No one hopes they’ll have to restore a building automation system. The goal, of course, is for nothing to go wrong at all. Controllers continue running, servers stay online, software updates install without incident, and every backup quietly sits in the background, never needing anyone’s attention. Most days, that’s exactly what happens. But anyone who’s worked in building automation for very long also knows that technology has a way of keeping us humble. Hardware eventually fails. Hard drives wear out. Someone accidentally overwrites a configuration file. A controller has to be replaced. Sometimes an unexpected cyber incident interrupts normal operations. Those events aren’t signs that someone failed; rather, they’re reminders that every system eventually faces the unexpected. The organizations that recover most effectively aren’t necessarily the ones with the newest technology or the largest budgets. More often, they’re the ones that spent time preparing before preparation seemed necessary. One of the ideas Dave Bohlmann returns to often is that operational technology has different priorities than traditional IT systems. In most office environments, protecting information is understandably the primary concern. Building automation has a different mission. The first priority is keeping buildings operating safely and reliably. Heating and cooling systems still need to function. Occupants still expect comfortable spaces. Critical facilities still depend on environmental control. That’s why availability sits at the heart of operational resilience. Backup and recovery planning support that goal, but they aren’t the goal themselves. Their purpose is to help organizations restore operations quickly and confidently when something unexpected interrupts normal business. That’s an important distinction because it shifts the conversation away from protecting files and toward protecting people, buildings, and the operations they support. When people hear the word backup, they often think about copying files to another location. For a building automation system, recovery involves much more than that. Configuration databases, controller programs, graphics, trends, alarms, licensing information, and system documentation all contribute to getting a building back online. Just as importantly, someone needs to know where those resources are stored, how current they are, and who is responsible for restoring them. That’s why experienced system integrators don’t simply ask whether backups exist. They ask whether recovery has been planned. Has anyone verified that the backup can actually be restored? Is there a documented recovery process? Have responsibilities been clearly defined between the asset owner, the system integrator, and IT? Those conversations often reveal opportunities to strengthen resilience long before they’re needed. Anyone can say they have backups. The more useful question is whether anyone has practiced using them. The difference matters. A recovery plan that exists only on paper may look complete until the day it’s needed. Organizations that periodically verify backups, document recovery procedures, and walk through recovery scenarios often discover small issues while they’re still easy to correct. Those exercises aren’t about expecting failure—they’re about building confidence. By the time an unexpected event occurs, everyone already understands their role, knows where critical information is stored, and has confidence that the recovery process will work as intended. Preparation turns uncertainty into familiarity. If an important BAS server became unavailable this afternoon, how confidently could your team answer these questions? ☐ Where are the most current backups stored? ☐ Have they been successfully restored and verified? ☐ Who leads the recovery effort? ☐ How long should recovery realistically take? ☐ Is the recovery process documented and understood? If those answers require guesswork, today is a good time to strengthen your recovery plan rather than waiting until circumstances force the conversation.
In this CyberBYTES episode, Fred Gordy explains why backup and recovery planning are fundamental to operational resilience. Learn practical ways to prepare your building automation system for the unexpected while keeping the focus where it belongs—maintaining safe, reliable building operations.
Building automation systems support the environments where people work, learn, receive medical care, manufacture products, and conduct business every day. Preparing to recover those systems isn’t an admission that failure is inevitable. It’s good stewardship. Organizations that invest time in recovery planning aren’t expecting something to go wrong tomorrow. They’re simply recognizing that technology changes, hardware ages, and unexpected situations eventually arise. When those moments come, preparation allows people to spend less time wondering what to do and more time restoring the operations others depend on. KMC Secure Connected Solutions helps building owners and system integrators evaluate recovery readiness, strengthen operational resilience, and develop practical strategies that support both cybersecurity and reliable building operations. Learn more about KMC SCS™ Explore KMC Dome™ The Hidden Cyber Risks of Smart Buildings The Cybersecurity Gap in Legacy Building Systems What Is Zero Trust and Why Does Your Building Need It?
Availability Is the Goal
A Backup Is Part of the Story—Not the Whole Story

Confidence Comes from Practice
CyberBYTES Quick Check
Watch the CyberBYTES Episode
Recovery Is Really About Stewardship
Continue the Conversation
