There comes a point in almost every building automation system’s life when someone asks a perfectly reasonable question.
“We’ve segmented the network, restricted remote access, and worked with IT to put the right protections in place. What else do we need?”
Sometimes the answer is, “Nothing right now.”
Not every building requires the same level of cybersecurity. A small office building doesn’t face the same operational risks as a hospital, a data center, or a research laboratory. The goal isn’t to apply every available security technology to every BAS. It’s to understand the level of risk you’re managing and make decisions that fit the building, the people who occupy it, and the way the system will be supported over time.
That’s an important distinction because cybersecurity isn’t about collecting technologies. It’s about reducing risk in practical ways.
Strong Foundations Solve Most Problems
Throughout this series, we’ve talked about the importance of cyber hygiene, understanding the different priorities of IT and OT, and building BACnet networks with security in mind from the beginning.
Those practices remain the foundation of a resilient BAS.
Good documentation, well-managed remote access, network segmentation, strong credentials, backups, and clearly defined responsibilities prevent a remarkable number of problems before they ever occur. Organizations that consistently follow those practices are already far ahead of those searching for a single technology to compensate for weak operational habits.
That’s why it’s important not to skip ahead.
Advanced security technologies work best when they’re building on a strong foundation rather than trying to replace one.
Every Building Reaches a Different Decision Point
As buildings become more connected, however, the conversation often changes.
Perhaps a healthcare system wants to provide secure remote access to multiple facilities. A university is integrating older controllers with newer IP-based equipment. A manufacturer is trying to meet corporate cybersecurity requirements while continuing to operate legacy building systems that still perform their jobs reliably.
In situations like these, traditional network protections may still be necessary—but they may no longer be sufficient on their own.
That’s when organizations begin asking different questions.
-
- How do we verify that a device really belongs on the network?
-
- How do we protect legacy equipment that was never designed with modern cybersecurity features?
-
- How do we support secure communications across a growing mix of old and new technologies?
Those aren’t signs that the original network design failed.
They’re signs that the building itself has evolved.
Choosing the Right Approach Means Understanding the Tradeoffs
One of the biggest mistakes organizations can make is assuming there’s a universal answer to every cybersecurity challenge.
In reality, different technologies solve different problems.
BACnet/SC extends the BACnet standard by bringing modern encryption and certificate-based authentication to BACnet/IP networks. For organizations with newer IP-based infrastructure and established IT processes, that may be a natural fit.
Other environments face a different reality. They may have decades of investment in MS/TP networks, legacy controllers, or equipment that simply can’t participate in certificate-based architectures. In those cases, technologies such as KMC DOME™ take a different approach by helping secure devices at the edge while supporting environments that include both newer and older equipment.
The important point isn’t deciding that one approach is universally better than the other.
It’s recognizing that every building has its own architecture, operational requirements, and long-term support model. Good cybersecurity starts by understanding those realities before selecting the technology that fits them.
Technology Is Only Part of the Decision
As organizations evaluate more advanced security options, it’s easy to focus on features.
Does it support encryption?
How are devices authenticated?
Will it work with existing equipment?
Those are all important questions, but they aren’t the only ones worth asking.
Who will manage the system after it’s deployed? How will new devices be approved and added over time? What happens if a credential expires, a device fails, or communications are interrupted? How will the organization recover if something unexpected happens?
Those questions rarely appear on a product datasheet, yet they’re often what determine whether a cybersecurity strategy succeeds over the long term. A solution that looks impressive on paper still has to be practical for the people responsible for operating and maintaining the building every day.
Building for the Future
One of the advantages of taking a layered approach to cybersecurity is that it leaves room for buildings to evolve.
Technology will continue to change. New standards will emerge, equipment will be replaced, and security expectations will continue to grow. Organizations don’t have to predict every future development, but they do benefit from choosing approaches that can adapt as those changes occur.
That’s one reason the conversation has shifted away from finding a single “best” security solution. Instead, the emphasis is increasingly on building flexible, resilient systems that can accommodate both today’s needs and tomorrow’s challenges.
After all, building automation has always been about planning for the long term.
Cybersecurity should be no different.
Ready to strengthen your BAS security?
As your building automation system grows and evolves, your cybersecurity strategy should evolve with it.
Download the full white paper, Beyond the Basics: Evaluating BACnet/SC, KMC DOME, or Both, to explore advanced BAS security approaches and the considerations that help determine which solution best fits your environment.
If you’d like help evaluating your building automation cybersecurity posture, KMC Secure Connected Solutions provides practical assessments, guidance, and recommendations tailored to your building and operational needs. Whether you’re planning for new construction, modernizing legacy systems, or evaluating advanced cybersecurity technologies, our team can help you identify practical next steps.
Learn more about KMC Secure Connected Solutions or contact KMC Controls to start the conversation.
