For years, building automation and IT operated in largely separate worlds.
Facilities teams focused on keeping buildings comfortable, efficient, and operating reliably. IT departments focused on protecting business systems, supporting users, and keeping information secure. They occasionally crossed paths, but for the most part, each group had its own responsibilities, its own priorities, and its own vocabulary.
Today, those worlds are intersecting more than ever before.
Building automation systems now exchange data with enterprise applications, support remote access, connect to cloud-based services, and provide building owners with unprecedented visibility into how their facilities operate. As buildings become smarter and more connected, cybersecurity is no longer something either department can address independently.
That shift has created an interesting challenge.
Not because one group understands cybersecurity better than the other.
Because they’re looking at the same building from two very different perspectives.
Speaking Different Languages
Imagine the first cybersecurity planning meeting for a new building automation project.
The IT team starts asking about vulnerability management, endpoint protection, certificate authorities, and authentication policies. The controls contractor responds with discussions about supervisory controllers, BACnet routers, MS/TP trunks, commissioning schedules, and equipment that may have been operating reliably for twenty years.
Everyone around the table is knowledgeable.
Everyone is trying to reduce risk.
Yet it’s surprisingly easy for those conversations to become frustrating because each side assumes the other sees the system the same way they do.
The reality is that they’re solving different problems.
An IT professional naturally thinks about protecting networks, identities, and information. A building automation professional is thinking about keeping occupants comfortable, maintaining critical equipment, and ensuring the building continues operating as expected. Those priorities overlap, but they aren’t identical—and that’s why the conversation sometimes feels more difficult than it should.
BACnet Was Built for Buildings
One of the most helpful things IT professionals can understand is that BACnet wasn’t designed to behave like a traditional enterprise protocol.
When BACnet was developed, its purpose was to help equipment from different manufacturers communicate with one another. Building owners needed interoperability. They needed controllers, sensors, workstations, and supervisory devices to exchange information reliably, regardless of who built them. Features that are common in today’s IT environments—such as encryption, certificate management, and authentication—weren’t central design requirements because most building automation systems operated on isolated networks.
As buildings became more connected, that operating environment changed dramatically, but the installed base didn’t disappear overnight. Many facilities still depend on legacy controllers with limited processing power, MS/TP trunks that communicate over RS-485, and equipment that’s expected to remain in service for decades rather than years. Those systems continue to perform their intended jobs extremely well, but they also require cybersecurity strategies that respect their operational realities instead of assuming they behave like desktop computers or servers.
Understanding that history often changes the conversation. Instead of asking why a BAS doesn’t support every modern IT security practice, the better question becomes: How do we achieve the same security objective in a way that fits the environment we’re working in?
The Conversation Gets Better When Both Sides Listen
That same shift happens on the facilities side as well.
For many years, cybersecurity was often viewed as something the IT department handled after the controls contractor finished commissioning the system. But today’s connected buildings don’t allow for that kind of handoff anymore. Decisions about remote access, user accounts, network segmentation, backups, and change management all influence the long-term security of the BAS, which means IT and facilities have to start talking much earlier in the process.
Interestingly, the most productive conversations aren’t usually about technology at all.
They quickly become conversations about ownership.
Who approves remote access after the project is complete? Who keeps network diagrams current as renovations and tenant improvements take place? How are administrator accounts managed when contractors change? If unusual activity appears on the network—or if communications suddenly stop—who takes the lead, and how will the rest of the team know what’s happening?
Those aren’t simply technical questions.
They’re operational questions.
And answering them well often has a greater impact on long-term cybersecurity than choosing one technology over another. The strongest organizations understand that technology works best when it’s supported by clear expectations, documented responsibilities, and good communication between everyone responsible for the building.
Everyone Is Looking at the Same Building
Perhaps that’s the biggest lesson to come out of the growing partnership between IT and facilities. Despite the occasional disagreements, both groups are working toward the same objective: reducing risk while helping the organization operate safely and reliably.
They simply experience that risk differently.
An IT professional naturally worries about protecting enterprise infrastructure, managing identities, and preventing unauthorized access. A facilities team experiences risk through the lens of the building itself—keeping occupants comfortable, maintaining critical equipment, and ensuring essential systems remain available when they’re needed most.
Neither perspective is more important than the other.
But neither is complete on its own.
As building automation systems become more connected, organizations need both ways of thinking. When IT gains a better understanding of how buildings operate, and facilities gain a better understanding of modern cybersecurity practices, the conversation shifts from negotiating competing priorities to solving shared problems.
That’s where resilient building automation begins.
Ready to strengthen your BAS security?
As IT and building automation continue to converge, organizations need cybersecurity strategies that respect both operational realities and modern security expectations.
Download the full white paper, Bridging the Gap: What IT Needs to Know About BACnet Networks, to explore practical guidance for improving collaboration between IT teams, facilities professionals, and system integrators.
If you’d like help evaluating your building automation cybersecurity posture, KMC Secure Connected Solutions provides practical assessments, guidance, and recommendations tailored to your building and operational needs. Whether you’re modernizing legacy systems or planning a new deployment, our team can help bridge the gap between IT and OT while strengthening your overall security strategy.
Learn more about KMC Secure Connected Solutions or contact KMC Controls to start the conversation.
