When Everyone Touches the Building, Who Owns Security? 

CyberBytes banner: Making Sense of Building Automation Cybersecurity on a blue gradient background, hosts Fred Gordy & Dave Bohlmann

One of the interesting things about modern buildings is that they’re rarely managed by just one group anymore. A facilities team may operate the building every day. A system integrator commissions the controls. IT manages the network. Equipment manufacturers provide updates. Service providers connect remotely for maintenance. Energy consultants review performance. Outside contractors come and go as projects evolve. Each of those people has a legitimate reason to interact with the building. 

Most of the time, that’s exactly what you want. 

The expertise that keeps today’s buildings running doesn’t come from one person or one department. It comes from people with different skills working together toward the same goal. But collaboration brings its own challenges. As more people become involved, it’s easier for small assumptions to develop between organizations. One group assumes another is handling remote access. Someone believes user accounts are being reviewed somewhere else. Documentation is expected to be updated after a project, but no one is quite sure who owns that responsibility. 

Rarely does anyone intentionally leave those gaps. 

They simply appear over time. 

That’s why building cybersecurity isn’t just about protecting technology—it’s also about coordinating people. 


The Spaces Between Organizations 

When cybersecurity incidents are discussed, it’s easy to imagine someone making a major mistake. In reality, many operational problems begin much more quietly than that. 

A contractor finishes a project but temporary accounts remain active. 

A software update is postponed because everyone assumes another organization is evaluating it. 

Facilities and IT each believe the other maintains documentation for network changes. 

Individually, none of those situations seem particularly significant. Collectively, they create uncertainty. And uncertainty has a way of slowing everything down. Troubleshooting takes longer because nobody is certain who owns a system. Routine maintenance requires multiple phone calls before work can begin. Simple questions become difficult to answer because responsibilities have gradually become blurred. 

Those aren’t failures of technology. 

They’re failures of coordination. 


Good Communication Is Part of Good Cybersecurity 

One of the things Fred Gordy consistently emphasizes is that cybersecurity isn’t simply a technical discipline. It’s an operational discipline. The strongest firewall in the world can’t compensate for unclear responsibilities between organizations. Likewise, excellent communication won’t eliminate every technical risk—but it often prevents small issues from becoming much larger ones. That’s why some of the most valuable cybersecurity conversations have very little to do with technology. They’re conversations like: 

“Who approves remote access?” 

“Who removes vendor accounts after a project?” 

“Who updates network documentation?” 

“Who coordinates software updates?” 

Those questions don’t require specialized cybersecurity expertise. 

They require clarity. 

And clarity is one of the foundations of operational resilience. 


Every Connection Should Have an Owner 

Fred often reminds customers that every connection into a building represents both an opportunity and a responsibility. That’s true whether the connection belongs to a technician, a service provider, a manufacturer, or a remote support platform. The goal isn’t to make one organization responsible for everything. That’s neither realistic nor practical. The goal is to make sure every responsibility belongs to someone. When ownership is clear, organizations spend less time deciding who should respond and more time solving the problem itself. Preparation doesn’t remove complexity. It makes complexity easier to manage. 


Strong Partnerships Build Strong Buildings 

Building automation has always been a team effort. As buildings become more connected, that reality becomes even more important. The organizations that respond most effectively to operational challenges aren’t necessarily the ones with the most advanced technology. They’re the ones where facilities teams, IT departments, system integrators, manufacturers, and service providers understand how they work together—and communicate before problems arise. That’s the kind of partnership operational resilience depends on. 

CyberBYTES Quick Check 

How clearly are responsibilities defined for your building today? 

☐ Who approves remote access? 

☐ Who removes temporary vendor accounts? 

☐ Who maintains system documentation? 

☐ Who coordinates software updates? 

☐ Who leads communication during an operational incident? 

If those answers aren’t immediately clear, improving coordination may be one of the most valuable steps your organization can take. 

 

Watch the CyberBYTES Episode 

In this CyberBYTES episode, Fred Gordy explains why building automation cybersecurity is a shared responsibility. Learn how stronger communication and clearly defined roles help organizations improve both cybersecurity and day-to-day operations. 

Moving from Awareness to Action 

Modern buildings depend on collaboration. KMC Secure Connected Solutions helps building owners, facilities teams, and system integrators evaluate cybersecurity practices, clarify operational responsibilities, and strengthen resilience through practical, real-world guidance. Whether you’re modernizing an existing building or supporting a growing portfolio, clearly defined roles and strong communication provide a foundation that technology alone can’t deliver. 


Related Resources 

Learn more about KMC SCS™

Explore KMC Dome™ 

The Hidden Cyber Risks of Smart Buildings

The Cybersecurity Gap in Legacy Building Systems

What Is Zero Trust and Why Does Your Building Need It?