Buildings have a funny way of accumulating history.
Every renovation, every service call, every expansion leaves something behind. A controller gets replaced. A temporary network connection stays in place because it works. Someone installs a gateway to solve an immediate problem, and ten years later nobody remembers it was ever added.
None of those decisions are bad decisions. In fact, most of them were exactly the right decision at the time. The challenge is that, over the years, those individual decisions become today’s operating environment.
That’s why visibility matters so much.
People often think of cybersecurity as something that starts with passwords, firewalls, or software updates. Those things certainly matter, but in building automation they’re rarely the first challenge organizations encounter. More often, however, the first challenge is simply understanding the environment they’re responsible for.
What systems are actually connected?
Which devices are still active?
Who installed them?
Who maintains them today?
If those questions take time to answer, you’re not necessarily looking at a cybersecurity problem—you’re looking at a visibility problem. And visibility problems have a way of becoming operational problems when organizations need answers quickly.
Before You Can Protect a Building, You Have to Understand It
One of the themes we’ve returned to throughout the CyberBYTES series is that operational resilience doesn’t begin during an emergency. It begins long before anything goes wrong. It’s easy to assume that because a building is operating normally, everyone understands how it’s put together. But buildings change over time. Spaces are remodeled. Equipment is upgraded. New technologies are added. Contractors come and go. Temporary solutions quietly become permanent because they continue working. Little by little, documentation falls behind reality.
Anyone who’s spent time commissioning or troubleshooting building automation systems has experienced this firsthand. What should have been a straightforward service call turns into an afternoon spent tracing network connections, opening panels, and asking questions that nobody immediately knows how to answer, simply because the building has evolved faster than its documentation.
Visibility Is More Than an Inventory
When people hear the words asset inventory, they often picture a spreadsheet—a list of controllers, IP addresses, firmware versions, and serial numbers, and that’s certainly part of it.
But a useful inventory is really about understanding relationships. It’s knowing not only what exists, but how everything fits together.
Dave Bohlmann makes this distinction in his guidance on operational technology. An inventory tells you what assets you own. Good configuration management tells you how those assets are configured, how they communicate, what’s changed over time, and why those changes were made. Together, they create something far more valuable than documentation: they create understanding.
The Building Knows Something You Don’t
Every experienced system integrator has had this moment: you’re standing in front of a control panel trying to solve a problem that should have taken thirty minutes. Most of the equipment makes sense. Then you notice one controller nobody remembers installing. Someone suggests disconnecting it because “it’s probably not doing anything anymore.” A few seconds later, another part of the building stops responding.
The technology didn’t fail.
The building simply knew something the people didn’t.
That’s why unknown assets eventually become unmanaged assets.
Not because they’re inherently dangerous, but because they quietly fall outside normal awareness. They don’t receive updates. They aren’t included in planning discussions. Their purpose slowly becomes a mystery. Eventually, they become the question everyone wishes had been answered before the service call—not during it.
Good Visibility Supports More Than Cybersecurity
One of the easiest mistakes to make is thinking that asset inventories only matter because of cybersecurity. In reality, they’re valuable every day. Accurate visibility helps organizations:
-
- Troubleshoot more efficiently
- Reduce commissioning time
- Plan upgrades with greater confidence
- Recover more quickly after failures
- Improve documentation for future technicians
- Support lifecycle planning and modernization
Cybersecurity is one benefit, but operational confidence is the bigger one.
CyberBYTES Quick Check
How confidently could your team answer these questions today?
- What devices are connected?
- Who is responsible for maintaining them?
- What firmware versions are currently running?
- Which assets have changed during the past five years?
- Does your documentation still reflect today’s building—not yesterday’s?
If those answers aren’t immediately clear, you’ve identified an opportunity to strengthen operational resilience before the next challenge arrives.
Watch the CyberBYTES Episode
In this CyberBYTES episode, Dave Bohlmann explains why asset visibility is one of the most important foundations of building automation cybersecurity. Learn why understanding what you have—and keeping that understanding current—helps organizations operate with greater confidence, recover more quickly, and make better decisions over the life of a building.
Moving from Awareness to Action
No building stays the same forever. The organizations that manage change most successfully aren’t necessarily the ones with the newest technology. They’re the ones that continue understanding their buildings as those buildings evolve. That’s where operational resilience begins. KMC SCS™ (Secure Connected Solutions™) helps building owners and system integrators better understand their environments through practical assessments, operational guidance, and cybersecurity expertise designed specifically for building automation systems. Whether you’re preparing for a modernization project, improving documentation, or simply trying to reduce uncertainty, greater visibility provides a stronger foundation for every decision that follows.

