operating with hidden operational risk.
During the same Stuck on a Bucket discussion, Gordy summarized the issue plainly:
“If you don’t know what you have, and you don’t know how it’s connected, and you don’t know who has access, you don’t need to go any further than those three things.”
Those operational gaps do not just create cybersecurity exposure. They create troubleshooting delays, inconsistent building performance, recovery risk, technician inefficiency, vendor dependency, and operational instability across the building lifecycle.
Modern BAS Environments Create New Operational Pressure
Historically, many BAS deployments operated in relatively isolated environments. Systems were often local, self-contained, and maintained by small groups with deep institutional knowledge.
That operating model no longer reflects reality.
Today’s facilities teams increasingly rely on remote service access, centralized portfolio visibility, cloud-connected analytics, third-party integrations, and distributed operational support teams.
At the same time, workforce pressures are reshaping how buildings are maintained. Experienced technicians are retiring. New personnel inherit undocumented systems. Integrators are asked to support more buildings with tighter staffing levels and faster response expectations.
In many commercial environments, troubleshooting no longer means fixing a single failed device. It means tracing years of accumulated operational drift across systems, users, remote connections, overrides, undocumented changes, and inconsistent standards.
As Gordy noted during the webinar, “The industry has spent 40 years building a problem.”
In many cases, the operational risk is not caused by a single catastrophic failure. It develops gradually through years of unmanaged complexity: outdated credentials, undocumented changes, inconsistent controller standards, unmanaged remote access, disconnected backup processes, and increasing reliance on tribal knowledge.
Operational Visibility Is Becoming a Business Requirement
For commercial building owners and operators, these issues increasingly extend beyond facilities departments.
Building operations now influence tenant experience, energy performance, sustainability reporting, operational transparency, insurance considerations, and long-term asset competitiveness.
As connected systems become more central to operations, owners are beginning to evaluate service providers differently as well.
Gordy addressed this shift directly during the webinar:
“One of these days, owners are going to judge you for how secure they are and what you did.”
Controls contractors and system integrators are no longer viewed solely as installation providers. Increasingly, they are expected to function as long-term operational partners capable of supporting lifecycle governance, recovery readiness, documentation discipline, secure remote access, and operational continuity.
Jesse Shoemaker framed the issue similarly during the discussion, noting that cybersecurity frameworks ultimately revolve around several practical operational questions:
- Who has access to systems?
- How are devices communicating?
- How do we reduce unnecessary exposure?
- How do we document and validate what is connected?
- And how do we improve security without disrupting operations?
That operational framing is becoming increasingly important as BAS cybersecurity expectations move closer to mainstream building operations.
Legacy Systems Create a Difficult Modernization Challenge
One of the most difficult realities facing facilities teams today is that modernization rarely happens all at once.
Most organizations operate a mix of legacy BAS infrastructure, newer IP-connected devices, aging field controllers, cloud-connected applications, and multiple generations of operational technology.
Replacing entire systems is often financially unrealistic or operationally disruptive. As a result, many facilities must find practical ways to improve operational resilience while continuing to support existing infrastructure.
This challenge was explored in KMC Controls’ previous article: The Cybersecurity Gap in Legacy Building Systems—and How to Bridge It.
As many organizations are discovering, modernization is rarely a clean replacement cycle. More often, it is a long-term operational balancing act between uptime, staffing limitations, legacy infrastructure, and evolving cybersecurity expectations.
A More Practical Approach to BAS Operational Resilience
Operational resilience in building automation environments does not begin with achieving perfect cybersecurity maturity.
It begins with operational clarity.
For many organizations, practical first steps include establishing clear credential management practices, improving documentation standards, validating backup and recovery procedures, reducing unnecessary remote access exposure, standardizing controller deployment practices, and improving visibility into connected assets.
From there, organizations can begin building more structured approaches around segmentation, secure remote access, lifecycle governance, and operational monitoring.
Solutions like KMC Dome™ are designed to help organizations improve operational security posture within existing BAS environments without requiring complete infrastructure replacement. KMC Dome creates encrypted communication overlays for legacy BACnet environments and supports more secure remote connectivity strategies while allowing facilities teams to continue operating within existing network architectures.
As discussed during the Stuck on a Bucket session, one of the practical advantages of this type of approach is that organizations can improve operational resilience incrementally rather than attempting to rebuild systems all at once.
The Industry Is Moving Toward Lifecycle Accountability
One of the more important themes emerging across the building automation industry is that operational accountability is expanding beyond initial deployment.
Owners increasingly expect clearer operational governance, documented recovery procedures, controlled remote access, lifecycle support strategies, and greater operational transparency from vendors and service providers.
At the same time, system integrators are being pulled into more strategic operational discussions earlier in the building lifecycle.
Buildings are no longer isolated mechanical environments. They are connected operational platforms that require long-term governance, visibility, and resilience planning.
Organizations that approach building automation as an ongoing operational lifecycle — rather than a one-time installation project — will likely be in a much stronger position to scale, modernize, and adapt over time.
Learn More
Watch the recent Stuck on a Bucket discussion with Fred Gordy and Jesse Shoemaker below to explore how operational technology cybersecurity, lifecycle governance, and practical modernization strategies are reshaping expectations for building owners and system integrators alike.
Additional KMC Controls resources:
Many thanks to Fred Gordy and Jesse Shoemaker for contributing their expertise to the creation of this article.
