
Tim Bauer
FachsprechpartnerSolution Architect for OT and BAS security
Tim Bauer is an independent consultant and Solution Architect for OT and BAS security. His work focuses on the intersection of IT, OT, building automation, and security.
secnostic registered trademark connects building automation, building management systems, and technical building services in a dependable OT view. Facilities, IT, and security teams can see assets, communication paths, remote access, vulnerabilities, and ownership without unnecessarily touching live building functions.
For facilities, building services, IT, security, and property portfolios.
NIST explicitly classifies building automation systems as operational technology. The BSI recommends starting with remote-maintenance access, IT crossings, and the device inventory; its INF.14 implementation guidance adds segmentation, roles, and protected building-automation networks.
Building automation is operational technology: NIST SP 800-82 explicitly includes building automation systems in OT and names HVAC, electrical systems, lighting, and access control among the examples. The BSI INF.14 module places information security across the planning, implementation, and operation of building automation.
The BSI security information recommends identifying remote-maintenance access, IT crossings, and the device estate early. For the communication layer, ISO 16484-5 specifies a data communication protocol for HVAC/R and other building systems. Section 71a of the German Building Energy Act sets requirements for specified non-residential buildings. Applicability must be assessed for each building; secnostic supplies context and evidence but replaces neither the BMS nor a conformity assessment.
Management servers, automation stations, gateways, sensors, and actuators connect HVAC, energy, lighting, access, and other building disciplines. In existing buildings, BACnet, KNX, Modbus, M-Bus, proprietary interfaces, remote maintenance, and cloud connections meet divided responsibilities. Without current shared context, dependencies, changes, and risks across buildings, IT, and suppliers remain hidden.
The technical function is visible, but inventory, access paths, and ownership are often split across several disciplines.
A permanent or forgotten supplier path remains risky when purpose, approval, and ownership are missing.
Retrofits, gateway replacements, and supplier changes cause documentation and the actual estate to diverge.
Long-lived components and older communication need tightly controlled crossings when modern safeguards are unavailable.
A vulnerability becomes actionable only when its building, discipline, dependency, maintenance window, and owner are known.
Each situation starts with an observable signal or an existing source and ends with an accountable person.
The secnostic registered trademark sensor observes approved IP segments passively. BMS exports, network data, and maintenance records add dormant or serial components; active queries run only after technical approval.
secnostic registered trademark inventory connects devices to buildings, disciplines, communication paths, lifecycle, and owners. The secnostic registered trademark platform governs tenants, roles, and access to secnostic registered trademark applications. focusAlert routes suitable operational and security events, but does not replace certified fire, evacuation, or safety alerting.

FachsprechpartnerSolution Architect for OT and BAS security
Tim Bauer is an independent consultant and Solution Architect for OT and BAS security. His work focuses on the intersection of IT, OT, building automation, and security.
The modules play different roles in the deployment: observation, inventory, platform governance, and handover to the right people.
models buildings, disciplines, BMS servers, controllers, gateways, field components, lifecycle, owners, dependencies, and evidence.
observes approved BMS and building IP networks passively and reports new devices or communication changes; controlled enrichment runs only after approval.
governs organizations, tenants, roles, and access to secnostic registered trademark applications, not direct access to field devices.
routes suitable BMS, monitoring, or security events to accountable people and keeps acknowledgment and escalation traceable.
Key questions before a first scoping conversation.
No. The BMS remains responsible for control, regulation, and visualization. secnostic registered trademark adds technical asset, communication, risk, and ownership context.
The starting point is passive-first. Dormant, serial, or unobserved components may require additional exports, documentation, or approved queries. Active discovery is therefore never assumed by default.
The scope can include management and engineering systems, automation stations, controllers, gateways, network components, sensors, actuators, meters, and remote-maintenance paths. Safety systems are included only where real interfaces exist.
No. Visibility and context show where segmentation, access controls, secure protocol variants, or replacement are needed. Technical protection must be implemented in the relevant building automation system.
No. secnostic registered trademark can support evidence for assets, communication, measures, and ownership. Applicability and conformity must be assessed for the specific organization and system.
We start with one building, campus, discipline, or remote-maintenance scope and show which operating and risk data is already usable.
Discuss the BACS scope