When most people picture a cyberattack, they imagine a skilled hacker sitting behind multiple computer screens, searching for a way to break into a network.
Those people certainly exist. But in the world of building automation, that’s often not where an attack begins. More often, it starts with an ordinary person trying to do their job.
A technician clicks what appears to be a legitimate email from a customer. A temporary remote connection stays active after a project wraps up because everyone assumes they’ll need it again soon. Someone reuses the same password across multiple customer sites, because it’s easier to remember. A USB drive gets plugged into a service laptop without anyone stopping to ask where it came from.
None of those actions seem especially dangerous on their own. In fact, they’re usually done with the best of intentions.
The problem is that attackers understand human nature remarkably well. They know it’s often easier to trick a trusted person than it is to defeat well-designed security technology.
That’s why one of the most important tools in cybersecurity isn’t software at all. It’s good cyber hygiene.
Good Buildings Depend on Good Habits
Buildings have a way of accumulating history.
Every renovation, every service call, and every system expansion leaves something behind. New controllers are added. Networks grow. Integrations multiply. Different contractors come and go over the years, each solving the problem in front of them with the information they have at the time.
There’s nothing inherently wrong with that. It’s simply how buildings evolve.
The same is true of cybersecurity.
A single weak password may not cause a problem. Neither will one undocumented configuration change or one forgotten remote access account. But over time, those small decisions accumulate, creating opportunities that weren’t there when the system was first commissioned.
Cyber hygiene is really about preventing those opportunities from piling up. Just as preventive maintenance helps keep mechanical equipment reliable, routine cybersecurity practices help keep connected building systems resilient.
Cybersecurity Is Part of the Job—Whether We Think About It or Not
Many building automation professionals don’t consider themselves cybersecurity specialists.
They’re focused on commissioning controllers, troubleshooting networks, resolving occupant comfort issues, and getting systems back online as quickly as possible. Those responsibilities are challenging enough without adding “cybersecurity” to the list.
But today’s connected buildings don’t separate those responsibilities as neatly as they once did.
Anyone who installs a controller, connects a laptop, creates a user account, enables remote access, or changes a network configuration is making decisions that affect the security of the entire system. Whether those decisions improve security or unintentionally weaken it often comes down to everyday habits rather than technical expertise.
Cybersecurity isn’t something that belongs exclusively to the IT department. In modern building automation, everyone with access to the system shares responsibility for protecting it.
Small Decisions Have Big Consequences
One of the most well-known examples of this came during the Target data breach in 2013.
The attackers didn’t begin by directly attacking Target’s building systems. Instead, they obtained credentials through an HVAC contractor, giving them an entry point into the retailer’s network. While every cyber incident is different, the lesson remains relevant today: trusted vendors, contractors, and service providers are often part of an organization’s security posture whether they realize it or not.
That’s why experienced organizations don’t rely on technology alone. They establish practical expectations for how work is performed.
- Unique user accounts instead of shared credentials.
- Strong passwords instead of factory defaults.
- Approved remote access methods instead of ad hoc connections.
- Documented changes instead of relying on memory.
- Prompt reporting when something doesn’t seem right—even if it turns out to be nothing.
None of these practices are complicated, but together they dramatically reduce risk.
Cyber Hygiene Is Really About Professionalism
The phrase cyber hygiene can make the topic sound more technical than it really is.
At its core, it’s simply another aspect of doing quality work.
Experienced building automation professionals already understand the value of labeling panels, documenting programming changes, backing up databases before major modifications, and leaving systems in good condition for the next technician. Cyber hygiene follows that same philosophy. It’s about creating an environment that’s easier to support, easier to troubleshoot, and far less vulnerable to avoidable mistakes.
That’s good for security.
It’s also good for customers.
A Strong Foundation for Everything That Follows
Throughout this Securing BAS series, we’ll explore topics like BACnet network hardening, IT and OT collaboration, authentication, encrypted communications, and modern approaches to protecting building automation systems.
All of those technologies are valuable. But none of them replaces thoughtful people following disciplined processes.
Good cybersecurity doesn’t begin with a firewall or an encryption protocol. It begins with everyday decisions made by the people who design, install, service, and manage building automation systems. The strongest BAS environments aren’t necessarily the ones with the most security technology—they’re the ones where good technology is supported by good habits.
Ready to strengthen your BAS security?
Cyber hygiene is the foundation of a secure building automation system, but it’s only one part of a comprehensive cybersecurity strategy.
Download the full white paper, Cyber Hygiene for OT Installers, for practical guidance on strengthening cyber hygiene across your organization and supporting more resilient BAS operations.
If you’d like help evaluating your building automation cybersecurity posture, KMC Secure Connected Solutions provides practical assessments, guidance, and recommendations tailored to your building and operational needs. Whether you’re beginning to address cybersecurity or planning a broader OT security strategy, our team can help you understand your current risks and identify practical next steps.
Learn more about KMC Secure Connected Solutions or contact KMC Controls to start the conversation.
