Your First Line of Defense: People, Awareness, and Skills

CyberBytes banner: Making Sense of Building Automation Cybersecurity on a blue gradient background, hosts Fred Gordy & Dave Bohlmann

When people think about cybersecurity, it’s natural to picture technology first. 

Firewalls. Passwords. Software updates. Secure remote access. Network monitoring. 

Those tools are all important, and throughout this CyberBYTES series we’ve explored many of them. We’ve talked about governance, asset visibility, secure remote access, backup strategies, and credential management because each plays an important role in protecting building automation systems. But after all those conversations, one lesson rises above the rest. 

Technology doesn’t make decisions. 

People do. 

Fred Gordy recalls working an incident that took ninety-two days to fully recover from. Drives were damaged. Controllers had to be replaced. Pumps suffered physical damage. Chillers required inspection before they could safely return to service. The incident began with something that seemed almost insignificant. 

Someone opened an email on a building automation workstation. The point isn’t that people make mistakes. 

The point is that even small decisions can have consequences that extend far beyond what anyone expected. 


Most Cybersecurity Happens Long Before an Incident 

It’s easy to think about cybersecurity only when something goes wrong. In reality, the strongest cybersecurity programs are built during ordinary days. They’re built when technicians follow established procedures instead of taking shortcuts. When unusual requests are questioned instead of accepted automatically. When software changes are documented. When remote access is closed after a project instead of being left available “just in case.” 

Those actions rarely feel dramatic. Most of the time, they simply become part of the way an organization operates. Over time, those habits become one of the strongest defenses a building can have—not because they’re complicated, but because they’re consistent. 


Good Habits Protect Good Technology 

Throughout this series, we’ve looked at the technical side of operational technology cybersecurity. We’ve discussed knowing what devices are connected, managing user accounts, securing remote access, and preparing for recovery before it’s needed. 

None of those practices stand on their own. A well-designed system still depends on people using it thoughtfully. A backup only helps if someone knows it exists and understands how to restore it. A secure remote connection only remains secure if access is reviewed as responsibilities change. An accurate asset inventory only stays accurate if someone updates it when new equipment is installed. Technology creates capability. 

People determine whether that capability is maintained. 

That’s why cybersecurity is ultimately an operational discipline rather than simply a technical one. 

System Integrators Help Shape Security Culture 

One point Fred makes in this CyberBYTES episode is that system integrators influence much more than controllers, programming, and network architecture. Every project is also an opportunity to influence how customers operate their systems after the work is complete. The conversations held during startup, the documentation left behind, the way remote access is configured, and the explanation of why certain procedures matter all contribute to the habits customers develop over time. That’s one reason experienced integrators become trusted partners rather than simply equipment suppliers. They’re not only delivering a building automation system. 

They’re helping customers operate it with confidence. 


Awareness Is a Skill That Grows Over Time 

One of the encouraging things about cybersecurity is that awareness isn’t something people either have or don’t have. 

It’s something organizations develop. 

Teams become more confident as they practice good habits. They learn to recognize unusual activity. They become comfortable asking questions before making changes. They understand why established procedures exist, even when shortcuts appear easier in the moment. Like any other professional skill, awareness grows through repetition, mentoring, and experience. The goal isn’t perfection. 

It’s steady improvement. 

CyberBYTES Quick Check 

How well does your organization support the human side of cybersecurity? 

☐ Do employees understand why cybersecurity procedures exist? 

☐ Are new technicians trained on secure BAS practices? 

☐ Do vendors and contractors follow the same expectations? 

☐ Are unusual requests verified before action is taken? 

☐ Does your organization regularly discuss lessons learned from projects or incidents? 

Strong cybersecurity begins with informed people making consistent decisions every day. 


Watch the CyberBYTES Episode 

In this CyberBYTES episode, Fred Gordy explains why people remain the first line of defense for building automation cybersecurity. Learn how awareness, practical habits, and ongoing guidance help reduce operational risk long before technology ever has to respond. 

The Strongest Systems Depend on the People Behind Them 

Technology will continue to evolve. Buildings will become more connected. New tools will make building automation systems more capable than ever before. What won’t change is the importance of the people responsible for those systems. The strongest organizations don’t rely on technology alone. They invest in awareness. They encourage good habits. They share knowledge, document their work, and help one another make sound decisions. That’s what operational resilience has been about from the beginning of this series. Not simply building secure systems. 

Building organizations that know how to keep them secure. KMC Secure Connected Solutions helps building owners and system integrators strengthen both the technical and human sides of building automation cybersecurity through practical assessments, guidance, and education tailored to operational technology environments. 


Continue the Conversation 

Learn more about KMC SCS™

Explore KMC Dome™ 

The Hidden Cyber Risks of Smart Buildings

The Cybersecurity Gap in Legacy Building Systems

What Is Zero Trust and Why Does Your Building Need It?